04 · Screening & Due Diligence

Assess the findings.
Support better decisions.

Manual OSINT research for defined people, compliance and business contexts — with a clear mandate, documented sources and human judgement. A professional service, not an automated tool.

Manual researchSource-basedPurpose-limited

Use cases

A precise answer to a legitimate question.

No indiscriminate data collection. Scope, necessity, exclusions, recipients and deletion are defined before research begins.

01

Pre-employment screening

Plausibility-check role-relevant applicant information and identify possible integrity, security or reputational issues before a hiring decision.

CV plausibility · professional history · public professional conduct

02

Employment screening

Support a specific, documented concern during employment through tightly scoped open-source research — never continuous monitoring.

Specific trigger · defined question · proportionality

03

Due diligence | AML | KYC

Research partners, customers, stakeholders or investors across open and official sources and surface material relationships, inconsistencies or reputational indicators.

Corporate links · ownership · adverse media · sanctions indicators

04

Security awareness

Understand your own digital traces and how they can enable social engineering, then prioritise practical safeguards.

Digital exposure · attack paths · prioritised measures

05

Internal investigations

Support HR, compliance or security matters with structured, case-limited research and a documented evidence chain.

Hypothesis testing · source chronology · defensible assessment

Process

Purpose first. Evidence second. Judgement always human.

  1. 01
    Define the mandate

    Purpose, decision context, legal responsibility and legitimate scope.

  2. 02
    Set the boundaries

    Criteria, sources, exclusions, retention and escalation paths.

  3. 03
    Research & verify

    Collect manually, challenge the source and corroborate where possible.

  4. 04
    Separate fact from judgement

    Report facts, uncertainty, contradictions and non-findings distinctly.

  5. 05
    Deliver securely

    Use restricted access and an agreed deletion and follow-up process.

Client documents

Scope before any real case data.

The current order and data-processing templates are provided in German for mandates governed by German law. An English working version can be prepared for an agreed cross-border engagement. The supplied agreement template covers Proton Drive case folders. A different secure channel requires separately agreed contractual terms, safeguards and retention periods before any case data is transferred.

Deliverables and schedule

You receive an executive summary, a source matrix, documented uncertainties and points requiring clarification. We agree on scope and timing after reviewing the purpose, available sources and legal framework.

Secure case channel

Do not send applicant, identity or investigation material through the public form or normal email attachments. Once scope and contract are approved, we agree on a time-limited, access-controlled transfer space or a separate Proton Drive case folder. Permitted data, recipients and the deletion date are recorded for the engagement.

Important questions

Clear limits before any mandate.

Is this an automated screening tool?

No. It is a personally conducted professional service. There is no automated risk score, black-box decision or automatic approval or rejection. The client retains the decision and legal responsibility.

Which sources are used?

Depending on scope, research may include public websites, professional networks, media archives, corporate or transparency registers and other lawfully usable open sources. Private accounts and access controls are not bypassed.

Is a background check automatically GDPR-compliant?

No. Public availability does not remove requirements for lawfulness, necessity, transparency and proportionality. Every engagement therefore begins with a written, limited scope; the client's legal or privacy function provides final approval.

Are applicants or other individuals informed?

Information duties under Articles 13 or 14 GDPR often apply. Timing, content and any exception must be assessed for the specific context. Process wording can be supported but does not replace legal advice.

Are private life or protected characteristics assessed?

No. Political opinions, religion, health, sexual orientation, union membership and other specially protected characteristics are excluded. Incidental findings are disregarded.

Does the service replace statutory AML or KYC checks?

No. OSINT can support customer due diligence through source research, ownership analysis and adverse-media review. Statutory identification, risk classification, approvals and reporting remain with the obliged entity.

How are results delivered and deleted?

The delivery channel, recipients, retention and deletion are defined in advance. Reports are never made public. Working data is deleted after completion and the agreed follow-up period unless a documented obligation requires longer retention.

Next step

Define the question before collecting data.

An initial conversation clarifies purpose, scope, jurisdiction and whether OSINT is an appropriate and proportionate method.

Discuss a screening need