Coris
Merchant intelligence and risk operations across processors
Coris combines MerchantProfiler business intelligence, CorShield merchant fraud scoring, configurable risk workflows, and continuous merchant monitoring. The platform adds card and ACH fraud analysis, case management, AI assistance, and agents that act under customer policies. Processor connections support payout restrictions. Managed Risk adds an operated service. Public product evidence is detailed, but the developer portal is password protected; exact API and control contracts need vendor access.
Our assessment
A merchant-focused platform with substantial onboarding intelligence and practical risk operations across connected processors. Product scope is documented; technical execution, licensed coverage, agent authority, and service terms need an account-specific evaluation.
Best fit and limitations
Useful for payment platforms, PayFacs, ISOs, and sponsor banks that need richer merchant evidence and one operating workflow across processors. It joins initial merchant acceptance with website, transaction, and portfolio monitoring. Teams can evaluate the software, individual intelligence products, or Managed Risk separately. Full AML and consumer identity requirements need a separate scope review.
- The Coris developer portal is password protected. Public research did not verify endpoint schemas, authentication, idempotency, webhook signatures/retries, rate limits, or a numerical decision-latency SLA.
- The product called Transaction Monitoring documents payment fraud, behavior, velocity, and payout risk. This is not sufficient evidence of an AML scenario library or suspicious-activity reporting.
- Payout controls depend on processor connections and permissions. Public materials document pause or delay actions but do not establish universal processor parity, settlement release semantics, or reserve management.
- KYB, bank-account verification, and owner adverse media do not establish document/biometric KYC, complete beneficial-ownership discovery, or PEP screening. Confirm list coverage and data licenses.
- Credit reports and merchant exposure analysis do not establish a loan-origination decision engine. MATCH is a terminated-merchant database, not a sanctions list.
- Website monitoring has explicit schedules. Some AI alert handling was described as rolling out; wider content sources were future plans. Confirm which agent skills and checks are enabled now.
- The bank-verification launch covers US accounts and labels richer risk/age data as future work. Global intelligence counts and an EU MCP endpoint do not establish every feature in every country.
Tools 21
MerchantProfiler business verificationMerchant KYB and onboarding evidence+
- Combine business registration, online presence, and application evidence into a merchant profile
- Use documented US Secretary of State checks and TIN matching alongside broader business intelligence
- Feed approval or review rules; registry coverage does not establish a complete beneficial-owner verification flow
CorShield merchant fraud modelBusiness impersonation and onboarding fraud+
- Compare applicant information with known business data to assess merchant fraud
- Return a fraud score and supporting reasons
- Use the model in the Coris platform or documented orchestration connections such as Alloy
Industry classificationMerchant activity assessment+
- Predict MCC and NAICS codes from business evidence using AI
- Flag activity that conflicts with the application or the platform's restricted-industry policy
MerchantVisionImage-based location review+
- Analyze Google Street View imagery for a supplied business address
- Assess business presence, signage, activity, and related visual evidence
- Support onboarding or periodic site checks; image age and availability still matter
SiteRating and website intelligenceWebsite legitimacy assessment+
- Inspect domain, content, policy pages, and other website attributes
- Surface possible copycat sites, placeholders, broken links, and connected scam reports
- Use the resulting evidence in merchant review rather than treating a website score as a compliance clearance
Continuous Website MonitoringRestricted-content and business-change detection+
- Screen merchant sites against configured keywords and topics, including authorized member-only content
- Schedule daily, weekly, or monthly alerts and detect domain or content changes
- Use the API or no-code portal; the launch article separates delivered checks from future expansion
Merchant sanctions screeningBusiness watchlist checks+
- Check businesses against sanctions data, with OFAC explicitly named
- Combine results with merchant eligibility and review policy
- Confirm list coverage, ownership treatment, matching settings, and update schedules
Adverse Media InsightsBusiness and owner reputation research+
- Surface reported criminal activity, fraud allegations, and legal disputes involving a business or its owners
- Combine media evidence with reviews, business listings, and other presence signals
