Workspace/Coris
← All platforms

Coris

Merchant intelligence and risk operations across processors

Coris combines MerchantProfiler business intelligence, CorShield merchant fraud scoring, configurable risk workflows, and continuous merchant monitoring. The platform adds card and ACH fraud analysis, case management, AI assistance, and agents that act under customer policies. Processor connections support payout restrictions. Managed Risk adds an operated service. Public product evidence is detailed, but the developer portal is password protected; exact API and control contracts need vendor access.

Our assessment

A merchant-focused platform with substantial onboarding intelligence and practical risk operations across connected processors. Product scope is documented; technical execution, licensed coverage, agent authority, and service terms need an account-specific evaluation.

Best fit and limitations

Useful for payment platforms, PayFacs, ISOs, and sponsor banks that need richer merchant evidence and one operating workflow across processors. It joins initial merchant acceptance with website, transaction, and portfolio monitoring. Teams can evaluate the software, individual intelligence products, or Managed Risk separately. Full AML and consumer identity requirements need a separate scope review.

  • The Coris developer portal is password protected. Public research did not verify endpoint schemas, authentication, idempotency, webhook signatures/retries, rate limits, or a numerical decision-latency SLA.
  • The product called Transaction Monitoring documents payment fraud, behavior, velocity, and payout risk. This is not sufficient evidence of an AML scenario library or suspicious-activity reporting.
  • Payout controls depend on processor connections and permissions. Public materials document pause or delay actions but do not establish universal processor parity, settlement release semantics, or reserve management.
  • KYB, bank-account verification, and owner adverse media do not establish document/biometric KYC, complete beneficial-ownership discovery, or PEP screening. Confirm list coverage and data licenses.
  • Credit reports and merchant exposure analysis do not establish a loan-origination decision engine. MATCH is a terminated-merchant database, not a sanctions list.
  • Website monitoring has explicit schedules. Some AI alert handling was described as rolling out; wider content sources were future plans. Confirm which agent skills and checks are enabled now.
  • The bank-verification launch covers US accounts and labels richer risk/age data as future work. Global intelligence counts and an EU MCP endpoint do not establish every feature in every country.

