Prometeo
Uruguay · www.prometeoapi.com · 11 vendors
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 8
- Financial Resilience: 6
Technology vendors
- HubSpot, Inc. — Technology — United States
- JN Data A/S — Technology — Denmark
- NVIDIA Corporation — Technology — United States
- and 10 more
Services catalogue
3 services in catalogue across 3 categories; runs on 11 sub-vendors.
- Bank Account Verification
- Banking APIs
- Biometric Verification
Insights
Last updated 2026-08-16 · revision 2
11 direct vendors, 224 subvendors
Direct vendors by controlling owner country (sample)
- United States: 7
- Japan: 1
- Australia: 1
Subvendors by controlling owner country (sample)
- Sweden: 6
- Switzerland: 1
- China: 8
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Prometeo's internal tech stack, featuring Amazon Web Services (AWS), Amazon CloudFront, and Next.js, along with its 'RESTful API Architecture' and 'Open Banking APIs,' indicates a modern, cloud-native, and API-first approach, which is highly conducive to migration. The existing 'ISO 27001 Information Security Management System (ISMS)' and focus on 'Multi-Country Financial Compliance & Regulatory Adherence' suggest a structured operational environment that can facilitate managing migration complexities. However, several factors introduce uncertainty. The 'Data Residency Requirements: Not specified' means potential unknown complexities during migration. Crucially, the 'Vendor Lock-in Risk: Unknown' and the contradictory information regarding vendors ('Total Vendors: 0' vs 'Total Services: 18' with diverse geographic origins) make it difficult to fully assess vendor-related migration challenges. The absence of financial stability data (revenue concentration, growth history) also means the ability to fund a significant migration effort cannot be assessed. While the tech stack is strong, these unknowns temper the overall migration readiness score.
Compliance
8 in-scope frameworks identified; showing 3.
ISAE 3000 (source) — Assessment Required
ISAE 3000 is relevant for companies that provide assurance reports to third parties about their controls and processes (e.g., as a basis for SOC-equivalent reports outside the US). As a fintech API provider serving clients across Latin America and potentially Europe, Prometeo may be asked by clients or regulators to provide third-party assurance reports on its controls. However, there is no evidence that Prometeo currently provides or is required to provide ISAE 3000 assurance reports. The risk is Low because ISAE 3000 is not a mandatory regulatory requirement for Prometeo's current business model, and its ISO 27001 certification partially addresses the assurance needs of its clients.
Evidence: https://www.prometeoapi.com/seguridad, https://www.prometeoapi.com/legales
AML — Assessment Required
Prometeo processes cross-border financial transactions, payment initiations, and account-to-account transfers across 110+ countries in the Americas. As a payment infrastructure provider facilitating money movement, Prometeo is subject to AML/CFT obligations in multiple jurisdictions. The risk is High because: (1) cross-border payment providers are a primary focus of AML regulators globally; (2) FATF (Financial Action Task Force) recommendations apply to payment service providers; (3) each country of operation has its own AML/CFT licensing and reporting requirements; (4) non-compliance can result in criminal liability, license revocation, and reputational damage; (5) Prometeo's 'zero tolerance for fraud' messaging suggests awareness but no specific AML compliance framework is publicly disclosed.
Evidence: https://www.prometeoapi.com/, https://www.prometeoapi.com/sobre-nosotros, https://www.prometeoapi.com/legales/politica-de-privacidad-uruguay
ISO 27001 (source) — Compliant
Prometeo has publicly confirmed ISO 27001 certification on its homepage and security page, displaying both the ISO/IEC 27001:2022 certificate badge and the IQNet certification mark. The company explicitly states it follows ISO 27001 procedures, conducts periodic audits, has an information security management system (ISMS) with internal policies, and performs semi-annual security testing. This is a verified, active certification. The risk is Low because the certification is confirmed and the company demonstrates ongoing compliance practices including 24/7 monitoring, WAF, Host IDS, TLS 1.2+ encryption, 2FA, and regular security training.
Evidence: https://www.prometeoapi.com/seguridad, https://www.prometeoapi.com/
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
Prometeo is a private, venture-backed Uruguayan fintech that does not disclose revenue, EBIT, or equity figures, making a quantitative resilience assessment impossible. However, qualitative indicators support a moderate-to-solid resilience score. The company has raised approximately US$15-17 million in disclosed funding through 2022, including a US$13 million Series A led by Antler Elevate with participation from PayPal Ventures and Samsung Next. This marquee investor base provides financial runway and reputational credibility for enterprise sales. The business model is infrastructure-style with recurring revenue (API calls, subscriptions, per-transaction fees) and high switching costs once integrated. Marquee enterprise clients including Citi, JPMorgan, BBVA, Santander, MercadoLibre, and dLocal, plus a Swift partnership, suggest a contracted enterprise/banking revenue mix that is inherently more resilient than SMB usage. ISO 27001 certification supports enterprise procurement. On the risk side, no priced funding round has been publicly announced since 2022, raising questions about runway in a tougher LatAm venture market. Regulatory fragmentation across LatAm markets, competition from Belvo, Fintoc, Finerio Connect, and Kushki, and likely revenue concentration among top enterprise clients all weigh on resilience.
Key strengths: Marquee investor base including PayPal Ventures, Samsung Next, and Antler Elevate, US$13M Series A raised in 2022, ~US$15-17M total disclosed funding, Enterprise/bank client roster (Citi, JPMorgan, BBVA, Santander, MercadoLibre, dLocal), Recurring infrastructure business model with high switching costs, ISO/IEC 27001:2022 certification, 7,500+ bank connections across 110+ countries providing regional moat, Partnership with Swift, Natural FX hedge (UYU costs, USD revenue from international clients)
Risk factors: No public financials; cash burn, runway, and profitability cannot be verified, No new priced funding round announced since 2022 in a tougher LatAm venture market, Regulatory fragmentation across Mexico, Brazil, Colombia, Chile, Peru, Uruguay, and US, Competitive pressure from Belvo, Fintoc, Finerio Connect, Palenca, Pomelo, Kushki, Likely revenue concentration among top enterprise/bank clients, FX risk if revenue mix skews less international than expected
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.