Digital Footprint OSINT FAQ
I want to know what my OSINT digital footprint looks like before I start a public-facing job — what would a professional audit find that I could not find with a free checker?
A professional audit goes beyond search results. We check people-search and broker sites, property and company records, breach data on criminal sources and your family's public accounts, verify which items are really about you, and show how they connect, for example a breached email that links to an old address. You get a risk-ranked list and a remediation plan, not just a scan result.
Our company keeps getting convincing phishing emails that name the right managers — can an OSINT assessment show us where attackers are getting our staff details?
Yes. A company exposure audit reconstructs what an attacker can see: staff names and roles from professional networks, your email format, job ads that reveal systems, exposed documents and leaked corporate credentials. We show which sources make the phishing convincing and which can be reduced. It is often the first step before authorized red team testing or staff training.
I'm being harassed online and someone posted my home address — can you help me find where else my address appears and get it taken down legally?
We can map where your address and other personal details appear, including people-search sites, records and social media, and give you the opt-out, search removal and platform reporting routes for each. Some public records cannot be removed. If you feel unsafe, contact the police first; we can provide a documented report of what was published and where, which may help them and your lawyer.
We live in California and have heard about the new DROP platform for data brokers — does that remove our family's information everywhere, or do we still need an audit?
DROP lets California residents send one deletion request to all registered data brokers, and brokers had to start processing those requests from August 2026. It does not cover websites that are not registered brokers, public records, social media, breach data or information published by others. An audit shows what is left after DROP and what to do about it.
How often should our organization repeat an OSINT audit of our executives and staff, and is a one-off assessment enough if nothing bad has happened yet?
A one-off audit is a good baseline, but exposure changes as breaches happen, people change jobs and new listings appear. Many organizations repeat a focused audit once a year and after major events such as an acquisition, a layoff or a leadership change. If the people involved are high-profile, ongoing monitoring is usually more useful than repeat audits.
Is it legal for you to collect our employees' personal information during a company footprint audit, and will the findings be shared with HR or managers?
We collect only what is publicly or commercially available and relevant to security risk, under a documented legitimate interest where GDPR applies. Findings about an individual's private life are reported in aggregate or shared only with that person, not used to judge employees. We agree with you in writing who receives which parts of the report before we start.
Can you just delete everything about me from the internet if I pay for an exposure audit, or what results are realistic to expect?
No one can delete everything. Realistic results are: most people-search listings opted out, sensitive search results removed, exposed passwords changed, impersonation accounts reported, and family accounts tightened. Public records, news coverage and content on sites outside your legal reach usually stay. The goal is to make you much harder to research, and we tell you upfront which items cannot be removed.