Skip to content
Home
Trust and methodology

Sourced, resolved, cited.

WhiteIntel fuses 41 public and licensed sources into one graph of 171.2M+ entities — every claim carries the record behind it. Here's exactly where the data comes from, how the same entity is resolved across sources, and how it's secured.

/01

Honesty by construction

Editorial principles
/01

A source on every claim

Every entity, edge and risk flag links to the registry or leak record behind it. Nothing is asserted without provenance.

/02

Absent ≠ non-existent

A missing ownership edge means “not yet observed in our sources”, not “does not exist”. We never imply completeness we don't have.

/03

Decision-support, not a verdict

Risk levels are heuristic investigative leads. WhiteIntel is not a legal determination of beneficial ownership.

/04

Unscored shown honestly

Where an entity isn't yet risk-scored we say “Unscored” rather than defaulting it to low.

/02

Where the data comes from

41 sources

The principal sources behind the corpus — what each contributes and its licence. 41 are fused in total; the largest and most-cited are shown here. Open sources serve freely; gated registers stay behind their licence.

OpenOwnership

Open

Global beneficial ownership (BODS, incl. UK PSC)

ODbL — attribute + share-alike

GLEIF

Open

Global LEI registry + parent/child

CC0 — public domain

ACRA Singapore

Open

SG company registry

Singapore Open Data — commercial-ok

ICIJ Offshore Leaks

Open

Panama · Paradise · Pandora · Bahamas

ODbL — attribute ICIJ

SEC EDGAR

Open

US filers, insiders (Forms 3/4/5)

US public domain

FAA

Open

US aircraft assets

US public domain

OFAC · EU · UK OFSI · UN

Open

Sanctions lists

Public / OGL / EU reuse

UK Companies House

Open

UK company register, officers, PSC + financials

Open Government Licence

France SIRENE

Open

French company + establishment registry

Open Licence — commercial-ok

Brazil RFB

Open

Brazilian company registry (CNPJ) + partners

Public record

OpenSanctions

Open

PEP · crime · debarment · sanctioned assets

CC-BY-NC 4.0 — non-commercial

Poland KRS

Open

Polish company register + shareholders

Public record

ADGM · DIFC

Open

UAE financial-free-zone registries

Public record

Gibraltar UBO

Gated

Gibraltar beneficial owners

Restricted — gated

OBRS Belize · Anguilla · St Vincent · Luxembourg

Gated

Offshore company registers

Restricted — gated
/03

Method and security

Resolution · controls

The same entity, across sources

Matches collapse into one cluster_id; the dossier shows every record in the cluster.

1

Identifier join

Exact strong-id match (LEI, sanctions id, company number, NIP, UEN, SEC CIK).

2

Name-block

Name + jurisdiction, only where a block spans ≥2 registries.

3

Sanctions bridge

Links null-jurisdiction sanctioned parties onto same-name registry/leak records.

Locked down by construction

What we operate behind the corpus — described plainly.

Access control

Row-Level Security is enforced on every corpus table; the public API reads through a single locked-down service role, never a broad database credential.

Least privilege

Read, ingest and mutation each run under a separate scoped role. Write functions are execute-revoked from anonymous callers.

Encryption

TLS in transit on every request; data encrypted at rest by the managed Postgres platform.

Data retention

One-off dossier exports stay re-downloadable for 90 days, then expire. Guest checkout keeps an email for delivery only.

/04

Commitments we stand behind

Our word

Every claim is sourced

Each entity, edge and flag links back to the registry or leak record behind it. If we can't cite it, we don't assert it.

Leads, not determinations

Risk levels are heuristic investigative leads — never a legal finding of beneficial ownership, sanction or wrongdoing.

Corrections on request

Flag a sourced error or request a lawful removal and we correct it; the fix propagates on the next ingest.

No fabricated data

We never invent entities, edges or figures to fill a gap. Absent means “not yet observed in our sources”, and is shown as such.

/05

Corrections, removals and disclosure

intel@whiteintel.dev
Corrections and removals

Spotted a sourced error, or need a lawful removal? Include the entity id or dossier URL and we correct it on the next ingest.

Security disclosure

We welcome coordinated, responsible disclosure. Email the details — affected URL, reproduction steps and impact — and we acknowledge, investigate and fix.

/06

Questions, answered

FAQ
From 41 sources — OpenOwnership (UK PSC), the UK Companies House, France SIRENE and Brazil RFB company registries, GLEIF, ACRA Singapore, ICIJ Offshore Leaks, SEC EDGAR, FAA, OpenSanctions, offshore UBO registries and the OFAC/EU/UK/UN sanctions lists — cross-source-resolved into one graph, with live UK Companies House lookups on top. Each carries its licence; commercial-safe sources are served openly and restricted registers are gated.
In three precision-ordered passes: (1) exact strong-identifier join (LEI, sanctions id, company number, NIP, UEN, SEC CIK); (2) name-and-jurisdiction blocking, only where a block spans two or more registries; (3) a sanctions name-bridge that links null-jurisdiction sanctioned parties onto same-name registry/leak records. Matches collapse into one cluster_id — the same real-world entity across sources.
Heuristically, from graph connectivity (degree), presence in a secrecy jurisdiction, and sanctions signals — as an investigative lead, never a legal conclusion. Unscored entities are labelled as such.
Row-Level Security is enforced on every table; the public API reads through a locked-down service role with input validation and rate limiting; write functions are execute-revoked from anonymous callers; no secrets are shipped to the client. Security posture is self-attested — reviewed internally, not audited or certified by a third party.
Email intel@whiteintel.dev with the entity id or dossier URL. We correct sourced errors and honour lawful removal requests; corrections propagate on the next ingest.

See it for yourself.

Open any entity — every claim on the dossier links back to its source.