Corporate structure, official registries, shell-company tells, and a due-diligence workflow.
Corporate due diligence pulls together nearly every technique from earlier chapters — search operators, identity pivoting, domain forensics, financial records — and points them at an organization rather than an individual. It's also one of the most common paying uses of professional OSINT work: vetting a business partner, verifying a supplier, screening an acquisition target, or checking a vendor before signing a contract.
Before researching any company, know what kind of entity you're looking at, because it determines what records exist and where. A publicly traded company has extensive mandatory disclosure obligations. A private limited company has much lighter filing requirements, varying enormously by country. A shell corporation may have almost no independent existence beyond a registration filing and a registered-agent address. Understanding which category a target falls into tells you which records to expect — and their conspicuous absence, where you'd expect them, is itself a finding.
Every jurisdiction maintains some form of company registry — Companies House in the UK, the SEC's EDGAR system in the US for public companies, and equivalent national registries elsewhere — that records a company's registered officers, filing history, registered address, and often its incorporation date. For publicly traded US companies, EDGAR's mandatory filings are a goldmine: the 10-K (annual report) and 10-Q (quarterly report) contain audited financials, risk disclosures, and management discussion that a company would never volunteer directly; 8-K filings disclose material events (executive departures, major litigation, mergers) as they happen, often before the news cycle catches up.
For non-profits, similar transparency exists through required tax filings (the IRS Form 990 in the US, for example) which disclose executive compensation, major donors in some cases, and program spending — a frequently underused resource for vetting a charity or NGO.
A company's own website and public social media are a rich, self-published source: robots.txt, sitemap structure, and website metadata can reveal an organization's technology stack and internal directory structure (apply the techniques from Chapters 3 and 9 directly). Job advertisements are an underrated intelligence source — they routinely reveal the specific technologies a company uses internally, team structure, expansion plans, and sometimes even client names accidentally included in a job description. Social media posts from company accounts reveal partnerships, office locations, and staff who might not otherwise be findable.
WHOIS and domain registration data (Chapter 9) applies directly here too — a company's domain registration date is a hard, independent check against its claimed founding date or years in business, exactly the technique used in the capstone worked example in Chapter 15.
Court records, lawsuits, and regulatory actions are public in most jurisdictions and are one of the highest-value, most under-searched sources in corporate due diligence. A pattern of consumer lawsuits, an active regulatory investigation, or a history of contract disputes tells you far more about real operational risk than a polished "About Us" page ever will. Combine this with negative news screening (Chapter 10) — systematically searching the company name plus terms like "lawsuit," "investigation," "fraud," or "recall" across news archives.
Government contracts, in particular, are often published in full or in summary as a transparency requirement, and reading one properly (not just skimming the headline value) reveals scope, subcontractor relationships, performance requirements, and sometimes penalty clauses that hint at past performance issues. Power mapping — the practice of diagramming the relationships between a company, its subsidiaries, its major contracts, and the individuals who sit across multiple related entities — turns a pile of individual filings into a picture of who actually controls what, which is often obscured deliberately through layered ownership.
A shell corporation exists on paper to hold assets, obscure ownership, or move money, without any real operating business behind it. Tells to look for: a registered address shared by dozens or hundreds of unrelated companies (a classic sign of a registered-agent mill), officers who appear as directors of an implausibly large number of unrelated entities, no discoverable website, no employees on LinkedIn, no digital footprint at all despite claimed years of operation, and incorporation in a jurisdiction chosen for secrecy rather than for any operational reason connected to the claimed business.
Before any significant business relationship, screen the company and its named officers against major sanctions and blacklists: the UN Security Council consolidated list, OFAC's SDN list (see Chapter 10), and equivalent national and EU designation lists. This isn't optional box-ticking in regulated industries — it's a legal requirement in many jurisdictions, and it's a fast, free check that should happen before any deeper research effort.
Corporate transparency varies enormously by country. Some jurisdictions (the UK, much of the EU) have relatively accessible public registries with officer and filing history searchable for free or near-free. Others make ownership deliberately opaque through nominee directors, bearer shares (where legal), or registration in secrecy jurisdictions specifically chosen for that opacity. When a target company is registered somewhere chosen for legal opacity rather than for any operational connection to its stated business, treat that jurisdictional choice itself as a finding worth flagging, not just a research obstacle to route around.
Start with the official registry entry: officers, registered address, incorporation date. Cross-check the domain registration date against claimed company history (Chapter 9). Pull financial filings if the company is public, or tax filings if it's a non-profit. Run negative-news and litigation searches on the company and its named principals (Chapters 3, 4, 10). Check sanctions lists. Examine the company website's technical footprint and job postings for operational detail. Map ownership and officer overlaps across related entities. Finally, weigh the whole picture: does the volume and consistency of what you found match what you'd expect for a company of its claimed size, age, and sector — or are there gaps that look like a shell?
A real due-diligence case often produces several red flags at once, not one clean signal — an odd registered address, a lawsuit, a thin web presence — each partial and none conclusive alone. Triage them the same way you would any set of competing leads (Chapter 15, §15.1): weigh each flag's credibility, how urgent it is to resolve before a decision deadline, and how much it actually matters to the specific question you're answering, rather than treating every flag as equally worth chasing to the end. And if the due-diligence trigger was an anonymous tip or an unverified claim about the company rather than something you found independently, run it through the content-only credibility checklist in Chapter 13, §13.5 before weighing it alongside your own findings.
For exercise 3, look specifically for technology names, internal tool references, and phrases like "as we expand into [region/market]" — job postings are written by people focused on attracting candidates, not on operational secrecy, which is exactly why they leak more real detail than a press release ever would. This is the same "people leak more through routine behavior than through deliberate statements" principle from Chapter 5, applied to organizations instead of individuals.