Company OSINT: How to Research a Business From Public Sources
Most open-source intelligence writing is about people — an email, a username, a phone number, and the identity behind them. But a large share of real investigative work starts with an organization: a vendor asking for payment terms, a counterparty in a compliance review, a brand impersonating yours, or a prospect you are deciding whether to pursue.
The method transfers. What changes is the entity you are resolving. Instead of asking who is behind this identifier, you ask what is this business, what does it operate, and does its public footprint support what it claims about itself.
This guide covers company OSINT as a repeatable process: the sources, the pivots, the corroboration discipline, and the limits.
Company OSINT vs. person-centric OSINT
The core loop is identical to any goal-based OSINT investigation: start from a seed, expand to connected artifacts, corroborate across independent sources, record confidence, and stop when the question is answered.
What differs is the artifact types you pivot through.
| Person-centric OSINT | Company OSINT | |
|---|---|---|
| Seed | Email, phone, username, wallet | Domain, legal name, brand |
| Core artifacts | Accounts, breach records, social profiles | Domains, registries, filings, listings |
| Strong link | Same identifier reused across platforms | Official cross-link between properties |
| Typical goal | Is this one real person? | Is this a real, operating business? |
| Main failure | Name collision between people | Brand vs. legal entity confusion |
That last row causes more bad conclusions than anything else. A brand is not a legal entity. One company can trade under five brand names; one brand name can belong to different companies in different countries. Keep the two separate in your notes from the first minute.
Step 1 — Fix the seed and resolve the entity
Start with the most specific identifier you have, and prefer a domain over a name. Names collide; domains do not.
From the official domain, capture the company's own claims before touching any third-party source:
- What it says it sells, and to whom
- The legal entity named in the footer, terms, and privacy policy
- Registered address, company number, and VAT/tax identifiers when published
- Contact channels and the domains those channels use
- Which markets, languages, and currencies it supports
The legal entity in the privacy policy is often the single most useful string on the entire site — it is the name that will match a registry record, while the brand name frequently will not.
Step 2 — Expand the domain footprint
A company's web presence is nearly always larger than its homepage. Product domains, documentation, status pages, staging environments, regional sites, help centers, and developer portals all extend the footprint, and each one is a source of evidence.
Work outward from the official domain through DNS records, certificate transparency logs, and the links the company itself publishes. This is a large enough topic that it has its own guide: how to map a company's domain and website footprint.
Treat a discovered property as related until you can say why. An official cross-link is strong evidence. Shared infrastructure alone is weak — thousands of unrelated sites share a CDN or a hosting provider.
Step 3 — Check the registry layer
Public company registries are the closest thing to authoritative ground truth, and their coverage varies enormously by jurisdiction.
Typical sources include:
- National company registers — incorporation date, registered address, status, directors, and filings, where the jurisdiction publishes them
- Aggregators — useful for finding which jurisdiction to look in, but always confirm against the primary registry
- Securities filings — for public companies, the richest available description of operations, segments, risks, and subsidiaries
- Trademark databases — brand ownership, which frequently reveals the legal entity behind a trading name
- Sanctions and enforcement lists — where relevant to your compliance obligation
Two cautions. A dissolved or dormant status is a material finding, but registry data lags reality — a company can be operating normally with a filing overdue, or defunct months before its status changes. And an address shared with hundreds of other companies usually means a registered-agent service, not a conspiracy.
Step 4 — Read the operating evidence
Registry records establish existence. They say little about whether a business actually operates. For that, look at artifacts a real operation produces as a by-product:
- Release notes and changelogs — dated evidence of ongoing product work
- Developer documentation and API references — depth here is hard to fake
- Package registries and public repositories — published packages, commit recency, maintainer accounts
- Status pages and incident history — a company with real customers publishes real incidents
- Job postings — roles, locations, and seniority reveal where investment is going
- App store and marketplace listings — review counts, update cadence, publisher name
- Partner directories and integration pages — relationships another party was willing to confirm
The strongest signal is not the existence of these artifacts but their recency and consistency. A documentation site last updated three years ago, a status page with no incidents ever, and a careers page listing roles that never close together describe something very different from an active business.
