Investigations

How an OSINT Investigation Actually Works: Method, Limits, and What a Firm Adds Beyond the Tools

Open-source work is mostly discipline rather than access. The tools return results; the method is what turns a result into something a board can act on, and what it can never turn into anything at all.

Fortaris Capital Advisors · September 30, 2026 · 14 min read

An investigator at a bare desk in a plain workroom, seen three-quarter with her face visible and her eyes on her hands, pressing the flap of an unmarked manila envelope closed, the small external hard drive it will hold lying on the desk beside her with its cable coiled next to it.
Provenance is a habit, not a recovery: the material sealed and logged at the moment of collection, because it cannot be reconstructed afterward.

The short answer

An OSINT investigation is a structured inquiry built from lawfully and publicly available material — registries, court and regulatory records, filings, archives, imagery and published content. It runs in a fixed order: scope the question, collect from primary sources, reconcile identity, corroborate independently, preserve provenance, and state plainly what could not be established.

What OSINT Is, and What the Word Has Come to Mean

Open-source intelligence is information collected from sources that are lawfully and publicly available, and analyzed into an answer. The definition carries two words that do a great deal of work. Publicly available means obtainable without circumventing a control — not merely findable by someone determined enough. Lawfully means the method of obtaining it was itself lawful, which is a separate question from whether the material sits on a public server.

The word has drifted. In common use it now often means "whatever can be found online," and a good deal of what is marketed as OSINT is really a subscription to an aggregator with a search box. That matters because the aggregator is the easiest part of the discipline to buy and the least consequential part of it to have. Everything that determines whether the output is usable — what was asked, where it came from, whether it is the same person, whether anything corroborates it, and what is missing — happens outside the tool.

It is worth stating the boundary early, because it is where the category's reputation is won or lost. Accessing an account that is not public, using a pretext to induce someone to grant access, or buying material somebody obtained improperly are not aggressive open-source techniques. They are a different activity with a different legal character, and the lawful space is large enough that there is no professional reason to enter it — the same logic that governs competitive intelligence.

Scoping: The Question Before the Search

Every open-source engagement that goes wrong goes wrong here. A search begun without a decision behind it produces volume, and volume is the enemy of a usable answer: it buries the two facts that mattered under four hundred that did not, and it consumes the budget that corroboration was going to need.

Competent scoping fixes four things before any collection starts. The decision the work has to support, stated as a question somebody is actually waiting on. The subject set, defined by identifiers rather than by names — entities with their registration numbers, individuals with dates and places of birth where known. The jurisdictions and languages in play, which determine which record systems exist at all. And the standard of proof, because the evidentiary bar for a board briefing is not the bar for a filing.

Scoping also sets what is out of scope, and saying so in the engagement letter is a discipline rather than a hedge. An open-source review of a company's ownership is not a review of its finances; a review of a principal's public record is not a background check governed by consumer-reporting rules. The wider discipline this work sits inside, and how it differs from a database screen, is set out in what investigative due diligence is.

  • The decision: the question the client is waiting on, written down before collection starts
  • The subject set: entities and people fixed by identifiers, not by name strings
  • The jurisdictions and languages: which record systems exist, and which of them are actually reachable
  • The standard: what level of corroboration a finding needs before it can be asserted
  • The exclusions: what this engagement is not, stated explicitly rather than assumed

Where the Material Actually Comes From

Most of an open-source answer is assembled from record systems rather than from the open web, and the proportion surprises people who have only ever used a search engine. The public record in a developed jurisdiction is deep, dull, and largely unindexed by the tools most people reach for first.

Corporate and beneficial-ownership registries establish who a company says it is and who it says controls it. Court records — federal and state dockets, pleadings, judgments, liens and bankruptcies — routinely place contracts, relationships and conduct on the public record in exhibits nobody expected to be read. Regulatory and licensing bodies hold enforcement histories, registrations and disciplinary records. Securities filings carry disclosures, related-party transactions and the names of the people who signed them. Property, permit and import records date and size physical things that press releases describe vaguely.

Published material is the second layer: media across the operating languages rather than English alone, trade press, archived versions of pages that have since changed, and material the subject published about themselves and later thought better of. Technical and geospatial records form a third: domain registration histories, commercially available imagery, and published infrastructure records that establish when something existed and where.

Two things about this list matter more than its contents. First, the great majority of it is free or nearly so, which is why an aggregator subscription is not what makes an investigation good. Second, almost none of it is in English-language search results by default, which is why jurisdiction and language competence do more for an answer than any tool. The most common practical application of the whole source set — establishing that a counterparty is what it claims to be — is walked through in how to verify a U.S. company before you sign.

Corroboration: What Turns a Result Into a Finding

A search result is not a finding. It becomes one by surviving three tests, in order, and an investigator who cannot say which test a given assertion passed is not in a position to assert it.

