Is OSINT Legal? And the Other Questions That Decide It
Short version first, then the detail. Collecting publicly available information is lawful in most jurisdictions, and legality turns on the source, the purpose, the jurisdiction and your lawful basis, not on the tool.
General information about how the category works. It is not legal advice.
- Passive collection only.
- Domains only, never a person.
- Not a consumer background check.
- The refusals are published.
The three answers people look for first
- We never touch the target.
- Collection is passive, from public records only. There is no active mode to enable.
- You cannot look up a person.
- The demo takes a domain and has no input that accepts a person. That is structural, not a promise.
- It is not a background check.
- Never for FCRA-regulated consumer decisions, and we refuse that use in writing.
Ten questions, including the ones with a no
The answers in full.
Open source intelligence is the collection and analysis of information that is already publicly available, and collecting public information is lawful in most jurisdictions. Legality turns on four things: the source, the purpose, the jurisdiction and your lawful basis. Reading a public DNS record, a company registry filing or a certificate transparency log is not the same act as accessing a system without authorization, scraping in breach of a contract you accepted, or processing personal data with no lawful basis under GDPR or a similar regime. Osintpro is built around that distinction: collection is passive and from public records only, and every case carries a written scope declaration so the purpose is on the record before the work starts. This is general information about how the category works and it is not legal advice. Take your own advice for your jurisdiction and your matter.
No. Collection is passive. Osintpro reads public records: DNS answers from public resolvers, RDAP and WHOIS registration data, certificate transparency logs, corporate registry filings and other public sources. It does not port scan, does not probe applications, does not attempt authentication, does not send traffic that a target would see as an attack, and does not need credentials. That boundary is what makes the tool usable on a vendor or an acquisition target you have no authorization to test. It is stated in full on the Security page.
No, and the demo has no input that would let you. The Domain Footprint demo accepts a domain and nothing else, which is a structural limit rather than a promise. Our acceptable use policy prohibits monitoring, profiling or locating an individual without a lawful basis, and prohibits harassment, stalking and any use intended to intimidate. Named refusals published in public are part of what makes this tool buyable inside a regulated organization.
Not for decisions regulated under the US Fair Credit Reporting Act, and not as a consumer background check of any kind. Osintpro is not a consumer reporting agency and its output is not a consumer report. Pre-engagement screening on this platform means authorized, consent-backed corporate screening of a business counterparty, with the basis recorded in the case scope. If you are making an employment, credit, insurance or tenancy decision about a consumer, use an FCRA-compliant provider instead.
Maltego is graph-first: it is very good at showing you how entities connect, and you still write the report by hand afterwards. SpiderFoot is collection-first: it will return hundreds of raw results, and the signal-to-noise work is yours. Both optimize collection. Osintpro optimizes what happens after collection. The unit of work is a scoped case rather than a query, every finding carries its raw record, its source endpoint and its UTC retrieval time, and the report is the native output rather than something you assemble at the end of the day.
Free tooling is genuinely good. theHarvester, Amass, the OSINT Framework directory and Shodan's free tier will collect a great deal, and every analyst should know them. The line where they stop is not collection, it is defensibility: no record of what you were authorized to look at, no retrieval timestamps you can prove, no chain from a claim back to the record it came from, no retention control and no report. As long as a finding has no consequences, free tooling is enough. The moment a vendor gets rejected or a claim goes to counsel, it is not.
That is the whole design. Every finding is emitted with three things attached: the raw record exactly as it was returned, the endpoint it was retrieved from, and the UTC moment of retrieval. The case header carries the scope you declared before collection started. Anyone reviewing the report can re-run the same lookup and compare. DNS records, registration data and certificates all change over time, which is exactly why a screenshot with no timestamp is an assertion rather than evidence.
It stays yours. Case data is retained for the window on your plan, 12 months on Analyst and 24 on Team, configurable on Practice and Enterprise, and you can delete a case at any time. We do not sell it, we do not use it to build a shared dataset, and we do not train models on it. Enterprise plans can choose the residency region. The Security page sets out what is collected, what is never collected and how deletion works.
Yes, on Enterprise. SAML 2.0 single sign-on with Okta, Entra ID or any compliant provider, SCIM provisioning so joiners and leavers follow your directory, granular roles, and an exportable audit log covering every case opened, every scope declared and every report exported. Those are the line items a procurement review asks for, which is why they are listed on the pricing page rather than hidden.
You confirm your address with a 6-digit code, and that opens an account with one free case in it: a real collection on one domain, with the scope record and the sourced, timestamped findings the paid report carries. Exports of the free case are stamped; Analyst exports them clean. On Analyst you pay by card on Stripe and the workspace opens straight away, with the private link mailed to the address on the subscription and 25 cases a month. On Team, Practice and Enterprise we write back with the next steps for getting set up on that plan. Coming back later takes nothing but the address: sign in sends a code to it, and there is no password.
Saying no, in public
What we refuse to help with.
Published so a buyer can hold us to it and an employee can point at it. The full list, with the reasoning for each line, is on social media OSINT.
- Monitoring or profiling an individual without a lawful basis
- Locating a private person or tracking their movements
- Consumer background checks under FCRA-regulated conditions
- Circumventing platform terms, rate limits or authentication
- Collection intended to harass, intimidate or retaliate
- Any active scanning or probing of a target's systems
Run one scoped sweep and see what a sourced finding looks like.
The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.
- Passive collection only, from public sources.
- A domain, never a person. There is no input for one.
- Your case data stays yours. No card required.