OSINT Services: Investigations, Due Diligence and Monitoring

OSINT services from OSINT-S turn publicly and commercially available information into answers you can act on: who a person really is, who controls a company, where the money went, and what is being said or planned about you online. Every finding comes with its source.

  • 7,000+ investigations since 2019
  • Source-referenced reports
  • Focused checks from 10 business days
  • No hacking, pretexting or private-account access

OSINT-S is operated by Molfar Intelligence (Molfar Limited, UK), a private intelligence company founded in Kyiv in 2019.

What are OSINT services?

OSINT services are investigations and monitoring built on open-source intelligence: information anyone can lawfully see, buy or request, such as company registries, court records, the media, social networks and leaked-data markets. An OSINT services provider collects that information, verifies it against independent sources and turns it into a report that answers one specific question. At OSINT-S a focused check takes from 10 business days, a comprehensive review up to a month, and urgent work is possible.

7,000+investigations completed · source
100+people on the team · source
750+public and restricted registers · source
60+countries investigated · source

Our OSINT Services

OSINT-S offers nine OSINT services. Together they cover most questions an organization asks of open sources, and each one starts with a written scope and ends with a source-referenced report.

Investigate

OSINT investigations

Case-based investigations into people, companies, online accounts and networks, from a single identity question to a multi-country inquiry.

Learn more →
Vet people

Background checks

Identity, career, public-records and online-footprint checks on candidates, executives, partners and counterparties.

Vet deals

Due diligence

Reputational, third-party and investor due diligence: ownership, sanctions, litigation, adverse media and local-language review.

Comply

KYC and AML checks

Enhanced customer due diligence when your standard screening returns a hit, a gap or a complex ownership chain.

Recover

Asset tracing

Tracing property, companies and holdings across jurisdictions to support litigation, enforcement and recovery.

Map

Company investigations

Who really owns and runs a company, who it trades with, and whether its claims hold up.

Protect

Dark web monitoring

Leaked credentials, stolen data and mentions of your company, staff and assets on criminal forums, markets and channels.

Learn more →
Watch

OSINT monitoring

Ongoing alerts on counterparties, portfolios, brands and events, triaged by an analyst before they reach you.

Learn more →
Defend

Threat intelligence

Open-source cyber threat intelligence on the actors, campaigns, phishing and vulnerabilities aimed at your organization.

Learn more →

What Are OSINT Services?

Professional open-source intelligence work done for a client: an analyst team collects, verifies and analyzes public and commercial information to answer a defined question, and delivers the answer with its evidence.

Open-source intelligence, or OSINT, is intelligence derived exclusively from publicly or commercially available information that addresses a specific requirement. That is the definition the US intelligence community uses (IC OSINT Strategy 2024–2026). OSINT services apply the same discipline to business questions: a hire, a deal, a dispute, a threat.

A search engine gives you claims. A professional OSINT team gives you findings. The difference is the work in between:

  • Scoping: turning a worry into a question that open sources can answer, within a lawful and proportionate purpose.
  • Collection: registries, court records, media archives in local languages, online footprint, imagery and specialist data, not just the first page of results.
  • Verification: testing each material claim against records created independently of it.
  • Analysis: connecting findings into ownership maps, networks and timelines, and saying how confident we are.
  • Reporting: an answer you can act on, with sources, captures and open questions listed.

Some providers call the same thing OSINT solutions or OSINT as a service. Whatever the label, you are buying a verified answer rather than a tool.

What Questions Can OSINT Services Answer?

Questions that turn on facts somebody, somewhere, has recorded in public: identity, ownership, relationships, assets, reputation and intent.

  • Is this person who they say they are? Identity, education and employment history, directorships, litigation and media coverage.
  • Who is really behind this company? Beneficial owners, nominee structures, related companies and links to sanctioned or politically exposed persons.
  • Where are the assets? Property, company holdings and vehicles recorded in registries across several countries.
  • Who runs this account or website? Attribution of anonymous accounts, domains and channels behind fraud, impersonation or harassment.
  • Has our data leaked? Employee credentials, customer records and internal documents offered on criminal forums and channels.
  • Is anyone planning to harm us? Threats against staff, offices and events, phishing infrastructure and actors targeting your sector.
  • What would a regulator, journalist or court find? The record a careful third party could build about you, your executives or a deal.

If the answer depends on information that is not lawfully accessible, such as private messages, bank records or phone metadata, OSINT is the wrong tool and we will say so at scoping.

Who Needs OSINT Services?

Teams that make decisions about people and counterparties they cannot fully see: security and risk, legal, investment, compliance, HR, insurance and public-interest organizations.

Corporate security and risk teams

Security teams use open sources to see threats before they arrive: impersonation of executives, leaked credentials, planned protests at a site, actors targeting the sector. Typical services: OSINT monitoring and threat intelligence.

