Pre-employment screening
Plausibility-check role-relevant applicant information and identify possible integrity, security or reputational issues before a hiring decision.
CV plausibility · professional history · public professional conduct
04 · Screening & Due Diligence
Manual OSINT research for defined people, compliance and business contexts — with a clear mandate, documented sources and human judgement. A professional service, not an automated tool.
Use cases
No indiscriminate data collection. Scope, necessity, exclusions, recipients and deletion are defined before research begins.
Plausibility-check role-relevant applicant information and identify possible integrity, security or reputational issues before a hiring decision.
CV plausibility · professional history · public professional conduct
Support a specific, documented concern during employment through tightly scoped open-source research — never continuous monitoring.
Specific trigger · defined question · proportionality
Research partners, customers, stakeholders or investors across open and official sources and surface material relationships, inconsistencies or reputational indicators.
Corporate links · ownership · adverse media · sanctions indicators
Understand your own digital traces and how they can enable social engineering, then prioritise practical safeguards.
Digital exposure · attack paths · prioritised measures
Support HR, compliance or security matters with structured, case-limited research and a documented evidence chain.
Hypothesis testing · source chronology · defensible assessment
Process
Purpose, decision context, legal responsibility and legitimate scope.
Criteria, sources, exclusions, retention and escalation paths.
Collect manually, challenge the source and corroborate where possible.
Report facts, uncertainty, contradictions and non-findings distinctly.
Use restricted access and an agreed deletion and follow-up process.
Client documents
The current order and data-processing templates are provided in German for mandates governed by German law. An English working version can be prepared for an agreed cross-border engagement. The supplied agreement template covers Proton Drive case folders. A different secure channel requires separately agreed contractual terms, safeguards and retention periods before any case data is transferred.
You receive an executive summary, a source matrix, documented uncertainties and points requiring clarification. We agree on scope and timing after reviewing the purpose, available sources and legal framework.
Secure case channelDo not send applicant, identity or investigation material through the public form or normal email attachments. Once scope and contract are approved, we agree on a time-limited, access-controlled transfer space or a separate Proton Drive case folder. Permitted data, recipients and the deletion date are recorded for the engagement.
Important questions
No. It is a personally conducted professional service. There is no automated risk score, black-box decision or automatic approval or rejection. The client retains the decision and legal responsibility.
Depending on scope, research may include public websites, professional networks, media archives, corporate or transparency registers and other lawfully usable open sources. Private accounts and access controls are not bypassed.
No. Public availability does not remove requirements for lawfulness, necessity, transparency and proportionality. Every engagement therefore begins with a written, limited scope; the client's legal or privacy function provides final approval.
Information duties under Articles 13 or 14 GDPR often apply. Timing, content and any exception must be assessed for the specific context. Process wording can be supported but does not replace legal advice.
No. Political opinions, religion, health, sexual orientation, union membership and other specially protected characteristics are excluded. Incidental findings are disregarded.
No. OSINT can support customer due diligence through source research, ownership analysis and adverse-media review. Statutory identification, risk classification, approvals and reporting remain with the obliged entity.
The delivery channel, recipients, retention and deletion are defined in advance. Reports are never made public. Working data is deleted after completion and the agreed follow-up period unless a documented obligation requires longer retention.
Next step
An initial conversation clarifies purpose, scope, jurisdiction and whether OSINT is an appropriate and proportionate method.
Discuss a screening need