One investigation intelligence platform for the whole organization.
Screening, deep investigations and cyber investigations on one engine, one evidence standard and one audit trail. Your teams share cases and templates; your administrators control who does what.
Talk to Enterprise SalesSecurity overviewSample reports
What is OSINTTotal Enterprise?
The same platform and engine as every OSINTTotal product, packaged for organizations: many users, shared cases, custom report templates, API access, governance controls and an annual contract with support. It is not a separate product, so a screening hit can escalate to a full investigation without leaving the case.
Who uses it?
Compliance and financial crime
KYB and enhanced due diligence at the depth of an investigation, with a file that holds at audit.
Corporate security and investigations
Insider, fraud and misconduct cases that cross people, companies and infrastructure.
Legal and deal teams
Counterparty, ownership and asset research with evidence a court or a board can check.
Security and CTI teams
External exposure and infrastructure investigations tied back to the people and companies behind them.
Available today
Every row below ships in the product now.
| Capability | What it does | Status |
|---|---|---|
| Isolated organization workspace | Row level security separates every organization in the database; the web app holds no credential that bypasses it. | Live |
| Members, invitations and roles | Owner, Admin, Analyst, Reviewer and Viewer, managed by your admins. | Live |
| Second factor at sign-in | Required for owners and admins; an admin can require it for every member. | Live |
| Hash-chained audit log | Append-only, each entry carries the previous entry's hash. Report versions, sign-offs, purges and API calls. | Live |
| Four-eyes sign-off | A reviewer who is not the analyst must sign off before a client report is released. | Live |
| Evidence preservation and export | Hashed captures, and an evidence pack zip with a manifest and the case's audit entries. | Live |
| API keys and MCP server | Scoped, expiring organization keys; five MCP tools behind the same case gate. | Live |
| Custom report templates | Your sections, labels, theme and logo, copied from base templates per report type. | Live |
| Report exports | PDF, DOCX and JSON, with an internal version and a client version. | Live |
| Continuous monitoring | Saved investigations re-run on a schedule and alert on material change. | Live |
| Retention and purge | A retention date on every case; a purge deletes its records and files. | Live |
| Multilingual collection | Queries run in the case's languages and jurisdictions. | Live |
On the roadmap
Not available yet. We list them so you can plan, and we will tell you plainly where each one stands.
| Capability | What it does | Status |
|---|---|---|
| SSO (SAML or OIDC) | Single sign-on with your identity provider. | Roadmap |
| SCIM provisioning | Automatic user provisioning and removal. | Roadmap |
| Proprietary source integration | Your own or licensed data sources, available only to your organization. | Roadmap |
| Compartmented cases | Access limited to named analysts within one organization. | Roadmap |
| Private deployment | A dedicated instance in a customer-controlled cloud or on premises. | Roadmap |
| Private model deployment | Analysis on a model hosted under the customer's control. | Roadmap |
How is it bought?
An annual contract sized by investigation and API volume, users and support. There is no public price; we scope it with you. Onboarding includes vetting of your organization, as for every customer.