Skip to content
Osintpro

OSINT Platform Security and Data Handling

A real page rather than a footer link. What we collect, what we never collect, where case data lives, how long, how to delete it, and the collection boundary that is built into the product rather than promised in a call.

Vulnerability reports: security@osintpro.com

  • Passive collection only.
  • No active mode to enable.
  • Never sold, pooled or trained on.
  • Deletion on request.

The guarantee that matters most

Passive collection only, with no active mode.

Osintpro reads records that registries, public resolvers and transparency logs already publish. It does not scan, probe, authenticate or send traffic a target would see as an attack. There is no setting that changes this, because there is no active collection code to enable.

That boundary is why the platform can be pointed at a vendor or an acquisition target with a documented business purpose rather than a signed testing agreement. It is the same collection behind third party risk screening and attack surface management on your own estate.

Sources we read

  • Public DNS resolvers over HTTPS
  • RDAP and WHOIS registration data
  • Certificate transparency logs
  • Public company registry filings
  • Public scan indexes, which record scanning already performed by their operator

Things we never do

  • Port scan or probe an application
  • Attempt authentication of any kind
  • Circumvent a rate limit, a control or a platform term
  • Accept an individual as the subject of a case
  • Sell case data, pool it, or train models on it

What we hold, and for how long

Data handling, retention and deletion.

Case records and findings

Why it exists
The output you paid for, including the raw records retained as evidence
Retention
12 months on Analyst, 24 on Team, configurable on Practice and Enterprise. Delete a case at any time.

Scope declarations

Why it exists
The audit trail that shows what each case was authorized to cover
Retention
Held for the life of the case, deleted with it.

Account and billing details

Why it exists
To run the account and issue invoices
Retention
For the life of the account, then as required by tax and accounting law.

Audit log

Why it exists
Every case opened, scope declared and report exported. Exportable on Enterprise.
Retention
For the life of the account, or per your configured policy on Enterprise.

Signup email address

Why it exists
To send you the confirmation code and write to you about your account
Retention
Until you ask us to remove it. Email contact@osintpro.com and it goes.

Your case data stays yours. We do not sell it, we do not pool it into a shared dataset, and we do not train models on it. Enterprise plans choose the residency region. What each module actually collects is listed on the OSINT analysis tools page.

Access, identity and audit

Controls available on Enterprise.

SSO and SAML

Okta, Entra ID or any SAML 2.0 provider

SCIM provisioning

Joiners and leavers handled by your directory

Roles and permissions

Who may open a case, who may sign one off

Audit log

Every case, every export, every scope declaration

Data residency

Choose where case data is stored

SLA

Written availability and support commitments

DPA

Signed data processing agreement

Invoicing and PO

Annual invoice, purchase order, net terms

Plan boundaries are on the pricing page. Enterprise includes a DPA, an SLA and security review support as standard.

Where a model is and is not used

Findings come from records, never from a model.

The line between what is derived and what is written matters more here than anywhere else on the site, so it is stated in full rather than summarized.

Every finding in a report is derived deterministically from a record that was retrieved, and the record travels with it. A language model is used for one thing only: writing the one-paragraph analyst summary from findings that already exist. If that call fails or is disabled, a deterministic summary is written from the same findings and nothing else changes.

A model never invents a finding, never grades a severity, and never sees anything a reader cannot also see in the report. That is deliberate: a finding you cannot trace back to a record is not evidence, whatever produced it.

Responsible disclosure

Reporting a vulnerability.

One address, a stated acknowledgement window, and the limits we ask you to work within, so a researcher knows where they stand before they start rather than afterwards.

Email security@osintpro.com with enough detail to reproduce. We acknowledge within two business days and will tell you honestly what we are doing about it and when.

Please do not test against other customers, do not access data that is not yours, and do not run denial-of-service testing. We will not pursue anyone who reports in good faith within those limits. There is no bug bounty program, and we would rather say that than imply one exists.

General contact: contact@osintpro.com, or every address we answer on the contact page. See also privacy and terms.

Run one scoped sweep and see what a sourced finding looks like.

The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.

See how a case runs
  • Passive collection only, from public sources.
  • A domain, never a person. There is no input for one.
  • Your case data stays yours. No card required.

Scope in, evidence out. The demo needs no card.