- Keep allegations, convictions, and open proceedings distinct during review
Connected litigation, credit, and MATCH dataAdditional merchant due diligence+
- Use the PACER connection for merchant or owner bankruptcy events
- Pull EU business credit reports through Creditsafe and configure monitoring
- Screen the Mastercard terminated-merchant database through the documented MATCH integration
Bank Account VerificationUS merchant payout-account checks+
- Submit an account number, routing number, and account name without a bank-login flow
- Return name-match and account-status results for supported US accounts
- Treat bank fraud scores, confidence scores, and account-age metadata as future items in the launch article
Device, IP, and contact intelligenceApplication consistency and fraud signals+
- Compare device and IP context with the claimed business location
- Assess email and phone details for disposable, mismatched, or spoof-related signals
- Use address and phone metadata to support investigation; no public device-SDK contract was verified
Merchant MonitoringOngoing portfolio risk+
- Track business status, website changes, and reputation shifts after onboarding
- Combine external changes with merchant transactions and platform data
- Route changed risk into configured alerts and periodic reviews
Card and ACH transaction fraudPayment risk assessment+
- Score card and ACH payments using payer behavior, payment history, and merchant context
- Detect unusual volume, velocity, and payment behavior
- Route high-risk activity to review or connected controls; this product is not established as an AML scenario engine
Risk rules and merchant decision workflowsMerchant acceptance and policy execution+
- Combine Coris signals, internal metadata, and connected transaction data in custom rules
- Run actions from events or schedules, approve eligible merchants, and route exceptions
- Use account tags and CRM connections to coordinate follow-up
Case managementReview operations+
- Prioritize, assign, and resolve alerts in a shared work system
- Keep merchant context and action history with the review
- Connect support and CRM workflows for merchant outreach
Connected payment and payout controlsProcessor-dependent risk actions+
- Hold or block risky payments through configured transaction rules
- Delay or pause payouts when merchant or transaction risk exceeds policy
- Use supported processor integrations; the public ACH example describes Stripe Connect
Exposure, reporting, and sponsor oversightPortfolio and operational control+
- Review merchant volume, chargebacks, refunds, and financial exposure
- Monitor rule outcomes, team work, and risk trends with retained action records
- Support sponsor oversight and periodic reviews; exposure estimates do not prove reserve-management execution
AI assistants and case summariesAnalyst research support+
- Generate case summaries and answer questions about merchant or transaction history
- Help analysts investigate risk and review portfolio patterns
- Keep assistive use distinct from separately configured agent actions
Policy-driven AI agentsConfigured review and action automation+
- Clear routine low-risk alerts and escalate exceptions under customer procedures
- Run onboarding, monitoring, or dispute workflows with permitted next steps
- Trigger merchant follow-up and connected payout restrictions; verify exact permissions and approval gates
Coris MCPConnected AI access to risk operations+
- Connect Claude or ChatGPT to merchant profiles, scores, transactions, alerts, notes, and account tags
- Query portfolio data and perform documented updates such as notes or alert assignment
- Authenticate through Coris; use the separately published default or EU MCP host
Managed RiskOperated merchant risk program+
- Have Coris operate merchant underwriting, reviews, escalations, and ongoing monitoring
- Retain visibility into merchant status and portfolio outcomes across payment processors
- Move to a self-managed program using the existing rules, workflows, and history when agreed
AI capabilities
Merchant models, visual analysis, assistants, and configured agents
CorShield and payment models produce risk assessments. AI also classifies merchant activity, analyzes site imagery and content, and summarizes review evidence. Assistants support an analyst; separately configured agents can resolve routine alerts, request information, and trigger connected payout controls. Coris MCP exposes both read and write workflows to a connected AI client. Public pages describe these actions, but protected technical docs prevent verification of the full permission and execution contract.
What to validate
Define each agent's policy, allowed actions, escalation rules, and approval gates. Validate decisions against retained source evidence and test failures before enabling write actions. Confirm MCP scopes, processor permissions, model versions, and logs. Keyword screening is not proof of deterministic entity matching; generated reasoning and customer success figures are not independent accuracy evidence.
