OSINT (Open-Source Intelligence) is the disciplined collection, processing, and analysis of publicly available information in order to support a specific decision. It is the lawful gathering of data from open sources — websites, public registers, media, and social networks — and never the breaching of protected systems or the bypassing of passwords. The key difference between professional OSINT and mere "googling" is methodology: a traceable process, an assessment of source reliability, and the cross-checking of findings.
What OSINT Is and Is Not
Open sources are all information that is lawfully and publicly available to anyone — without intrusion, deception, or abuse of authority. OSINT is neither espionage nor hacking; it is a structured intelligence process that converts raw data into verified, usable knowledge. It is precisely this conversion — from a random data point to an assessed finding — that separates a professional intelligence inquiry from superficial web browsing.
Typical open sources include:
- the surface web: websites, news, blogs, forums;
- social networks and publicly posted profiles;
- official and business registers (e.g. the court register, AJPES, the land register);
- professional and academic publications, patents, and public tenders;
- geospatial data, satellite imagery, and street-level photography;
- publicly released datasets and documents.
The Intelligence Cycle: From Question to Decision
Every credible inquiry follows the intelligence cycle — a sequence of phases that ensures the result is focused, verifiable, and useful to the client. Without this framework, data collection quickly becomes unstructured, biased, and legally risky.
- Direction. A precise definition of the intelligence question, its scope, and its legal basis — what we want to learn and why.
- Collection. The systematic gathering of data from open sources, with the origin of every data point consistently recorded.
- Processing. Organizing, translating, de-duplicating, and structuring raw data into a manageable form.
- Analysis. Correlating data, identifying patterns, assessing reliability, and forming well-founded conclusions.
- Dissemination. A clear, documented report tailored to the decision-maker, with sources and a level of confidence stated.
The cycle is iterative: findings in the analysis phase often raise new questions and trigger a fresh round of collection. It is precisely this feedback loop that distinguishes an intelligence inquiry from a one-off lookup.
From the Surface Web to Dark-Web Awareness
Open sources are not uniform; they differ in accessibility, reliability, and legal sensitivity. A professional researcher knows which layer of information is appropriate for a given purpose — and where legal risk begins.
- Business and public registers. The court register, AJPES, the land register, and European registers (e.g. the BRIS system) are the foundation of due-diligence reviews of ownership structures and beneficial owners.
- Social networks. A rich source of context about individuals and their connections, yet also the most prone to misrepresentation and outdated information.
- Data leaks and disclosures. Data from disclosures (e.g. so-called offshore leaks) may be publicly accessible through investigative consortia, but its use requires particular legal and ethical judgment.
- The dark web. For most commercial inquiries, awareness of exposure is enough — whether a client's data appears in stolen datasets — without actively entering illicit spaces.
Assessing Source Reliability: The Admiralty (NATO) System
Not every piece of information is of equal value. A well-established tool for grading it is the so-called Admiralty, or NATO, system, which separately assesses two things: the reliability of the source and the credibility of the information itself.
- Source reliability (A–F): from A (completely reliable) through C (fairly reliable) to E (unreliable) and F (cannot be judged).
- Information credibility (1–6): from 1 (confirmed by other sources) through 3 (possibly true) to 5 (improbable) and 6 (cannot be judged).
A finding graded "B2" therefore denotes a usually reliable source and probably true information. This separate grading prevents a common error, in which a trusted source is automatically taken to lend credibility to each of its claims — and vice versa.
Verification and Cross-Checking
Verification is the heart of OSINT. A single mention is not proof; a finding is considered confirmed only once it is independently supported by several separate sources. A disciplined researcher consciously guards against confirmation bias — the tendency to see only what supports an already-formed assumption.
- cross-comparing at least two independent sources;
- geolocation and photo analysis (reverse image search, checking shadows, signage, architecture);
- reviewing metadata and timestamps where these are lawfully accessible;
- examining the original rather than relying on second-hand summaries.
Digital Footprint Analysis and Reducing Exposure
A digital footprint is the sum of the traces an individual or organization leaves online — from posts and photographs to domain registrations and data leaks. Digital footprint analysis reveals what is publicly available about a subject and how a malicious actor might exploit it.
For companies, this insight cuts both ways. On one hand it supports investigations and fraud prevention; on the other it enables defense: reducing the exposure of senior executives, removing unnecessarily disclosed data, and training employees so that their online behavior does not open the door to social engineering.
