Datavillage logo
Security Fraud · Privacy Security

Datavillage

Datavillage helps financial institutions treat fraud and AML as an engineering discipline, connecting threat intelligence, detection design, investigation and continuous improvement into one closed loop supported by specialised AI agents that always stay under human approval.

Active GDPR compliant Contact Sales API available Verified by Guidaio
Overview

What is Datavillage?

Datavillage is a Belgian company that positions itself as a specialist in what it calls Fraud & AML Engineering: the practice of continuously designing, building, operating and improving the controls that protect financial institutions against financial crime. Its argument is that most banks and payment providers run financial crime as a collection of disconnected activities — intelligence in one team, detection in another, investigation in a third, improvement nowhere — while attackers keep adapting, so static controls inevitably fall behind.

The answer it proposes is a closed loop of four phases. Fraud Intelligence monitors external signals, normalises new typologies and compares them against existing coverage. Detection Engineering breaks each typology into detectable scenarios and indicators, drafts the logic, and generates synthetic scenarios and backtest suites before anything ships. Alert and Investigation prioritises alerts, reconstructs the episode across systems and assembles cited evidence so an analyst starts from a documented case rather than a customer ID and a score. Continuous Improvement turns confirmed outcomes into structured knowledge, measured control effectiveness and tuning proposals that feed straight back into intelligence.

Three technology building blocks support this. A set of six specialised AI agents — typology, coverage, indicator, testing, investigation and improvement — works across the lifecycle, and custom agents can be trained on a customer's own rules, cases and policies. A fraud knowledge layer links typologies, scenarios, indicators, metrics, detections, alerts and outcomes in one versioned, machine-readable hierarchy with access control and an audit trail. A detection-as-code practice applies pull-request review, automated replay and synthetic testing, staged rollout and rollback to control logic.

Two things are worth understanding before evaluating it. First, the offer is deliberately hybrid: asked whether it is a consultancy or a technology vendor, the company answers that both can be part of an engagement, so what is delivered depends on the mission. Second, everything is built to run inside the institution's own environment and around the stack it already owns, rather than replacing it. There is no self-service product, no published pricing and no public API documentation; the only hands-on entry point is a benchmark sandbox for detection rules, offered to financial institutions against a business email address.

What it does

  • Map the fraud and AML typologies that matter to your products, channels and customers, then diff them against real detection coverage
  • Turn a typology into concrete scenarios and indicators, checking data feasibility before any logic is written
  • Build detection logic as versioned, reviewed and backtested code rather than untracked vendor configuration
  • Generate synthetic datasets and scenario suites to test controls before they reach production
  • Reconstruct a fraud episode across channels and hand investigators an assembled, cited evidence pack
  • Prioritise and enrich alert queues on evidence strength instead of score alone
  • Feed confirmed investigation outcomes back into tuning proposals, subject to human approval
Audience

When to use Datavillage / When not to

A quick filter to help you decide if Datavillage is the right fit.

When to use Datavillage

  • Banks and payment providers whose fraud and AML activities are split across disconnected teams, tools and vendors
  • Fraud and financial crime teams that want to keep their existing monitoring, screening and case management stack and engineer around it
  • Compliance and risk functions that must demonstrate coverage, lineage and auditability to a supervisor
  • Institutions attacking one specific problem first, such as APP scams, account takeover, mule detection or alert optimisation
  • Organisations that want to own the resulting capability internally rather than depend on a vendor console

When not to use Datavillage

  • Companies outside financial services: the benchmark sandbox is explicitly restricted to financial institutions
  • Buyers who need a published price list, since every route leads to a quote and a contact form
  • Teams looking for a ready-to-use product they can sign up for and start using the same day
  • Small organisations without internal fraud, AML, data or engineering teams to build alongside
  • Anyone needing a mobile app, a self-service account or a documented public API to integrate on their own
Get started

How to use Datavillage

A typical end-to-end flow, from setup to results.

