x-ray-a-company
X-ray a company
Take a brand, a website, or an invoice and produce a defensible picture of who you are actually dealing with. Four layers — legal entity, people, infrastructure, reputation and risk — worked in that order. Skipping the first ruins everything after it: the trading name on the contract, the brand on the website, and the entity liable in court are routinely three different things, and every later finding attaches to the wrong one if you assume they match.
Step 1 — Authorized scope
Write the target, the decision the work supports, the risk areas in scope, the jurisdictions involved, and what is out of bounds. Read ../../ETHICS.md. Corporate research on public filings is broadly lawful and often mandatory, but two limits bite. Stay passive toward the company's own systems — reading DNS and certificate logs is OSINT, authenticating or probing is not. And named individuals inside the company are still data subjects: an officer's directorships are fair game, their family is not.