Law firms and litigators

Before you sue or enforce, you need to know where the assets are, who the witnesses are and what the other side has said in public. Typical services: asset tracing and OSINT investigations.

Investors, private equity and venture capital

Founders, co-investors and cap tables are rarely as simple as the pitch deck. Typical service: investor due diligence.

Banks, fintech and compliance teams

When automated screening returns a hit, a gap or an opaque ownership chain, an analyst resolves it with records from the countries involved. Typical service: KYC and AML checks.

HR, executive search and boards

Senior hires and board appointments deserve more than a reference call. Typical service: background checks.

Insurers

Open sources often show whether a claim, a claimant or an incident is what it appears to be. Typical service: OSINT investigations.

NGOs, media and public bodies

Networks behind disinformation, sanctions evasion or supply-chain abuse are often visible in public records. Molfar, which operates OSINT-S, lists organizations from USIP and the Open Society Foundations to Helsing, Ajax Systems and Wikborg Rein among its clients (client list).

How OSINT services work OSINT services turn a client question into a verified report in four stages: the question, collection from open sources, verification and the report. 01 · BRIEF Your question Subject, decision, deadline, lawful purpose 02 · COLLECT Open sources 750+ registers, courts, media, online, leak data 03 · VERIFY Verification Independent sources, senior fact-check 04 · REPORT Your answer Facts, open questions, risks, sources
How OSINT services work at OSINT-S: from your question to a verified, source-referenced answer.

How an OSINT Engagement Works

Six steps, from a short brief to a debrief on the findings. You see a written scope and a fixed quote before any research starts.

  1. Brief and legality checkYou tell us the question and the decision it supports. We confirm the purpose is lawful and proportionate, and turn down requests that are not.
  2. Scope and fixed quoteWe agree the subjects, jurisdictions, depth, deadline and deliverables in writing, with a price that does not move unless the scope does.
  3. Team and collectionA team is formed around the task: analysts for the languages and countries involved, working with registries, court and media archives, online footprint and specialist data.
  4. VerificationEach material finding is checked against independent sources, and the head of the department fact-checks the results before anything is reported.
  5. Report and debriefYou receive a source-referenced report that separates confirmed facts, open questions and material risks, with an analyst debrief on request.
  6. Optional monitoringIf the risk is ongoing, we keep watching the same subjects and alert you when something material changes.

What Does a Finished OSINT Report Include?

A report you can defend: every material statement is tied to a source, and confirmed facts are kept apart from what remains uncertain.

  • Executive summary with the answer to your question and a clear risk view.
  • Findings with sources: registry extracts, court references, media and online records, each with its link or reference and the date it was observed.
  • Evidence pack: captures of the pages and records relied on, so the findings can be checked later even if the originals change.
  • Maps where they help: ownership and control structures, relationship networks, timelines and asset maps.
  • Open questions and next steps: what could not be confirmed from open sources, and what it would take to resolve it.

Reports are written in English and, where the case needs it, draw on local-language records and media. If the report may be used in proceedings, tell us at the brief so the evidence is collected and documented with that in mind.

Where We Work: 60+ Countries

Molfar's investigations have covered 60+ countries. We are strongest where records are thin or not in English, and we regularly work on UK, EU and US subjects.

RegionWhat we do there
United KingdomContracts through Molfar Limited (Companies House 13558891); a UK team led by James Westlake; due diligence, background checks and asset tracing for UK funds, manufacturers, fintech and defense companies (UK page).
United StatesInvestigations, due diligence and threat intelligence on US subjects and on foreign counterparties of US clients. For US employment decisions, we flag Fair Credit Reporting Act requirements at scoping.
European UnionCompany, ownership and sanctions work across EU registries, scoped under the GDPR.
Ukraine, Central and Eastern EuropeThe team's home ground: local-language registries, courts and media, and Russia-linked networks.
ElsewhereMulti-country cases with offshore structures, scoped country by country.

Which Sources Do We Use, and Which Lines Don't We Cross?

Lawfully accessible open sources and licensed data, including criminal forums and leak sites for cyber work, plus agreed local inquiries where they are lawful. No hacking, no pretexting, no access to private accounts.

Our analysts work with 750+ public and restricted registers worldwide, court and corporate records, media archives, social networks and online communities, satellite and street-level imagery, and specialist data on leaks and cybercrime. Where a case needs it and the law allows, we agree local verification or human-source inquiries with you in advance and keep them proportionate to the question.

What we will not do. We do not hack or log in to accounts, pose as someone else to obtain records, bypass privacy settings, buy unlawfully obtained data to identify individuals, or locate people without a lawful purpose. We do not work for representatives of authoritarian regimes.

