IntelBase OSINT Review: Features, Pricing and Alternatives

IntelBase OSINT is a web platform that turns an email address or a username into a list of registered accounts, profile details, breach records and an identity verdict. This review is based on the vendor's site, pricing page, API documentation and terms of service, checked on 10 October 2026. We did not run lookups ourselves.

  • Email and username lookups
  • Breach and infostealer records
  • Plans from $24.99 a month, annual
  • Not for FCRA-regulated decisions
Short answer

IntelBase OSINT is a browser-based lookup service for email addresses and usernames. It checks 230+ email platforms and 580+ username platforms live, adds breach and infostealer records, and scores whether accounts belong to one person. It suits security, fraud and investigation teams. Paid plans run from $24.99 a month billed annually; enterprise pricing is custom.

What IntelBase OSINT Does

IntelBase answers one question fast: which online accounts and exposure records are linked to this email address or username?

The home page describes IntelBase as "the intelligence platform trusted by security teams, investigators, and enterprises worldwide" (IntelBase). It works on two identifier types only, email addresses and usernames, and returns:

  • Accounts. Registrations found on 230+ email platforms and 580+ username platforms, checked live.
  • Profile details. Names, bios, locations and work history pulled from linked accounts.
  • Exposure. Breach records and infostealer data, which the vendor puts at "40B+" records combined.
  • Scores and verdicts. Ratings for authenticity, credential exposure and ownership, with the reasons for each, plus a timeline.

It does not search phone numbers, names, company records or domains, so it covers one step of an investigation rather than the whole case.

Key Features of the IntelBase Platform

Beyond single lookups, IntelBase adds monitoring, team workspaces, bulk search, reporting and an API on higher plans.

Identity

AI identity matching

Groups accounts that appear to belong to the same person and explains the verdict.

Visual

Graph and timeline

A timeline of findings and a graph view of connections between accounts.

Alerts

Monitoring

Watches identifiers for new breaches, infostealer logs or registrations; webhook alerts start on Max.

Scale

Bulk lookups

Up to 100 identifiers at once on Max and Enterprise.

Teams

Shared workspaces

Shared lookup history, pooled daily quotas, audit logs and central billing.

API

REST API

Email and username endpoints with API keys and IP whitelisting; not on the free plan.

Data Sources: Live Checks, Breaches and Infostealer Logs

Two kinds of data: live checks of whether an identifier is registered on a platform, and stored breach and infostealer records.

The API documentation shows how a lookup is built. An email lookup returns registered and unregistered platforms, data breaches, stealer logs, password-reuse and domain insights, and an identity block; breach and stealer sections can be switched off per request and their visibility "depends on your plan". A username lookup returns accounts and an identity verdict, with no breach or stealer data (IntelBase API docs).

Infostealer logs are records taken from infected devices, and the site says they can include cookies, sessions and autofill data. That makes them useful for account-takeover and fraud work, and sensitive to handle. The terms describe the service as aggregating "information from public and third-party sources" and warn that "results may be incomplete, outdated, or incorrect" (IntelBase Terms of Service).

IntelBase Pricing and Plans

Three published tiers with daily lookup quotas, plus a free sign-up whose limits the pricing page does not state.

PlanPriceLookupsMain additions
Free sign-up$0Not statedRun a first lookup; API not included
Pro$24.99 a month, billed annually400 a dayEmail and username lookup, breach data viewing, identity matching, graph, PDF export, API
Max$83.99 a month billed annually, or $99.99 billed monthly1,000 a dayThree team seats, shared workspace, infostealer insights, bulk lookup, webhook alerts
EnterpriseCustomCustomFull infostealer intelligence, SSO/SAML, audit logs, white-label reports, custom SLA

Source: IntelBase pricing, checked 10 October 2026. The page did not show a monthly-billed price for Pro. API access requires a paid plan (docs).

Who IntelBase Suits, and Who It Does Not

It fits security, fraud and investigation teams that triage email and username identifiers in volume; it does not fit hiring, tenant or credit decisions.

Good fitPoor fit
Fraud and account-takeover teams checking whether a sign-up email looks real and exposedEmployment, tenant, credit or insurance screening, which the terms exclude
Threat investigators mapping the accounts behind a usernameCases that start from a name, phone number or company
Teams that want an API and webhook alerts inside their own toolsAnyone who needs court-ready evidence without further verification

Limitations, FCRA and Privacy Risks

The terms rule out consumer-report uses and targeting individuals, and results still need independent verification.

