Dotfile
Dotfile is a French-built business verification platform where AI agents pre-investigate KYB and AML cases across 200+ jurisdictions, then hand every borderline decision back to your compliance team with a complete, explainable audit trail.
What is Dotfile?
Dotfile is a business verification platform built for the compliance teams of regulated financial institutions. Its subject is KYB, know your business: establishing that a company is real, understanding who ultimately controls it, and screening it against sanctions and financial crime lists before onboarding it as a customer, a borrower or a counterparty. The platform rests on four pillars. The first is coverage. Dotfile connects to data providers in more than 200 jurisdictions, offers real-time access to over 400 million companies, and routes each request automatically to the best source for that country, falling back to an alternative when a provider is down or thin. Some 60 providers are pre-integrated, and customers may bring their own vendor contracts rather than being locked into Dotfile's. The second is automation. Dotfile Autonomy deploys specialised AI agents that pre-investigate a case from end to end: collecting documents, reading them, resolving screening hits, mapping ownership and drafting a risk summary. The vendor claims a 95% cut in review time, AML hits resolved in half a second and 94% of false positives eliminated. Genuinely uncertain cases escalate to a human analyst with the reasoning already assembled. The third is ownership intelligence. The Unravelling engine builds ownership graphs from more than 150 million entities across 100-plus registries, calculating direct and indirect stakes through intermediary layers and flagging crossings of the 25% beneficial-ownership threshold. The fourth is orchestration. A single case file holds every document, check result and decision, while Integration Studio connects Dotfile to over a thousand business applications through drag-and-drop workflows, with no engineering backlog. Explainability is the company's stated organising principle: its About page argues the industry is moving toward fully autonomous compliance, and insists every action the AI takes stays traceable and visible to the compliance officer, with no black box. Access is through a web console and a documented REST API. The homepage advertises EU-located servers, SOC 2 certification, an audit log and SSO. No price is published anywhere.
What it does
- Verify a business in more than 200 jurisdictions from a single integration
- Trace ownership down to the ultimate beneficial owners with automatic graph mapping
- Screen counterparties for sanctions, PEPs, adverse media and watchlist hits
- Let AI agents pre-investigate routine cases end to end and escalate only what needs judgment
- Extract structured data from unstructured PDFs, deeds and registry filings
- Order official documents straight from government registries in over 100 countries
- Monitor counterparties continuously for ownership, sanctions and financial changes
When to use Dotfile / When not to
A quick filter to help you decide if Dotfile is the right fit.
When to use Dotfile
- Compliance teams at regulated financial institutions - banks, payment providers, lenders, crypto and stablecoin issuers - for whom KYB and AML checks are a licence condition rather than a nice-to-have
- Fintechs onboarding business customers in many countries at once, who would otherwise have to contract a separate data vendor in every jurisdiction they enter
- Analysts buried under high-volume, low-risk onboarding, where most files are clean documents, no screening hits and straightforward ownership
- Firms exposed to layered corporate structures - holdings, family offices, shell companies - that must trace beneficial ownership past the 25% threshold and prove it
- Operations and engineering teams that want verification, screening and monitoring in one case file and one API instead of a patchwork of disconnected tools
When not to use Dotfile
- Anyone who needs a price before speaking to a salesperson: nothing is published, and every pricing route on the site ends at a demo form
- Individuals and small unregulated businesses with no KYB or AML obligation - without one, the product has no purpose
- Teams hoping to self-serve: there is no sign-up, no free plan and no free trial, only a qualified demo followed by a negotiated order form
- Buyers looking for standalone consumer identity verification - individual KYC exists here, but it sits inside a business case rather than on its own
- Mobile-first users: Dotfile ships no iOS or Android application, and the product is a web console plus an API
How to use Dotfile
A typical end-to-end flow, from setup to results.
