Skip to content
Osintpro

Background Check Software for Authorized Corporate Screening

This is authorized, consent-backed screening of a business counterparty. It is not a consumer background check, it is not for FCRA-regulated decisions, and it is not a people search. That is the first line of this page because it is the most important thing on it.

What it does cover: the company you are about to engage, its infrastructure and its registration record, checked passively and documented so the file holds up.

See pricing
  • Authorized use only.
  • Domains only, never a person.
  • Every finding sourced and timestamped.
  • Passive collection only.

The boundary, before anything else.

Osintpro is not a consumer reporting agency and its output is not a consumer report.

It must not be used to make employment, credit, insurance or tenancy decisions about a consumer, in the United States under the Fair Credit Reporting Act or under equivalent regimes elsewhere. Those decisions require an FCRA-compliant provider with the dispute and adverse-action processes that regime demands, and we deliberately do not offer them.

It is also not a people search. The demo on this site accepts a domain and has no input for a name, an email address or a phone number. Where a matter genuinely involves an individual, it proceeds on a documented lawful basis with the scope recorded before collection, and never as speculative profiling. See the published acceptable use boundary.

What pre-engagement screening actually means here.

You are about to engage a counterparty: a supplier, a reseller, a contracting firm, a marketplace seller, an agency, a partner. Before money moves or data is shared, you want to know that the entity is real, that it is as established as it claims, and that engaging it does not create obvious exposure for you.

That is a question about an organization, answerable from public records, and it is the question this platform is built for. Registration age against claimed trading history. Mail posture, because a counterparty whose domain can be spoofed is a counterparty whose invoices can be spoofed at you. Infrastructure control, hostname surface, certificate policy.

It is also the question most often answered badly, because it is usually done by someone in procurement or operations with six browser tabs and fifteen minutes, and the file ends up with a spreadsheet cell reading "checked, fine".

The workflow, start to file.

  1. Step 1

    Declare the scope and the basis

    Subject, requester, purpose, the basis for screening, what is explicitly out of scope. Written before collection so it constrains the work rather than justifying it afterwards.

  2. Step 2

    Run the passive collection

    Registration, DNS and mail posture, hostname surface, hosting attribution. Nothing reaches the counterparty and nothing appears in their logs, which is what makes this appropriate before a contract exists.

  3. Step 3

    Read the derived findings

    Each with a severity, the raw record, the source endpoint and the UTC retrieval time. A reviewer can re-run any line and either agree or not.

  4. Step 4

    File the artifact against the counterparty

    One document per engagement, dated, with the scope on the header. This is what an auditor asks for and what a spreadsheet row cannot be.

  5. Step 5

    Re-screen at renewal and read the diff

    Same scope, new timestamps. What changed is the finding, and it is the part that turns screening into a control rather than a ritual.

Screen a counterparty domain.

Pick "Vendor due diligence", tick the authorization box, and run the domain of a company you are genuinely assessing. Domains only. There is no input here that accepts a person.

  • It runs in your browser. Queries go to public DNS and RDAP endpoints, not through us.

  • Nothing reaches the subject. The domain you enter is never contacted, probed or scanned.

  • A domain, never a person. There is no input on this panel that accepts an individual.

  • Findings carry their evidence. Raw record, source endpoint and the UTC moment of retrieval.

Domain footprint sweep

passive collection only

stamped on the report
Samples:

Every finding will carry four things

  • 1 Severity. What the record means for the decision in front of you.
  • 2 The raw record. Exactly as the source returned it, unedited.
  • 3 The source endpoint. The request that produced it, so it can be re-run.
  • 4 The UTC retrieval time. Records change. Without this it is an assertion.

Reads dns.google and rdap.org from your browser. Nothing is sent to the domain you enter.

Tick the authorization box, then run the sweep. Enter the domain you are authorized to assess, then run the sweep. Run the sweep. The report lands here.

The findings that most often change a decision.

A domain much younger than the claimed history

The single most common signal in invoice and vendor fraud. A company claiming two decades of trading on a name registered this year needs an explanation before money moves.

No enforced DMARC policy

Their domain can be impersonated in practice, which means invoices and payment-change requests can arrive at your finance team wearing their name.

An expiry date inside ninety days

On a domain carrying production mail this is an operational risk with a deadline attached, and it is one of the few findings that comes with a countdown.

No transfer lock on a business-critical name

A hijacking exposure. On a counterparty that handles your data or your customers, it is a reasonable thing to raise in the contract conversation.

Administrative hostnames resolving in public

Not a vulnerability by itself, but a maturity signal, and one worth pairing with whatever their security questionnaire claimed.

Registration data inconsistent with the pitch

Registrar, delegation and dates that do not match the story on the website. Rarely conclusive, frequently the thread worth pulling.

Consent, basis and what goes in the file.

Screening a company's public infrastructure needs a documented business purpose. Screening anything about a person needs a lawful basis, and in most cases the practical route is consent obtained as part of the engagement, recorded in the case scope before collection begins.

The reason to record it rather than remember it is not compliance theatre. It is that six months later, when somebody asks why your organization was looking at a counterparty, the answer needs to exist in writing and be older than the question.

This is general information about how the work is done and it is not legal advice. Take your own advice for your jurisdiction and your matter. The FAQ covers the legality question in more depth, and third party risk screening covers the program-level version of this workflow.

Run one scoped sweep and see what a sourced finding looks like.

The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.

See how a case runs
  • Passive collection only, from public sources.
  • A domain, never a person. There is no input for one.
  • Your case data stays yours. No card required.

Scope in, evidence out. The demo needs no card.