The first is identity. Name matching is the single largest source of error in open-source work, and it is worse across scripts and transliterations, worse for common names, and worse still where an aggregator has already merged two people into one record. Identity is reconciled on identifiers — dates and places of birth, registration and filing numbers, addresses over time, known aliases — and where it cannot be reconciled, the correct output is that it could not be.

The second is primacy and currency. An aggregator's summary of a filing is not the filing. Read the original where it was filed, note its date, and establish whether it has since been superseded — a dissolved entity, a vacated judgment, a lapsed registration and a settled matter all look identical in a cached summary and mean entirely different things.

The third is independence. One source is an assertion. Two sources that both derive from the same press release are still one source, and a great deal of apparent corroboration online is circular in exactly that way. Genuine corroboration comes from material that could not have been copied from the first source — a filing against a news report, a court exhibit against a company statement, an image's own metadata against a claimed date.

Diagram of a filter stack: a search result enters at the top and passes three tests — is it the same subject, is this the primary source and is it current, does a second independent source carry it — before it becomes a sourced, dated finding.
Three tests, in order. What fails one still belongs in the report, named as what could not be established.

Provenance: Why a Screenshot Is Not Evidence

Open-source material is uniquely perishable. Pages change, accounts are deleted, registries update in place, and the thing that supported a conclusion in March can be gone in June with no record that it was ever there. A finding that cannot be re-examined is a finding that cannot be defended.

The working standard is to preserve, at the moment of collection, enough to reconstruct what was seen: the original source location, the date and time of retrieval, the material itself captured in a form that has not been re-encoded, and a contemporaneous note of what it was collected for. Where the work may support litigation or a regulatory response, hashing the captured file at collection and logging custody from that point is what distinguishes a record from a recollection. The international reference point for this discipline is the Berkeley Protocol on Digital Open Source Investigations, developed with the UN human rights office, and it is worth reading whatever the subject matter.

A screenshot pasted into a report satisfies none of this. It has no verifiable source, no retrieval time, and no integrity guarantee, and its only evidential weight is the credibility of the person who produced it. That may be adequate for an internal briefing. It is not adequate when the question becomes contested, which is precisely when the file gets looked at.

  • The source location as it was, recorded in full rather than described
  • The retrieval date and time, captured at collection rather than reconstructed later
  • The material preserved in an unaltered form, hashed where the matter may become contested
  • A contemporaneous note of why it was collected and what it was taken to show
  • An unbroken record of who has held the file since

The Limits That Are Legal Rather Than Technical

The constraints that matter in practice are rarely about capability. They are about authority, and they are the reason a firm's method is worth more scrutiny than its toolset.

Access is the first line. Material behind a login, a paywall the investigator has not paid, or any other control is not public, and obtaining it with someone else's credentials is a different act with a different legal character under the federal computer-access statute. Gaining access under a false identity belongs in a different place again. Since Van Buren in 2021 and hiQ v. LinkedIn in 2022, a fabricated account or a breach of a site's terms is not clearly a federal computer-crime offense — but it does break the platform's terms, it can breach state law, and it can breach the rules of professional conduct where a lawyer directs it. Where the target is bank or telephone records, pretexting is prohibited outright by the Gramm-Leach-Bliley Act (15 U.S.C. § 6821) and by 18 U.S.C. § 1039. Related is inducement: persuading an employee, a former employee or an intermediary to hand over material they are obliged to keep confidential exposes the client, not only the researcher.

Purpose is the second. Where an open-source review will be used to make a decision about employment, credit, insurance or tenancy, federal consumer-reporting rules may govern the entire engagement, including notice and dispute rights, regardless of the fact that every underlying record was public. The correct time to establish that is at scoping, not at delivery.

Jurisdiction is the third. Personal data on individuals in Europe and a growing number of other regimes carries obligations that attach to the processing rather than to the source, and a lawful collection in one place can be an unlawful retention in another. None of this is exotic, and none of it prevents the work. It simply has to be decided before it is done, which is one of the things distinguishing a professional engagement from a search — as with any of the corporate investigation services a firm offers.

What Open Sources Cannot Tell You

The most valuable sentence in an open-source report is usually the one describing what could not be established, and the most common failure of an inexperienced one is that the sentence is missing.

Absence is the first trap. Nothing found is not the same as nothing there, and the gap between them widens sharply in jurisdictions with thin registries, sealed courts or a constrained press. A clean open-source picture of a subject in such a place establishes very little, and reporting it as reassurance is the most consequential error in the discipline.

