For REACH registrants, only representatives and consultancies

Your study reports, saved into IUCLID.

Upload a study report. Review the drafted record. Once you approve it, it is typed into the IUCLID tab you are already logged into, field by field. No server install, no REST API project, and no IUCLID credentials shared with anyone.

Works on any IUCLID reachable from your browser Nothing to install beyond a browser extension 7 day free trial

The genetic toxicity record in the video below was drafted for 0.61 EUR of model usage. Every job shows you its cost before you approve it. Access is 99 EUR a month for the whole organisation, however many people use it.

The problem

Dossier preparation is expert work buried under data entry.

A single robust study summary can mean transcribing dozens of fields from a study report into IUCLID by hand, picking the right entry from every phrase list, and getting the units right. The judgement takes minutes. The typing takes hours, and it is where the errors come from.

Transcription, not science

Every value in a study record already exists in the report. The work is finding it, mapping it onto IUCLID's field model, and typing it in without slipping a decimal.

Integration projects that never start

The IUCLID REST API is the textbook answer, and it requires enablement, server configuration and an IT project per installation. Most teams never get past that first meeting.

Credentials nobody wants to hand over

Any tool that logs into IUCLID for you needs an account, a password and a network route into your dossier repository. That is a conversation with your security team, every time.

When teams start using this

Nobody buys this on a quiet week.

The moment is almost always the same: a pile of study reports, a date attached to them, and the same number of people as last month. If one of these is your quarter, the rest of this page is worth ten minutes.

A deadline arrives

A compliance check or a substance evaluation decision lands, with a date on it and a list of endpoints to close.

Studies come back

A testing proposal is granted and the reports arrive from the laboratory in batches, faster than anyone can transcribe them.

The band changes

A tonnage band is crossed and a higher annex applies, so endpoints that were never populated suddenly have to be.

Dossiers are inherited

An acquisition, a transferred registration or a change of only representative brings in dossiers nobody on the team authored.

A portfolio is won

A consultancy signs a client with forty substances and has to staff it this quarter, at the price already quoted.

How it works

Four steps, and only one of them happens on your screen.

The cloud does the reading, the drafting and the bookkeeping. Your browser does the writing. Between the two sits a human decision that nothing can skip.

Upload and tag

Drop your PDF study reports onto a substance, picked from your own IUCLID inventory rather than a name you typed. Tag each file with the endpoints it covers, or let the AI propose the tags. One report can feed several endpoints, an OECD 422 being the obvious case.

Draft with AI

Claude Opus reads the report against the IUCLID field schema for that endpoint and drafts a complete study record as structured data. Scanned reports are transcribed first by Claude Haiku's vision model, so image-only PDFs are not a dead end.

Review and approve

The draft lands in a review queue with its authoring notes, its format check and its cost. Nothing is ever written into IUCLID before a person approves it. Every derived value is flagged as a draft for expert review.

Write into IUCLID

Open your IUCLID tab and click the toolbar icon. A side panel opens beside IUCLID, confirms it is on the right record, creates the study record if it does not exist, fills each field the way a person would, and reports field by field what it wrote back to your queue.

The Dossier Flow side panel beside IUCLID, showing Record written and reported back
                  to Dossier Flow.
Pairing, an approved job, the fields going in, the saved record. Recorded against an ECHA IUCLID Cloud test instance on a test substance, unedited and in real time.
A job in the Dossier Flow review queue. The substance, endpoint, source PDF, cost and
                format check are listed, followed by the authoring notes, and the Approve, Edit and
                Reject buttons.
The step that is not automated. A drafted record arrives with its authoring notes, its format check and what it cost to draft, 0.61 EUR in this case, and waits. Nothing reaches IUCLID until someone presses Approve.
How a study report becomes an IUCLID record A study report is uploaded to the Dossier Flow cloud, where a language model drafts a record and the result is validated against the IUCLID field schema. A person reviews and approves it, which produces an action plan. The browser extension executes that plan inside the user's own authenticated IUCLID session. The cloud never touches IUCLID. Our cloud Your computer the boundary Study report PDF you upload and tag Draft model reads it against the schema You approve a person, every single time Action plan add and fill only, no delete exists Extension checks the record, then types Your IUCLID your session, your login what was written is reported back to your queue
The credentials, the session and the dossier stay to the right of the line. The reading and the drafting stay to the left. The only thing that crosses is a plan a person approved.
Why this approach

The portability is the product.

Driving the interface the way a person does sounds like the crude option. In this market it is the one that actually reaches every installation, because it asks nothing of yours. Here it is beside the three things a team does today.

