Skip to content

Legal and ethical use

OSINTTotal is for professional investigations with a lawful purpose, run by vetted organizations. The controls below are not small print. They are why a report from the platform can be shown to a regulator, a court or a board.

Read the Acceptable Use PolicyTerms of ServicePrivacy Notice

Who can use the platform?

Organizations we have vetted. Before the first case we check that the legal entity exists and is active in its registry, that its website and email domain match it, that its stated use fits the policy, and that the entity and its owners are not on sanctions lists. We can re-vet at any time.

What purposes are allowed?

Each organization is approved for one or more of these, and each case must fit one:

  • Know your business: customer, partner or supplier onboarding
  • Third-party and supply chain risk review
  • Investment, M&A or lending due diligence
  • AML, sanctions or anti-bribery compliance
  • Fraud, corruption or misconduct investigation
  • Litigation support or asset tracing by or for counsel
  • Security exposure review of your own organization and its staff
  • Pre-engagement screening outside the US, with the candidate informed

Investigating a person is allowed only inside one of these purposes, for example the directors and owners of a company you are onboarding.

What happens before a case runs?

Every case records its purpose, the decision the report supports, a lawful basis and a retention date. Runs cannot start without that record, and the person starting a run attests to it; the attestation is stored with the job. API keys follow the same gate.

What is never allowed?

  • Stalking, harassment, or surveillance of a person outside a lawful professional engagement
  • Locating or contacting a person, or tracing someone in order to approach them
  • Investigating anyone under 18
  • US employment, tenant, credit or insurance screening, or any other purpose under the FCRA
  • Collecting or inferring health, religion, sexual life, ethnic origin or other protected traits
  • Pretexting, logging in under a false identity, or accessing systems or accounts without authorization
  • Using leaked credentials or buying leaked datasets
  • Reselling, licensing or bulk exporting collected data, or building a people database from it

Collection itself stays on public and lawfully accessible sources. Breach data is used only as a reported indicator that an account was exposed; we do not view or test leaked credentials.

How is source provenance kept?

Every finding cites stored captures with their source address, retrieval time and SHA-256 hash, and every source is graded by class. Methodology

How is misuse detected and handled?

Report versions, sign-offs, purges and API calls are written to a hash-chained audit log per organization. Queues and searches are rate limited. We may ask about any case, its gate and its use. If we believe the policy was breached we can suspend the organization at once: cases and jobs stop, data stays readable for export, and the suspension and its reason go in the audit log.

What is the customer responsible for?

  • Keep the case purpose and lawful basis accurate. A wrong one is a breach of the policy.
  • Collect only what the decision needs, and turn off modules you do not need.
  • Have an analyst review every report before it is used.
  • Give people the notice the law requires, or record why an exemption applies.
  • Set the shortest retention that fits the purpose, and purge the case when it ends.

What can a person named in a sample do?

Ask us to remove or correct a public sample. A removal request normally hides it right away while we review it. The privacy notice explains the rights of people whose data appears in investigations.

Remove or correct a samplePrivacy Notice

Legal and ethical use | OSINTTotal