Public information is still personal data. Under the EU and UK GDPR, investigations rely on a legitimate interest that has to pass a balancing test (EDPB Guidelines 1/2024), and data protection authorities have reminded businesses that publicly accessible personal information remains protected (joint statement, 2023). In the UK, obtaining personal data without the controller's consent can be an offense under section 170 of the Data Protection Act 2018; in the US, pretexting for financial records is banned under the Gramm-Leach-Bliley Act.

Examples of Our OSINT Work

Four cases from Molfar's published case studies show the range: sanctions evidence, asset tracing, partner vetting and investor due diligence.

34 dossiers · under 2 weeks

Sanctions-grade dossiers in under two weeks

A government client needed evidence packs on individuals linked to a sanctions program. Molfar delivered 34 dossiers in under two weeks; five people were later sanctioned by presidential decree.

Read the case on molfar.com →
assets mapped · used for EU freezes

Tracing the assets of a sanctioned official

Molfar mapped Hungarian assets linked to the head of Russia's foreign intelligence service. The dossier was used as a basis for EU-level asset freezes.

Read the case on molfar.com →
3 undisclosed properties

Transparency check on a strategic partner

Before a partnership, Molfar verified a counterparty's disclosures and found three undisclosed European properties worth an estimated €173,000–€312,000.

Read the case on molfar.com →
investment halted

Investor due diligence in defense tech

An investor asked for a check on a defense-tech startup. Molfar linked a co-founder to a 2.6 billion UAH gambling enterprise, and the investment was halted.

Read the case on molfar.com →

Case studies are published by Molfar Intelligence, which operates OSINT-S. Most are anonymized at the client's request.

How Much Do OSINT Services Cost?

Each request is priced after scoping, as a fixed quote. Urgent work carries a 50% surcharge. Public benchmarks run from about $75 an hour for a basic US private investigator to €7,500 a year for a professional OSINT platform license.

The price depends on the number of subjects and countries, how much ownership or network mapping is needed, the languages involved, how thin the records are, and the deadline. A focused check takes from 10 business days and a comprehensive review up to a month (Molfar). If we cannot deliver on the agreed date, we tell you and reduce the fee (FAQ).

Public reference points (checked 6 October 2026)
ItemFigureSource
US private investigator, basic work$75–$125 an hourTalo cost guide
UK OSINT contractor day rate (median)£575 a dayITJobsWatch
Due diligence report on one US subject$550 (individual), $750 (business)Global Backgrounds
Maltego Professional platform€7,500 a yearMaltego pricing

See the full breakdown in our OSINT pricing guide.

OSINT Services vs OSINT Tools vs an In-House Team

Tools give you data, an in-house team gives you control, and a service gives you a verified answer without hiring. Many buyers combine a tool for routine checks with a service for the decisions that matter.

OSINT-S (service)OSINT tools and platformsIn-house OSINT team
Who does the workOur analystsYour staffYour staff
Typical costFixed fee per taskFrom £19 a month to six figures a yearSalaries (UK median £65,579 for OSINT roles, ITJobsWatch) plus tools and training
VerificationBuilt in, with a second checkUp to the userDepends on the team
Languages and regionsAssembled per taskLimited by the tool's coverageLimited by who you hire
Best forHigh-stakes, occasional or cross-border questionsHigh volumes of routine lookupsConstant, sensitive, in-house demand

Popular OSINT tools and what they cost

ToolWhat it doesPublished price
MaltegoLink analysis and graph investigations€0 / €3,000 / €7,500 a year (Maltego)
OSINT IndustriesLookups on an email, phone number or username£19–£99 a month (OSINT Industries)
Intelligence XSearch across leaks, archives and the dark web€2,500–€20,000 a year (Intelligence X)
ShodanInternet-connected devices and exposed services$49 one-off; $69–$1,099 a month (Shodan)
HunchlyCapturing web pages as evidence€149 a year (Hunchly)

Tools are only as good as the analyst using them. To compare providers, see our ranking of the best OSINT companies in 2026.

How to Choose an OSINT Provider

Ask seven questions before you sign: who does the work, which sources they can reach, how they verify, what the report separates, what they refuse to do, who you contract with, and whether the price is fixed.

  1. Who will work on my case, and in which languages? The answer should match the countries involved.
  2. Which sources can you reach for this question, and which can you not? Honest limits are a good sign.
  3. How do you verify a finding? Look for independent corroboration and a second check before reporting.
  4. What will the report separate? Confirmed facts, assessments and open questions should never be mixed.
  5. What will you refuse to do? A provider that will hack, pretext or buy leaked data puts you at risk.
  6. Who is the legal entity, and where is it registered? You need a contract, confidentiality terms and data-protection terms.
  7. Is the price fixed, and what if you miss the deadline? A fixed quote against a written scope avoids surprises.

