Introducing Complead. One AI-native platform for financial crime compliance. Read the story
New Ready Integrations available Check the new integrations

We started with one list. We continue with the whole risk picture.

Complead is the financial crime platform built by the team behind Sanction Scanner. Six years, one engine, and a single question we keep answering for compliance teams: is this customer, this company, this transaction what it claims to be.

Discover Our Journey

Two sentences we are willing to be measured against. Everything else on this page is evidence for or against them.

Vision

We are redefining compliance and risk in the financial system not as a separate department or barrier, but as a layer embedded in the core of the system. We are building a financial infrastructure where controls are implemented at the payment, record, and ledger level the moment risk arises; where every professional responsible for a decision can find an immediate and transparent answer to the "why" question.

Mission

To level the playing field in financial crime prevention by delivering enterprise-grade infrastructure to payment companies and tier-one banks alike. We eliminate consulting bottlenecks and put full control of data, speed, and explainability directly into the hands of the people who own the risk.

Our story starts in a gap

In 2020, a financial institution in Istanbul faced only two options:

First, traditional corporate platforms designed and priced exclusively for large banks: six-figure base prices, implementation times of up to nine months, and professional service bills for every minor rule change...

Second, inadequate solutions that fell below these scales. A growing fintech company, a mid-sized bank, or a payment institution in its second year could neither afford the budget of the first option nor take on the risks of the second.

That's why we started developing for those in between.

The real surprise came later: it turned out that top-tier banks wanted exactly the same thing; a flexible system that could be configured within a week and directly by the risk-takers themselves, instead of months-long consulting projects.

Six years on, the sentence we started with has not moved: compliance software should be judged by what it covers, how fast it answers and whether it can explain itself.

Fatih Coskun

Our founding

I started this in Istanbul in 2020, after watching the same conversation happen in a dozen compliance meetings: The platform that could actually do the job cost more than the risk it was managing. The one that fit the budget could not do the job.

We did not begin with a product. We began with the part everyone skips because it is slow and does not demo well: the data. 3,000 sources, 1,500 lists, 220 countries, and the hardest of them, politically exposed persons, assembled jurisdiction by jurisdiction out of official gazettes and parliamentary records, because no global registry of them exists.

February 2022 was the first public test. Thousands of new entries, amendments by the hour, and not one customer disrupted. That week decided what kind of company this would be.

Six years later, the platform screens, monitors, investigates, and files for more than 800 institutions in over 80 countries. The name changed this year because the work outgrew it. The standard underneath it did not.

Fatih Coskun Founder and Chief Executive Officer Read the founder's note

Three layers, in this order

The order matters more than the layers. Intelligence built on weak data produces confident errors, and in compliance a confident error is a penalty. So the data came first, for longer than was comfortable.

Layer 01

The data layer

Over 3,000 sources and 1,500 lists from 220+ countries, consolidated into one real-time structure rather than a folder of feeds.

PEP data was the hard part. There is no central global registry of politically exposed persons, so we built it jurisdiction by jurisdiction: official gazettes, parliamentary records, government announcements, read in the local language.

Layer 02

The product layer

Screening came first. Adverse media, transaction monitoring, fraud detection, KYB and case management followed.

Each one shipped into the same system instead of beside it. That is the difference between a suite and a platform: one customer record, one risk score, one audit trail, no reconciliation between modules that were supposed to agree.

Layer 03

The access layer

Sub-200 millisecond responses, 99.95%+ uptime, same-day integration, no consulting fee to get started.

Compliance software is bought by a risk owner and lived with by an engineer. If the engineer cannot get it into production in the week it was signed, the risk owner bought a project, not a product.

Born global, scaled to worldwide

We never had a domestic market to grow out of. The first customer outside Turkiye arrived before the business was old enough to have a home market, so the product was jurisdiction-agnostic from the first release: local name structures, local PEP definitions, local reporting formats, local list behavior. Compliance is not one problem. It is roughly two hundred of them, and the boundary between them is a border.

80+countries live 220+countries covered 3offices

Why Complead, and why now

Sanction Scanner was an honest name for what we did in 2020. It stopped being an honest name for what we do now. Today the platform builds a complete customer risk profile, watches transactions as they move, catches fraud, maps ownership down to the natural person, and assembles the case file an examiner will actually read. Sanctions screening is one chapter of that, and it is no longer the longest one. One made-up word, three real ones. Each of them is a claim, and each of them is checkable.

