Vestigo
Agentic banking
Our vision for agentic banking — and what we offer
Ready today
Informational and advisory agents, structured service operations, analytics. The agent is a client of services you already run.
Ready, with security designed in
Agents executing operations on a customer's own products. Entirely feasible to run safely, once the security model is deliberately worked through.
Emerging
Agentic payments. The direction is clear, broad adoption will take time. We build toward it so you do not start from zero.
Human in the loop, by design
Our agents can analyze, prepare and recommend, but critical actions such as payments, card operations and account changes are executed only after explicit approval from an authorized person at your bank. Decision-making stays with you, while every step remains transparent, auditable and compliant.
Governance
Every action is a structured operational record, with a full audit trail. Agents act freely on safe operations, and a human approves anything that changes data. Inside your app, on your APIs, under the same rules as every other channel.
Customers increasingly expect to reach any service simply by asking for it, and banking will not be the exception. But banks will not open customer data to the public internet — so the agent belongs inside the bank’s own application, on the bank’s own APIs.
Conversational AI is no longer the territory of early adopters. People who have never touched an API now use it daily for ordinary tasks, and generative AI — through chat and through agents — is becoming one of the dominant ways people interact with computers. The expectation follows them into every service they use, including their bank.
That expectation has to be met somewhere, and there is only one place it can land — inside the bank’s own application, where the bank keeps control of what the agent can see and do.
The agent has to be aware of two worlds at once
The bank's world
Products, rules, regulation, limits, customer guidance — everything the bank already knows and enforces.
The customer's world
Their accounts, cards, transactions and entitlements, reached through the bank's own APIs, under the bank's own permissions.
MCP tools on our production APIs
We expose our issuing CMS and payments APIs as Model Context Protocol tools, built directly on the production platform. Any MCP-capable client can call them, so your teams build their own agents and experiences while the platform keeps enforcing the same business rules, validations and entitlements it enforces for every other channel.
Agents that collaborate over A2A
On top of those tools we provide agents for all core functionalities — issuing, disputes, BNPL, payments, and so on. Each agent encapsulates one business domain, with its own model and its own set of tools, and each is exposed over the Agent2Agent protocol. When an intent reaches beyond one domain, the agent handling it delegates over A2A to the agent that owns the rest, so a single customer request is resolved end to end. New domains join by registering, not by rewriting what already works.