Duna
Duna is a business identity platform for regulated companies, automating know your business, know your customer, customer due diligence and anti money laundering checks during onboarding. The platform collects and structures company data, routes checks to third party data providers, applies real time risk scoring and runs automated audit trails. Its stated direction is a shareable digital passport for every business, evolving into a network where one verification is reused across institutions for one click onboarding. Buyers are banks, fintechs, payment infrastructure providers and regulated platforms, concentrated in Europe.
Capability Axes
Capability grades
15 of 15 axes rated · 4 graded A or B
The company describes itself as AI native throughout and the models do real work: extraction and structuring of company documents, real time risk scoring, smart routing that decides which third party data provider to query for a given jurisdiction and entity type, and automated audit generation. The removal test still returns a product.
Strip the models and what remains is an onboarding orchestration platform with a good applicant interface, configurable workflows and connections to registry and screening providers, which is a real and saleable thing. This is the Alloy shape, where models sit on top of a decision and routing engine rather than constituting it, and it earns the same grade for the same reason.
Automation is the pitch and the oversight model is undescribed. Real time risk scoring, smart routing and automated audits are named, and the outcome claims are all throughput and conversion, but no review queue, escalation path, approval threshold or analyst adjudication surface appears in public material.
The decision being automated gates a business's access to a bank account, a payment facility or a marketplace, and the founder's own framing acknowledges that legitimate customers are refused today. Nothing describes what happens to a business the system cannot verify, whether an alternative evidence route exists, or who reviews a refusal. Compare Persona, which earns an A on this axis specifically for step up verification that routes a failing applicant into an additional evidence path instead of rejecting them.
No accuracy figure, validation evidence, false positive or false negative rate, or model documentation was located anywhere. The published numbers are throughput and conversion, which measure how fast and how many rather than how often the system was right, and the two can move together while correctness falls.
Automated audits are named as a feature, which is the platform auditing the onboarding process rather than anyone auditing the models that drive it, the same distinction recorded for Elysian's claim review product. For output that supports a regulated institution's customer due diligence file, no validation support or documentation package is offered.
Strong for a company founded in 2023 with 21 to 50 staff. Named customers span the buyer set rather than clustering in one segment: SVEA Bank and Brand New Day Bank on the bank side, Plaid and CCV, a Fiserv subsidiary, in payments infrastructure, plus Moss, Sequra and Bol. Outcomes are quantified and unusually specific for an early company, with customers reported as achieving onboarding 10.6 times faster, 4.8 times productivity gains and up to 38 percent higher onboarding conversion.
More than 40 million euros raised across a seed led by Index Ventures and a 30 million euro Series A led by CapitalG, Alphabet's growth fund. What holds this at B is that the outcome figures are presented as aggregates of what customers report rather than attributed to a named institution with a quoted executive, and estimated annual revenue of roughly 2.5 million dollars puts the deployed footprint well behind the naming.
The stated destination is explicitly a cross institution data architecture: a digital passport for every business, evolving into a network for shareable identity and one click onboarding. That is the most consequential stewardship question a vendor in this lane can raise and none of the governing terms are published.
No statement of who owns a passport, whether the verified business or the institution that paid for the verification, no consent or opt out mechanism, no account of what a receiving institution sees versus what the originating one holds, and no description of how a passport is corrected or revoked. Buyers are adopting ahead of terms that do not exist yet, which is the same shape recorded for Feathery's roadmap data network. The benchmark answers to compare against are DiligenceVault consent, Saphyre permissioning and DwellFi tenant containment.
No data protection agreement, retention schedule, subprocessor list or deletion commitment was located, and a company based in the Netherlands and Germany sits inside the European data protection regime by default. The payload deserves an explicit account that does not exist.
Know your business work resolves beneficial ownership, which means collecting identity documents and personal details for directors and ultimate beneficial owners who are individuals with no relationship to Duna and often no knowledge that a verification is running.
The shareable passport direction sharpens this further, because reuse of a business passport across institutions carries the personal data of those individuals with it, and nothing published states whose consent governs that reuse or how it is withdrawn.
No attestation, certification, trust centre or dedicated security page was located, and no service organisation control report or international information security standard certificate is announced or offered on request. That is a visible gap for a vendor holding identity documents and beneficial ownership records on behalf of licensed banks, and it is the first item a bank vendor risk review raises. Peers in this lane set a clear bar: Sumsub and Incode both hold and publish accredited presentation attack detection certification, and Rulebase names attestations alongside residency.
The regulatory domain is named clearly and repeatedly, know your customer, know your business, customer due diligence and anti money laundering for regulated institutions, and the company states its intent to maintain the high regulatory standards banks require. What is absent is any named instrument, supervisor or admission process.
