Security and trust
A report is only useful if it holds up when someone questions it. This is how we keep the evidence, the data and the customer list in order.
Evidence chain
Every captured page is stored with its SHA-256 hash, source address and retrieval time. Each finding in a report points to that capture, so a reader can see where it came from and that it has not changed.
Each organization has an append-only, hash-chained audit log. Report versions, sign-offs, purges and our own operator actions are recorded in it with the name of the person who acted.
Hosted in the EU
| What | Where |
|---|---|
| Database, sign-in and file storage | Supabase, Frankfurt (eu-central-1) |
| Collection and report rendering | Worker machines operated by OSINTTotal; results stored in Frankfurt |
| Web app functions | Vercel, Frankfurt (fra1), global edge for static files |
| LLM analysis, when switched on for a job | Anthropic, United States, under SCCs; inputs not used for training |
The full list, including the data sources that receive query terms, is on the sub-processors page.
Your cases stay yours
Row level security separates every organization in the database. The web app runs each query as the signed-in user and holds no credential that bypasses it. File downloads use links signed for 60 seconds.
Owners and admins sign in with a second factor. Data is encrypted in transit and at rest, and backups are encrypted.
DPA and sub-processors
We process case data for you under a data processing agreement. New sub-processors are announced 30 days ahead. You set a retention date on every case, and a purge deletes its records and files.
No resale of data
We do not sell personal data or collected evidence. Our terms also forbid customers from reselling raw data or building a people database from it. Finished reports go to your own client, for the purpose of the case.
Customers vetted before the first run
A new organization can sign in and set up, but cannot open a case until we approve it. We check that the legal entity exists and is active in its registry, that the website and email domain match it, that the stated use fits our Acceptable Use Policy, and we screen the entity and its owners against sanctions lists.
What the service is never used for
- US employment, tenant, credit or insurance screening (FCRA)
- Locating or contacting a person
- Investigating anyone under 18
- Collecting or inferring health, religion, sexual life, ethnic origin or other protected traits
- Reselling or bulk exporting raw data
- Leaked credentials, false identities or logging in where we hold no lawful access
Every case records its purpose, the decision it supports, its lawful basis and a retention date before collection starts. Read the full Acceptable Use Policy.