Trust, Security & Compliance

Built to pass your TPRM review — and your next exam.

Cotribute is SOC 2 Type 2 certified and FIS GKYC certified, with credit unions and community banks in production nationwide. Everything your risk team needs — reports, architecture, uptime history — is available before a sales call ever happens.

Certifications and partner validations

SOC 2 Type 2

Independently audited controls over security, availability, and confidentiality — not a point-in-time snapshot, but sustained operation over the audit period. Full report available in the due-diligence package.

FIS GKYC Certified

Certified against FIS's Global KYC program requirements for identity verification and compliance workflows.

Core partner certifications

Jack Henry VIP Partner, Corelation Preferred Partner, Banno Certified, and Fiserv AppMarket Partner — each program includes the vendor's own security and integration review of Cotribute.

Continuous transparency

Our Vanta-powered trust center publishes control status continuously, and status.cotribute.com shows real-time and historical uptime. No NDA required to look.

trust.cotribute.com ↗ · status.cotribute.com ↗

How we govern AI

Cotribute's 3 agentic AI Growth Agents have been in production since June 2025 — under governance rules designed for regulated institutions, not consumer apps.

Human-in-the-loop

AI agents recommend and prepare; your staff and your configured rules decide. Approval checkpoints are structural, not optional settings.

No autonomous actions

No agent takes an action outside the decisioning rules your institution configured and approved. There is no self-directed behavior to explain to an examiner.

No member data in public models

Member and customer data is never sent to public AI models and is never used to train shared models. Data boundaries are contractual and technical.

MCP Connect: read-only and audited

MCP Connect v1.0 is read-only. Every query is logged with 7-year retention, and PII is masked by default. Your AI assistants can see governed data — they cannot change anything.

Where we sit in your regulatory picture

Your institution remains the regulated entity for every account and loan. Cotribute's job is to make your obligations easier to meet and easier to evidence:

  • BSA/AML and OFAC — identity verification, watchlist screening, and fraud checks run inside the application flow, with results written to an examiner-ready audit trail. Your BSA officer owns review triggers; SAR/CTR obligations stay with you and we flag thresholds.
  • FinCEN CDD Rule — business account opening captures beneficial ownership and control-person data as part of the flow, not as a paper afterthought.
  • Reg B adverse action — declined loan applications generate compliant adverse action notices with correct reason codes, automatically.
  • NCUA 2026 supervisory priorities — examiners are evaluating AI through existing third-party risk and vendor management frameworks. Our documentation is written to slot into that framework: model governance, audit logs, data boundaries, and human oversight, all in writing. See our NCUA AI Readiness Guide.

The due-diligence package

One request, everything your TPRM review needs — typically the same week you ask.

SOC 2 Type 2 report

The full auditor's report, under NDA through the trust center.

Architecture overview

Data flows, hosting, encryption in transit and at rest, and integration architecture for your core.

Pre-filled vendor questionnaire

Standard due-diligence questionnaire answered in advance, so your team reviews instead of chasing.

Insurance certificates

Current certificates of insurance, including cyber coverage.

Request the due-diligence package

Compliance FAQ

ComplianceWill Cotribute survive our third-party risk management review?

That's what the due-diligence package is for: SOC 2 Type 2 report, architecture overview, a pre-filled vendor questionnaire, and insurance certificates, delivered up front. Credit unions and community banks nationwide have taken Cotribute through TPRM reviews and into production. Request it via the Talk with Us page and it goes to your risk team directly.

ComplianceHow do the AI features hold up in an NCUA or FDIC exam?

Examiners currently evaluate AI through existing frameworks — third-party oversight, BSA/AML, and fair lending — rather than a separate AI rulebook. Cotribute's AI is human-in-the-loop with no autonomous actions, every AI-assisted decision traces to rules your institution configured, and audit logs are exportable in examiner-ready form. We provide the documentation examiners ask vendors for.

ComplianceIs member data used to train AI models?

No. Member and customer data is never sent to public AI models and never used to train shared models. MCP Connect access is read-only, PII-masked by default, and every query is logged with 7-year retention.

ComplianceWho owns adverse action and fair lending obligations?

Your institution does — as with any origination system. Cotribute operationalizes them: declined applications generate Reg B-compliant adverse action notices with reason codes automatically, and decisioning runs on the 70+ configurable rules your credit and compliance teams approve, so decisions are explainable rule by rule.

ComplianceWhere can we see uptime history?

status.cotribute.com shows real-time status and historical uptime publicly. The Vanta trust center at trust.cotribute.com publishes continuous control monitoring. Both are linked from every page of this site and require no NDA to view.

Start the review before the demo

Browse the trust center now, or request the full due-diligence package for your risk team.

Trust Center ↗ Request the DD package