Private digital intelligence bureau Lawful OSINT — Cyber monitoring — Due diligence

Primary sources · France, UK, EU and international

Official source directory

Eighteen primary portals for company, domain, security, privacy and AI checks: uses, limitations, jurisdiction and bilingual CSV/JSON downloads.

Editorial selection of primary portals; each record describes a use and limitation without commercial ranking.

Choose a source for the fact you need to establish

A company register, a security advisory and a threat report answer different questions. Preserve the stable identifier, source date, consultation time and document used. The entries below describe where to begin; they do not endorse a transaction or replace an investigation.

Results: 18

Annuaire des Entreprises

France

Find a French entity and its legal identifiers.

Useful check: Start with the SIREN; distinguish establishment from legal entity.

Limit: An administrative record guarantees neither solvency nor contact authenticity.

Primary reference · Checked

DATA INPI

France

Consult RNE records and industrial-property databases.

Useful check: Record the identifier, consulted document and date.

Limit: Check the access and reuse conditions for each dataset.

Primary reference · Checked

BODACC

France

Search civil and commercial notices.

Useful check: Link the notice to the exact entity and publication date.

Limit: A notice describes a published event, not the entire current position.

Primary reference · Checked

Companies House

United Kingdom

Find UK companies, officers and filed documents.

Useful check: Use the company number and read filing history.

Limit: Filing information does not validate every economic claim.

Primary reference · Checked

ICANN Lookup

gTLD

Consult domain registration data through RDAP.

Useful check: Record the exact domain, dates and registrar.

Limit: Redacted fields and extension-specific rules limit identification.

Primary reference · Checked

CERT-FR

France

Follow alerts, security advisories and response guidance.

Useful check: Read the reference, affected versions and revisions.

Limit: An advisory does not prove your system is vulnerable or compromised.

Primary reference · Checked

ENISA Threat Landscape

European Union

Understand European trends and their observation methods.

Useful check: Separate publication year, observation period and population.

Limit: Overlapping periods do not form a comparable annual series.

Primary reference · Checked

Cybermalveillance.gouv.fr

France

Find defensive advice and an assistance pathway.

Useful check: Select guidance matching the observed signal.

Limit: General guidance does not replace handling an active incident.

Primary reference · Checked

CNIL — violations de données

France / GDPR

Understand breach documentation and notification criteria.

Useful check: Have the controller and DPO assess the risk.

Limit: Duties depend on role, risk and context; avoid an automatic rule.

Primary reference · Checked

NIST — Generative AI Profile

International

Structure a review of generative AI risks.

Useful check: Connect risk to the use case and validation controls.

Limit: This voluntary framework does not certify a model or individual answer.

Primary reference · Checked

GLEIF · LEI

International

Identify an entity and inspect reported relationships associated with its LEI.

Useful check: Retain the LEI, registration status, renewal date and relationship reporting exceptions.

Limit: An LEI identifies an entity; it does not certify solvency. Relationship data may include reporting exceptions.

Primary reference · Checked

Commission européenne · VIES

European Union

Check recognition of a VAT number for intra-EU transactions.

Useful check: Record country, number, result and time; distinguish a negative response from an unavailable service.

Limit: VAT validation establishes neither bank-account control nor correspondent authenticity.

Primary reference · Checked

Commission européenne · sanctions financières

European Union

Access EU financial sanctions lists and associated legal texts.

Useful check: Connect a match to the exact entity, regime and current legal text.

Limit: Absence from the financial list does not cover all sectoral restrictions.

Primary reference · Checked

UK Sanctions List

United Kingdom

Consult current UK designations and unique identifiers.

Useful check: Use the UK Sanctions List; the former OFSI consolidated list has not been updated since 28 January 2026.

Limit: A fuzzy match requires identifier comparison. The scope of restrictions needs a separate assessment.

Primary reference · Checked

OFAC · Sanctions List Search

United States

Find potential matches in SDN and consolidated non-SDN lists.

Useful check: Retain search settings and compare aliases, countries and published identifiers.

Limit: The search score measures similarity, not culpability probability or a legal decision.

Primary reference · Checked

CISA · Known Exploited Vulnerabilities

United States

Identify a CVE with documented real-world exploitation in the KEV catalog.

Useful check: Match the CVE to the installed product and version, then consult the vendor advisory.

Limit: Absence from the catalog does not prove a CVE is not exploited. US federal deadlines are not universal deadlines.

Primary reference · Checked

FIRST · EPSS

International

Consult a CVE exploitation estimate for the next thirty days.

Useful check: Retain score date, probability and percentile in separate fields.

Limit: The score measures neither business impact nor the compromise probability of your own system.

Primary reference · Checked

NIST · National Vulnerability Database

United States

Consult references and severity metrics associated with a CVE.

Useful check: Record score source, CVSS version, vector and differences from the vendor advisory.

Limit: A CVSS score expresses technical severity; it is not a complete risk measure.

Primary reference · Checked

A reproducible query log

  1. Write the question and identifier before searching.
  2. Record the portal, query, filters, date and relevant document.
  3. Separate the recorded fact from what remains to be confirmed.
  4. Use an independent channel before payment or access approval.

Compare source types and evidential limits

FAQ

Does an official record guarantee a safe transaction?

No. It establishes information within its own scope. A real company or domain can be impersonated. Confirm the contact and requested action independently.

How should missing information be handled?

Record the query, date and access limitations. Do not equate a missing result with proof of non-existence. Request a relevant document or use another lawful source.

How can the directory be reused?

Download the CSV or JSON. Retain the use, limitation, reference and check date together. Portal access and publication rules may change.