Staleness and error are the second. Registries carry lapsed, superseded and simply wrong entries; aggregators propagate them and strip the dates that would have revealed the problem. The third is deliberate shaping: subjects with something to protect seed favorable material, litigate unfavorable material into removal, and rely on the fact that a researcher in a hurry reads the first page. A record that is unusually tidy is itself a finding worth a second look.

Attribution is the fourth and hardest. Establishing that an account, a company or a document is connected to a specific person is frequently the whole question and frequently not answerable from open sources alone. And the fifth is simply the offline world: what was agreed in a room, who actually directs a nominee, and what a former counterparty thinks are not in any record system, which is why the serious end of this work has never been purely open-source, and why it sits inside a broader corporate intelligence capability rather than standing alone. Cross-border asset tracing shows the same boundary from the other side.

What a Firm Adds Beyond the Tools

If the material is largely public and the software is widely available, the fair question is what a firm is actually for. The honest answer is that the tools produce results and almost everything else produces the answer.

Scoping converts a worry into a question that can be resolved. Jurisdiction and language competence determine whether the relevant record system is even consulted — a great many open-source reports on foreign subjects are, in effect, reports on the English-language internet. Primary retrieval means going to the registry, the docket or the regulator rather than reading a summary of it. Corroboration is labor, and it is the labor most often skipped. Provenance is a habit that costs nothing at collection and cannot be recovered afterward.

Then there is judgment, which is the part that does not automate. Knowing which of two hundred results is the one that matters; recognizing that a tidy record is a finding; knowing when the open-source picture has gone as far as it can and the question now needs a primary inquiry with a person; and knowing when to stop, because an investigation that cannot end is an investigation that was never scoped. A firm's value is concentrated in those judgments and in the fact that it will write down, and stand behind, what it could not establish.

That is also the practical test to apply to any provider, including this one. Ask how they scope, how they corroborate, how they preserve, and what their last report said it could not determine. Fortaris runs open-source work as one component of senior-led investigations rather than as a product, and the investigative practice it belongs to is built around the evidentiary standard rather than around the collection.

How to Read an OSINT Report

A report can be assessed without re-doing the work, and the tells are consistent. Look first at whether the language distinguishes what is established from what is inferred from what a source asserted. A document that presents all three in the same register is asking the reader to do the analysis.

Then look for dates: on the underlying records, not only on the report. Then for sourcing that identifies where a record was obtained rather than that it exists. Then for an explicit statement of limitations, including the jurisdictions where coverage was thin and the questions that remain open. Then for confidence levels on the judgments that carry weight.

Finally, look at what the report declines to say. A provider willing to write "we could not establish this, and here is why" is a provider whose positive findings are worth something. One that answers every question with equal confidence has told you how the work was done.

  • Established, inferred and asserted are visibly distinguished in the language
  • Records carry their own dates, and the retrieval dates are stated
  • Sources are identified by where they were obtained, not merely that they exist
  • Limitations are explicit: thin jurisdictions, unreachable systems, open questions
  • Material judgments carry confidence levels, and some questions are left unanswered

Key takeaways

  • OSINT is defined by two constraints rather than by technique: the material must be publicly available without circumventing a control, and the method of obtaining it must itself be lawful.
  • Scoping does most of the work. A search without a decision behind it produces volume, and volume buries the two facts that mattered and consumes the budget corroboration needed.
  • Most of the answer comes from record systems — registries, dockets, regulators, filings, permits — not from the open web, and rarely from English-language results by default.
  • A result becomes a finding by surviving three tests in order: identity reconciled on identifiers, the primary source read at its own date, and a second source that could not have been copied from the first.
  • Preserve provenance at collection — source, retrieval time, unaltered material, contemporaneous note — because a screenshot pasted into a report has no verifiable source and no integrity guarantee.
  • The limits are mostly legal rather than technical: access controls, inducement, consumer-reporting rules where the output drives an employment or credit decision, and data-protection obligations that attach to processing rather than to the source.
  • Nothing found is not nothing there. The most valuable line in an open-source report is usually the one stating what could not be established.

Frequently asked

8 questions

What is an OSINT investigation?

An OSINT investigation is a structured inquiry built from lawfully and publicly available material — corporate registries, court and regulatory records, securities and property filings, archives, published media and imagery — analyzed into an answer to a defined question. It is distinguished from a search by its order of operations: scope, collect from primary sources, reconcile identity, corroborate independently, preserve provenance, and state what could not be established.

Is OSINT just searching the internet?

No, and the gap is where most of the value sits. The great majority of a serious open-source answer comes from record systems — registries, dockets, regulators, permit and filing databases — that are largely absent from general search results, frequently not in English, and often not covered by commercial aggregators. The search engine is a starting point for a small part of the collection, not the method.

Where does OSINT cross a legal line?