Tools 21

MerchantProfiler business verificationMerchant KYB and onboarding evidence
+
  • Combine business registration, online presence, and application evidence into a merchant profile
  • Use documented US Secretary of State checks and TIN matching alongside broader business intelligence
  • Feed approval or review rules; registry coverage does not establish a complete beneficial-owner verification flow
Source 14
CorShield merchant fraud modelBusiness impersonation and onboarding fraud
+
  • Compare applicant information with known business data to assess merchant fraud
  • Return a fraud score and supporting reasons
  • Use the model in the Coris platform or documented orchestration connections such as Alloy
Source 14
Industry classificationMerchant activity assessment
+
  • Predict MCC and NAICS codes from business evidence using AI
  • Flag activity that conflicts with the application or the platform's restricted-industry policy
Source 1
MerchantVisionImage-based location review
+
  • Analyze Google Street View imagery for a supplied business address
  • Assess business presence, signage, activity, and related visual evidence
  • Support onboarding or periodic site checks; image age and availability still matter
Source 9
SiteRating and website intelligenceWebsite legitimacy assessment
+
  • Inspect domain, content, policy pages, and other website attributes
  • Surface possible copycat sites, placeholders, broken links, and connected scam reports
  • Use the resulting evidence in merchant review rather than treating a website score as a compliance clearance
Source 12
Continuous Website MonitoringRestricted-content and business-change detection
+
  • Screen merchant sites against configured keywords and topics, including authorized member-only content
  • Schedule daily, weekly, or monthly alerts and detect domain or content changes
  • Use the API or no-code portal; the launch article separates delivered checks from future expansion
Source 7
Merchant sanctions screeningBusiness watchlist checks
+
  • Check businesses against sanctions data, with OFAC explicitly named
  • Combine results with merchant eligibility and review policy
  • Confirm list coverage, ownership treatment, matching settings, and update schedules
Source 13
Adverse Media InsightsBusiness and owner reputation research
+
  • Surface reported criminal activity, fraud allegations, and legal disputes involving a business or its owners
  • Combine media evidence with reviews, business listings, and other presence signals
  • Keep allegations, convictions, and open proceedings distinct during review
Source 13
Connected litigation, credit, and MATCH dataAdditional merchant due diligence
+
  • Use the PACER connection for merchant or owner bankruptcy events
  • Pull EU business credit reports through Creditsafe and configure monitoring
  • Screen the Mastercard terminated-merchant database through the documented MATCH integration
Source 5
Bank Account VerificationUS merchant payout-account checks
+
  • Submit an account number, routing number, and account name without a bank-login flow
  • Return name-match and account-status results for supported US accounts
  • Treat bank fraud scores, confidence scores, and account-age metadata as future items in the launch article
Source 8
Device, IP, and contact intelligenceApplication consistency and fraud signals
+
  • Compare device and IP context with the claimed business location
  • Assess email and phone details for disposable, mismatched, or spoof-related signals
  • Use address and phone metadata to support investigation; no public device-SDK contract was verified
Source 1
Merchant MonitoringOngoing portfolio risk
+
  • Track business status, website changes, and reputation shifts after onboarding
  • Combine external changes with merchant transactions and platform data
  • Route changed risk into configured alerts and periodic reviews
Source 1
Card and ACH transaction fraudPayment risk assessment
+
  • Score card and ACH payments using payer behavior, payment history, and merchant context
  • Detect unusual volume, velocity, and payment behavior
  • Route high-risk activity to review or connected controls; this product is not established as an AML scenario engine
Source 3
Risk rules and merchant decision workflowsMerchant acceptance and policy execution
+
  • Combine Coris signals, internal metadata, and connected transaction data in custom rules
  • Run actions from events or schedules, approve eligible merchants, and route exceptions
  • Use account tags and CRM connections to coordinate follow-up
Source 2
Case managementReview operations
+
  • Prioritize, assign, and resolve alerts in a shared work system
  • Keep merchant context and action history with the review
  • Connect support and CRM workflows for merchant outreach
Source 2
Connected payment and payout controlsProcessor-dependent risk actions
+
  • Hold or block risky payments through configured transaction rules
  • Delay or pause payouts when merchant or transaction risk exceeds policy
  • Use supported processor integrations; the public ACH example describes Stripe Connect
Source 3
Exposure, reporting, and sponsor oversightPortfolio and operational control
+
  • Review merchant volume, chargebacks, refunds, and financial exposure
  • Monitor rule outcomes, team work, and risk trends with retained action records
  • Support sponsor oversight and periodic reviews; exposure estimates do not prove reserve-management execution
Source 2
AI assistants and case summariesAnalyst research support
+
  • Generate case summaries and answer questions about merchant or transaction history
  • Help analysts investigate risk and review portfolio patterns
  • Keep assistive use distinct from separately configured agent actions
Source 4
Policy-driven AI agentsConfigured review and action automation
+
  • Clear routine low-risk alerts and escalate exceptions under customer procedures
  • Run onboarding, monitoring, or dispute workflows with permitted next steps
  • Trigger merchant follow-up and connected payout restrictions; verify exact permissions and approval gates
Source 4
Coris MCPConnected AI access to risk operations
+
  • Connect Claude or ChatGPT to merchant profiles, scores, transactions, alerts, notes, and account tags
  • Query portfolio data and perform documented updates such as notes or alert assignment
  • Authenticate through Coris; use the separately published default or EU MCP host
Source 11
Managed RiskOperated merchant risk program
+
  • Have Coris operate merchant underwriting, reviews, escalations, and ongoing monitoring
  • Retain visibility into merchant status and portfolio outcomes across payment processors
  • Move to a self-managed program using the existing rules, workflows, and history when agreed
Source 6

AI capabilities

Merchant models, visual analysis, assistants, and configured agents

CorShield and payment models produce risk assessments. AI also classifies merchant activity, analyzes site imagery and content, and summarizes review evidence. Assistants support an analyst; separately configured agents can resolve routine alerts, request information, and trigger connected payout controls. Coris MCP exposes both read and write workflows to a connected AI client. Public pages describe these actions, but protected technical docs prevent verification of the full permission and execution contract.

Assess business impersonation and payment riskClassify business activity and inspect website or location evidenceSummarize cases, resolve permitted alerts, and escalate exceptions
What to validate

Define each agent's policy, allowed actions, escalation rules, and approval gates. Validate decisions against retained source evidence and test failures before enabling write actions. Confirm MCP scopes, processor permissions, model versions, and logs. Keyword screening is not proof of deterministic entity matching; generated reasoning and customer success figures are not independent accuracy evidence.

