OSINT Platform Security and Data Handling
A real page rather than a footer link. What we collect, what we never collect, where case data lives, how long, how to delete it, and the collection boundary that is built into the product rather than promised in a call.
Vulnerability reports: security@osintpro.com
- Passive collection only.
- No active mode to enable.
- Never sold, pooled or trained on.
- Deletion on request.
The guarantee that matters most
Passive collection only, with no active mode.
Osintpro reads records that registries, public resolvers and transparency logs already publish. It does not scan, probe, authenticate or send traffic a target would see as an attack. There is no setting that changes this, because there is no active collection code to enable.
That boundary is why the platform can be pointed at a vendor or an acquisition target with a documented business purpose rather than a signed testing agreement. It is the same collection behind third party risk screening and attack surface management on your own estate.
Sources we read
- Public DNS resolvers over HTTPS
- RDAP and WHOIS registration data
- Certificate transparency logs
- Public company registry filings
- Public scan indexes, which record scanning already performed by their operator
Things we never do
- Port scan or probe an application
- Attempt authentication of any kind
- Circumvent a rate limit, a control or a platform term
- Accept an individual as the subject of a case
- Sell case data, pool it, or train models on it
What we hold, and for how long
Data handling, retention and deletion.
Case records and findings
- Why it exists
- The output you paid for, including the raw records retained as evidence
- Retention
- 12 months on Analyst, 24 on Team, configurable on Practice and Enterprise. Delete a case at any time.
Scope declarations
- Why it exists
- The audit trail that shows what each case was authorized to cover
- Retention
- Held for the life of the case, deleted with it.
Account and billing details
- Why it exists
- To run the account and issue invoices
- Retention
- For the life of the account, then as required by tax and accounting law.
Audit log
- Why it exists
- Every case opened, scope declared and report exported. Exportable on Enterprise.
- Retention
- For the life of the account, or per your configured policy on Enterprise.
Signup email address
- Why it exists
- To send you the confirmation code and write to you about your account
- Retention
- Until you ask us to remove it. Email contact@osintpro.com and it goes.
Your case data stays yours. We do not sell it, we do not pool it into a shared dataset, and we do not train models on it. Enterprise plans choose the residency region. What each module actually collects is listed on the OSINT analysis tools page.
Access, identity and audit
Controls available on Enterprise.
SSO and SAML
Okta, Entra ID or any SAML 2.0 provider
SCIM provisioning
Joiners and leavers handled by your directory
Roles and permissions
Who may open a case, who may sign one off
Audit log
Every case, every export, every scope declaration
Data residency
Choose where case data is stored
SLA
Written availability and support commitments
DPA
Signed data processing agreement
Invoicing and PO
Annual invoice, purchase order, net terms
Plan boundaries are on the pricing page. Enterprise includes a DPA, an SLA and security review support as standard.
Where a model is and is not used
Findings come from records, never from a model.
The line between what is derived and what is written matters more here than anywhere else on the site, so it is stated in full rather than summarized.
Every finding in a report is derived deterministically from a record that was retrieved, and the record travels with it. A language model is used for one thing only: writing the one-paragraph analyst summary from findings that already exist. If that call fails or is disabled, a deterministic summary is written from the same findings and nothing else changes.
A model never invents a finding, never grades a severity, and never sees anything a reader cannot also see in the report. That is deliberate: a finding you cannot trace back to a record is not evidence, whatever produced it.
Responsible disclosure
Reporting a vulnerability.
One address, a stated acknowledgement window, and the limits we ask you to work within, so a researcher knows where they stand before they start rather than afterwards.
Email security@osintpro.com with enough detail to reproduce. We acknowledge within two business days and will tell you honestly what we are doing about it and when.
Please do not test against other customers, do not access data that is not yours, and do not run denial-of-service testing. We will not pursue anyone who reports in good faith within those limits. There is no bug bounty program, and we would rather say that than imply one exists.
General contact: contact@osintpro.com, or every address we answer on the contact page. See also privacy and terms.
Run one scoped sweep and see what a sourced finding looks like.
The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.
- Passive collection only, from public sources.
- A domain, never a person. There is no input for one.
- Your case data stays yours. No card required.