  1. Read the Fraud & AML Engineering page to check whether the lifecycle model matches how your controls are organised today
  2. Browse the six solution pages to identify the problem closest to yours, from emerging fraud intelligence to scam prevention or mule and destination risk
  3. Review the three technology pages covering AI agents, the fraud knowledge layer and the detection-as-code approach
  4. Request access to the benchmark sandbox with a business email address, if you work for a financial institution
  5. Use the sandbox to generate synthetic datasets, test your own detection rules against known scenarios and read the resulting gap report
  6. Download the playbook or a one-page fraud pattern brief to circulate the approach internally
  7. Open the contact form from the relevant solution or technology page, so the enquiry arrives already qualified
  8. Discuss where you stand in your fraud and AML journey so the company can propose an engagement model
  9. Start with a maturity assessment across the lifecycle to locate the structural gaps and sequence a roadmap
  10. Adopt incrementally: one typology family or one agent at a time, each with a measured baseline before the next
Quick read

Pros & Cons

Pros

  • Works with the stack you already own instead of demanding a rip-and-replace of monitoring, screening or case management
  • Detection logic stays yours: definitions live in your repositories, exports use open formats and no vendor lock-in is claimed
  • Runs inside the customer's own environment and data platform, with no data exfiltration required
  • AI governance is explicit: reasoning traces, cited sources, mandatory human approval and no autonomous case closure
  • Auditability is a first-class argument, with immutable change history and lineage from typology to production alert
  • Knowledge transfer is part of the pitch, so the institution is meant to operate the capability after handover
  • Substantial free material: a benchmark sandbox, a playbook, three fraud pattern briefs and a dozen dated articles

Cons

  • No pricing whatsoever is published: no plans, no ranges, no pricing page, so every evaluation starts with a sales conversation
  • APIs and webhooks are sold as a product capability but no public API documentation exists anywhere on the site
  • No named customers, reference logos, case studies with figures or testimonials
  • The scope of what is actually delivered is ambiguous by design, since the company itself answers that consulting and technology can both be part of an engagement
  • No named subprocessors and no customer-facing data processing agreement are published, and the privacy policy explicitly excludes contracted services
  • The site is entirely JavaScript-rendered: every route returns the same empty shell to anything that does not execute scripts, and there is no sitemap
  • No team, leadership or company history is presented, and no social media presence is linked from the site
Pricing

Pricing & Plans

No pricing is published. There is no pricing page, no plan list and no monetary amount anywhere on the site, and every call to action leads to a contact form for a quote. Commercial terms are therefore established engagement by engagement. Two things are available without a commercial commitment: a benchmark sandbox for testing detection rules, granted against a business email address and restricted to financial institutions, and downloadable material comprising a playbook and one-page fraud pattern briefs. No permanent free plan and no free trial of the commercial offer are announced.

Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Datavillage handles your data.

GDPR overview

GDPR implementation is documented in concrete terms. The privacy policy, effective 1 January 2025, states it is designed to comply with Regulation (EU) 2016/679 and attaches a lawful basis to each purpose: legitimate interest, contract performance, consent or legal obligation. All seven data subject rights are listed, from access and rectification through to withdrawal of consent, and are exercised at contact@datavillage.ai, with proof of identity possibly required. The Belgian Data Protection Authority is named and linked as the supervisory body. Transfers outside the European Economic Area rely on Standard Contractual Clauses, binding corporate rules or adequacy decisions. Security is described as an information security management system aligned with ISO/IEC 27001 — an alignment claim, not a certification. As the publisher is established in Belgium, no Article 27 representative is required.

Who owns the data?

The published privacy policy of Datavillage SRL, last updated on 1 January 2025, covers only data collected through the website and expressly excludes services delivered under separate contractual agreements. Within that scope the company states it does not sell or rent personal data, sharing it only with hosting, analytics and email providers, with authorities where legally required, and with auditors and advisers under confidentiality. Website content itself is owned or licensed by Datavillage SRL. For client engagements the site claims the opposite posture on ownership: control definitions stay in the customer's own repositories, work runs on the customer's data platform without exfiltration, and models export in open formats. No client contract is published.

