Dotfile logo
Security Fraud · Document Processing Files

Dotfile

Dotfile is a French-built business verification platform where AI agents pre-investigate KYB and AML cases across 200+ jurisdictions, then hand every borderline decision back to your compliance team with a complete, explainable audit trail.

Active GDPR compliant Contact Sales API available Verified by Guidaio
Overview

What is Dotfile?

Dotfile is a business verification platform built for the compliance teams of regulated financial institutions. Its subject is KYB, know your business: establishing that a company is real, understanding who ultimately controls it, and screening it against sanctions and financial crime lists before onboarding it as a customer, a borrower or a counterparty. The platform rests on four pillars. The first is coverage. Dotfile connects to data providers in more than 200 jurisdictions, offers real-time access to over 400 million companies, and routes each request automatically to the best source for that country, falling back to an alternative when a provider is down or thin. Some 60 providers are pre-integrated, and customers may bring their own vendor contracts rather than being locked into Dotfile's. The second is automation. Dotfile Autonomy deploys specialised AI agents that pre-investigate a case from end to end: collecting documents, reading them, resolving screening hits, mapping ownership and drafting a risk summary. The vendor claims a 95% cut in review time, AML hits resolved in half a second and 94% of false positives eliminated. Genuinely uncertain cases escalate to a human analyst with the reasoning already assembled. The third is ownership intelligence. The Unravelling engine builds ownership graphs from more than 150 million entities across 100-plus registries, calculating direct and indirect stakes through intermediary layers and flagging crossings of the 25% beneficial-ownership threshold. The fourth is orchestration. A single case file holds every document, check result and decision, while Integration Studio connects Dotfile to over a thousand business applications through drag-and-drop workflows, with no engineering backlog. Explainability is the company's stated organising principle: its About page argues the industry is moving toward fully autonomous compliance, and insists every action the AI takes stays traceable and visible to the compliance officer, with no black box. Access is through a web console and a documented REST API. The homepage advertises EU-located servers, SOC 2 certification, an audit log and SSO. No price is published anywhere.

What it does

  • Verify a business in more than 200 jurisdictions from a single integration
  • Trace ownership down to the ultimate beneficial owners with automatic graph mapping
  • Screen counterparties for sanctions, PEPs, adverse media and watchlist hits
  • Let AI agents pre-investigate routine cases end to end and escalate only what needs judgment
  • Extract structured data from unstructured PDFs, deeds and registry filings
  • Order official documents straight from government registries in over 100 countries
  • Monitor counterparties continuously for ownership, sanctions and financial changes
Audience

When to use Dotfile / When not to

A quick filter to help you decide if Dotfile is the right fit.

When to use Dotfile

  • Compliance teams at regulated financial institutions - banks, payment providers, lenders, crypto and stablecoin issuers - for whom KYB and AML checks are a licence condition rather than a nice-to-have
  • Fintechs onboarding business customers in many countries at once, who would otherwise have to contract a separate data vendor in every jurisdiction they enter
  • Analysts buried under high-volume, low-risk onboarding, where most files are clean documents, no screening hits and straightforward ownership
  • Firms exposed to layered corporate structures - holdings, family offices, shell companies - that must trace beneficial ownership past the 25% threshold and prove it
  • Operations and engineering teams that want verification, screening and monitoring in one case file and one API instead of a patchwork of disconnected tools

When not to use Dotfile

  • Anyone who needs a price before speaking to a salesperson: nothing is published, and every pricing route on the site ends at a demo form
  • Individuals and small unregulated businesses with no KYB or AML obligation - without one, the product has no purpose
  • Teams hoping to self-serve: there is no sign-up, no free plan and no free trial, only a qualified demo followed by a negotiated order form
  • Buyers looking for standalone consumer identity verification - individual KYC exists here, but it sits inside a business case rather than on its own
  • Mobile-first users: Dotfile ships no iOS or Android application, and the product is a web console plus an API
Get started

How to use Dotfile

A typical end-to-end flow, from setup to results.

