Skip to content

Trust you can check, not take on faith.

Buyers of investigations need to know three things: that a finding can be traced to its source, that the platform is used only for lawful work, and that their own case data stays theirs. Here is how each one is enforced, and where to read the detail.

Can a finding be traced to its source?

Yes. Every capture is stored unchanged with its SHA-256 hash, source address and retrieval time. Every finding cites those captures, carries a confidence label set by rule, and states whether it is a fact, an assessment or a hypothesis. Signed-off reports export as an evidence pack that a third party can verify.

Read the methodology

Does a person review the report?

A client report cannot be released until it passes the QA rules and a reviewer who is not the analyst signs it off. The database compares the two user accounts, so one person cannot do both.

Is there an audit trail?

Each organization has an append-only audit log in which every entry carries the hash of the one before it, so a removed or altered entry breaks the chain. Report versions, sign-offs, purges, API calls (refused ones included) and our own operator actions are recorded with who acted.

Who can use OSINTTotal?

Vetted organizations only. A new organization can set up its workspace but cannot open a case until we check that the legal entity exists and is active, that its website and email domain match, that its stated use fits the Acceptable Use Policy, and that the entity and its owners are not on sanctions lists.

Every case then records its purpose, the decision it supports, a lawful basis and a retention date before collection starts. Legal and ethical use

Where does case data live?

In the EU: database, sign-in and files in Frankfurt. Row level security separates organizations in the database itself. You set a retention date on every case, and a purge deletes its records and files. Security details

What if a sample names me?

The five product samples are fictional. Published samples on public subjects can be removed or corrected on request; a removal request normally hides the sample right away while we review it. Request removal or correction

What we do not claim

  • Security or compliance certifications. We hold none today and do not imply otherwise.
  • Government or defense deployments, or named customers.
  • Air-gapped, classified-ready, sovereign or on-premises deployment.
  • That automated findings are always right. Every report states its confidence, exclusions and gaps.

If a security questionnaire asks for something not on these pages, ask us and we will answer in writing.

Contact us

Trust | OSINTTotal