Dotfile
Dotfile is a Paris business verification platform founded in 2021 by Vasco Alexandre and Titouan Benoit inside the startup studio Hexa, formerly eFounders, with a second office in San Francisco and a presence in London opened in 2024. It sells an end to end know your business platform that assembles a picture of a company from dozens of data sources in around ten seconds, drawing on more than 400 million global business records. The platform is organised in two halves. A customer lifecycle layer covers data orchestration, a configurable risk engine, an integration studio, case management and a white label client portal.
A data intelligence layer covers business data and beneficial ownership discovery, anti money laundering and sanctions screening, online reputation scoring, identity verification, and a product called Dotfile Autonomy. Solutions are packaged for business onboarding, individual onboarding, perpetual monitoring, back book remediation and fraud detection. It states that automated document verification and corporate structure analysis cut manual review time by roughly 80 percent, and it sells specialised risk scoring for cryptocurrency businesses alongside readiness features for the European MiCA regime.
More than 50 customers across ten countries include banks, private equity firms and fintechs, among them Spendesk, Younited Credit, Flowdesk, Keyrock and Roundtable. It raised 2.5 million euros in a seed round backed by V13 Invest, the corporate venture arm of the French lottery operator, alongside Serena, Kima Ventures, Pareto Holdings and Super Capital, then 6 million euros led by Seaya Ventures in September 2024. It names its data supply chain openly, taking registry coverage from Kyckr and electronic identity verification across more than 45 countries from GBG, and runs a trust centre on its own subdomain.
Capability Axes
Capability grades
15 of 15 axes rated · 5 graded A or B
An orchestration spine with a genuine analytical layer on top, which puts it a full grade below the agent native vendors in this pocket. The removal test is what decides it: strip the models and data orchestration, the integration studio, case management, the client portal, the configurable rule based risk engine and access to more than 400 million business records all survive as a working compliance platform.
What the models add is real but separable, covering automated document verification, corporate structure analysis, reputation scoring and the product marketed as Dotfile Autonomy. Held above a C, which is rare in this index and reserved for genuinely peripheral AI, because the analysis is central to the ten second verification claim rather than decorative. This is the same shape as the channel platform rule applied elsewhere: a working spine that added models, not a model that grew a spine.
Traceability is the stated design principle, with the company summarising the platform as verifying any business and defending every decision, every signal orchestrated and every decision traceable. Case management sits in the product as a named module, so a human review stage exists in the path by construction, and the claim that automation cuts manual review time by around 80 percent implies the remaining share still reaches a person.
The risk engine is configurable by the customer, which puts the decision thresholds in the institution's hands rather than the vendor's. Held at B because none of the controls are described: no threshold is published for what the automated path may conclude alone, no escalation or abstention rule appears, and the product named Dotfile Autonomy implies autonomous operation without any published account of what bounds it.
The published figures measure work removed rather than decisions made correctly. An 80 percent reduction in manual review time and a ten second verification are throughput claims, and neither speaks to whether the corporate structure analysis, the document verification or the risk scoring is right.
No accuracy rate, no false positive or false negative figure, no benchmark, no evaluation methodology, no model documentation and no validation material for a customer's own model risk function was located. For a platform selling into regulated institutions that are themselves expected to validate the financial crime models they rely on, that is the disclosure a buyer would most want and none of it exists publicly.
Five named customers and two quantified claims, and as with several vendors in this index the two are never joined. The named customers are real and checkable. The numbers, a business verified anywhere in the world in around ten seconds and manual review time cut by roughly 80 percent, are stated as platform properties rather than as results measured at a named institution.
No case study attaches a figure to a customer, no processing volume is published, and no independent party has published a result. That is the B bar met and the A bar missed by the same gap that separates most of this pocket from an A.
Nothing states whether customer data, uploaded documents, analyst decisions or verification outcomes are used to train or improve models or scoring served to other customers. The question is live because the platform aggregates from shared upstream sources and applies risk scoring across a common corpus of more than 400 million business records, so improvements derived from one institution's activity could plausibly reach another.
Nothing addresses retention of the personal data of directors and beneficial owners collected during verification, or what happens to an institution's accumulated case history when it leaves. Vendors in other pockets have answered this plainly, so it is answerable.
A privacy policy and terms of service, and a substantial body of published writing about European data protection obligations aimed at customers rather than describing the vendor's own handling. No subprocessor list, no retention schedule, no deletion commitment and no data processing agreement terms were located.
The gap matters more than usual here because the platform ingests beneficial ownership data, identity documents and directors' personal details across many jurisdictions, and because the company routes that material through named third party suppliers, so a buyer would want the onward processing terms stated rather than inferred.