At access and at inducement. Material behind a login or any other control is not publicly available, and obtaining it with someone else's credentials has a different legal character under the federal computer-access statute. A false identity is a separate question: since Van Buren in 2021 and hiQ v. LinkedIn in 2022, a fabricated account or a breach of a site's terms is not clearly a federal computer-crime offense, but access obtained that way still breaks the platform's terms, can breach state law, and can breach the rules of professional conduct where a lawyer directs it — and pretexting for bank or telephone records is prohibited outright by the Gramm-Leach-Bliley Act (15 U.S.C. § 6821) and 18 U.S.C. § 1039. Persuading someone to hand over material they are obliged to keep confidential exposes the client as well as the researcher. Purpose matters too: an open-source review used for an employment or credit decision may be governed by consumer-reporting rules regardless of how public the underlying records were.

How is an open-source finding corroborated?

In three steps. Identity is reconciled on identifiers rather than names — dates and places of birth, registration numbers, aliases and transliterations. The primary source is read where it was filed, with its own date, rather than an aggregator's summary. And a second source is sought that could not have been copied from the first, because two accounts that both derive from one press release are still a single source.

Why is a screenshot not enough?

Because open-source material is perishable and a screenshot carries no verifiable source location, no retrieval time and no integrity guarantee. If the finding is ever contested, its only weight is the credibility of whoever produced it. The working standard is to preserve the source location, the retrieval date and time, the unaltered material, and a contemporaneous note of what it was taken to show — hashing the file where the matter may become contested.

What can an OSINT investigation not establish?

That something does not exist; open sources are thin or closed in many jurisdictions, and a clean picture there proves very little. It also struggles with stale or erroneous records propagated without dates, with material that has been deliberately seeded or litigated into removal, and above all with attribution — connecting an account, entity or document to a specific person is often the whole question and often not answerable from public sources alone.

What does a firm add if the sources are public and the tools are available?

Scoping that turns a worry into a resolvable question; jurisdiction and language competence that determines whether the right record system is consulted at all; retrieval from primary sources rather than summaries; the labor of corroboration, which is the step most often skipped; provenance discipline that cannot be recovered after collection; and the judgment to know which result matters, when open sources have run out, and when to stop. Also the willingness to write down what could not be established.

How should I assess an OSINT report I have been given?

Check that its language distinguishes what is established from what is inferred from what a source asserted; that the underlying records carry their own dates and the retrieval dates are stated; that sources are identified by where they were obtained; that limitations and unreachable jurisdictions are named explicitly; and that material judgments carry confidence levels. A report that answers every question with equal confidence has told you how it was made.

Sources & further reading

  1. 01Berkeley Protocol on Digital Open Source Investigations (UN OHCHR and UC Berkeley Human Rights Center)The international reference standard for open-source methodology: collection, preservation, verification, and the professional and ethical obligations attaching to publicly available digital material.
  2. 02Computer Fraud and Abuse Act, 18 U.S.C. § 1030The federal computer-access statute that marks the boundary between reading what is publicly available and obtaining material by circumventing an access control or using credentials that are not yours.
  3. 03Gramm-Leach-Bliley Act, 15 U.S.C. § 6821, and 18 U.S.C. § 1039The two federal pretexting statutes: obtaining a person's financial-institution records, or their telephone records, by false pretenses is prohibited outright — the clearest legal line around access under a false identity, and one that does not depend on computer-access law.
  4. 04Fair Credit Reporting Act, 15 U.S.C. § 1681Governs reports used for employment, credit, insurance and tenancy decisions — a purpose test that can apply to an open-source review regardless of how public the underlying records were, and which belongs in scoping rather than in delivery.
  5. 05SEC EDGAR and U.S. Courts PACERSecurities filings and federal dockets — the two primary-source systems that carry more primary-source detail on companies and principals than any aggregated summary of them, including exhibits placing contracts and relationships on the public record.
  6. 06ACFE — Report to the NationsThe Association of Certified Fraud Examiners' recurring study of occupational fraud, widely cited on how schemes are detected and how they are concealed.
  7. 07EU General Data Protection Regulation (Regulation 2016/679)Obligations that attach to the processing of personal data rather than to its source, so a lawful collection in one jurisdiction can create an unlawful retention in another — a scoping question on any cross-border subject.

Related practice

Investigative Services

When the matter is real, Fortaris brings federal-grade investigative judgment to it — led by a Managing Director, in confidence.

Confidential intake

Send a confidential inquiry

Reviewed by a senior principal — usually the same day.

Your message is treated in confidence. For the most sensitive matters, call Kevin Cronin directly.

By providing a telephone number you agree that Fortaris may contact you about your inquiry by phone or text message. We do not send marketing texts. Message frequency varies; message and data rates may apply. Reply STOP to opt out or HELP for help. See our Privacy Policy and Terms.