Implementation
Integration checklist
- Choose direct APIs, the no-code portal, a named orchestration connection, or Managed Risk. Obtain the protected technical contract for that path before implementation.
- Map merchant, owner, application, processor-account, payment, and case identifiers. Define which internal metadata augments the risk profile and how updates are reconciled.
- Set processor and CRM permissions by action. Separate data ingestion from payment blocking, payout delay, case updates, and merchant outreach; validate each operation in the chosen integration.
- The ACH launch describes Stripe Connect with a restricted API key and charge-triggered webhook ingestion. It does not document a Coris-to-client webhook contract or prove synchronous authorization timing.
- For website and visual checks, handle missing, stale, inaccessible, or conflicting evidence. Agree authorized access for member-only content and the scan schedule for each merchant class.
- Review read/write MCP access and approval controls before connecting a production environment. Public host names and login steps do not establish a complete tool schema or permission model.
Commercial scope
Quote required for the selected software, intelligence, integrations, monitoring, agents, and any managed service. Confirm usage units, provider fees, scanning frequency, review users, implementation, support, and minimums. The bank-verification launch describes usage-based terms and no charge for not-found results for risk-platform customers; those terms are scoped to that offer and require current confirmation. No platform-wide unit price or included data contract is assumed.
Questions for the demo
- Which MerchantProfiler, CorShield, payment, monitoring, agent, and Managed Risk features are included in our contract?
- Which registry, watchlist, bank, credit, litigation, and website sources cover our merchants, and how are missing results handled?
- Which actions work on each processor, what permissions do they require, and how do retries, failures, and reversals behave?
- What can an agent or MCP client change without approval, and can we inspect its policy version, evidence, action trace, and escalation?
- Can we access the API specification, sandbox, event contracts, rate limits, and service targets before committing?
- How are monitoring frequency, source freshness, false positives, review workload, and delayed payment losses measured?
Engineering
- Inputs
- Customer platform metadata used with Coris risk signals · Merchant application and business information, with device, IP, contact, and online-presence context · Business name and postal code for documented merchant intelligence checks · Bank account number, routing number, and account name · ACH charge and payer details, merchant intelligence, and software-platform metadata · Connected merchant and transaction records · Configured data-warehouse and CRM information · Merchant website, custom keywords or topics, and configured monitoring schedule · Authenticated AI-client requests over a Coris environment · Business address used to retrieve street imagery · Customer procedures, risk policies, case context, and permitted action settings
- Outputs
- Merchant risk decisions and configured review workflows · Merchant fraud scores and explanations · Industry classification, business verification, website, and location signals · US TIN and Secretary of State verification, business sanctions checks, and adverse-media findings · Name-to-account matching result · Account-open and ability-to-receive-funds result · ACH fraud score from 0 to 100 with three leading reasons · Risk alerts, case updates, merchant outreach, and configured processor actions · Website content, domain-change, and restricted-policy alerts · Merchant profiles, fraud scores, transactions, alerts, notes, and account tags · Documented updates such as notes, alert assignment, and case progression · Image-derived business-presence, signage, and activity findings · Case summaries, routine alert decisions, escalations, and merchant follow-up · Connected payout pause or delay when configured · Operated merchant-underwriting reviews, escalations, monitoring, and portfolio visibility
- Webhooks
- The documented Stripe Connect flow uses ACH-charge webhook notifications to trigger data collection. This does not establish a Coris-to-customer event schema, signature method, retry policy, or ordering guarantee.
- Decision timing
- The launch article lists daily, weekly, or monthly website alerts. This is a configured scan schedule, not an end-to-end detection latency guarantee.
