Before you buy a company, take on a partner, or sign a major supplier, the other side controls what gets disclosed. Open-source intelligence (OSINT) due diligence adds an independent layer. We check public records, corporate registries, sanctions and watchlists, litigation, and adverse media to verify what you were told and surface what you were not. This work is confidential, so everything below is anonymized and generalized. We describe how we run it, not who we ran it for.
Private equity, M&A, and procurementOur clients for this work are investors, acquirers, and companies that are about to commit real money or reputation to a counterparty: an acquisition target, a joint-venture partner, a franchisee, or a large supplier. Standard due diligence leans on documents the target provides, management interviews, and disclosed contracts. That is necessary, but it only covers what the other side decides to show. OSINT due diligence is the independent counterweight. We research the same subjects from the outside, using public and openly licensable sources, then compare what we find against what was disclosed. Because engagements like this are confidential, we do not publish client names, target names, or specific findings. The account below is anonymized and describes the methodology and reasoning we apply on every engagement.
Document-driven due diligence has a structural blind spot: the target curates the file. Management presents its best case, legal review covers the contracts that were handed over, and financials reflect what was booked. Meanwhile a lot of material information lives in public records that no one on the other side has any reason to point you to: court and insolvency filings, regulator actions, corporate registry history, beneficial-ownership links, sanctions and watchlists, and years of news coverage. The questions that matter most are the ones a counterparty will never volunteer. Is there litigation or a regulatory action that was not disclosed? Do the people running the business have the track record they claim? Are the customer references and reviews real? Are there ownership links to entities or individuals that carry legal, sanctions, or reputational risk?
We run OSINT due diligence as a repeatable methodology, not an ad-hoc web search. Sourcing happens in layers, from official registries down to technical and archived web data. Every material finding is confirmed against at least two independent sources before it reaches the report, and anything we cannot verify is either dropped or clearly labeled as unconfirmed with a confidence level. The output is a structured, evidence-linked risk report that a deal team or investment committee can act on without a technical briefing. The sections below describe each part of that methodology.
We work outward from the most authoritative sources. Corporate and business registries and official gazettes come first, then court, insolvency, and regulatory records, then sanctions, watchlist, and politically-exposed-person data, then news and adverse-media archives, and finally technical and archived web data such as domain history and cached pages. Each layer answers a different question, and each is treated as a lead to confirm, not a conclusion.
For each entity we reconstruct the corporate picture from registry filings: incorporation history, directors and officers, share transfers, dormancy, dissolutions, and cross-border structures. We trace beneficial ownership to the people who actually control the business, then run every relevant name and entity against sanctions lists, watchlists, and politically-exposed-person data across the jurisdictions that matter. Ownership links are where undisclosed risk most often hides.
We search court and insolvency records, regulator enforcement actions, and long-tail news archives for each subject. Coverage is dated and put in context: an old, resolved dispute is not the same as active litigation or a recent enforcement action. We separate substantiated reporting from opinion and rumor, and we note when a subject appears in coverage under a variant spelling or a former company name.
This is where most of the real work sits. Common names, namesakes, and reused company names produce false matches constantly. We disambiguate people and entities using corroborating identifiers, confirm every material finding against at least two independent sources, and trace claims back to a primary record wherever one exists. Anything that cannot be confirmed is dropped or flagged as unconfirmed with a stated confidence level. We do not report rumor as fact.
Findings are organized by category (legal, financial, ownership, reputational, operational) and by severity, so a deal team can triage them fast. Every finding carries its source, the supporting evidence, a confidence level, and a plain-language explanation of why it matters. The report is written to plug directly into an existing investment-committee or procurement review, not to be re-interpreted by a specialist.
This is confidential work. We do not disclose client names, target names, or specific findings, and we do not reuse one engagement's data on another. Everything on this page is anonymized and generalized on purpose. Real deliverables are shared only with the client, under agreed data-handling and retention terms, and we can walk a prospective client through our approach without exposing anyone else's engagement.
Every engagement starts with a scoping conversation: who the subjects are, which questions the client actually needs answered, which jurisdictions are in play, and what has already been covered by standard due diligence so we do not duplicate it. From there, collection runs layer by layer, with a working evidence log for each subject. As leads come in, we disambiguate names, confirm material findings against independent sources, and trace claims back to primary records. We share preliminary findings early so the client can redirect the deeper dig where it will pay off, then deliver a structured risk report with severity ratings, confidence levels, and linked evidence. Delivery is secure, and data handling and retention follow terms agreed with the client up front.
Timeline: Scoped per engagement; typically days to a few weeks depending on the number of subjects and jurisdictions
Disclosure is controlled by the counterparty. OSINT due diligence is the independent layer that verifies what you were told and surfaces what you were not, from public records the other side has no reason to point you to.
The value is in verification, not collection. Finding a lead is easy; confirming it against independent sources, ruling out namesakes, and separating fact from rumor is the work that makes a finding safe to act on.
Litigation, insolvency, regulator actions, and beneficial-ownership links routinely sit in public records that document-driven due diligence never checks. That is exactly where undisclosed risk tends to hide.
Confidentiality is part of the product. We anonymize, we do not reuse data across engagements, and we agree data-handling and retention terms up front. That discipline is why clients trust us with sensitive work.
Format matters as much as content. Severity ratings, confidence levels, evidence links, and plain-language impact let a deal team or committee act on findings without a technical briefing.
Know what the public internet knows about your business, partners, and competition.
Learn more