Reuse rights

The terms allow visitors to view, download and print website content for personal, non-commercial use only. Any reproduction, modification, distribution, transmission, republication or display requires prior written consent from Datavillage SRL, so end users cannot freely reuse the material. For personal data, the site collects identity details, technical data, browsing behaviour and anything entered into forms, then processes it to answer enquiries, send marketing where consent is given, secure and measure the site, and meet legal obligations. Sharing is limited to service providers under GDPR data processing agreements, to legal and regulatory authorities, and to auditors, legal and compliance advisers. Automated decision-making or profiling producing legal effects is excluded, and the policy states the company does not sell or rent personal data.

Data retention & training

Retention summary
The privacy policy, effective 1 January 2025, states that data is collected only where relevant to the stated purposes and kept no longer than necessary. Contact form submissions are retained for up to twenty-four months. Marketing data is kept until consent is withdrawn. Analytics data follows the retention period defined by the provider, and data held for legal compliance is kept for as long as the law requires. Session cookies are deleted when the browser closes, while persistent cookies remain until they expire or are deleted. Erasure can be requested at contact@datavillage.ai as one of the seven listed rights. These periods apply to the website only: the policy expressly excludes services delivered under separate contractual agreements, so no retention period is public for client engagement data.
Trains on customer data
Unclear
GDPR contact

Hosting summary

No hosting country or region is declared for customer data. The privacy policy contains only a conditional clause stating that if personal data is transferred outside the European Economic Area, adequate safeguards such as Standard Contractual Clauses, binding corporate rules or adequacy decisions are applied. Sharing is described by category — hosting, analytics and email delivery providers under GDPR data processing agreements — without naming a single provider, so no subprocessor list exists. That silence is consistent with the delivery model described elsewhere on the site: the product is meant to run inside the institution's own environment, on its existing warehouse or lakehouse, with control definitions stored in its repositories and no data exfiltration required. Language models are described as model-agnostic, hosted or in-tenant, chosen with the customer's security team. In practical terms, the jurisdiction question is answered by the customer's own infrastructure rather than by the vendor, and nothing published resolves it for the marketing site's own contact data beyond the transfer clause above.

Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Datavillage.

  • The brand pivoted: until recently the same name and domain carried a confidential data collaboration and clean room positioning, so older third-party sources may describe a different product
  • ISO/IEC 27001 appears twice as an alignment claim, worded "aligned with" and "in line with" — it is not stated as a certification and should not be read as one
  • The regulatory frameworks displayed across the product, such as FATF recommendations, Wolfsberg principles, EBA taxonomies or PSD3 and PSR, are what the software works on or what the customer must meet, not accreditations held by the publisher
  • Handing triage, enrichment and evidence assembly to agents can erode the investigative instinct of analysts who stop reconstructing cases themselves, which is precisely the skill the tool depends on for its feedback loop
  • An assembled, confidently written evidence pack invites acceptance: reviewers under queue pressure may approve a proposed reading rather than test it, and the human approval gate then becomes a formality
  • No customer-facing data processing agreement and no named subprocessors are published, and the privacy policy explicitly excludes services delivered under contract
  • Because the site renders entirely in JavaScript and publishes no sitemap, its claims are hard to archive, index or verify independently over time
Setup

Setup & Integrations

Technical difficulty

High, and by design. There is no self-service sign-up: entry is through an engagement. Deployment means integrating with the institution's existing data platform, warehouse or lakehouse, monitoring and screening engines, case management, Git repositories, CI/CD and change management, and it assumes fraud, AML, data, product and engineering teams available to build alongside. A typical sequence begins with a maturity assessment and a roadmap spanning twelve to twenty-four months. Incremental adoption is possible, one typology family or one agent at a time. Only the benchmark sandbox is immediately accessible, against a business email address.