- Deployment
- Hosted API · Hosted dashboard
- Dependencies
- Bank Verification enabled for the customer account · Stripe Connect integration with a restricted API key and suitable permissions · Authorized access arrangements for member-only website screening · Authenticate and grant access through Coris · Published MCP hosts: https://mcp.coris.ai/mcp and https://mcp.eu.coris.ai/mcp · Agreed agent authority and action-specific processor or CRM permissions · Separately agreed managed-service scope and decision authority
Verified details 61
- Inputs
Customer platform metadata used with Coris risk signals
Source Checked 2026-09-18 - Outputs
Merchant risk decisions and configured review workflows
Source Checked 2026-09-18 - Deployment
Hosted API
Source Checked 2026-09-18 - Deployment
Hosted dashboard
Source Checked 2026-09-18 - Inputs
Merchant application and business information, with device, IP, contact, and online-presence context
Source Checked 2026-09-18 - Outputs
Merchant fraud scores and explanations
Source Checked 2026-09-18 - Outputs
Industry classification, business verification, website, and location signals
Source Checked 2026-09-18 - Inputs
Business name and postal code for documented merchant intelligence checks
Source Checked 2026-09-18 - Outputs
US TIN and Secretary of State verification, business sanctions checks, and adverse-media findings
Source Checked 2026-09-18 - Inputs
Bank account number, routing number, and account name
Source Checked 2026-09-18 - Outputs
Name-to-account matching result
Source Checked 2026-09-18 - Outputs
Account-open and ability-to-receive-funds result
Source Checked 2026-09-18 - Country scope
United States
Source Checked 2026-09-18 - Dependency
Bank Verification enabled for the customer account
Source Checked 2026-09-18 - Inputs
ACH charge and payer details, merchant intelligence, and software-platform metadata
Source Checked 2026-09-18 - Outputs
ACH fraud score from 0 to 100 with three leading reasons
Source Checked 2026-09-18 - Webhooks
The documented Stripe Connect flow uses ACH-charge webhook notifications to trigger data collection. This does not establish a Coris-to-customer event schema, signature method, retry policy, or ordering guarantee.
Source Checked 2026-09-18 - Connected provider
Stripe Connect
Source Checked 2026-09-18 - Dependency
Stripe Connect integration with a restricted API key and suitable permissions
Source Checked 2026-09-18 - Inputs
Connected merchant and transaction records
Source Checked 2026-09-18 - Inputs
Configured data-warehouse and CRM information
Source Checked 2026-09-18 - Outputs
Risk alerts, case updates, merchant outreach, and configured processor actions
Source Checked 2026-09-18 - Connected provider
Stripe Connect
Source Checked 2026-09-18 - Connected provider
Adyen for Platforms
Source Checked 2026-09-18 - Connected provider
TSYS
Source Checked 2026-09-18 - Connected provider
Fiserv
Source Checked 2026-09-18 - Connected provider
Mastercard MATCH
Source Checked 2026-09-18 - Connected provider
Emailage
Source Checked 2026-09-18 - Connected provider
ScamAdviser
Source Checked 2026-09-18 - Connected provider
PACER
Source Checked 2026-09-18 - Connected provider
Creditsafe
Source Checked 2026-09-18 - Connected provider
Salesforce
Source Checked 2026-09-18 - Connected provider
Zendesk
Source Checked 2026-09-18 - Connected provider
Intercom
Source Checked 2026-09-18 - Connected provider
Slack
Source Checked 2026-09-18 - Connected provider
Alloy
Source Checked 2026-09-18 - Connected provider
Taktile
Source Checked 2026-09-18 - Connected provider
Amazon Redshift
Source Checked 2026-09-18 - Connected provider
Snowflake
Source Checked 2026-09-18 - Inputs
Merchant website, custom keywords or topics, and configured monitoring schedule
Source Checked 2026-09-18 - Outputs
Website content, domain-change, and restricted-policy alerts
Source Checked 2026-09-18 - Decision timing
The launch article lists daily, weekly, or monthly website alerts. This is a configured scan schedule, not an end-to-end detection latency guarantee.
