Open-source intelligence
OSINTWhat you can find, before anyone else does
What could an attacker learn about you without breaking a single rule? We map the information that is already out in the open — about the organisation, about key people, about the other party in a deal — and deliver it as a source-critical report with stated confidence levels. You get an assessment you can act on. Not a pile of raw data.
Digital exposure
What can an attacker see from the outside?
We map what your organisation leaves behind in open sources: roles and responsibilities, suppliers, facilities, technology and working routines. It is the material an attacker would use to prepare — and the same material we use ourselves when preparing a physical penetration test.
Background checks
Before you hire or enter into a partnership
A structured check of what is publicly available about a person or a company you are about to commit to. We stay in open sources, work on a lawful basis, and write just as plainly what we could not confirm as what we could.
Due diligence
Individuals, companies and third parties
Ownership, relationships, history and public reputation mapped from open sources before you sign. Typically used ahead of an investment, a contract, a partnership or the onboarding of a new supplier into the value chain.
Threat assessment
Who poses a risk — and how likely is it?
Profiling of the actors and environments that could pose a threat to you: what they are after, how they operate, and what that means in concrete terms for your priorities. The assessment is written to go straight onto a management table.
Incident investigation
When something has already happened
Support for your own investigation after an incident, a breach or a leak: what exists in the open about the sequence of events, what can be placed in time, what connects — and where the gaps are that only you can close with internal data.
Key people and leadership
The risk around those who are most exposed
An assessment of the exposure that comes with being a director, a board member or publicly known — for the person and for those closest to them. We point out what is public, what it could be used for, and what can be removed or shut down.
What you receive
A report that can be passed on
The deliverable is written to be read by someone other than the person who commissioned it — a management team, a lawyer, an insurer or a security function.
Typical deliverables
- Structured intelligence report with executive summary
- Findings with source references and stated confidence levels
- Supporting data, artefacts and timelines
- Clear conclusions and actionable recommendations
- Delivered in a professional, client-ready format
Who is it for?
- Due diligence on individuals, companies or third parties
- Investigations into activity, exposure or risk
- Threat intelligence and threat actor profiling
- Incident response and breach investigations
- Insurance, legal, compliance and corporate security teams
- Private individuals seeking clarity and evidence
Commercial basis
An hourly rate, no hidden items
All prices exclude VAT. All prices are indicative and can be adapted to the client's specific needs and the complexity of the engagement.
Next step
Test the assumptions.
Find the way in.
A short conversation is enough to establish whether an OSINT engagement answers your question — and how much scope it needs. It costs nothing and commits you to nothing.