How OSINTTotal turns data into defensible intelligence.
A finding is only useful if someone can check it. OSINTTotal ties every statement in a report to stored evidence, says how sure it is and why, and shows what was searched and came back empty. The rules below are the ones the platform runs, not a description of intent.
AI handles investigative legwork. Investigators make or review high-impact intelligence judgments where the engagement requires it.
Eleven steps from mandate to signed report
- 01
Define the mandate
Before any collection, the case records its purpose, the decision the report supports, a lawful basis and a retention date. Runs cannot start without it.
- 02
Resolve the target
Identifiers such as registry numbers, domains, emails and handles anchor the subject. Same-name results that do not match are labelled as namesakes and excluded, and an adverse finding needs a probable identity match or better before it can appear.
- 03
Collect relevant sources
Native connectors run first, then the most reliable sources in the catalog, in the case's languages and jurisdictions. Collection is passive: public and lawfully accessible sources only.
- 04
Generate and prioritize pivots
Names, companies, domains and handles found along the way become new leads. A discovered value is used as a query only after a well-supported finding names it, so a guess cannot pull in more evidence.
- 05
Correlate entities
People, companies, domains and accounts are linked, and each link cites the record it came from.
- 06
Verify material relationships
Every finding is checked against the stored text it cites: the names, dates, numbers and identifiers it states must appear in its quoted evidence. Findings that cannot be traced are dropped. A check can lower confidence, never raise it.
- 07
Preserve evidence
Each capture is stored unchanged with its SHA-256 hash, source address and retrieval time, and gets an evidence reference. The position and hash of each quote are kept, so a finding can be re-checked against the stored bytes later.
- 08
Assign confidence
Every finding gets a confidence label and every evidence item an Admiralty grade, both set by rule. The tables below give the thresholds.
- 09
Identify contradictions and gaps
Contradicted findings are marked and must be explained. Categories that came back empty are reported as empty, with the reason: no verified hit, not publicly verifiable, needs a manual or paid source, or the source failed.
- 10
Produce the assessment and report
QA rules check the draft before it can be signed off. Errors block release: universal negatives such as "has no criminal record", speculative or motive language, an unverified claim worded as an accusation, a found result without evidence. Warnings go to the reviewer: a hypothesis with no counter-hypothesis, an unexplained contradiction, an uncited sentence.
- 11
Expert review
A client report cannot be released until a reviewer who is not the analyst signs it off. Both names and the sign-off time go on the cover, and the evidence pack export refuses an unsigned version.
How is confidence assigned?
Each finding carries two scores from 0 to 100: how sure we are that the evidence is about this subject, and how well the evidence supports the statement. The label comes from the weaker of the two.
| Label | Rule |
|---|---|
| Confirmed | Identity and claim both score 85 or more |
| High | The weaker of the two scores is 70 to 84 |
| Medium | The weaker score is 50 to 69. Findings resting only on search snippets stop here (capped at 60) |
| Low | The weaker score is below 50. A finding whose quotes do not contain the names or numbers it states is capped here |
| Claimed | The subject says it about themselves and nothing independent confirms it |
Every finding is also marked as a Fact, an Assessment or a Hypothesis. An inferred relationship is never written as a fact.
How is each source graded?
Every evidence item gets an Admiralty code such as B2, set by rule rather than by judgment. The letter is the reliability of the source class; the number is how well other, independent sources support the same claim.
| Grade | Class | Typical sources |
|---|---|---|
| A | Authoritative | Official registries, courts, regulators, sanctions lists |
| B | Established | Reputable media, archives, standard DNS and certificate records |
| C | Aggregator | Third-party databases and indexes that repackage other sources |
| D | Self-published | The subject's own website, profile or filing text |
| E | Anonymous | Forums, pseudonymous posts |
| F | Search snippet | A search result excerpt without the page behind it |
| Grade | Rule |
|---|---|
| 1 | Two or more other independent sources support the same claim |
| 2 | One other independent source supports it |
| 3 | No other source supports it (6 instead for anonymous sources and snippets) |
| 4 | Another source contradicts it |
| 6 | Truth cannot be judged: the item supports no claim |
Independence is checked, not assumed. Copies of one story count once: captures with the same hash, or the same article path on different sites, are one source. A page that repeats the subject’s own text is not independent, and neither are aggregators or search snippets.
How is evidence preserved?
Each captured page or document is stored unchanged with its SHA-256 hash, source address and retrieval time. Re-running a case does not duplicate evidence. Findings point to evidence references, and the exact quote each finding relies on is stored with its position and its own hash.
A signed-off report can be exported as an evidence pack: the report, every cited capture, a manifest of hashes, sources and retrieval times, and the case’s entries from the hash-chained audit log, so a recipient can verify it independently.
How are gaps and contradictions shown?
A report lists what was checked and came back empty next to what was found. Empty results are labelled no verified hit, not publicly verifiable, requires a manual or paid source, or not searched because the source failed. They are never written as proof that something does not exist.
When sources disagree, the finding is marked as contradicted, and the reviewer is warned until it is explained. A hypothesis should state the alternative that would explain the same evidence; the QA check flags one that does not.
What this does not do
It does not make the platform infallible. Confidence labels describe the evidence, not the truth. Public sources are incomplete, registries lag, and some facts are not public at all. That is why every report states its exclusions and gaps, and why a person signs off before it is released.
See it in a report
The five fictional samples show these labels, grades and gaps on every finding.