  1. Request access through the demo form, which asks for your name, business email, company, job title, company size, industry and country - there is no self-service sign-up
  2. Agree a plan and an order form with the sales team, which fixes your price per seat and the credits included
  3. Sign in to the web console at app.dotfile.com and set up your workspace, roles, permissions and spaces
  4. Configure your data sources: pick default providers per country, let Dotfile route automatically, or connect your own vendor contracts
  5. Build the templates and controls that define which checks run on which type of case
  6. Set your risk logic in the no-code policy engine, with rules by segment, country and risk threshold
  7. Publish a white-label client portal to collect documents and information from the businesses you are onboarding
  8. Create a case by entering a company registration number, then let Dotfile enrich the profile, identify UBOs and flag mismatches
  9. Review escalated cases in the unified case file, where documents, screening results, comments and decisions sit together
  10. Connect Dotfile to your CRM and internal tools through Integration Studio or the REST API and webhooks, then monitor jobs and invoices from the admin menus
Quick read

Pros & Cons

Pros

  • One integration replaces one vendor per country: 200+ jurisdictions, 60+ providers and automatic fallback when a source fails
  • No vendor lock-in is claimed - you can bring your own provider contracts and switch sources without changing your code
  • Explainability is placed at the centre: every AI action is traceable and visible to the compliance officer, with audit-ready documentation
  • Named customer case studies back the performance claims, including Keyrock, Roundtable, Defacto and the NYDFS-chartered trust company Bastion
  • A credible security posture for the sector: EU-located servers, SOC 2, SSO/OIDC, audit log, custom retention policies and a public trust centre
  • A documented public API with a changelog and webhooks, alongside 1,000+ no-code connectors, so both engineers and business users can integrate it
  • A European vendor governed by French law, which simplifies the GDPR analysis for an EU buyer, with a client portal translatable into six languages

Cons

  • No public pricing at all: no grid, no range, no entry point - the pricing URL simply redirects to the demo form
  • No free trial and no free plan are announced, and there is no way to evaluate the product without a sales conversation
  • The privacy policy is dated February 2024 and does not cover the KYB and AML data customers upload, which is the very substance of the product
  • No data processing agreement is published or announced as available on request
  • No subprocessor list can be read: the Vanta trust centre is rendered entirely in JavaScript and its API refuses unsigned requests
  • The performance figures - 95% less review time, 120x faster, 94% of false positives removed, 0.5 second resolution - are vendor claims with no published methodology
  • Nothing is said about whether customer data trains AI models, so there is neither a commitment nor an opt-out to rely on; there is also no mobile app and no link to any social account
Pricing

Pricing & Plans

Dotfile publishes no prices. There is no free plan and no free trial announced, and no entry-level amount can be quoted: the pricing route on the website redirects to the demo form, and the sitemap contains no pricing page. The product documentation confirms the underlying structure without disclosing any figure. Customers subscribe to a named plan, buy seats at the price per seat set in their own order form, and draw on a balance of Dotfile Credits, where one credit equals one euro, one pound or one dollar depending on the billing currency. That same balance also pays for the verification checks; every plan includes credits and can be topped up with credit packages. Seat purchases and releases appear on the following monthly invoice, and extended company data and official documents are bought on demand.

Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Dotfile handles your data.

GDPR overview

GDPR references are concrete but thin. The homepage carries a GDPR Compliant badge alongside SOC 2, EU-located servers and 99.99% availability, and section 3 of the privacy policy commits the company to bringing its processing into compliance with the regulation. Because Dotfile SAS is established in Paris, no Article 27 representative is required or named. Transfers outside the EEA rely on an adequacy decision or on standard contractual clauses adopted by the Commission, the data protection contact is hello@dotfile.com, and a right to complain to a supervisory authority is stated without naming one. Two reservations: the policy is dated February 2024, and the same sentence also invokes the Belgian Law of 30 July 2018, although the company is a French SAS whose terms elect French law - a template leftover worth clarifying.

Who owns the data?

Dotfile SAS, the French company behind the platform, states that it acts as a data controller for the personal data described in its privacy policy, determining the purposes and the means of processing. That policy covers users, supplier representatives, job candidates and visitors to the website and the premises. Processors are engaged only where necessary and under written instructions, and personal data may be passed to third parties such as banks during a restructuring. Data subjects are granted the full set of GDPR rights: information, access, rectification, erasure, objection to marketing, restriction, portability and withdrawal of consent. One gap stands out: the policy never addresses the KYB and AML data that customers upload into the platform.

