Enforcement and market surveillance
Online sellers of unsafe or counterfeit goods, unlicensed operators and the companies behind them.
OSINT for government has moved from a niche skill to a first step in most public-sector investigations. We give departments, regulators and agencies extra analyst capacity, specialist research and training, at the unclassified level and under your legal framework.
OSINT for government is the use of publicly and commercially available information to answer public-sector questions: who owns a supplier, whether an investor is linked to a sanctioned party, whether a product seller is operating illegally, or what an agency's attack surface looks like from outside. OSINT-S delivers it as tasked research, monitoring and training, within your authorities and at the unclassified level.
In US policy, OSINT is intelligence derived only from publicly or commercially available information that answers a specific requirement.
The US intelligence community defines OSINT as intelligence derived exclusively from publicly or commercially available information that addresses specific intelligence priorities, requirements or gaps, and its current strategy calls it "the INT of first resort" (IC OSINT Strategy 2024–2026). The older statutory definition, from the 2006 defense authorization act, adds that the information must be collected, exploited and disseminated in a timely manner to an appropriate audience (Pub. L. 109-163, sec. 931).
Both definitions point to the same discipline: a stated requirement, lawful sources, and a product someone uses to decide. Outside intelligence agencies, the same method serves regulators, auditors, procurement teams and local authorities.
Most government OSINT work is investigative and regulatory, not secret: suppliers, investors, sellers, grant recipients and exposure.
Online sellers of unsafe or counterfeit goods, unlicensed operators and the companies behind them.
Undisclosed links between bidders, shell suppliers and recipients of public funds.
Beneficial owners, state links and sanctions exposure behind investors and acquirers.
Identity and document consistency, facilitation networks and online advertising of illegal services.
Exposed systems, leaked staff credentials and impersonation of the agency or its officials.
Open-source assessments of regions, sectors and actors to inform policy and planning.
Due diligence, company investigations, geopolitical analysis, red-team reconnaissance, monitoring and training cover most requirements.
All of these are part of the same set of OSINT services we offer to public bodies and companies, run by one analyst team under one review standard.
Platforms suit agencies with trained analysts and a data governance process; managed research suits surges, specialisms and teams still building capability.
Buying a data platform is itself a governance decision. Under the ODNI policy framework for commercially available information, adopted by intelligence community elements in 2024, purchased data containing substantial personal information, or data that reveals sensitive activities such as the exercise of constitutional rights, counts as "sensitive CAI" and needs a documented assessment of necessity, authority, privacy risk and data quality, plus safeguards on access and retention (IC Policy Framework for CAI, 2024). Civilian agencies outside the intelligence community face similar questions under their own privacy rules.
| Option | Works well when | Watch-outs |
|---|---|---|
| Licensed platform | Steady caseload, trained analysts, approved data governance | License scope, data provenance, user auditing |
| Managed research | Surges, specialist questions, one-off reviews | Clear tasking and data-handling terms |
| Training plus mentoring | Building in-house capability over a year | Needs management time and a recording standard |
Public notices show the range: multi-year frameworks worth tens of millions, single tool subscriptions, and catalog services on G-Cloud.
| Buyer and notice | What was bought | Value and term |
|---|---|---|
| UK Home Office (Find a Tender) | OSINT, social media analysis and geospatial analysis for border security | £33 million excl. VAT, 2 years plus an optional 12 months from April 2026 |
| UK Department for Business and Trade, Office for Product Safety and Standards (Find a Tender) | Renewal of a Maltego Monitor subscription | £46,450 excl. VAT, September 2025 to July 2026 |
| G-Cloud 15 catalog (Digital Marketplace) | OSINT-based penetration testing: footprint mapping, exposed assets, leaked credentials | Call-off from the framework |
For smaller requirements, a written scope and a fixed quote usually fit below-threshold procurement rules. We work through whichever route your procurement team uses.
Public bodies need a lawful basis, proportionality and, for systematic online research about individuals, they may need surveillance authorization.
In the UK, the Home Office code on covert surveillance applies to public authorities, local councils included. It treats preliminary checks of online material as unlikely to engage privacy, but says systematic collection and recording about a particular person or group should lead the authority to consider a directed surveillance authorization (CSPI Code, paras 3.10–3.17). Personal data is also covered by UK GDPR or the GDPR, depending on the body (GDPR).
Requirement, data-handling terms, collection, senior review and delivery, with knowledge transfer if you want it.
Illustrative patterns of the work public bodies bring, not descriptions of specific clients.
Three bidders on a tender share a phone number, a former director and a registered address in public records.
A proposed acquisition of a sensitive supplier needs a view of the buyer's ultimate owners and their links.
An online seller of unsafe products closes and reopens under new names; research links the stores.
Send the questions, the deadline and the legal basis. We return a written scope and a fixed quote; urgent delivery carries a 50% surcharge, and the fee goes down if we miss the agreed date.
Outsource the first cases and use them to decide. A few tasked investigations show which questions recur, which sources matter and how much analyst time each case takes. That evidence makes the business case for hiring or for a platform. Many departments end up with a mix: a small in-house team, a licensed tool for routine checks, and outside capacity for surges and specialist questions. Training can run alongside so staff learn the method from real case types.
The Home Office code says preliminary checks of public online material are unlikely to engage privacy, but systematic collection and recording about a particular person should lead you to consider a directed surveillance authorization. Repeated visits to one trader's profiles, with findings recorded for enforcement, can cross that line. Your RIPA coordinator decides. If we support the case, we set out the planned frequency and recording in writing so the decision can be made first.
Data products that bundle personal information, location data or records that reveal sensitive activities raise the most questions. The ODNI framework on commercially available information asks intelligence community elements to document mission need, legal authority, privacy risk, data quality and original sources, and to restrict access and retention. Civilian agencies can ask the same: where does the data come from, how was consent or notice handled, and can usage be audited per user?
Yes. Ownership, directors, litigation, sanctions exposure, state links and adverse media can all be researched in open and commercially available sources. We work at the unclassified level only, so our report is a starting point that your security officials can compare with their own holdings. A focused review starts from 10 business days and a comprehensive one takes up to about a month; urgent delivery is possible for a 50% surcharge.
We can map the fake sites, their registration and hosting details, linked domains, payment pages and any public traces of the operators, then hand you a report suitable for takedown requests and referral to police. After that, our monitoring platform updates hourly, and an analyst checks new look-alike domains and accounts before alerting you. We do not access the sites' back ends or contact the operators.
Yes. We build exercises around your typical case types with fictional subjects, and align the recording standard with your policies on online research, data protection and, where relevant, surveillance authorization. Typical modules cover search technique, company and ownership research, seller and website attribution, image verification, capture and logging. The aim is research that one officer can check and repeat after another.
No. We do not monitor people for lawful political criticism, protest, religious or press activity, and we would advise any public body against it. If there is a specific, credible threat of violence or a coordinated impersonation of your department, we can investigate that narrow issue under a written requirement. For communications planning, aggregate analysis of public narratives that does not profile individuals is a different and more defensible task.
Sources checked 7 October 2026. Figures about third-party firms and tools are as published by them or by the cited source on that date.