Tessera Investor FAQ
What's the moat — what stops a big incumbent (Compliance.ai, Onfido) from copying you?
Three things. First, our regulatory knowledge graph took 18 months to build and continuously updates from 847 regulatory sources — that's not a weekend project. Second, incumbents are locked into rule-based architectures; retrofitting AI onto legacy systems is painful and slow (we've seen Compliance.ai try twice). Third, our customers become the moat: every false positive they flag improves our models. We're 14 months ahead on training data from production environments.
Why now? What's changed?
Three converging shifts. LLMs finally work for regulatory text interpretation (GPT-3 couldn't do this reliably; GPT-4+ can). Regulatory volume increased 34% in 2023 alone — compliance teams are drowning. And the cost of non-compliance just jumped: average fintech enforcement action is now $4.2M, up from $1.8M in 2021. CFOs are finally releasing budget.
What's your current MRR and growth rate?
$127K MRR as of last month. Growing 18% month-over-month for the past four months. We were at $41K MRR six months ago. Pipeline suggests we'll hit $200K MRR by end of Q1, but I'm not modeling that aggressively.
What's your NDR / churn picture so far?
NDR is 138% over the past two quarters — expansion from customers adding modules (AML after KYC, then transaction monitoring). We've lost one customer: a Series A startup that shut down entirely. No competitive losses yet. Honest caveat: our oldest customer is only 11 months old, so retention data is still immature.
What's the CAC payback?
Currently 7 months for SMB (sub-$3K MRR), around 11 months for mid-market. Enterprise is too early to tell — we've closed two, both with 6+ month sales cycles. We're not optimizing CAC yet; we're still learning which channels work. Founder-led sales is artificially deflating the number.
How are you using AI today vs traditional rule-based logic? Where are the limits?
AI handles regulatory interpretation (reading new guidance, mapping to customer obligations), document classification, and anomaly detection in transaction patterns. Rules still govern the actual compliance checks — we're not having AI make compliance decisions, just surface what needs human review. The limit: anything requiring legal judgment. We flag, we don't adjudicate.
What happens when a regulator changes a rule? How fast do you propagate that?
Our ingestion pipeline catches new regulatory publications within 4 hours. Classification and impact analysis takes another 2-6 hours depending on complexity. Customers see affected workflows flagged within 24 hours. For major changes (like the new FinCEN beneficial ownership rules), we do a manual QA pass. We've never missed a deadline for a customer, but we've had two close calls where our automation misclassified the urgency.
Who's your competition we should be watching?
Compliance.ai has brand and budget but moves slowly. Ascent RegTech is closest to our approach — watch them. Unit21 is adjacent (fraud/AML focus) but could expand. The real threat isn't another startup; it's if Stripe or Plaid decides compliance is a must-have feature and builds natively. That's a 2-year window we need to use.
What's the org plan post-raise — how many engineers, sales hires?
We're 9 people today (5 eng, 2 compliance domain experts, 2 founders doing everything else). Post-raise plan: 4 engineers (2 ML, 2 platform), 2 AEs, 1 sales engineer, 1 head of customer success. We're not hiring a VP Sales until we hit $300K MRR — founders are still closing. Total team of 17 by month 12 post-close.
What's your defensible IP?
Two provisional patents: one on our regulatory graph construction methodology, one on our cross-jurisdictional obligation mapping. More valuable than patents: 23 months of production training data across 12 regulatory frameworks, and our compliance team's annotation guidelines (11,000+ labeled regulatory interpretations). That's hard to replicate.
How does pricing scale? When does an enterprise customer become $100K+ ACV?
Base platform is $2K/month. Each module (KYC, AML, transaction monitoring) adds $1-3K. We hit $100K+ ACV when a customer operates in multiple jurisdictions (adds $15K per jurisdiction), needs API volume over 50K calls/month, or requires dedicated support. Our two enterprise customers are at $94K and $156K ACV respectively. Both are multi-jurisdiction fintechs.
What's the biggest risk you see, honestly?
Regulatory liability. If our system misses something and a customer gets fined, even if our contract limits liability, the reputation damage could kill us. We mitigate with human-in-the-loop design and explicit 'we're a tool, not a law firm' positioning, but the risk is real. Second risk: we're dependent on foundation model providers. If OpenAI's API costs triple or they restrict our use case, we have a 90-day scramble. We're building fallback capacity with open-source models, but we're not there yet.