Cleafy
Milan-based real-time banking fraud detection vendor protecting mobile and web banking sessions from malware, overlay attacks, and social-engineering takeovers.
Visit Website ↗ + Add to CompareOverview
Cleafy builds real-time fraud detection technology embedded into banking and financial-services mobile and web applications, designed to spot the malware, overlay attacks, and social-engineering session takeovers that traditional endpoint antivirus typically misses because the attack happens inside a legitimate, authenticated banking session. Founded in Milan in 2014, the company’s engine focuses on detecting hostile infrastructure and attacker intent before a fraudulent transaction completes, rather than only flagging fraud after the fact.
Cleafy has raised a total of about €22 million, including a €12 million Series B led by United Ventures and eCAPITAL, and reports protecting over 250 million end users across more than 150 financial institutions in Europe and Latin America, with named clients including ING, BCC Iccrea Group, Illimity Bank, and Banca Popolare di Sondrio (Suisse) confirmed via independent press coverage of its funding rounds. The company also claims more than 85 international patents on its detection engine, a claim that is vendor-stated and has not been independently audited by this review.
Banking-malware and mobile-fraud detection is a genuinely hard, adversarial problem, since fraud techniques (overlay attacks, on-device remote-access-trojan fraud, social engineering) evolve quickly to evade detection, and Cleafy competes with other European and global fraud-detection vendors in a space where independent, apples-to-apples accuracy benchmarks are rare. Its differentiation is European banking-sector depth and a real customer base at meaningful scale, rather than a uniquely novel detection technique.
Innovation Matrix Assessment
Raised a €12M Series B in early 2026 explicitly earmarked for expanding predictive detection capabilities and threat analysis, following an earlier €10M round in 2023, indicating sustained product investment.
Deployed in production across 150+ financial institutions protecting a reported 250 million end users, a substantial operational footprint for a fraud-detection specialist of its size.
Two funding rounds in three years plus named enterprise banking clients (ING, BCC Iccrea, Illimity Bank) confirmed via independent fintech press coverage indicate real, verifiable commercial momentum.
In-session behavioral and infrastructure-based fraud detection embedded directly in banking apps is a meaningfully different approach than traditional post-transaction fraud scoring, though several other European vendors pursue similar in-app fraud detection models.
Named, independently reported financial-institution customers at meaningful scale (150+ banks, 250M end users) provide real evidence of production efficacy, but the '85+ patents' claim is vendor-stated and no independent third-party detection-accuracy benchmark was found.
Mobile and online banking fraud, particularly malware-driven overlay attacks and social-engineering session takeovers, is a growing, well-documented threat category for financial institutions globally.
Why CISOs Should Care
Gives banks and financial-services security teams a purpose-built layer for detecting in-session fraud and malware inside mobile/web banking apps that traditional endpoint or network security tools are not positioned to see.
What Makes It Different
Focuses specifically on detecting hostile attacker infrastructure and intent before a fraudulent transaction completes, rather than only scoring fraud risk after the fact, with real production scale across 150+ European and Latin American banks.
The Matrix Verdict
58/100 — INCREMENTAL INNOVATOR
A credible, well-funded European banking-fraud specialist with genuine named-customer evidence at real scale; scored solidly but not top-tier given the vendor-sourced patent claims and lack of independent accuracy benchmarking.
Editorial Note: Claims vs. Verified Findings
Funding rounds, investor names, and named clients (ING, BCC Iccrea, Illimity Bank, BPS Suisse) are independently confirmed via multiple fintech press outlets covering the funding announcements. The claims of '250 million end users protected' and '85+ international patents' are company-stated and have not been independently audited by this review.
Sources
Alternatives to Cleafy
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…