- Request access through the demo form, which asks for your name, business email, company, job title, company size, industry and country - there is no self-service sign-up
- Agree a plan and an order form with the sales team, which fixes your price per seat and the credits included
- Sign in to the web console at app.dotfile.com and set up your workspace, roles, permissions and spaces
- Configure your data sources: pick default providers per country, let Dotfile route automatically, or connect your own vendor contracts
- Build the templates and controls that define which checks run on which type of case
- Set your risk logic in the no-code policy engine, with rules by segment, country and risk threshold
- Publish a white-label client portal to collect documents and information from the businesses you are onboarding
- Create a case by entering a company registration number, then let Dotfile enrich the profile, identify UBOs and flag mismatches
- Review escalated cases in the unified case file, where documents, screening results, comments and decisions sit together
- Connect Dotfile to your CRM and internal tools through Integration Studio or the REST API and webhooks, then monitor jobs and invoices from the admin menus
Pros & Cons
Pros
- One integration replaces one vendor per country: 200+ jurisdictions, 60+ providers and automatic fallback when a source fails
- No vendor lock-in is claimed - you can bring your own provider contracts and switch sources without changing your code
- Explainability is placed at the centre: every AI action is traceable and visible to the compliance officer, with audit-ready documentation
- Named customer case studies back the performance claims, including Keyrock, Roundtable, Defacto and the NYDFS-chartered trust company Bastion
- A credible security posture for the sector: EU-located servers, SOC 2, SSO/OIDC, audit log, custom retention policies and a public trust centre
- A documented public API with a changelog and webhooks, alongside 1,000+ no-code connectors, so both engineers and business users can integrate it
- A European vendor governed by French law, which simplifies the GDPR analysis for an EU buyer, with a client portal translatable into six languages
Cons
- No public pricing at all: no grid, no range, no entry point - the pricing URL simply redirects to the demo form
- No free trial and no free plan are announced, and there is no way to evaluate the product without a sales conversation
- The privacy policy is dated February 2024 and does not cover the KYB and AML data customers upload, which is the very substance of the product
- No data processing agreement is published or announced as available on request
- No subprocessor list can be read: the Vanta trust centre is rendered entirely in JavaScript and its API refuses unsigned requests
- The performance figures - 95% less review time, 120x faster, 94% of false positives removed, 0.5 second resolution - are vendor claims with no published methodology
- Nothing is said about whether customer data trains AI models, so there is neither a commitment nor an opt-out to rely on; there is also no mobile app and no link to any social account
Pricing & Plans
Dotfile publishes no prices. There is no free plan and no free trial announced, and no entry-level amount can be quoted: the pricing route on the website redirects to the demo form, and the sitemap contains no pricing page. The product documentation confirms the underlying structure without disclosing any figure. Customers subscribe to a named plan, buy seats at the price per seat set in their own order form, and draw on a balance of Dotfile Credits, where one credit equals one euro, one pound or one dollar depending on the billing currency. That same balance also pays for the verification checks; every plan includes credits and can be topped up with credit packages. Seat purchases and releases appear on the following monthly invoice, and extended company data and official documents are bought on demand.
Data, GDPR & hosting
A consolidated view of how Dotfile handles your data.
GDPR overview
GDPR references are concrete but thin. The homepage carries a GDPR Compliant badge alongside SOC 2, EU-located servers and 99.99% availability, and section 3 of the privacy policy commits the company to bringing its processing into compliance with the regulation. Because Dotfile SAS is established in Paris, no Article 27 representative is required or named. Transfers outside the EEA rely on an adequacy decision or on standard contractual clauses adopted by the Commission, the data protection contact is hello@dotfile.com, and a right to complain to a supervisory authority is stated without naming one. Two reservations: the policy is dated February 2024, and the same sentence also invokes the Belgian Law of 30 July 2018, although the company is a French SAS whose terms elect French law - a template leftover worth clarifying.
Who owns the data?
Dotfile SAS, the French company behind the platform, states that it acts as a data controller for the personal data described in its privacy policy, determining the purposes and the means of processing. That policy covers users, supplier representatives, job candidates and visitors to the website and the premises. Processors are engaged only where necessary and under written instructions, and personal data may be passed to third parties such as banks during a restructuring. Data subjects are granted the full set of GDPR rights: information, access, rectification, erasure, objection to marketing, restriction, portability and withdrawal of consent. One gap stands out: the policy never addresses the KYB and AML data that customers upload into the platform.
Reuse rights
The published terms say nothing about a customer's right to reuse or redistribute data obtained through the platform. They govern use of the website and the software, reserve all site content to Dotfile or third-party rights holders, and permit copying for personal use only. The privacy policy instead sets out Dotfile's own purposes: managing the user relationship, commercial follow-up with suppliers, recruitment, aggregate audience measurement and fraud detection on the website, premises security, and then audits, disputes and restructuring operations. Data reaches the company directly from the individual, from applications connected to the service such as Google Connect, Zapier and Slack, and from publicly available sources including internet research. Dotfile states that it takes no decision based solely on automated processing producing legal or similarly significant effects. Neither the website nor the developer documentation ever mentions training AI models on customer data.