Source 4

Implementation

Integration checklist
  • Choose direct APIs, the no-code portal, a named orchestration connection, or Managed Risk. Obtain the protected technical contract for that path before implementation.
  • Map merchant, owner, application, processor-account, payment, and case identifiers. Define which internal metadata augments the risk profile and how updates are reconciled.
  • Set processor and CRM permissions by action. Separate data ingestion from payment blocking, payout delay, case updates, and merchant outreach; validate each operation in the chosen integration.
  • The ACH launch describes Stripe Connect with a restricted API key and charge-triggered webhook ingestion. It does not document a Coris-to-client webhook contract or prove synchronous authorization timing.
  • For website and visual checks, handle missing, stale, inaccessible, or conflicting evidence. Agree authorized access for member-only content and the scan schedule for each merchant class.
  • Review read/write MCP access and approval controls before connecting a production environment. Public host names and login steps do not establish a complete tool schema or permission model.
Commercial scope

Quote required for the selected software, intelligence, integrations, monitoring, agents, and any managed service. Confirm usage units, provider fees, scanning frequency, review users, implementation, support, and minimums. The bank-verification launch describes usage-based terms and no charge for not-found results for risk-platform customers; those terms are scoped to that offer and require current confirmation. No platform-wide unit price or included data contract is assumed.

Questions for the demo
  1. Which MerchantProfiler, CorShield, payment, monitoring, agent, and Managed Risk features are included in our contract?
  2. Which registry, watchlist, bank, credit, litigation, and website sources cover our merchants, and how are missing results handled?
  3. Which actions work on each processor, what permissions do they require, and how do retries, failures, and reversals behave?
  4. What can an agent or MCP client change without approval, and can we inspect its policy version, evidence, action trace, and escalation?
  5. Can we access the API specification, sandbox, event contracts, rate limits, and service targets before committing?
  6. How are monitoring frequency, source freshness, false positives, review workload, and delayed payment losses measured?

Engineering

Your systemInputs & context
CorisChecks & signals
Your controlsDecision & review
Illustrative integration boundary. Confirm the actual interfaces and decision authority.
Inputs
Customer platform metadata used with Coris risk signals · Merchant application and business information, with device, IP, contact, and online-presence context · Business name and postal code for documented merchant intelligence checks · Bank account number, routing number, and account name · ACH charge and payer details, merchant intelligence, and software-platform metadata · Connected merchant and transaction records · Configured data-warehouse and CRM information · Merchant website, custom keywords or topics, and configured monitoring schedule · Authenticated AI-client requests over a Coris environment · Business address used to retrieve street imagery · Customer procedures, risk policies, case context, and permitted action settings
Outputs
Merchant risk decisions and configured review workflows · Merchant fraud scores and explanations · Industry classification, business verification, website, and location signals · US TIN and Secretary of State verification, business sanctions checks, and adverse-media findings · Name-to-account matching result · Account-open and ability-to-receive-funds result · ACH fraud score from 0 to 100 with three leading reasons · Risk alerts, case updates, merchant outreach, and configured processor actions · Website content, domain-change, and restricted-policy alerts · Merchant profiles, fraud scores, transactions, alerts, notes, and account tags · Documented updates such as notes, alert assignment, and case progression · Image-derived business-presence, signage, and activity findings · Case summaries, routine alert decisions, escalations, and merchant follow-up · Connected payout pause or delay when configured · Operated merchant-underwriting reviews, escalations, monitoring, and portfolio visibility
Webhooks
The documented Stripe Connect flow uses ACH-charge webhook notifications to trigger data collection. This does not establish a Coris-to-customer event schema, signature method, retry policy, or ordering guarantee.
Decision timing
The launch article lists daily, weekly, or monthly website alerts. This is a configured scan schedule, not an end-to-end detection latency guarantee.
Deployment
Hosted API · Hosted dashboard
Dependencies
Bank Verification enabled for the customer account · Stripe Connect integration with a restricted API key and suitable permissions · Authorized access arrangements for member-only website screening · Authenticate and grant access through Coris · Published MCP hosts: https://mcp.coris.ai/mcp and https://mcp.eu.coris.ai/mcp · Agreed agent authority and action-specific processor or CRM permissions · Separately agreed managed-service scope and decision authority
Verified details 61
  • Inputs

