Methodology
A Structured, Systematic Review of Every Relevant Public Source
Comprehensive digital exposure intelligence requires systematic examination of every significant public data category. The following describes the sources examined, the logic applied and the framework used to classify findings.
Search Universe
Sources Examined in Every Engagement
The following represents our core search universe. Additional sources may be incorporated based on the specific jurisdictions, industries or exposure concerns identified during the intake process. Every source examined is documented in the final report.
Corporate Filings and Registry Sources
Corporate registries expose personal information that directors and shareholders did not intend for broad public access. Officer appointment dates, resignation records and associated entity networks are examined across all relevant jurisdictions. Companies House alone contains the residential addresses of hundreds of thousands of UK directors, many indexed by search engines and replicated by third-party aggregators.
Search Engine Intelligence
Search engines are the primary gateway through which personal information is discovered. We use structured operator techniques extending well beyond simple name searches: site-specific queries, temporal filtering, inurl and intitle operators and correlated identifier searches. Cached and archived copies are examined independently of live source pages.
Press Coverage and Media Archives
Media coverage creates a permanent record. Articles, profiles, interviews and press releases are indexed indefinitely. Even when original publications remove or amend content, cached copies and syndications typically persist. Press archive exposure is frequently underestimated, particularly for individuals who have held public-facing roles.
Data Broker and People-Search Platforms
Data brokers aggregate public records, consumer data and property transactions into detailed profiles accessible to anyone. Data removed from one platform frequently persists on dozens of others. A credible review requires systematic examination of the full broker network, not selective spot-checks.
Residential Address Exposure Sources
Residential address exposure is consistently one of the highest-impact findings. Associating a named individual with a physical location carries direct security implications. All known sources are examined, including historical records, and cross-referenced to assess the extent of propagation across the data broker ecosystem.
Credential Breach and Data Leak Sources
Data breaches expose email addresses, passwords and phone numbers. Severity increases substantially when breach data intersects with address or employment information. Each finding is assessed in context, examining the nature of exposure and the degree to which compromised data enables further harm.
Social Media and Platform Indexing
Social platforms are routinely indexed by search engines and scraped by data aggregators. Content published publicly at any point may persist in caches and aggregated datasets long after settings are tightened. We examine both direct profile exposure and secondary indexing through third-party references.
Trademark and Intellectual Property Registries
IP filings frequently contain home addresses, personal email addresses and telephone numbers permanently accessible through official registries and third-party aggregators. This is among the most overlooked and reliable sources of personal exposure.
Search Logic
How We Ensure Accuracy and Completeness
Layered Cross-Reference Approach
Each source category is examined independently, then findings are cross-referenced to identify composite exposure patterns. An address identified in a corporate filing is subsequently checked against people-search platforms, property archives and breach databases to determine the full extent of its propagation.
Jurisdiction-Aware Search Execution
Data sources vary significantly by jurisdiction. UK corporate registries operate under different disclosure rules than US state filings. European data broker regulation differs from the US landscape. Our methodology adapts to each jurisdiction's specific data landscape and regulatory context.
Disambiguation Logic
Common names are among the most technically demanding aspects of open-source intelligence. We apply disambiguation logic using multiple corroborating data points: known addresses, dates of birth, employment history and associated entities. The basis for each attribution is documented, and uncertain attributions are flagged for client confirmation.
Name Variation Analysis
Individuals may be indexed under first name only, initials, maiden names, abbreviated forms, transliterations or common misspellings. Our methodology accounts for all known and reasonably anticipated variations.
Address Confirmation Protocol
Where address exposure is identified, findings are verified against known addresses provided during intake. Confirmed address exposure is weighted as high-impact regardless of source.
Manual Verification Layer
All findings from the initial search phase are subject to human review: accuracy verified, context assessed, disambiguation applied. Professional judgment is applied to every finding before inclusion in the report.
Risk Classification
Weighted by Exposure Severity and Composite Risk
Every finding is assessed both in isolation and as part of a composite exposure profile. The risk classification considers the nature of the data, its accessibility, its potential for misuse and its context in relation to other findings.
Publicly available information with limited risk in isolation: corporate directorship listings, general press mentions, or professional profile information consistent with the individual's known public role. Documented for completeness; monitoring may be warranted but immediate remediation is not required.
Information presenting moderate risk through its nature or potential for misuse in combination with other findings: email address exposure, partial address information, or social profiles revealing personal details beyond the professional. Prioritised for remediation following high-risk actions.
Information presenting significant and immediate risk: residential address exposure, credential breach data linked to personal accounts, or composite findings where multiple categories of sensitive data are exposed across interconnected sources. Summarised prominently in the executive section and require priority remediation.
Composite Risk Assessment
Individual findings are assessed in the context of the full exposure profile. Combinations frequently present materially higher risk than any single finding. Composite patterns receiving particular attention:
Residential address exposure combined with credential breach data creates elevated identity exploitation and physical security risk.
Corporate directorship data combined with personal address exposure links the professional and personal identity of the subject in a manner that can be exploited for targeted approaches.
Social media profiles combined with employer information and residential data create a comprehensive personal profile that is accessible to any interested party without restriction.
Press archive exposure combined with data broker indexing ensures that historical information remains continuously discoverable, regardless of the passage of time or changes in the subject's public profile.