Reuse rights

The published terms say nothing about a customer's right to reuse or redistribute data obtained through the platform. They govern use of the website and the software, reserve all site content to Dotfile or third-party rights holders, and permit copying for personal use only. The privacy policy instead sets out Dotfile's own purposes: managing the user relationship, commercial follow-up with suppliers, recruitment, aggregate audience measurement and fraud detection on the website, premises security, and then audits, disputes and restructuring operations. Data reaches the company directly from the individual, from applications connected to the service such as Google Connect, Zapier and Slack, and from publicly available sources including internet research. Dotfile states that it takes no decision based solely on automated processing producing legal or similarly significant effects. Neither the website nor the developer documentation ever mentions training AI models on customer data.

Data retention & training

Retention summary
Dotfile keeps personal data only for as long as the purpose of the processing requires. One period is stated precisely: invoices and accounting documents, which may contain personal data, are kept for seven years from the end of the accounting year in which they were issued, as accounting law requires. Beyond that, the company lists the criteria it applies rather than fixed durations: the date of last contact, security reasons, current or potential disputes and litigation, and any legal obligation to retain or delete. The right to erasure is recognised but is not absolute, and data may be kept where the law requires it or to defend legal claims. On the product side the homepage advertises custom data retention policies, without explaining how they work. No retention period is published for the KYB and AML data customers upload.
GDPR contact

Hosting summary

Dotfile states that its servers are located in the European Union. The homepage security banner reads EU-located Servers, and the Dotfile Autonomy page repeats the point in its audit trail section as EU data residency with encryption. Beyond that regional commitment, nothing is published: no host country is named, no cloud provider is identified, and no technical region is disclosed. The privacy policy does allow for some recipients to be located outside the European Economic Area, or to process data from outside it, in which case Dotfile relies on a European Commission adequacy decision or on standard contractual clauses. Custom data retention policies are advertised on the homepage as a product capability. A public trust centre at trust.dotfile.com, operated on Vanta, would normally carry the detailed hosting, subprocessor and certification records, but it is rendered entirely in JavaScript and could not be read during this review.

Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Dotfile.

  • You cannot judge the cost before engaging with sales, which makes budget comparison against alternatives impossible at the research stage and puts you in a weak negotiating position
  • The privacy policy dates from February 2024 and never describes what happens to the KYB and AML data you upload - for a platform processing personal data about directors and beneficial owners, that omission deserves a direct question before signing
  • The same policy invokes Belgian law although the company is a French SAS whose terms elect French law: a template leftover that suggests the legal documentation has not kept pace with the product
  • Nothing is published about training AI models on customer data - there is neither a non-training commitment nor an opt-out, so you cannot rely on either
  • No data processing agreement is published and no subprocessor list can be read, since the trust centre is rendered entirely in JavaScript behind a signed API
  • The headline performance figures come from the vendor without published methodology; treat 95% review-time reduction, 120x speed and 94% false-positive elimination as claims to test in a pilot, not as guarantees
  • The deeper human risk is over-trust: when an agent auto-approves most cases, an analyst can drift into rubber-stamping and lose the pattern recognition that catches the unusual file - the audit trail proves what was decided, not that anyone genuinely read it
Setup

Setup & Integrations

Technical difficulty

Moderate, and split in two. There is no self-service sign-up, so the first hurdle is commercial: a demo, then an order form. After that, business users can do a great deal without code, since Integration Studio offers drag-and-drop workflows and over a thousand pre-built connectors, and the policy engine is configured without programming. Developers get a documented REST API, webhooks and SSO/OIDC to wire in. The real work is configuration rather than coding: check templates, controls, risk rules by segment and country, roles, permissions and the client portal. No deployment timeline is published.

Deployment

Web appAPI

Integrations

Salesforce HubSpot Slack Pipedrive Microsoft Teams Google Drive Google Sheets Zapier ComplyAdvantage LSEG World Check Creditsafe Kyckr KYC Spider Companies House InfoCamere INPI Onfido IDnow GBG Trustfull

Supported languages

EnglishFrenchGermanSpanishItalianDutch
Company

Behind Dotfile

Company name
Dotfile SAS
Founded
25/02/2022
Country of origin
🇫🇷 France
Headquarters
229 Rue Saint Honoré 75001 Paris, France
EU office
229 Rue Saint Honoré 75001 Paris, France
US office
490 Post St. Ste. 640, San Francisco, California
UBO
Vasco Alexandre
UBO country
🇫🇷 France
Domain registrar country
🇺🇸 United States
Support contact

