"Public" is doing a lot of work in the phrase "public data". It is worth being precise about what it covers, because the difference between lawful diligence and surveillance is not the technology. It is the source.
What we read
Every family of sources in the pipeline is public by right: public and company registries, published press, open web data and public profiles. Nothing we crawl requires access that was not given to us.
That constraint is not a limitation we tolerate. It is what makes a finding usable as evidence rather than as a hint you cannot cite.
What we do not touch
- No content behind a login, a paywall or a privacy setting.
- No purchased breach data, whatever it is marketed as.
- No inference about health, beliefs or affiliations from what we read.
A source that has to be obtained quietly cannot be shown to a regulator. If it cannot be shown, it is not diligence.
Where the line between us falls
We provide the collection, the correlation and the record. The legal basis for running a search on a given person is yours: your obligation, your policy, your regulator.
That division is deliberate. We can tell you that a source is public and that a search happened at a given moment. Only you can say why that person was in scope.
What the record proves
Every search leaves a trace with its sources and its timestamps. Months later, when someone asks why a file was flagged, the answer is a document rather than a recollection.