  Author it by hand Send it to a consultancy Build a REST API integration Dossier Flow
Setup on your IUCLID None None, or a shared account API enablement, server configuration, a project per installation None
Works on IUCLID Cloud Yes, by hand Usually in their instance, not yours Only where the API is exposed and reachable Yes, if your browser can reach it
Credentials required Yours, typed by you Often an account for someone outside your organisation A service account and a network route Yours, in your own session. We never see them
Time per study record Hours of transcription Days of turnaround, plus your review anyway Fast once built, months to build Minutes of review
Cost per study record Your specialist's hourly rate, times hours A line on an invoice, per record The build, amortised over the dossiers that follow Under a euro of model cost for many records, plus the flat fee
Who carries the regulatory judgement Your expert Shared, and argued about at submission Whoever wrote the mapping, months ago Your expert. Approval is a person, every single time
Human sign off before writing Implicit At the end, on work you did not watch Depends on the integration Structural. Approval is what releases a write
Deployment footprint None None Servers, middleware, maintenance One browser extension
What you keep if you stop Everything Everything, once they hand it over Everything, and an integration to keep maintaining Ordinary IUCLID records in your own dossier. No wrapper, no export, nothing that stops working

Nothing here is a criticism of consultancies. Plenty of teams will keep using one, and this is what a consultancy runs internally to make that work pay.

The architecture

The boundary is drawn at the page, not at your data.

Dossier Flow never connects to your IUCLID. It has no address for it, no account on it and no route to it. The only thing that touches IUCLID is a browser extension acting inside the session you opened yourself.

Our cloud

The brain and the library

Holds your substances, your tagged reports and your drafts. Runs the authoring models against the IUCLID field schema, validates the result, and emits an action plan once you approve it.

  • Each organisation's data isolated at database and file storage level
  • Source PDFs deleted once every endpoint they were tagged to is resolved
  • Passwords, sessions and tokens stored hashed, never in the clear
Your browser

A pair of hands, nothing more

The extension picks up plans you approved and writes them into the IUCLID tab in front of you, keyed on IUCLID's own stable field anchors. It refuses to write if the open record is not the one the plan is for.

  • Your IUCLID address, username, password and session never leave your machine
  • No blanket host permission. It knows two addresses: your Dossier Flow service, and the IUCLID address you allow it once
  • No analytics, no advertising, no tracking, no other website touched
IUCLID open in a browser with a genetic toxicity in vitro record on screen and a
                picklist open. The Dossier Flow side panel sits to the right, naming the endpoint and
                substance and reading Writing the fields: 29 of 96.
The boundary, as the user sees it. IUCLID on the left is their own session, logged in by them. The panel on the right names the endpoint it is working on and counts the fields as they go in, and closing it stops the run.
Non destructive by design

It can add to your dossier. It cannot take anything out of it.

This is not a policy we promise to respect, it is the whole vocabulary the extension has. An approved plan can open a tab, create a study record, create a data source reference, fill a field, add a repeatable block entry, and save. There is no delete operation, no clear operation and no way to express one, so no plan can ever ask for a deletion.

When a record for that endpoint already exists, the extension reopens it rather than duplicating it, and writes only the fields the plan names. Anything else in that record is left exactly as it was. If it finds more than one existing record, it stops and asks you, because guessing which one was meant is not a decision software should take with your dossier.

A wrong record is a hard stop

Before a single field is written, the extension checks that the record on screen matches the approved plan. A mismatched substance stops the run outright and is never auto-recovered from.

Nothing fails silently

Every field is reported back: written, skipped because IUCLID had it read only, or missed. The result is recorded against the job, so a gap shows up in your queue rather than at submission. If the browser interrupts a run, the extension reads back its own note in the page and reports what it managed to write instead of repeating it, which is what keeps an interruption from turning into a duplicate record.

IUCLID stays the system of record

Nothing is submitted to ECHA on your behalf and nothing is saved that you did not approve. IUCLID's own Save is the commit point, exactly as it is when you type by hand.

For your IT and security team

Written to survive a security review, not to dodge one.

You are being asked to let a tool near your registration data and to accept that a language model reads your study reports. Both deserve a specific answer rather than a reassuring one. The short version is here. The long version, with every extension permission and its justification, is a page of its own.

What we do not hold

The shortest part of any review is the attack surface that does not exist.

  • No IUCLID URL, hostname or IP address for your installation
  • No IUCLID account, password, API key or session token
  • No inbound connection to your network, no firewall rule to open, no VPN
  • No card data. Payment runs on Stripe's hosted pages, never through our forms

The model reads. It does not act, and it does not decide.

The question everyone asks, answered in three lines.

