Runtime vs Sardine
Runtime vs Sardine compared: Sardine is an agentic fraud and AML platform with ten risk agents. Runtime is an agent harness for every payment team, in your cloud. Where each fits, and how to run both.
TL;DR: Sardine is the stronger choice when you need fraud detection, AML monitoring, and purpose-built risk agents from one vendor. Runtime is the better fit when agents need to work across every team that touches a transaction, in your cloud, with your models. Many teams will run both.
| Feature | ||
|---|---|---|
| What it is | Agent harness for every payment team | Fraud and AML platform with agents |
| Fraud scoring and device intelligence | Connects to your risk vendors | Built in, plus Sonar consortium |
| Ready-made risk agents | You build them from your SOPs | Ten agents, from KYC to SARs |
| Teams covered | Risk, payment ops, finance, support, more | Fraud, risk, and compliance |
| Data outside the risk stack | Ledger, processor, bank files, tickets | Sardine data and integrations |
| Runs in your cloud | Yes, or fully self-hosted | Hosted platform |
| Bring your own models | Any model, including open-weight | Not published |
| Audit trail | Every query, tool call, approval, cost | Explainable decisions with audit trails |
| Pricing | Free, Teams from $99/seat/month | Not published |
Sardine and Runtime at a glance
Sardine is a fraud prevention and compliance platform that now calls itself an agentic financial crime platform. It covers onboarding (KYC, KYB, document and bank verification), fraud prevention (payment, card issuing, merchant monitoring, account takeover, bots), and AML (transaction monitoring, sanctions screening, customer risk rating, case management, sponsor bank monitoring). On top of that it sells ten AI agents, including Transaction Monitoring, Sanctions Screening, Graph Analyst, and SAR Generation, and runs Sonar, a data consortium that shares fraud signals across members. Customers listed on its site include FIS, Nubank, Gusto, and Deel. Sardine is for fraud, risk, and compliance teams that want detection and risk agents from one vendor.
Runtime is the AI agent harness for payment and fintech teams: one system for building and running many agents across the org, not one agent. Anyone on payment ops, risk, compliance, finance, onboarding, or support builds agents from their SOPs. Agents work on their own isolated computers in your cloud, reach your tools through APIs, databases, CLIs, MCP servers, and a browser, and are called from Slack, Teams, email, or the dashboard. Runtime is for operators who want agents on every queue that touches a transaction.
Good products, different jobs. Sardine decides whether something is risky. Runtime runs the work that follows, across every team.
How they differ
Detection versus the work around it
Sardine's core is detection: device intelligence, behavioral biometrics, risk scoring, rules, and consortium data, with agents that resolve the alerts it raises. Runtime does none of the scoring. Its agents start where an alert, ticket, or exception lands and do the investigation: pull the transaction from the processor, check the ledger, read the bank file, look at the support history, and draft a decision with evidence.
One team versus every team
Sardine's agents are built for fraud, AML, and compliance analysts. That is a deep, well-defined scope. Payment problems rarely stay in it. A single stuck payment touches four teams: support gets the ticket, payment ops traces it, finance sees a recon break, and risk or compliance may review it. Today each team investigates it separately, in different tools. On Runtime it is one investigation with one record, and every run adds to a shared memory of resolved tickets, fraud caught, and reconciliation edge cases.
Where it runs and which models it uses
Sardine is delivered as a hosted platform through its dashboard and API, and it does not publish which models power its agents or a self-hosted option. Runtime runs agent computers in your AWS, GCP, or Azure account, or fully self-hosted with Helm. You bring your own models, including open-weight models served in your cloud for PCI and PII work, with routing and fallbacks when a provider goes down. Card numbers and SSNs are stripped from prompts and logs, and credentials are masked.
Opinionated agents versus agents built from your SOPs
Sardine's agents arrive ready to work inside its case flow, and Sardine reports a KYC agent auto-resolving 88% of onboarding edge cases. That is a real advantage on day one. Runtime agents are built from your own procedures with a forward-deployed AI engineer, so they follow your policy, your sponsor bank's expectations, and your systems. Once a process is solved, an agent can turn it into deterministic code that lives in your repo.