Compliance

The work itself, called by its own name. It does not get a softer word, because the softer words are what got this category the reputation it has.

Complete

One architecture instead of six products that meet at a CSV export. The blind spots in compliance live in the gaps between systems, not inside them.

Lead

Risk is addressed before the event, rather than being restructured after. Leadership, both in approach and processes, produces results, and that's what we do.

Complead today

None of these arrived in a launch. The data coverage was assembled country by country, the customer count one compliance team at a time, and the response time by rewriting the screening path three times. We publish them because they are the only honest way to describe a compliance vendor: what does it cover, how fast does it answer, and who trusts it with production traffic.

800+ Financial institutions
80+ Countries with live customers
220+ Countries of data coverage
99.999% Platform uptime
3,000+ Sanction, PEP and media sources
1,500+ Ready Fraud & Monitoring Rules
<70 ms API response
15 min List refresh interval

Six years, in the order it happened

No round number in this list is an announcement. Each year is the year something started working in production. Pick one.

Founded in Istanbul

First sanctions screening customers go live. The data layer starts as a list problem and quickly becomes a jurisdiction problem.

Our values

Not values in the poster sense. These are the arguments we have with customers, regulators and each other, written down so they can be held against us. The first two are the ones the other six answer to.

The customer owns the configuration

Thresholds, procedures and risk appetite belong to the institution that answers for them. Complead is configured by the compliance team that owns the risk, in minutes, not through a six-month professional services engagement. When our default disagrees with your policy, your policy wins.

We are judged on your examination, not our demo

The review that matters happens months after the contract, when a regulator opens a file we helped close. Everything we build is shaped by that room rather than by the one where the software gets bought.

Data before intelligence

Intelligence built on weak data produces confident errors, and in compliance a confident error is a fine, a remediation program and a year of supervisory attention. We spent the first two years underneath the product because nothing above the data layer survives without it.

Explainable, or it does not ship

Every output carries its evidence, its reasoning and its work log, written in the form an examiner expects. Unexplainable output is not a feature with a caveat, it is a liability with a demo.

Humans own the decision

AI changes the analyst's job, it does not remove it. The expertise moves up a level: from clearing alerts to governing the system that clears them. That is a harder job than the one it replaces, and a better one.

The right alerts, not fewer alerts

Any system can produce fewer alerts. The goal is to find the risk that is actually there without missing the risk that is also there, and we report both sides of that number.

Two hundred problems, not one

Different PEP definitions, different name structures, different reporting formats, different thresholds for the same behavior. A platform that treats compliance as one problem is a platform that works in one country.

Earned, not announced

Everything we ship is funded by the customers running it in production. It is a slower way to build a company and a much harder one to argue with, because the feature either earned its place or it never got built.

Scroll sideways, or let it run

Three offices, all of them on the water

New York on the Hudson, London on the Thames, Istanbul on the Bosphorus. Not a coincidence: money moves where trade moves, and trade has always followed water. It also means the commute is a boat more often than you would expect. The lists do not observe office hours either. Sanctions programs land on Friday evenings and regulators publish on public holidays, so the three offices exist to keep the data layer from being asleep for long.

New York, on the Hudson

New York, on the Hudson

Open, and our foothold in the United States. Incorporated as a full entity rather than a sales office, because OFAC and FinCEN work belongs closest to the institutions that answer for it.

London, on the Thames

London, on the Thames

Our UK entity, a short walk from the river. Customer, partner and contract work for the UK and Europe runs through it, in the city that writes half the rules we build against.

Istanbul, on the Bosphorus

Istanbul, on the Bosphorus

Where most of the team sits, in Uskudar. Engineering, data operations, compliance research and support within earshot of each other, and the place the data layer is maintained hour by hour.

Checked by people who are paid to be skeptical

Recognition is pleasant. Certification is the part customers actually diligence, so both are listed with their status rather than their logo.

Deloitte Technology Fast 50 three consecutive years
INC-100 two consecutive years
Deloitte Technology Fast 500 EMEA two consecutive years
Fast Company Best Startups listed
FinCrimeTech50 listed
Regtech 100 listed
TOBB 100 Fast Growing Companies listed

Ask us the hard question

The one your last vendor answered with a roadmap slide. Bring your own data, your own thresholds and your own false positive rate, and we will run it.

We hire people who want the whole problem

Not a ticket from it. Engineering, data operations, compliance research and sales, in three cities.

See open roles