Deployment

API
Company

Behind Datavillage

Company name
Datavillage SRL
Founded
INFORMATION_NOT_FOUND
Country of origin
🇧🇪 Belgium
Headquarters
30B Cours Saint-Michel, 1040 Brussels, Belgium
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Legal contact
Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What is Fraud & AML Engineering?
It is the practice of continuously evolving the controls used to fight financial crime. It connects fraud intelligence, detection engineering, alert and investigation, and continuous improvement so that new threats, detection logic and investigation outcomes keep feeding each other instead of sitting in separate teams and tools.
What does Datavillage actually do?
It helps financial institutions build and connect those capabilities, from understanding emerging fraud typologies and engineering detection logic to improving investigations and learning from confirmed outcomes, combining financial crime expertise, engineering and AI.
Do we have to replace our existing fraud or AML systems?
No. The site states the approach is designed to work with the technology already in place, complementing existing transaction monitoring, fraud detection, case management and data platforms rather than requiring a rip-and-replace.
Where does the AI fit, and who decides?
Specialised agents cover typology monitoring, coverage analysis, indicator drafting, testing, investigation and improvement. Governance, validation and final decisions remain human: approval is required before any control change is deployed, and there is no autonomous case closure.
Is Datavillage a consultancy or a technology vendor?
Both, by its own answer. An engagement can mix designing a capability, engineering specific controls with your teams, and deploying technology and AI agents. The starting point is stated to be the problem to solve rather than a predefined software stack.
How much does it cost?
No price is published anywhere on the site. There is no pricing page and no plan list, so the commercial terms are set through a quote after contact.
Can we try anything before committing?
Yes. A benchmark sandbox is available on request against a business email address, restricted to financial institutions. It generates synthetic datasets, lets you test rules against known fraud and AML scenarios, and returns a performance report with gaps and recommendations.
Is there an API?
APIs and webhooks are claimed as a product capability on the AI agents and fraud knowledge pages, so that agents fit existing workflows and so monitoring and case tools can read and write the same knowledge. However, no public API documentation is published.
Where does the data live?
No hosting country or region is declared for customer data. The site instead describes running inside the institution's own environment and data platform, with no data exfiltration required and a choice between hosted or in-tenant language models.
Who publishes the tool?
Datavillage SRL, a Belgian company with enterprise number BE0720755134, listing offices at 30B Cours Saint-Michel in Brussels and Sluitstraat 79 in Leuven. The single published contact address is contact@datavillage.ai.
Conclusion

Should you pick Datavillage?

Datavillage makes an unusually coherent argument for a small vendor: that financial crime controls fail less because detection is weak than because intelligence, detection, investigation and improvement never form a loop. The material behind that argument is substantial and specific — a versioned knowledge layer linking typology to production alert, detection-as-code with review gates and backtests, six named agents with a narrow job each, and a consistent insistence that humans approve every material decision. The commitments that matter most to a regulated buyer are the structural ones: work runs inside your environment, control definitions stay in your repositories, and exports use open formats.

What is missing is everything a buyer normally uses to compare. There is no price, no plan, no reference customer, no case study with numbers, no service commitment and no API documentation despite APIs being sold as a capability. The company itself declines to say whether it is a consultancy or a technology vendor, answering that both can be part of an engagement — honest, but it means the scope of what you would actually receive cannot be established from the website. The published privacy policy covers the marketing site only and explicitly excludes contracted services, so nothing public describes how mission data is governed.

One further caution: the brand carried a completely different positioning around confidential data collaboration and clean rooms until recently, so older third-party write-ups may describe another product entirely. Treat the site as a well-argued starting point for a conversation with an institutional fraud or AML function, not as a product you can evaluate on paper. The benchmark sandbox is the cheapest way to test whether the engineering claims hold.