A standing trust centre exists on its own subdomain, which is the artifact this index looks for and is more than a badge row, but no certification was located in the vendor's own accessible material and a targeted search for its security credentials returned nothing about this company. Recorded as a genuine not found rather than not looked for, on the same basis as quartr.
This is a grade that could move: the portal is the obvious place a SOC 2 attestation or ISO certification would sit, and confirming its contents is the single cheapest check available on this vendor. Until then nothing is credited, because a portal whose contents are unverified is a route to evidence rather than evidence.
A software supplier outside the regulatory perimeter. No licence, registration, supervised sandbox participation or regulator run scheme was located. Its customers hold the anti money laundering obligations and answer to supervisors such as the French financial intelligence unit; the vendor supplies the tooling and holds neither.
Its published regulatory expertise, covering the French digital asset regime and the MiCA transition, is subject matter knowledge rather than regulatory standing, and this index has consistently kept those separate.
No fairness disclosure, no evaluation across jurisdictions or business types, no governance certification. Two exposures are specific enough to be worth naming. The first is common to this pocket: sanctions and politically exposed person matching performs unevenly across scripts, transliterations and naming conventions, so some people are flagged for how they are named rather than for what they have done. The second is particular to this vendor and sharper.
Online reputation scoring is sold as a named product, and a business is then partly judged on its web presence, which systematically disadvantages newer companies, companies operating in languages with thinner online coverage, and companies in markets where less business activity is documented online. Nothing published examines whether that signal performs evenly across the countries the platform covers.
The business being verified carries the consequence and has no relationship with the vendor. A company wrongly scored on reputation, wrongly resolved in its ownership structure or wrongly matched against a screening list may be delayed or refused an account without ever learning that a vendor's analysis produced the outcome, and nothing published describes how such a finding is contested or corrected, or whether a correction reaches other institutions that ran the same check.
The regulated customer absorbs the supervisory consequence of a decision assembled from suppliers and models it did not build, and no allocation of responsibility between the vendor, its data suppliers and the institution is stated anywhere.
A distinction worth recording because it cuts against the usual pattern in this index: this vendor names its DATA supply chain openly, identifying Kyckr for registry coverage and GBG for electronic identity verification across more than 45 countries, and names nothing at all about its MODEL supply chain.
No provider, family or version appears for the components performing document verification, corporate structure analysis or reputation scoring, and no third party provider case study naming this vendor was located. A company willing to tell buyers where its data comes from and unwilling to say where its inference comes from is treating the two as different classes of dependency, and only one of them is disclosed.
A named integration product, the integration studio, sits in the platform alongside an API first architecture, and the company names the suppliers it draws on rather than describing them generically: company registry coverage from Kyckr and electronic identity verification across more than 45 countries from GBG. Naming upstream providers is a real disclosure and most of this pocket does not do it.
Held below an A because the named connections are data suppliers feeding the platform rather than systems of record on the customer's estate: no core banking platform, no customer relationship or case management system, and no loan origination or payments system is identified as an integration target.
A multi tenant cloud application reached through an API and a hosted portal, with no published deployment or residency choices: no region selection, no cloud provider named, no on premise or private option, and no statement of where customer data or the personal data of verified directors and beneficial owners physically rests.
The company is French with a United States entity and routes data through suppliers in multiple jurisdictions, which makes the absence of a residency statement more consequential rather than less, since a buyer cannot tell from published material whether European personal data stays in Europe.
No pricing published: no list price, no tier structure, and no statement of whether the platform is charged per check, per verified entity, per seat or by subscription, which matters here because the platform bundles many separately metered upstream data sources and the cost basis determines whether a buyer can predict spend. Every commercial route terminates in a demo booking. The company publishes extensive material on what compliance costs institutions in general while publishing nothing about what its own product costs.
More than 50 customers across ten countries spanning banks, private equity firms, fintechs and digital asset businesses, with five named: Spendesk, Younited Credit, Flowdesk, Keyrock and Roundtable. The cryptocurrency segment is addressed specifically rather than generically, with risk scoring built for digital asset service providers and features aimed at the French PSAN regime and the MiCA transition. Offices in Paris, London and San Francisco.
Held below an A on scale: the customer count is modest, no institution count or processing volume is published, and the base is concentrated in France and continental Europe with the American and British expansions recent.
Alternatives to Dotfile
The closest documented capability profiles to Dotfile in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
A lighter documented profile than Dotfile
A lighter documented profile than Dotfile
Documents Deployment Model and Data Residency where Dotfile does not
Documents AI Safety and Data Stewardship where Dotfile does not
Stronger documented coverage on AI Centrality
Stronger documented coverage on Operational and Outcome Evidence and Institution and Segment Coverage
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.