No reference to the European anti money laundering directives or the new anti money laundering regulation and authority, no national supervisor named, no registration or accreditation, and no mapping of which obligation each product step discharges. Naming the acronyms of a regime is describing the market, not stating a regulatory position. Duna holds no licence and needs none, which is the correct posture for a technology supplier under the index convention.
One genuine credit, then the gap. The founder names refusals of legitimate customers as a real cost alongside fraud and fines, and the platform measures a 38 percent conversion improvement, which means wrongful exclusion is treated as a tracked business outcome rather than an externality. Most identity vendors market false positive reduction purely as analyst efficiency. The gap is that no analysis of which businesses are refused is published.
The AiPrise finding applies directly: registry completeness, name matching, transliteration and adverse media coverage all perform worst in exactly the jurisdictions and for exactly the business types that are already underserved, so error rates are not evenly distributed and a conversion average conceals that. No per market accuracy, no false positive rate by jurisdiction or entity type, and no statement on how thin digital or registry footprints are treated.
No guarantee, indemnity or falsifiable accuracy commitment was located. Two things keep this off the floor. The affected party is a business rather than an individual, so it has more capacity to contest a refusal than a declined consumer, and the vendor's incentive is genuinely aligned because it sells conversion improvement, which means a wrongful refusal is a metric it is trying to reduce. Against that sits a risk specific to the roadmap and worth stating plainly.
Today a business refused by one institution can approach another, and that second independent assessment is the de facto appeal. A shared passport reused across the network removes it: an error, a stale registry record or an adverse media false match propagates to every participant at once, and the business's existing remedy, going somewhere else, is precisely what one click onboarding is designed to eliminate. Nothing published describes correction, revocation or challenge of a passport.
The architecture is described, the parties are not. Smart routing to third party data providers is a core capability, which means registry, screening and adverse media sources sit in the decision path for every check, and not one of them is named anywhere. No model provider, hosting arrangement or subprocessor is disclosed either, and whether company documents and beneficial ownership records reach an external model provider during extraction is unstated.
This is the fourth party question a bank examiner asks directly, and the comparison in this lane is unflattering: Alloy names more than 270 data partners each with its own page and lets the customer choose its chain, while Sumsub names specific screening providers under bring your own key.
Smart routing to third party data providers is the substantive integration story: registry, screening and enrichment sources are selected per jurisdiction and entity type rather than the customer wiring each one, which is the same architecture that earns Alloy its position and removes real integration work from the buyer. Dynamic applicant interfaces and configurable workflows sit on top.
What is not evidenced is the other direction: no named integration to a core banking platform, case management system or customer relationship system was located, so a bank cannot confirm how verification outcomes land in the systems its analysts and examiners actually work in. No individual data provider is named either, which is where Alloy earns its A on supply chain and Duna does not.
No cloud provider, region selection, residency commitment or private deployment option was located. For a European vendor selling to European banks the default assumption is regional hosting, but assumption is not disclosure, and the shareable passport direction makes the question harder rather than easier because a network for reusable identity implies data held centrally and accessible across institutions and borders. Nothing published describes where a passport lives or which jurisdictions it crosses when reused.
No pricing, packaging, tiers or basis of charge is published and every route into the product is a contact or demo request. Nothing indicates whether charging is per verification, per seat, per platform or a hybrid, and in this category that matters because the underlying third party data provider calls carry their own per check cost that a buyer inherits.
That is the orchestration cost stack problem first recorded with Alloy, and it is a category wide transparency gap rather than a Duna specific failing. Sumsub remains the benchmark with published per verification rates.
The stated buyer set is large banks, fintechs, platforms and financial institutions, and the named customers bear that out across five distinct shapes: licensed banks, payment infrastructure, a payment terminals and acquiring business owned by a major processor, spend management, buy now pay later and marketplace. Built under the Persona precedent, where financial services is a named and separately maintained segment even though platforms outside financial services are also served.
The limit is geographic rather than segmental: the footprint and the registry coverage that matters most are European, with the company based in the Netherlands and Germany, and no equivalent depth is evidenced in North America or Asia.
Alternatives to Duna
The closest documented capability profiles to Duna in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Documents Autonomy and Oversight Model where Duna does not
Documents Autonomy and Oversight Model where Duna does not
Stronger documented coverage on AI Centrality
Documents Autonomy and Oversight Model and Deployment Model and Data Residency where Duna does not
Documents AI Governance and Bias Disclosure and Security Certifications and Trust Center where Duna does not
A lighter documented profile than Duna
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.