    Customer platform metadata used with Coris risk signals

    Source Checked 2026-09-18
  • Outputs

    Merchant risk decisions and configured review workflows

    Source Checked 2026-09-18
  • Deployment

    Hosted API

    Source Checked 2026-09-18
  • Deployment

    Hosted dashboard

    Source Checked 2026-09-18
  • Inputs

    Merchant application and business information, with device, IP, contact, and online-presence context

    Source Checked 2026-09-18
  • Outputs

    Merchant fraud scores and explanations

    Source Checked 2026-09-18
  • Outputs

    Industry classification, business verification, website, and location signals

    Source Checked 2026-09-18
  • Inputs

    Business name and postal code for documented merchant intelligence checks

    Source Checked 2026-09-18
  • Outputs

    US TIN and Secretary of State verification, business sanctions checks, and adverse-media findings

    Source Checked 2026-09-18
  • Inputs

    Bank account number, routing number, and account name

    Source Checked 2026-09-18
  • Outputs

    Name-to-account matching result

    Source Checked 2026-09-18
  • Outputs

    Account-open and ability-to-receive-funds result

    Source Checked 2026-09-18
  • Country scope

    United States

    Source Checked 2026-09-18
  • Dependency

    Bank Verification enabled for the customer account

    Source Checked 2026-09-18
  • Inputs

    ACH charge and payer details, merchant intelligence, and software-platform metadata

    Source Checked 2026-09-18
  • Outputs

    ACH fraud score from 0 to 100 with three leading reasons

    Source Checked 2026-09-18
  • Webhooks

    The documented Stripe Connect flow uses ACH-charge webhook notifications to trigger data collection. This does not establish a Coris-to-customer event schema, signature method, retry policy, or ordering guarantee.

    Source Checked 2026-09-18
  • Connected provider

    Stripe Connect

    Source Checked 2026-09-18
  • Dependency

    Stripe Connect integration with a restricted API key and suitable permissions

    Source Checked 2026-09-18
  • Inputs

    Connected merchant and transaction records

    Source Checked 2026-09-18
  • Inputs

    Configured data-warehouse and CRM information

    Source Checked 2026-09-18
  • Outputs

    Risk alerts, case updates, merchant outreach, and configured processor actions

    Source Checked 2026-09-18
  • Connected provider

    Stripe Connect

    Source Checked 2026-09-18
  • Connected provider

    Adyen for Platforms

    Source Checked 2026-09-18
  • Connected provider

    TSYS

    Source Checked 2026-09-18
  • Connected provider

    Fiserv

    Source Checked 2026-09-18
  • Connected provider

    Mastercard MATCH

    Source Checked 2026-09-18
  • Connected provider

    Emailage

    Source Checked 2026-09-18
  • Connected provider

    ScamAdviser

    Source Checked 2026-09-18
  • Connected provider

    PACER

    Source Checked 2026-09-18
  • Connected provider

    Creditsafe

    Source Checked 2026-09-18
  • Connected provider

    Salesforce

    Source Checked 2026-09-18
  • Connected provider

    Zendesk

    Source Checked 2026-09-18
  • Connected provider

    Intercom

    Source Checked 2026-09-18
  • Connected provider

    Slack

    Source Checked 2026-09-18
  • Connected provider

    Alloy

    Source Checked 2026-09-18
  • Connected provider

    Taktile

    Source Checked 2026-09-18
  • Connected provider

    Amazon Redshift

    Source Checked 2026-09-18
  • Connected provider

    Snowflake

    Source Checked 2026-09-18
  • Inputs

    Merchant website, custom keywords or topics, and configured monitoring schedule

    Source Checked 2026-09-18
  • Outputs

    Website content, domain-change, and restricted-policy alerts

    Source Checked 2026-09-18
  • Decision timing

    The launch article lists daily, weekly, or monthly website alerts. This is a configured scan schedule, not an end-to-end detection latency guarantee.