For a side-by-side view of providers and platforms, see the top OSINT companies compared; if you only need one person for a small task, read how to hire an OSINT investigator.

Why Choose OSINT-S?

Seven years of investigative practice, a team assembled around each question, and reports that separate what is proven from what is not.

  • Track record. Molfar, the team behind OSINT-S, has completed 7,000+ investigations since 2019 and has been covered by outlets such as PBS NewsHour and the Kyiv Independent.
  • Depth where records are thin. The team works in local languages and has deep experience in Ukraine, Central and Eastern Europe and Russia-exposed networks, alongside the UK, EU and US.
  • A UK legal entity. Contracts are with Molfar Limited, registered in England and Wales.
  • Our own monitoring platform. Ongoing work runs on Minos, Molfar's information-threat platform, with analysts reviewing what it surfaces.
  • Confidentiality. We never disclose sources or client data without written consent, and we can work under your NDA.

Want to know more about the team? Read about OSINT-S as an OSINT agency, or about OSINT consulting and training if you need advice rather than a report.

When We Are Not the Right Choice

If you need physical surveillance, process serving or a licensed private investigator in a particular US state, forensic imaging of devices, or information that only a court order can unlock, you need a different provider or legal process. If your case requires a provider with no stated position on Russia's war against Ukraine, note that Molfar is Ukraine-born and openly pro-Ukrainian. We will tell you at the first call if one of these applies.

Tell Us the Question. We'll Scope It for Free.

Send a short brief: who or what, the decision it supports, and your deadline. An analyst replies with a scope, a timeline and a fixed quote.

OSINT Services FAQ

What are OSINT services?

OSINT services are investigations and monitoring based on open-source intelligence: information that is publicly or commercially available, such as registries, court records, media and social networks. A provider collects and verifies it, then reports an answer to a specific question with the sources behind it.

What does OSINT stand for?

OSINT stands for open-source intelligence. The US intelligence community defines it as intelligence derived exclusively from publicly or commercially available information that addresses specific intelligence priorities, requirements or gaps (IC OSINT Strategy 2024–2026).

What is the difference between OSINT tools and OSINT services?

OSINT tools are software your own staff use to search and analyze open sources. OSINT services are work done for you: analysts choose the sources, verify the findings and deliver a report. Tools suit high volumes of routine lookups; services suit high-stakes, cross-border or occasional questions.

Are OSINT services legal?

Yes, when the purpose is legitimate and the methods are lawful. Public information is still personal data under the GDPR, so investigations need a lawful basis and must be proportionate. Hacking, pretexting and access to private accounts are illegal in most countries, and we do not do them.

How much do OSINT services cost?

Each request is priced after scoping as a fixed quote; urgent work carries a 50% surcharge. For context, basic US private investigator work costs about $75–$125 an hour and UK OSINT contractors earn a median of £575 a day. See our pricing guide.

How long does an OSINT investigation take?

A focused check takes from 10 business days and a comprehensive review up to a month. Some smaller tasks take a business day, and urgent delivery is available for an extra fee.

What types of organizations use OSINT services?

Corporate security and risk teams, law firms, investors, banks and fintech companies, HR and executive search, insurers, NGOs, media and public bodies. Any organization that makes decisions about people or counterparties it cannot fully see.

Do OSINT services include the dark web?

They can. Criminal forums, markets, leak sites and messaging channels are open sources in the sense that anyone can observe them, and they matter for cyber and fraud work. We observe and document; we do not buy stolen data to identify people. See dark web monitoring.

What is OSINT as a service?

OSINT as a service means buying the outcome, verified intelligence, instead of the tools and staff to produce it. You can commission one-off investigations or ongoing monitoring with analyst-reviewed alerts.

Do you provide OSINT services in the UK and the US?

Yes. Contracts are with Molfar Limited, a UK company, and we regularly work on UK, EU and US subjects. For US employment decisions, we flag Fair Credit Reporting Act requirements at scoping.

Can OSINT find someone's phone number or home address?

Sometimes, because such details appear in registries, listings or old records. We only look for them when there is a lawful purpose, such as tracing a debtor or a witness, and we do not help anyone locate a person to harass or harm them.

Do you access private social media accounts or messages?

No. We do not log in to other people's accounts, use fake profiles to gain access to private content, or bypass privacy settings. What is private stays out of scope.

Can OSINT reports be used in court?

Open-source findings are used in litigation and arbitration, but admissibility depends on the court and on how the evidence was collected and documented. If your report may be used in proceedings, tell us at the brief so we preserve and document the evidence accordingly, and involve your lawyers early.

Who operates OSINT-S?

OSINT-S is operated by Molfar Intelligence, a trading name of Molfar Limited (Companies House 13558891). Molfar was founded in Kyiv in 2019 by Artem Starosiek.