Where Sardine is stronger
- Detection. Device intelligence, behavioral biometrics, fraud scoring, and rules are Sardine's core product. Runtime has none of them.
- Consortium data. Sonar shares risk signals across member companies. Runtime does not offer shared fraud data.
- Ready-made risk agents. Ten agents for KYC, sanctions, PEP screening, transaction monitoring, and SAR drafting work out of the box.
- Breadth inside risk. Onboarding, fraud, AML, and case management sit on one platform with one vendor contract.
- Scale and references. Sardine names large customers such as FIS, Nubank, and Gusto.
Pricing
Sardine: Pricing is not published; it is sold through sales.
Runtime: Free ($0, one session), Teams from $99 per seat per month, and Enterprise with custom pricing and self-hosting. The value case is usually the work of the analysts you were about to hire. Rain replaced $250k in vendor spend with Runtime.
Which should you choose
Choose Sardine if
- You need fraud detection, AML monitoring, and onboarding checks from one vendor
- Device intelligence and consortium signals matter to your fraud program
- Your bottleneck is fraud and compliance alerts, and you want agents that resolve them inside the same platform
- Other teams are not in scope for agents yet
Choose Runtime if
- Investigations need data outside the risk stack: ledger, processor, bank files, tickets
- Payment ops, finance, support, and risk all have growing queues
- Agents must run in your cloud, with your models, and stop for approval before money moves
- You want a record of every run that your sponsor bank or examiner can review
- You want an engineer to build the first agents with your team
Running both
Many teams will keep Sardine for detection and scoring and use Runtime agents for the cross-team work around its alerts: the case that needs a ledger check, the merchant review that needs processor history, the customer who is also waiting on support. Agents pull alert context through Sardine's API, draft the decision, and wait for a person before anything moves money.
See Runtime on your busiest queue
Bring one SOP. A forward-deployed AI engineer builds the first agent with your team, inside your cloud.
Frequently asked questions
What AI agents does Sardine offer?
Sardine lists ten agents on its site: OSINT Search, Data Analyst, Rule Assistant, Transaction Monitoring, Business Due Diligence, Doc KYC, PEP Screening, Graph Analyst, Sanctions Screening, and SAR Generation. They run inside Sardine's fraud and AML platform.
Can Runtime replace Sardine?
Not for detection. Runtime does not score transactions, profile devices, or run a fraud consortium. It runs agents that investigate and act across your systems, so it usually sits next to a risk platform like Sardine rather than replacing it.
Can Runtime and Sardine run together?
Yes. Sardine detects, scores, and opens alerts. Runtime agents can pick up the cases that need context from outside the risk stack, such as the ledger, processor, bank files, or support tickets, draft the decision with evidence, and wait for a person to approve before anything moves money.
Is Sardine pricing public?
No. Sardine does not publish pricing; it is sold through sales. Runtime publishes its tiers: Free for one session, Teams from $99 per seat per month, and custom Enterprise pricing with self-hosting.
Which is better for a fintech without a large engineering team?
If the main need is fraud and AML detection, Sardine gives you that out of the box. If the need is getting agents onto several operational queues, Runtime pairs you with a forward-deployed AI engineer who builds the first agents with your team.
Related comparisons
Sardine vs Sift
Sardine vs Sift compared for fintech and payments: fraud scoring, AML and KYC coverage, AI agents, network data, and pricing. Plus where Runtime fits as the agent layer for every payment team.
Runtime and Sift
Runtime vs Sift: Sift scores fraud and decides in real time. Runtime agents work the review queue Sift creates, investigating across ledger, processor, and tickets, then write the decision back.
Runtime vs Footprint
Runtime is one agent harness for every payment team, from risk to payment ops, finance, and support. Footprint is an identity and risk operations platform with AI agents for KYC, KYB, and fraud.
Runtime and Alloy
Runtime vs Alloy: Alloy orchestrates identity, KYC, KYB, and fraud decisions. Runtime agents work the manual review queue, re-reviews, and cross-team investigations around those decisions.