    Source Checked 2026-09-18
  • Deployment

    Hosted API

    Source Checked 2026-09-18
  • Deployment

    Hosted dashboard

    Source Checked 2026-09-18
  • Dependency

    Authorized access arrangements for member-only website screening

    Source Checked 2026-09-18
  • Inputs

    Authenticated AI-client requests over a Coris environment

    Source Checked 2026-09-18
  • Outputs

    Merchant profiles, fraud scores, transactions, alerts, notes, and account tags

    Source Checked 2026-09-18
  • Outputs

    Documented updates such as notes, alert assignment, and case progression

    Source Checked 2026-09-18
  • Connected provider

    Claude

    Source Checked 2026-09-18
  • Connected provider

    ChatGPT

    Source Checked 2026-09-18
  • Dependency

    Authenticate and grant access through Coris

    Source Checked 2026-09-18
  • Dependency

    Published MCP hosts: https://mcp.coris.ai/mcp and https://mcp.eu.coris.ai/mcp

    Source Checked 2026-09-18
  • Inputs

    Business address used to retrieve street imagery

    Source Checked 2026-09-18
  • Outputs

    Image-derived business-presence, signage, and activity findings

    Source Checked 2026-09-18
  • Connected provider

    Google Street View

    Source Checked 2026-09-18
  • Inputs

    Customer procedures, risk policies, case context, and permitted action settings

    Source Checked 2026-09-18
  • Outputs

    Case summaries, routine alert decisions, escalations, and merchant follow-up

    Source Checked 2026-09-18
  • Outputs

    Connected payout pause or delay when configured

    Source Checked 2026-09-18
  • Dependency

    Agreed agent authority and action-specific processor or CRM permissions

    Source Checked 2026-09-18
  • Outputs

    Operated merchant-underwriting reviews, escalations, monitoring, and portfolio visibility

    Source Checked 2026-09-18
  • Dependency

    Separately agreed managed-service scope and decision authority

    Source Checked 2026-09-18
Illustrative contract

An example for your internal adapter. This is not a vendor endpoint, request, or response.

json
{
  "contract": "internal-risk-review/v1",
  "vendorId": "coris",
  "internalCorrelationId": "example-001",
  "vendorRecordId": null,
  "control": "Merchant KYB and onboarding evidence",
  "evidence": [],
  "status": "pending",
  "decision": "review",
  "requiresHumanReview": true
}
Integration limits
  • Illustrative internal integration contract. This is not a vendor request, response, endpoint, or SDK example.
  • Empty country, deployment, or provider lists mean not verified in this review. A documented country refers to the specific product noted in its source, not universal platform coverage.
  • The portal redirected to a password page on September 18, 2026. No restricted content was accessed. Direct API authentication, endpoint schemas, idempotency, event signatures/retries, rate limits, and sandbox contracts remain unverified.
  • Public material confirms API and no-code access but does not publish a complete request/response contract. No self-hosted option or hosting-region commitment was verified.
  • Data completeness varies by source and feature. These descriptions are product inputs and outputs, not verified JSON field names.
  • The article names OFAC and US registration checks. Its general country count does not establish every check in every market. No full watchlist or beneficial-ownership contract was verified.
  • United States country scope applies to this bank-verification feature only. The announcement describes bank fraud scores, confidence scores, and account-age metadata as future additions; these are not treated as delivered fields. Endpoint, provider identity, and exact schema remain unverified.
  • Thresholds can route payments for review or a delayed merchant payout. This charge-triggered example is not evidence that every deployment evaluates synchronously before authorization. Older Fuzio naming in the article is retained only as source context.
  • The page names these integrations but does not establish equal scope, included licensing, or write permissions across them. PACER is litigation/bankruptcy data; Creditsafe is EU business credit data; MATCH is terminated-merchant screening. None is a blanket sanctions or credit-decision entitlement.
  • Some alert-handling agents were described as rolling out; social/content expansion and further geography coverage were roadmap items. The article does not publish login-storage, crawl, or event delivery contracts.
  • Both read and write access are described. Exact OAuth scopes, tool names, approval gates, and rate limits were not published in the article. The EU host is a routing choice, not a verified country-availability or data-residency guarantee. No MCP calls were made.
  • The launch describes GPT-4 with Vision. It does not prove the current model version, imagery freshness, or universal address coverage. Image analysis is not a physical site visit.
  • These are current product claims. They were not tested in a customer environment, and the protected technical contract was not available. Confirm approval, trace retention, failure handling, and reversibility.
  • The page describes a transition to a self-managed program using existing rules, workflows, and history. It does not publish staffing, hours, contractual SLAs, liability allocation, or a complete handover/export contract.

Sources 16

Source review dates are shown above. Product claims come from public sources. Fit, limits, and evaluation questions are our analysis. This is not a hands-on performance test. Methodology · Changelog