Cauce installs inside the financial institution's infrastructure and verifies compliance on every credit decision before it is executed. It does not route applications, does not score the applicant and does not take the decision. Your customers' data never leaves your infrastructure.
Cauce is not the pipeline: it is one stage of it. The others belong to the institution.
The institution obtains the applicant's data with the applicant's consent. Cauce takes no part and obtains no consent.
The institution's own scoring engine. Cauce does not score the applicant and does not replace that engine.
This is where Cauce operates. It checks the decision already reached against rules configured by the institution: due diligence, sanctions and PEP lists, limits and policy, consent. It requires human confirmation where the law demands it, generates the explanation of the decision, and keeps the audit trail.
The institution executes its decision. Cauce takes no part.
Cauce does not compete with the institution's decision engine: it verifies its decisions and keeps the evidence.
Loop: execute → evaluate → modify → verify → retain, always in a sandbox and validated by CASE before production. It never changes live on its own — rollback and human oversight.
Every decision comes with a readable explanation traceable to the source data. Ready for XAI audits.
Configurable rules per jurisdiction: Ecuador, Mexico, Brazil, Colombia, Chile, Peru, Argentina.
Versioned REST/JSON, signed webhooks and a synthetic-data sandbox to integrate in days, not months.
Banks, credit unions and cooperatives, finance companies and supervised credit fintechs. Licensing is to the financial institution, never to the public: the only contractual customer is the supervised institution.
CACE-Bench is an open synthetic benchmark (MIT) for evaluating credit AI. Its reference run regenerates byte for byte from a single command: compliance false positives from 22.51% to 4.96% (−77.9%) over 23,000 synthetic cases, seed 0, with 95% Wilson intervals. In that same run, 15.57% of cases come out undecidable: the provider chain is not enough to conclude. Figures from a synthetic benchmark, illustrative of the method and not of production performance. Validation on production data has not been done.
The CASE compliance engine audits every AI decision and maps its metrics to the region's regulatory frameworks. Its methodology and a reproducible synthetic benchmark are open — CACE-Bench: measure us against our own standard. Encrypted data, consent and data-subject rights.
On-premise or in the institution's own private cloud. No transfer of information outside the institution's infrastructure or outside the customer's jurisdiction. The regulatory obligation rests with the institution; Cauce produces the evidence with which it is demonstrated. Cauce is today a research project at a stage prior to incorporating a legal entity: we do not claim organizational certifications we do not yet hold.
Encryption in transit and at rest. Data minimization: the demo persists no personal data and the benchmark runs on synthetic data. Per-tenant isolation. We do not resell or monetize data. Per-country residency as a design option.
Cauce acts as a processor by design: the controller is the obligated party. Non-delegation clause — scoring, the decision and the report to the FIU stay with the client. We deliver signals and attributions, not a solvency assessment.
On the roadmap, to begin once the entity is incorporated: SOC 2 Type II, ISO/IEC 27001, 27017 and 27018, ISO/IEC 42001; subprocessor registry, incident SLA and DPA templates. Current status: not audited — we will publish each milestone with its date.
Cauce is a project of Digital Economy Lab focused on regulatory verification prior to the credit decision in Latin America. It is at a stage prior to incorporating a legal entity: we say so plainly, because in RegTech traceability starts with transparency about who is behind it.
The open CACE-Bench benchmark and the reference agent are authored by Ravil Akhtyamov — Head of research project, Digital Economy Lab.
Cauce and Digital Economy Lab are affiliated. To avoid conflict of interest, the lab does not audit Cauce deployments, and this affiliation is disclosed in the benchmark methodology. CACE-Bench evaluates third-party models and agents by the same standard.
[email protected] · Open CACE-Bench repository: github.com/rav11l/cace-bench
Request a demo or early access to the pilot. We reply within 48 hours. The pilot is free; we define the scope and success metrics together.
| Country | Regulator · FIU | Verifies before the decision |
|---|---|---|
| Peru | SBS / UIF-Perú | Due diligence and enhanced regime, sanctions and PEP lists (Res. SBS 2660-2015); human oversight and documentation of the logic and of the data sources in high-risk systems (Ley 31814 and DS 115-2025-PCM; deadline for the financial sector: 10.09.2026). |
| Chile | CMF / UAF | Due diligence, sanctions and PEP lists (Ley 19.913); right to object to decisions based solely on automated processing and, where the exceptions apply, guarantees of human intervention, expression of the data subject's point of view and review (Ley 21.719, art. 8° bis; full effect expected 01.12.2026). |
| Brazil | BACEN / COAF | Independent model validation, backtesting and documentation of stress testing (Res. CMN 4.557/2017, arts. 9 and 12); right to request review of automated decisions (LGPD art. 20). |
| Mexico | CNBV / UIF | KYC and a 10-year file; risk-based customer classification with semi-annual reassessment and automated monitoring and alerting mechanisms (Reglas de la LFPIORPI, as amended by Acuerdo 115/2026, DOF 07.08.2026; staged entry into force 30.11.2026 · 01.03.2027 · 01.06.2027). |
| Colombia | SFC · SES / UIAF | Risk-based due diligence and reporting through the UIAF system (SARLAFT 4.0 — Circular Externa 027/2020); open finance system under implementation (Decreto 0368/2026). |
| Ecuador | SEPS · SB / UAFE | Due diligence, sanctions and PEP lists, consent and limits; right not to be subject to decisions based wholly or partly on automated assessment (LOPDP art. 20); a specific rule on AI and personal data requiring a prior impact assessment and an audit of the system (Resolución SPDP-SPD-2026-0009-R, RO 19.02.2026). |
| Argentina | BCRA / UIF | Risk-based due diligence (Res. UIF 14/2023), sanctions and PEP lists; model inventory, explainability, independent validation and assessment of external AI providers (BCRA supervisory guidance on AI, June 2026 — supervisory expectations, not binding rules). |
This is not legal advice and not a certification of compliance: the regulatory obligation rests with the institution, and compliance must be assessed with local counsel.
python examples/benchmark_your_pipeline.py --demo --n 3000
python examples/benchmark_your_pipeline.py --endpoint https://tu.api/verify
See the adapter (Case → Narrative) →