Data retention & training
Hosting summary
Dotfile states that its servers are located in the European Union. The homepage security banner reads EU-located Servers, and the Dotfile Autonomy page repeats the point in its audit trail section as EU data residency with encryption. Beyond that regional commitment, nothing is published: no host country is named, no cloud provider is identified, and no technical region is disclosed. The privacy policy does allow for some recipients to be located outside the European Economic Area, or to process data from outside it, in which case Dotfile relies on a European Commission adequacy decision or on standard contractual clauses. Custom data retention policies are advertised on the homepage as a product capability. A public trust centre at trust.dotfile.com, operated on Vanta, would normally carry the detailed hosting, subprocessor and certification records, but it is rendered entirely in JavaScript and could not be read during this review.
Things to keep in mind
Risks and trade-offs to weigh before adopting Dotfile.
- You cannot judge the cost before engaging with sales, which makes budget comparison against alternatives impossible at the research stage and puts you in a weak negotiating position
- The privacy policy dates from February 2024 and never describes what happens to the KYB and AML data you upload - for a platform processing personal data about directors and beneficial owners, that omission deserves a direct question before signing
- The same policy invokes Belgian law although the company is a French SAS whose terms elect French law: a template leftover that suggests the legal documentation has not kept pace with the product
- Nothing is published about training AI models on customer data - there is neither a non-training commitment nor an opt-out, so you cannot rely on either
- No data processing agreement is published and no subprocessor list can be read, since the trust centre is rendered entirely in JavaScript behind a signed API
- The headline performance figures come from the vendor without published methodology; treat 95% review-time reduction, 120x speed and 94% false-positive elimination as claims to test in a pilot, not as guarantees
- The deeper human risk is over-trust: when an agent auto-approves most cases, an analyst can drift into rubber-stamping and lose the pattern recognition that catches the unusual file - the audit trail proves what was decided, not that anyone genuinely read it
Setup & Integrations
Technical difficulty
Moderate, and split in two. There is no self-service sign-up, so the first hurdle is commercial: a demo, then an order form. After that, business users can do a great deal without code, since Integration Studio offers drag-and-drop workflows and over a thousand pre-built connectors, and the policy engine is configured without programming. Developers get a documented REST API, webhooks and SSO/OIDC to wire in. The real work is configuration rather than coding: check templates, controls, risk rules by segment and country, roles, permissions and the client portal. No deployment timeline is published.
Deployment
Integrations
Supported languages
Behind Dotfile
Fundraising
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What does Dotfile actually do?
Who is behind the product?
How much does Dotfile cost?
Is there a free trial or a free plan?
Does Dotfile have an API?
Where is the data hosted?
What certifications does Dotfile hold?
Which languages are supported?
Is there a mobile app?
What exactly does the AI do, and who decides?
Should you pick Dotfile?
Dotfile is a focused, well-documented tool for a narrow but demanding audience: the compliance teams of regulated financial institutions that must verify businesses, trace ownership and screen for financial crime across borders. Its strongest argument is coverage through a single integration - more than 200 jurisdictions, 60-plus pre-integrated data providers, automatic routing with fallback, and the freedom to bring your own vendor contracts. Its second argument is explainability: the company stakes its positioning on the idea that an AI decision a compliance officer cannot justify to a regulator is worthless, backing this with audit trails, data lineage and visible reasoning. The automation is real but deliberately bounded: Dotfile does not claim to replace the analyst, only to clear the routine work so the analyst can spend time on genuine risk, and it is explicit that hard calls remain human. The main reservation is commercial rather than technical: pricing is entirely opaque. No grid, no range, no trial, and every pricing link leads to a demo form, so no buyer can situate the budget beforehand. A second reservation concerns the legal documentation, which has fallen behind the product. The privacy policy dates from February 2024, still carries a stray reference to Belgian law in a French company's notice, and never describes what happens to the KYB and AML data customers upload - a real gap for a platform whose business is processing personal data about directors and beneficial owners. It also says nothing about whether that data trains AI models. The vendor itself is credible: a French company incorporated on 25 February 2022, roughly €8.5 million raised from Seaya Ventures, Serena Capital and Hexa, and named, verifiable customers. Worth a conversation if KYB is a regulatory obligation for you; not worth the effort otherwise.
- Choosing a selection results in a full page refresh.
- Opens in a new window.