  • It has no network access to your systems, no credentials and no way to trigger an action
  • Its output is checked against the IUCLID field schema, then approved by a person
  • Drafting runs under commercial API terms that do not use your content to train models
  • bcrypt passwords, hashed tokens, CSRF on every form, CSP and HSTS, every query scoped to your organisation

Seven extension permissions, each with a reason your reviewer can check.

activeTab, scripting, storage, sidePanel, notifications, alarms and debugger, with what each one is for, why no blanket host permission is granted, and why no code is fetched at runtime. Running a formal vendor assessment? Send us the questionnaire and we will return it completed.

Coverage

108 endpoints across four IUCLID chapters.

Study records, the endpoint summaries that roll them up, and the hazard assessment values that close a chapter. All authored through the same draft, review and approve loop.

4 Physicochemical properties
Melting and boiling point, vapour pressure, water solubility, partition coefficient, granulometry, nanoform properties and more
39
5 Environmental fate and pathways
Hydrolysis, biodegradation in water, soil and sediment, adsorption and desorption, bioaccumulation, phototransformation, monitoring data
18
6 Ecotoxicological information
Short and long term aquatic toxicity, algae, sediment and soil organisms, birds, bees and terrestrial plants
21
7 Toxicological information
Acute toxicity, irritation and corrosion, sensitisation, repeated dose, genetic toxicity, carcinogenicity, reproduction and development, human data
30

Endpoint study records

One record per study report and endpoint, drafted against that endpoint's own IUCLID field schema. Materials and methods, results, applicant summary and conclusion, guideline and GLP status, all in their proper fields.

Endpoint summaries

Once a section's studies are in, Dossier Flow drafts the endpoint summary that rolls them up, from the records themselves rather than from the PDFs again. It reads the section's existing contents back out of IUCLID first, through the same extension, so records that were entered some other way are weighed in rather than ignored.

DNEL, DMEL and PNEC derivations

Chapter level hazard assessment values derived with the ECHA guidance defaults, R.8 for human health and R.10 for the environment. Every assessment factor and derived value is flagged as a draft for your toxicologist or ecotoxicologist to confirm.

A completed Genetic toxicity in vitro record inside IUCLID, showing the applicant's
                summary and conclusion and an executive summary describing an Ames test performed to
                OECD TG 471 under GLP.
What is left behind: an ordinary IUCLID record, in your dossier, indistinguishable from one typed by hand. No wrapper, no proprietary format, nothing that stops working if you stop subscribing.

Supported today: IUCLID 6, version 10.0.0. Support for a new IUCLID release is published as a version pack on our side, not as software you have to reinstall. Tell us which version you run and we will confirm where it stands.

For consultancies and only representatives

If you sell dossiers at a fixed price, this is a margin question.

Your cost is your people's time and your price was agreed months ago. Transcription is the part of that cost that buys you nothing, and it is the part your client will never pay more for.

More dossiers per person

The judgement stays with your regulatory staff, where your clients think they are paying for it. The transcription stops consuming the same hours. Your throughput moves without your headcount moving, and the work that scales is the work you would have turned down.

Their IUCLID, not yours

Records are written inside whichever IUCLID session is open in front of the person doing the work, so a client who insists their dossier never leaves their own instance is accommodated rather than argued with. You do not become the custodian of their confidential studies, and you do not need an account on their system.

One price, whatever the portfolio

A flat organisation fee and metered drafting, with no seat counting and no per-dossier surcharge. Taking on a client with forty substances does not change what the tooling costs you, which makes it easier to quote one.

Working through a security review before you can trial anything, or authoring for several client organisations at once? Write to us and we will go through how it is set up.

Pricing

One subscription, plus the AI you use.

A flat access fee per organisation, and drafting credits you top up as you use them. No seat counting, no per-dossier surcharge, no annual commitment. Most records cost well under a euro to draft, and every job shows you its price before you approve it, so a dossier is never a surprise on an invoice.

Access
99 EUR per month, per organisation

Excluding VAT. Billed monthly, cancel any time.

  • No seat counting. Invite your whole team, owner and member roles
  • Every endpoint, summary and derivation in all four chapters
  • The browser extension, on as many browsers as you pair
  • 7 day free trial with 2 EUR of drafting credit, no card needed to start
Sign up for the free trial
Drafting credits

Pay for the AI you use

Drafting a record calls a large language model, and that has a real cost. Rather than hide it in a bigger subscription, we bill it through a wallet you top up. Every top-up is credited to your wallet in full, and drafting is billed at the model cost plus a small service margin. Every job shows what it cost before you approve it, so the price of a dossier is never a surprise.