Fundraising

€6 million announced on 25 September 2024, led by Seaya Ventures with support from existing investors Serena Capital and Hexa
€2.5 million in a first round roughly a year earlier, during 2023
The About page names Serena Capital and Seaya Ventures as the company's backing investors
At the time of the 2024 round Dotfile reported more than 50 customers across 10 countries, including Spendesk, Younited Credit, Flowdesk and Keyrock, and had opened a London office in June 2024
More recent traction claimed on the About page: 80+ financial institutions, 15 countries and 3x year-over-year revenue growth
Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What does Dotfile actually do?
It verifies businesses. Dotfile establishes that a company is real, traces its ownership down to the ultimate beneficial owners, and screens it for financial crime across more than 200 jurisdictions, so that a regulated institution can onboard it with a defensible record.
Who is behind the product?
Dotfile SAS, a French company registered under number 910 892 777, with its seat at 229 Rue Saint Honoré, 75001 Paris, France, and a US office at 490 Post St. Ste. 640, San Francisco, California. Its terms elect French law and French courts.
How much does Dotfile cost?
There is no public price. Access begins with a demo, after which an order form sets your plan, your price per seat and the credits included. Additional seats are billed in Dotfile Credits, where one credit equals one euro, pound or dollar depending on your billing currency.
Is there a free trial or a free plan?
Neither is announced anywhere on the website or in the product documentation. The only entry point is the demo form, and the company does not state that a free option is unavailable either - it simply never mentions one.
Does Dotfile have an API?
Yes. A public REST API is documented on docs.dotfile.com, with an API reference, a changelog and webhooks. The API exposes case, company and individual objects, and the platform is presented as API-first throughout the site.
Where is the data hosted?
The homepage advertises EU-located servers and the Autonomy page mentions EU data residency with encryption. No specific country, cloud provider or technical region is named. The privacy policy allows for recipients outside the EEA under an adequacy decision or standard contractual clauses.
What certifications does Dotfile hold?
The homepage displays SOC 2 Certified and GDPR Compliant badges, together with claims of 99.99% availability, custom data retention policies, SSO/OIDC, an audit log and advanced permissions. A public trust centre is hosted at trust.dotfile.com.
Which languages are supported?
The client portal can be translated into French, English, German, Spanish, Italian and Dutch. The marketing website itself is available in English and French.
Is there a mobile app?
No. Dotfile is used through its web console at app.dotfile.com and through its API. No iOS or Android application is offered, and no app store badge appears anywhere on the site.
What exactly does the AI do, and who decides?
Dotfile Autonomy runs specialised agents for AML screening, documents, ownership and reputation. They pre-investigate routine cases end to end and auto-approve the clean ones under your policy logic, while edge cases escalate to a human analyst with a complete audit trail and a recommendation already prepared.
Conclusion

Should you pick Dotfile?

Dotfile is a focused, well-documented tool for a narrow but demanding audience: the compliance teams of regulated financial institutions that must verify businesses, trace ownership and screen for financial crime across borders. Its strongest argument is coverage through a single integration - more than 200 jurisdictions, 60-plus pre-integrated data providers, automatic routing with fallback, and the freedom to bring your own vendor contracts. Its second argument is explainability: the company stakes its positioning on the idea that an AI decision a compliance officer cannot justify to a regulator is worthless, backing this with audit trails, data lineage and visible reasoning. The automation is real but deliberately bounded: Dotfile does not claim to replace the analyst, only to clear the routine work so the analyst can spend time on genuine risk, and it is explicit that hard calls remain human. The main reservation is commercial rather than technical: pricing is entirely opaque. No grid, no range, no trial, and every pricing link leads to a demo form, so no buyer can situate the budget beforehand. A second reservation concerns the legal documentation, which has fallen behind the product. The privacy policy dates from February 2024, still carries a stray reference to Belgian law in a French company's notice, and never describes what happens to the KYB and AML data customers upload - a real gap for a platform whose business is processing personal data about directors and beneficial owners. It also says nothing about whether that data trains AI models. The vendor itself is credible: a French company incorporated on 25 February 2022, roughly €8.5 million raised from Seaya Ventures, Serena Capital and Hexa, and named, verifiable customers. Worth a conversation if KYB is a regulatory obligation for you; not worth the effort otherwise.