  • Not a consumer reporting agency. The terms state that IntelBase "is not a consumer reporting agency" and forbid using it for credit, insurance, employment or tenant screening. In the US those uses fall under the FCRA, with its own rules for employers (FTC guidance).
  • No targeting people. Users may not "stalk, harass, threaten, discriminate against, or harm any person", and lookups on anyone known or believed to be under 18 are prohibited.
  • Personal data. Breach and infostealer records are personal data. Under the GDPR you need a lawful basis, a specific purpose and data minimization (GDPR). Never use exposed passwords or session cookies to log in to an account.
  • False matches. Common usernames are reused by different people, and identity scores are probabilistic. Treat every link as a lead to confirm.
  • Narrow scope and little vendor detail. Only two identifier types; the terms do not name a legal entity, and the IntelBase GitHub organization has no public repositories.

The site also offers people a way to request removal of their data.

IntelBase Alternatives for Email and Username OSINT

OSINT Industries and Epieos are the closest commercial alternatives; Holehe, Sherlock and Maigret are free open-source tools for parts of the same job.

  • OSINT Industries: commercial email, phone and username lookups (pricing).
  • Epieos: email and phone reverse lookups with paid plans (pricing).
  • Holehe: an open-source command-line tool that checks whether an email is registered on sites.
  • Sherlock and Maigret: open-source username search across many sites, without breach data.

For other categories, browse our OSINT tools catalog.

Need the Answer, Not the Tool?

If the question is who is behind an email or username, an analyst-led investigation returns verified findings rather than raw matches.

A lookup tool tells you where an identifier appears. It does not tell you whether the matches are the same person, whether the data is current, or what it means for your decision. OSINT-S does not resell IntelBase or any other tool and has no partnership with the vendor. Our email address investigations and username investigations start from a lawful purpose, verify links across independent sources, and pass senior analyst review. Ongoing exposure is covered by leaked credential monitoring.

Compare these with our other OSINT services for companies and law firms.

Get an Analyst-Verified OSINT Identity Check

Send the email address or username and the decision it supports. We confirm a fixed quote after written scoping; focused checks start from 10 business days.

IntelBase OSINT FAQ

Someone on our fraud team suggested IntelBase OSINT for checking suspicious sign-up emails — what does it actually return, and is it more than a breach checker?

Yes, it is more than a breach checker. IntelBase OSINT returns the accounts registered to an email or username across 230+ email platforms and 580+ username platforms, profile details from those accounts, breach and infostealer records, and scores for authenticity, credential exposure and ownership. For fraud teams, the identity verdict and exposure scores are the useful parts. Breach and stealer-log visibility depends on your plan (IntelBase API docs).

I'm a freelance investigator and only need a handful of lookups a week — is there a free IntelBase plan, and how much would the cheapest paid plan cost me?

There is a free sign-up that lets you run a first lookup, but the pricing page does not state its limits, and the API is not available on it. The cheapest published paid plan is Pro at $24.99 a month billed annually, with 400 lookups a day. Max costs $83.99 a month billed annually or $99.99 billed monthly. Enterprise pricing is custom, through sales.

We screen job applicants and want to check their online accounts before interviews — can we legally use IntelBase as part of our hiring process?

No. IntelBase's terms state that it is not a consumer reporting agency and forbid using it for employment, credit, insurance or tenant decisions. In the US, background information used for hiring falls under the Fair Credit Reporting Act, which requires disclosure, consent and adverse-action steps (FTC). Use an FCRA-compliant screening provider for applicants, and keep IntelBase for security and fraud work within its terms.

The tool says three accounts with the same username belong to one person — how far can I trust that match before I put it in a report for my client?

Treat it as a lead, not a finding. Identity matching is probabilistic, and common usernames are often reused by unrelated people. The terms also warn that results may be incomplete, outdated or incorrect. Before reporting, confirm each link with independent evidence such as matching photos, consistent biographical details, cross-links between profiles or dated posts, and record where and when you captured each item.

Our security team found an employee's work email in IntelBase infostealer results — what should we do with that, and can we look at the stolen passwords?

Act on the exposure, not the contents. Reset the affected credentials, revoke active sessions, check the device for malware and review access logs. Do not use exposed passwords or session cookies to log in to any account, and limit who sees the raw records, because they are personal data under the GDPR and similar laws. Higher IntelBase plans include infostealer insights; ongoing alerts can also come from a managed monitoring service.

We need to know who runs an anonymous account harassing our CEO, and I'm not sure a lookup tool is enough — when does it make sense to hire investigators instead?

Hire investigators when the result will drive a legal, HR or safety decision. A username lookup can show where else the handle appears, but attributing an anonymous account needs corroboration across sources, careful handling of false matches and documentation that holds up with lawyers or police. OSINT-S works from a written scope and lawful purpose, with focused checks from 10 business days and urgent delivery for 50% more.