OTVS v1.0

How We Verify OSINT Tools

Our Open-Source Tool Verification Standard (OTVS) is an evidence-first, 16-stage audit we run against every entry in the OSINT Tools directory — built around one rule: we don't call something verified unless there's recorded evidence for it.

Why we built this

Our OSINT Tools directory lists 471 tools our investigations team relies on for verification, geolocation, and research. Because many of these tools handle sensitive data — usernames, phone numbers, images, location data — we wanted every listing to carry an honest signal about privacy, data handling, and digital-security practices, instead of a single unexplained badge.

OTVS is how we produce that signal. Each tool is checked across 16 separate stages, from confirming its official identity to reviewing its privacy policy, licensing, and known risks. Every claim in the audit is backed by a recorded piece of evidence — a page, a policy document, a repository, a support article — and where we couldn't find that evidence, the tool is marked accordingly rather than assumed safe.

What the tag on each tool means

Every tool card in the directory carries one of three tags. They describe how confident we are in the evidence behind that tool's review — not a guarantee that the tool itself is safe to use.

Evidence-Reviewed

Reviewed using direct evidence — we reached the tool's official page or source ourselves during the audit.

168 of 471 tools

Indirectly Reviewed

Reviewed using indirect evidence — our audit tooling could not fetch the official page directly, so we relied on search results instead.

84 of 471 tools

Needs Re-Verification

Initial review relied on general knowledge rather than a live check. These are our top priority for re-verification.

219 of 471 tools

We're publishing all three counts, including the less flattering ones, because that's the same evidence-first principle applied to ourselves: we'd rather tell you exactly how much confidence to place in a listing than round it up to a single reassuring word.

The 16 audit stages

Behind each tag is a full pass through 16 stages. Every stage is scored as Verified (direct evidence supports it), Partially Verified (some evidence, but incomplete), Unknown (no sufficient evidence either way — not a negative finding), Not Checked, or Not Applicable.

01

Identity

The tool's name and vendor match its official presence.

02

Official URL

The listed link is the authoritative destination, not a reseller or aggregator.

03

Reachability

The site or service is currently live and reachable.

04

Training

For courses: the offering and provider currently exist.

05

Data Collection

What user or target data the tool actually collects.

06

Privacy Policy

A current, attributable privacy notice exists.

07

Third-Party Sharing

Disclosed sharing or transfer of data to third parties.

08

Source Code Public

Whether the actual source repository is publicly accessible.

09

Open Source

Whether the license meets the Open Source Definition — public code alone isn't enough.

10

License

The exact license attached to the relevant code.

11

For-Profit Status

Whether the operator is a commercial or non-commercial entity.

12

Function Test

Whether the advertised function was reproducibly tested.

13

Security

A basic review of security practices and advisories — not a penetration test.

14

Maintenance

Whether the tool is currently maintained and active.

15

Legal Access

Login, payment, jurisdiction, or API-key requirements to use it.

16

Risk Review

Documented OSINT, privacy, legal, or abuse-related risks.

Where our evidence is weaker — and why

In the interest of the same honesty this whole system is built on, here are the two limitations that produced most of the "Indirectly Reviewed" and "Needs Re-Verification" tags:

Some official pages couldn't be fetched directly. Our audit tooling was blocked from directly opening a number of sites — mostly username, phone, and people-search tools — by a live-approval requirement that isn't available during an unattended audit run. For those, we used search-based evidence instead of a direct page check, and marked the result "Indirectly Reviewed" rather than "Evidence-Reviewed."

Our search tool ran out of quota partway through the audit. Once that happened, tools reviewed for the remainder of that pass had to rely on general knowledge instead of a live check. We marked these conservatively as "Needs Re-Verification" rather than assume they'd pass a live check.

Function testing is not yet performed. As a matter of policy, we don't create accounts, log in, or make paid purchases just to test a tool's functionality — so this stage is scored "not tested" for essentially every tool. That's a scope decision, not a finding that a tool doesn't work.

Kept current

We re-audit this database on a roughly two-year cycle, prioritizing tools currently tagged "Indirectly Reviewed" or "Needs Re-Verification." If you notice a broken link, an outdated policy, or a concern with any listing before then, you can flag it directly from its card in the directory using the report icon — every report reaches our team by email.

Browse the OSINT Tools directory