Step 5 — Corroborate across independent sources
This is where company OSINT either becomes evidence or stays a collection of screenshots.
For every material claim, ask: how many independent sources support it? The company's own homepage, its own about page, and its own press release are one source wearing three hats. A registry filing, a partner's website, and an app store listing are three.
The same discipline that governs entity resolution in identity graphs applies here: a link is only as strong as the evidence that two things are the same thing. Record the source and the date next to every finding, and keep conflicts visible rather than resolving them by preference.
Step 6 — Separate observation from inference
Write findings in two columns.
Observed: The privacy policy names a legal entity registered in 2019. Three product domains cross-link from an official group page. The changelog shows releases in each of the last four months. A careers page lists two roles in a new market.
Inferred: The company appears to be actively operating and expanding into that market.
The observation is source-backed. The inference is a hypothesis you could be wrong about. Keeping them apart is what makes the output usable by someone who was not there when you gathered it — and it is the difference between a report that survives review and one that does not.
What company OSINT cannot tell you
Public sources have hard boundaries, and pretending otherwise is how research becomes a liability:
- Revenue, runway, and customer counts are not public for private companies. Estimates from third-party sites are models, not measurements.
- Intent is never observable. A job posting is not a budget. An integration is not dissatisfaction with an incumbent.
- Absence of evidence is not evidence. A company with a thin public footprint may be small, private, offline-oriented, or in a jurisdiction with limited disclosure — not fraudulent.
- Registry data lags. Confirm status directly when a decision depends on it.
- Employees are people. Researching an organization does not license compiling personal profiles of the individuals who work there. Keep the investigation at the level of the business.
Where this goes next
Company OSINT serves three common goals, and each one deserves a different depth:
- Risk and due diligence — is this counterparty real, operating, and who it claims to be? See how to verify a company is legitimate.
- Fraud and abuse — is this business entity part of a pattern? The pivots resemble investigating fraud and abuse signals, with domains in place of identifiers.
- Commercial research — does this company have a credible reason to care about what you sell? That is the subject of the company intelligence guides.
Frequently asked questions
What is company OSINT? The practice of building a sourced picture of an organization from publicly available information — its official domain and connected web properties, public registry and filing records, app and marketplace listings, partner pages, developer artifacts, and its active public accounts. It is the same open-source method used in identity investigations, applied to a business rather than a person.
Is company OSINT legal? Collecting and reviewing publicly available business information is ordinary research and is broadly lawful. What is regulated is how you obtain and use it: stay within public sources, respect the terms of the platforms you use, avoid accessing anything restricted or authenticated, and follow the privacy and sector rules that apply to your decision — particularly where personal data or a regulated determination is involved.
Where do you start when you only have a company name? Find the domain first. Search the name with distinguishing terms, check trademark databases, and look for the entity in a company register to establish jurisdiction. Once you have an official domain, the rest of the footprint expands from it and name collisions stop being a problem.
How do you tell a real company from a shell? Not from any single record. Look for the by-products of operation and how recent they are: dated releases, maintained documentation, incident history, closing job postings, reviewed marketplace listings, and relationships that a third party has confirmed. A real operation leaves a trail across independent sources; a shell usually has registration and a website, and nothing that continues after them.
How long should a company investigation take? Match depth to the decision. Confirming a counterparty exists and is in good standing is a short task. Mapping a multi-brand group's structure, markets, and current activity is not. Set the question first, and stop when it is answered.
Investigate a domain
DefenceCore investigates domains and URLs the same way it investigates identifiers — following connected public signals and returning a sourced evidence map rather than a list of raw records.
→ Run an investigation · See a sample report
If you want the business-context version of this research — what a company sells, its products and connected websites, the markets it mentions, and its public records — DefenceCore is testing a manually prepared company intelligence review.