When Companies Use OSINT
OSINT is not an end in itself but a tool for concrete business and security decisions. The most common scenarios include:
- Due diligence. Vetting business partners, suppliers, and investment targets before a deal is concluded.
- Background checks. Assessing the credibility of candidates for sensitive positions in accordance with the law.
- Fraud prevention and investigation. Uncovering fictitious entities, conflicts of interest, and hidden connections.
- Corporate security. Early detection of threats, monitoring data disclosures, and protecting reputation.
- Support for investigations. Collecting and documenting evidence for internal inquiries or court proceedings.
Legal and Ethical Boundaries: GDPR and Slovenian Law
The fact that information is publicly available does not mean it may be collected, stored, or shared without limit. The processing of personal data, even when it originates from open sources, is fully subject to the General Data Protection Regulation (GDPR) and Slovenia's Personal Data Protection Act (ZVOP-2).
Responsible OSINT practice rests on a few firm principles:
- Legal basis and purpose. Every processing operation needs a valid legal basis (often legitimate interest) and a clearly defined purpose set in advance.
- Data minimization. We collect only what is necessary for the specific question — not everything that is available.
- Proportionality. Any interference with privacy must be proportionate to the goal and to the interests of the individual.
- No deception or intrusion. Misrepresentation (so-called pretexting), bypassing passwords, and accessing protected content are all impermissible.
In Slovenia, detective work is additionally governed by the Detective Services Act, which precisely defines the legitimate purposes and permissible methods of obtaining information. For this reason, in sensitive inquiries it is advisable to work with licensed professionals who operate within that legal framework.
Forensic Documentation and Chain of Custody
A finding is worth only as much as its origin can be proven. If a report is to be usable in legal or disciplinary proceedings, every step must be documented in a way that can be repeated and verified.
- capturing the original content (screenshots, archival copies) with timestamps;
- recording URLs, dates, paths, and the method of acquisition;
- hash values to prove that files have not been altered;
- an unbroken chain of custody that shows who handled the evidence and when.
OSINT and Artificial Intelligence
Artificial-intelligence tools accelerate translation, pattern recognition, and the processing of large volumes of data. Yet AI does not remove the researcher's responsibility — on the contrary, it increases it. Language models can "hallucinate" non-existent facts, and automated correlation can wrongly link innocent individuals.
The use of AI in inquiries must therefore comply with the European Artificial Intelligence Act (EU AI Act), which is being introduced in phases and, among other things, prohibits certain practices, such as the untargeted scraping of facial images to build facial-recognition databases. The principle is simple: artificial intelligence is a tool, but the final judgment and responsibility always rest with a human.
Frequently Asked Questions
Is OSINT legal?
Yes. OSINT is legal as long as it is based on publicly and lawfully accessible sources and respects personal data protection (GDPR, ZVOP-2) and sector-specific law. It becomes unlawful when it involves intrusion, deception, bypassing passwords, or processing personal data without a legal basis and a clear purpose.
What is the difference between OSINT and invasion of privacy?
OSINT collects information that is already publicly available and processes it proportionately and for a clearly defined purpose. Invasion of privacy means obtaining protected or private data without a basis — for example, by breaking into devices, by misrepresentation, or through excessive, disproportionate profiling of an individual. The dividing line lies in legal basis, purpose, and proportionality.
When does a company need an OSINT inquiry?
Most often before concluding an important deal (due diligence on a partner), when hiring for sensitive positions, on suspicion of fraud or an insider threat, when protecting reputation and senior executives, and whenever evidence must be gathered in a documented, forensically sound manner.
Can OSINT findings be used as evidence?
They can, if they are gathered lawfully and properly documented. An unbroken chain of custody and the verifiability of the source are essential; without them, even the most striking finding has limited evidentiary value. Admissibility in any specific proceeding is always decided by the competent authority or court.
Open-source intelligence is a powerful tool for managing risk — but only when guided by a clear methodology, an assessment of reliability, and firm legal and ethical boundaries. The Institute for Security and Strategic Research advocates the responsible use of OSINT, which supports better decisions while protecting the rights of individuals.
Sources and standards
- 01Regulation (EU) 2016/679 (General Data Protection Regulation)EUR-Lex, 2016
- 02Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act)EUR-Lex, 2024
- 03ISO/IEC 27037 — guidelines for handling digital evidenceISO
- 04Information Commissioner of the Republic of SloveniaInformacijski pooblaščenec RS
- 05Eurostat: crime statisticsEurostat




