Sprout.ai
AI-powered insurance claims automation and fraud detection
About Sprout.ai
Sprout.ai (legally Sprout.ai Limited, originally founded as BlockClaim) is a London, UK-based insurtech founded in 2018. Its platform automates insurance claims processing end to end — ingesting and understanding claim documents, checking policy coverage, detecting fraud and producing auto-adjudicated or handler-augmented decisions to speed up settlement and improve consistency. The company positions AI as a decision-support and automation layer for claims handlers rather than a full replacement, targeting insurers that want faster, more accurate routine-claims processing while keeping humans in the loop for complex cases. It has worked with insurers internationally and has been recognised in UK startup and entrepreneur awards. On security and compliance, Sprout.ai is ISO 27001 certified to the 2022 standard (Certificate No. 12285), most recently recertified in September 2025, and complies with GDPR, with two appointed Data Protection Officers covering multiple regions. Its cloud hosting providers maintain ISO 27001, ISO 27018, SOC 2, PCI DSS, FedRAMP and HIPAA certifications, and Sprout.ai states it operates servers in data centres around the world to support customer data-residency requirements. Sprout.ai does not itself publish a SOC 2 attestation, and it does not publicly state whether customer data is used to train its models — prospective EU/UK customers should confirm both points and the specific hosting region in the DPA. Sprout.ai has raised roughly $38M across multiple rounds from investors including Amadeus Capital Partners, Praetura Ventures, Octopus Ventures, Playfair Capital and Techstars, with around 50 employees as of 2026. Funding stage is treated conservatively as Series A given the round structure.
TrustKit Score Breakdown
?72% StrongPricing
CustomQuick Facts
Frequently Asked Questions
Is Sprout.ai GDPR compliant?
Sprout.ai has a TrustKit compliance score of 72% (Strong). Data Residency: UK-headquartered with global data centres and stated support for customer data-residency requirements, but no published default UK/EU-only region. EU/UK buyers should confirm an EEA/UK hosting location in the DPA. Scored conservatively pending explicit residency disclosure.. Legal Jurisdiction: Incorporated as Sprout.ai Limited in England and Wales (UK), an adequacy-recognised jurisdiction under UK and EU GDPR with no US parent. Strong for UK insurers; EU customers rely on the UK adequacy decision..
Where does Sprout.ai store data?
Sprout.ai hosts data in: Cloud-hosted; servers in data centres worldwide to support customer data-residency requirements. Specific UK/EU region not publicly fixed — confirm via DPA.. UK-headquartered with global data centres and stated support for customer data-residency requirements, but no published default UK/EU-only region. EU/UK buyers should confirm an EEA/UK hosting location in the DPA. Scored conservatively pending explicit residency disclosure.
Does Sprout.ai train on user data?
Sprout.ai: No public statement on whether customer data is used to train models. GDPR-compliant with two DPOs and role-based, need-to-know access. Confirm no-training and retention terms in the DPA.. GDPR-compliant with two DPOs and strict need-to-know role-based access, but no public explicit no-training-on-customer-data statement or published retention controls. Scored 3 pending DPA confirmation of training and retention terms.
What certifications does Sprout.ai hold?
Sprout.ai holds: ISO/IEC 27001:2022 (Cert No. 12285), GDPR. Holds ISO/IEC 27001:2022 (Cert No. 12285, recertified Sept 2025). No own SOC 2 Type II attestation is published (its hosting providers' SOC 2 does not count for Sprout itself), so it meets the single-major-certification tier.