OSINT: what is public, but nobody assembles

OSINT stands for open source intelligence — deriving knowledge from publicly accessible sources. That sounds unremarkable, and it is. The value comes not from privileged access but from method: individual facts, each meaningless on its own, form a picture when assembled in the right order.

An example

A commercial register extract gives a business address. That address also appears for another company, liquidated two years ago. Its managing director at the time is connected through a professional network to the current authorised signatory. A press release from that period describes a dispute. Every one of those facts is freely available. Together they answer the question of who you are dealing with.

What we work with

  • Commercial, associations and insolvency registers, the Federal Gazette
  • Court decisions and official publications
  • Press and media archives
  • Professional and social networks, publicly visible content only
  • Domain and website history
  • Geodata and imagery from public mapping services
  • Sector databases and archives

Where OSINT ends

Publicly accessible does not mean: behind a login, inside a closed group, or obtained under a false identity. We do not create fake profiles to reach private content and we do not buy data from questionable sources. The reason is the same as everywhere in our work: such findings are legally worthless and create risk that outweighs their value.

When OSINT is the right instrument

Whenever a question can be answered from information rather than observation. That is more often the case than clients expect — and considerably cheaper than surveillance. We therefore check first, on every enquiry, whether research alone will suffice.

Outcome

A report with a timeline, a relationship map and a citation for every finding. Everything is verifiable — you can retrace each point yourself.

What OSINT is — and what it is not

OSINT stands for open source intelligence: the systematic evaluation of sources open to anyone. Commercial and association registers, insolvency notices, published judgments, tenders, trade directories, press, archives, public profiles and image material with analysable metadata.

What OSINT is not: hacking, buying data, or covert access to accounts or messages. Anything behind an access restriction stays out of scope. The value of the method lies not in reaching the hidden but in connecting the open correctly.

Why the connections matter more than the facts

A single entry rarely says anything. It becomes interesting when the same address appears at three companies, when a director changes position shortly before an insolvency, when a firm has published no accounts for years yet takes on major contracts. These patterns lie in plain sight — they simply go unnoticed by anyone not looking for them.

We work in a structured way: define the research objective, fix the sources, document the findings, flag the contradictions. Every statement in the report is backed by a verifiable reference. Assumptions are marked as assumptions, not presented as results.

What clients use it for

Before contracts and investments, to prepare proceedings, to trace assets before enforcement, to check partners abroad — and as a stage before surveillance, because good research often shows straight away whether surveillance is needed at all.

Where the matter concerns one person’s statements before a hire, a background check is the more direct route. Where it concerns events inside your own company, the route runs through corporate investigations.

What usually brings clients to us

Before entering a business relationship: who actually stands behind the company, since when has it existed, were there predecessor firms that were dissolved? Second, before enforcement: where might assets be found, are there holdings in other companies, property, vehicles?

Third, to prepare proceedings: what is already publicly documented about the facts, and does it contradict what the other side asserts? An assertion can often be shaken with open sources alone, before any evidence is formally taken.

What determines the scope

Scope depends on the number of people and companies to be checked, the countries involved, and how far back the connections should be traced. An initial check on one company is possible within one to two days; a branched structure across several countries takes considerably longer.

We deliver interim findings so you can decide whether going deeper is worth it. You receive the price before the assignment begins.

Frequently asked questions

Is OSINT legal?

Yes, provided only lawfully accessible sources are used and there is a legitimate interest in processing personal data.

How long does research take?

A focused enquiry usually two to five working days.

Can OSINT replace surveillance?

Often yes, where the question is one of information. Where it concerns actual conduct, no.

Related services