10 EUR 25 EUR 50 EUR 150 EUR 500 EUR

Consultancies and larger teams

Producing dossiers for several clients, or working through a formal security review before you can trial anything? Write to us. We will answer the questionnaire and discuss what your setup needs.

Contact us
Your own arithmetic

We are not going to tell you what you will save.

We do not know your rates and we are not going to invent them. Put your own numbers in and the page does nothing but multiply. Nothing is sent anywhere, this runs entirely in your browser.

By hand, at your rate 16,200 EUR 180 hours of a specialist's year
With Dossier Flow, review plus drafting plus subscription 3,948 EUR 30 hours of review, 60 EUR of credits, 1,188 EUR of access
Difference 12,252 EUR and 150 specialist hours back

Your figures, your arithmetic. The only number we supply is the access fee. If the result does not justify it for your volume, it does not, and we would rather you saw that here.

Questions

What people ask before they trial it.

Do you need access to our IUCLID installation?

No. We never ask for its address, an account on it, or a network route to it. The extension works inside the IUCLID tab you opened and logged into yourself, which is why it works the same on IUCLID Cloud, on a server behind your firewall and on a local installation.

What happens to our study reports?

They are stored while they are being worked on, and used to draft the records you review. Once every endpoint a report was tagged to has been approved, the stored file is deleted. A rejected draft keeps its source for a short grace period so you can retry without uploading again. Excerpts are sent to our AI provider for drafting and are not used to train models.

Can it write something we did not approve?

No. An approval is what turns a draft into an action plan, and the extension only ever executes plans that carry one. Before writing it verifies that the record open in front of you is the record the plan targets. A wrong substance stops the run and is never recovered from automatically.

Can it overwrite or delete work we already have in IUCLID?

It cannot delete. The instruction set an approved plan can express is limited to opening a tab, creating a record or a reference, filling a field, adding a repeatable entry and saving. No delete or clear operation exists in it. Where a record for that endpoint is already there, the extension reopens it instead of duplicating it and writes only the fields the plan names, which will replace the content of those specific fields exactly as typing into them would. Everything else in the record is untouched, and more than one existing record stops the run.

Can the AI act on our IUCLID by itself?

No, and not because we forbid it. The model has no network access to your systems, no credentials and no mechanism to trigger anything. It reads a report and returns structured data. That data is checked against the IUCLID field schema, then a person approves it, and only an approval produces something the extension will execute. Remove the human and the pipeline stops at a draft.

What happens if the browser interrupts it half way through a record?

It reports rather than repeats. The extension keeps its own note of what it has written inside the IUCLID page, so when you reopen the panel it reads that note back and tells you what it managed to do, instead of starting again and creating a second copy of the same study record. In the rare case where the page it was writing into is gone and nothing can be confirmed, it says so plainly, names the record for you to check, and leaves the decision with you. It never guesses and it never writes over what it cannot see.

What does one study record actually cost to draft?

Less than most people expect. The genetic toxicity record shown further up this page cost 0.61 EUR of model usage. A long repeated dose or reproductive toxicity report costs more, because there is more of it to read and more to write. Every job prints its own cost in the review queue before you approve it, and your wallet balance is on screen throughout, so the figure is never something you find out afterwards. That is on top of the flat 99 EUR monthly access fee, which does not vary with how much you author.

How accurate is the drafting?

Accurate enough to be worth reviewing, never accurate enough to be trusted unread. That is the whole design. Drafts arrive with authoring notes, a schema format check, and explicit flags on every derived value. The reviewer is the quality gate, and the tool is built to make that review fast rather than to remove it.

Our study reports are scanned, not digital text. Does that work?

Yes. When a report's pages carry no extractable text, those pages are transcribed by a vision model before drafting starts, and the resulting record is flagged so you know to check the transcription along with the interpretation.

Which IUCLID versions do you support?

IUCLID 6, version 10.0.0 today. Version support lives in a pack on our side rather than in software you install, so a new release is something we publish, not something you upgrade. If you run a different version, tell us and we will give you a straight answer on timing.

Are you affiliated with ECHA?

No. IUCLID is published by the European Chemicals Agency. Dossier Flow is an independent product and is not affiliated with or endorsed by ECHA.

What does a team need to get started?

An account, a browser, and the reports. Create your organisation, add the people who will review, install the extension in the browser you use for IUCLID, and pair it once with a short code that an owner confirms. That is the whole setup.

See it on one of your own studies.

The fastest way to judge this is to run it against a report you already know by heart. Start the trial and draft your first record, or write to us and we will walk through it with you.

Not ready to sign up? Ask for the security pack and a walkthrough on a call, or send your vendor questionnaire and we will return it completed: contact us