Sprout.ai icon

Sprout.ai

AI-powered insurance claims automation and fraud detection

by Sprout.aiGBUnited Kingdom🌐Cloud-hosted; servers in data centres worldwide to support customer data-residency requirements. Specific UK/EU region not publicly fixed — confirm via DPA.
TrustKit Score72%Strong

About Sprout.ai

Sprout.ai (legally Sprout.ai Limited, originally founded as BlockClaim) is a London, UK-based insurtech founded in 2018. Its platform automates insurance claims processing end to end — ingesting and understanding claim documents, checking policy coverage, detecting fraud and producing auto-adjudicated or handler-augmented decisions to speed up settlement and improve consistency. The company positions AI as a decision-support and automation layer for claims handlers rather than a full replacement, targeting insurers that want faster, more accurate routine-claims processing while keeping humans in the loop for complex cases. It has worked with insurers internationally and has been recognised in UK startup and entrepreneur awards. On security and compliance, Sprout.ai is ISO 27001 certified to the 2022 standard (Certificate No. 12285), most recently recertified in September 2025, and complies with GDPR, with two appointed Data Protection Officers covering multiple regions. Its cloud hosting providers maintain ISO 27001, ISO 27018, SOC 2, PCI DSS, FedRAMP and HIPAA certifications, and Sprout.ai states it operates servers in data centres around the world to support customer data-residency requirements. Sprout.ai does not itself publish a SOC 2 attestation, and it does not publicly state whether customer data is used to train its models — prospective EU/UK customers should confirm both points and the specific hosting region in the DPA. Sprout.ai has raised roughly $38M across multiple rounds from investors including Amadeus Capital Partners, Praetura Ventures, Octopus Ventures, Playfair Capital and Techstars, with around 50 employees as of 2026. Funding stage is treated conservatively as Series A given the round structure.

TrustKit Score Breakdown

?72% Strong
Data Residency
Where is your data stored and processed?
UK-headquartered with global data centres and stated support for customer data-residency requirements, but no published default UK/EU-only region. EU/UK buyers should confirm an EEA/UK hosting location in the DPA. Scored conservatively pending explicit residency disclosure.
3/5
Legal Jurisdiction
Which laws govern the company and your data?
Incorporated as Sprout.ai Limited in England and Wales (UK), an adequacy-recognised jurisdiction under UK and EU GDPR with no US parent. Strong for UK insurers; EU customers rely on the UK adequacy decision.
4/5
Data Retention & Training
Is your data used for model training?
GDPR-compliant with two DPOs and strict need-to-know role-based access, but no public explicit no-training-on-customer-data statement or published retention controls. Scored 3 pending DPA confirmation of training and retention terms.
3/5
Certifications
ISO 27001, SOC 2, Cyber Essentials, etc.
Holds ISO/IEC 27001:2022 (Cert No. 12285, recertified Sept 2025). No own SOC 2 Type II attestation is published (its hosting providers' SOC 2 does not count for Sprout itself), so it meets the single-major-certification tier.
3/5
Regulatory Fit
Suitability for regulated industries and professional services
Purpose-built for the regulated insurance sector (claims automation and fraud detection), directly relevant to FCA-supervised UK insurers and EIOPA-scope EU insurers. Strong regulated-industry fit.
5/5

Pricing

Custom
EnterpriseContact Sales
Full pricing details →

Quick Facts

Starting PriceCustom enterprise pricingData HostingCloud-hosted; servers in data centres worldwide to support customer data-residency requirements. Specific UK/EU region not publicly fixed — confirm via DPA.Trains on Your DataNo public statement on whether customer data is used to train models. GDPR-compliant with two DPOs and role-based, need-to-know access. Confirm no-training and retention terms in the DPA.Founded2018Employees11-50

Frequently Asked Questions

Is Sprout.ai GDPR compliant?

Sprout.ai has a TrustKit compliance score of 72% (Strong). Data Residency: UK-headquartered with global data centres and stated support for customer data-residency requirements, but no published default UK/EU-only region. EU/UK buyers should confirm an EEA/UK hosting location in the DPA. Scored conservatively pending explicit residency disclosure.. Legal Jurisdiction: Incorporated as Sprout.ai Limited in England and Wales (UK), an adequacy-recognised jurisdiction under UK and EU GDPR with no US parent. Strong for UK insurers; EU customers rely on the UK adequacy decision..

Where does Sprout.ai store data?

Sprout.ai hosts data in: Cloud-hosted; servers in data centres worldwide to support customer data-residency requirements. Specific UK/EU region not publicly fixed — confirm via DPA.. UK-headquartered with global data centres and stated support for customer data-residency requirements, but no published default UK/EU-only region. EU/UK buyers should confirm an EEA/UK hosting location in the DPA. Scored conservatively pending explicit residency disclosure.

Does Sprout.ai train on user data?

Sprout.ai: No public statement on whether customer data is used to train models. GDPR-compliant with two DPOs and role-based, need-to-know access. Confirm no-training and retention terms in the DPA.. GDPR-compliant with two DPOs and strict need-to-know role-based access, but no public explicit no-training-on-customer-data statement or published retention controls. Scored 3 pending DPA confirmation of training and retention terms.

What certifications does Sprout.ai hold?

Sprout.ai holds: ISO/IEC 27001:2022 (Cert No. 12285), GDPR. Holds ISO/IEC 27001:2022 (Cert No. 12285, recertified Sept 2025). No own SOC 2 Type II attestation is published (its hosting providers' SOC 2 does not count for Sprout itself), so it meets the single-major-certification tier.

Compare Sprout.ai With

Similar Tools