Source Checked 2026-09-18 - Deployment
Hosted API
Source Checked 2026-09-18 - Deployment
Hosted dashboard
Source Checked 2026-09-18 - Dependency
Authorized access arrangements for member-only website screening
Source Checked 2026-09-18 - Inputs
Authenticated AI-client requests over a Coris environment
Source Checked 2026-09-18 - Outputs
Merchant profiles, fraud scores, transactions, alerts, notes, and account tags
Source Checked 2026-09-18 - Outputs
Documented updates such as notes, alert assignment, and case progression
Source Checked 2026-09-18 - Connected provider
Claude
Source Checked 2026-09-18 - Connected provider
ChatGPT
Source Checked 2026-09-18 - Dependency
Authenticate and grant access through Coris
Source Checked 2026-09-18 - Dependency
Published MCP hosts: https://mcp.coris.ai/mcp and https://mcp.eu.coris.ai/mcp
Source Checked 2026-09-18 - Inputs
Business address used to retrieve street imagery
Source Checked 2026-09-18 - Outputs
Image-derived business-presence, signage, and activity findings
Source Checked 2026-09-18 - Connected provider
Google Street View
Source Checked 2026-09-18 - Inputs
Customer procedures, risk policies, case context, and permitted action settings
Source Checked 2026-09-18 - Outputs
Case summaries, routine alert decisions, escalations, and merchant follow-up
Source Checked 2026-09-18 - Outputs
Connected payout pause or delay when configured
Source Checked 2026-09-18 - Dependency
Agreed agent authority and action-specific processor or CRM permissions
Source Checked 2026-09-18 - Outputs
Operated merchant-underwriting reviews, escalations, monitoring, and portfolio visibility
Source Checked 2026-09-18 - Dependency
Separately agreed managed-service scope and decision authority
Source Checked 2026-09-18
Illustrative contract
An example for your internal adapter. This is not a vendor endpoint, request, or response.
{
"contract": "internal-risk-review/v1",
"vendorId": "coris",
"internalCorrelationId": "example-001",
"vendorRecordId": null,
"control": "Merchant KYB and onboarding evidence",
"evidence": [],
"status": "pending",
"decision": "review",
"requiresHumanReview": true
}Integration limits
- Illustrative internal integration contract. This is not a vendor request, response, endpoint, or SDK example.
- Empty country, deployment, or provider lists mean not verified in this review. A documented country refers to the specific product noted in its source, not universal platform coverage.
- The portal redirected to a password page on September 18, 2026. No restricted content was accessed. Direct API authentication, endpoint schemas, idempotency, event signatures/retries, rate limits, and sandbox contracts remain unverified.
- Public material confirms API and no-code access but does not publish a complete request/response contract. No self-hosted option or hosting-region commitment was verified.
- Data completeness varies by source and feature. These descriptions are product inputs and outputs, not verified JSON field names.
- The article names OFAC and US registration checks. Its general country count does not establish every check in every market. No full watchlist or beneficial-ownership contract was verified.
- United States country scope applies to this bank-verification feature only. The announcement describes bank fraud scores, confidence scores, and account-age metadata as future additions; these are not treated as delivered fields. Endpoint, provider identity, and exact schema remain unverified.
- Thresholds can route payments for review or a delayed merchant payout. This charge-triggered example is not evidence that every deployment evaluates synchronously before authorization. Older Fuzio naming in the article is retained only as source context.
- The page names these integrations but does not establish equal scope, included licensing, or write permissions across them. PACER is litigation/bankruptcy data; Creditsafe is EU business credit data; MATCH is terminated-merchant screening. None is a blanket sanctions or credit-decision entitlement.
- Some alert-handling agents were described as rolling out; social/content expansion and further geography coverage were roadmap items. The article does not publish login-storage, crawl, or event delivery contracts.
- Both read and write access are described. Exact OAuth scopes, tool names, approval gates, and rate limits were not published in the article. The EU host is a routing choice, not a verified country-availability or data-residency guarantee. No MCP calls were made.
- The launch describes GPT-4 with Vision. It does not prove the current model version, imagery freshness, or universal address coverage. Image analysis is not a physical site visit.
- These are current product claims. They were not tested in a customer environment, and the protected technical contract was not available. Confirm approval, trace retention, failure handling, and reversibility.
- The page describes a transition to a self-managed program using existing rules, workflows, and history. It does not publish staffing, hours, contractual SLAs, liability allocation, or a complete handover/export contract.
Sources 16
Source review dates are shown above. Product claims come from public sources. Fit, limits, and evaluation questions are our analysis. This is not a hands-on performance test. Methodology · Changelog
