
Protective intelligence is the continuous discipline of collecting, verifying, and acting on information about threats to a specific person or organization, and open-source intelligence (OSINT) is its primary collection layer — the lawful gathering of public, social, and commercial data used to build that threat picture. Together they turn scattered public signals into a defensible, decision-ready protective posture, delivered through a defined methodology with auditable deliverables and firm legal limits. For a corporate security or executive-protection program, understanding exactly where OSINT ends and protective intelligence begins — and where both stop, legally and ethically — is the difference between a program that holds up under scrutiny and one that creates liability it was meant to prevent.
General counsel and chief security officers increasingly hear both terms used loosely, sometimes interchangeably, by vendors selling everything from a one-time background check to a full protective detail. That looseness is a problem: OSINT is a collection method, not a program, and protective intelligence is a decision discipline, not a data feed. A corporate security function that cannot articulate the difference — and cannot show its methodology, its deliverables, and its legal guardrails in specific terms — is not running a defensible program, whatever it calls itself. This guide lays out what each term actually means, how a competent provider structures the work end to end, what a real deliverable looks like, and exactly where the ethical and legal lines sit.
What Is OSINT, and How Does It Fit Inside Protective Intelligence?
Open-source intelligence is the practice of collecting and analyzing information that is publicly or commercially available — meaning no hacking, no unauthorized access, and no deception used to obtain private data. That includes social media activity, public records (property, court, corporate, voter), news and media coverage, data-broker and people-search listings, breach-exposure databases that catalog already-leaked credentials, domain and infrastructure registration data, and metadata embedded in publicly posted images and documents. None of this requires bypassing a login screen or tricking someone into disclosing something they did not intend to share — if it does, it is no longer OSINT, it is an unauthorized-access or social-engineering activity that sits outside the discipline entirely and, in most jurisdictions, outside the law.
Protective intelligence is the broader discipline that OSINT feeds. It is the ongoing process of defining what matters for a specific principal or organization, collecting against that requirement, analyzing what comes back for credibility and relevance, and disseminating a decision-ready assessment to the people who act on it — a protective detail, a general counsel, a board. OSINT answers the question what is out there. Protective intelligence answers the harder question: does any of it matter, and what should we do about it? A program that only does the first without the second produces a pile of screenshots. A program that does both produces a defensible security decision.
Where the Signal Actually Comes From: The Open-Source Collection Landscape
Not all open-source categories carry the same weight or the same risk. A mature program tunes its collection to the sources that are actually predictive for the principal or organization in question, rather than scraping everything indiscriminately. The table below maps the major source categories to what they typically reveal and how they are used inside a corporate security or EP program.
| Source category | What it typically reveals | Representative program use |
|---|---|---|
| Social media & forums | Sentiment, fixation, grievance escalation, leakage of intent, location tags | Behavioral-trend monitoring on a named subject or a general threat stream |
| Public records | Property ownership, litigation history, corporate filings, liens, voter records | Verifying identity, mapping affiliations, exposure baselining for a principal |
| Data-broker & people-search sites | Home address, phone numbers, relatives, past addresses | Footprint audit; identifying what a hostile actor could find in minutes |
| Breach-exposure databases | Previously leaked credentials and personal data tied to an email or domain | Flagging account-takeover risk before it is exploited |
| News & media archives | Prior coverage, public statements, past incidents, reputational history | Due diligence and background-intelligence context |
| Domain, DNS & infrastructure data | Ownership and hosting behind a suspicious site or account | Attributing a hostile or impersonating account to an infrastructure footprint |
| Public image & document metadata | Capture location, device, and timestamp data left in publicly posted files | Corroborating or disputing a claimed location or timeline |
The discipline is in restraint as much as reach. A program that monitors every category on this list for every subject produces noise that drowns the signal that matters. A well-run program scopes collection to the categories most likely to be predictive for the specific requirement in front of it, and expands only when the analysis calls for it.
The Methodology: How OSINT Becomes a Protective-Intelligence Deliverable
A credible program follows a repeatable sequence rather than an ad hoc scramble every time a request comes in. The steps below are the backbone of that sequence for a corporate security or executive-protection program:
- Define the requirement. Identify the protected person, asset, or organization, the specific decision the work will inform, and the timeframe — a one-time due-diligence check and a continuous executive-monitoring program are scoped completely differently from day one.
- Build the baseline. Establish what a subject’s normal public footprint looks like before looking for anomalies; without a baseline, analysts cannot reliably tell a new signal from background noise.
- Collect under managed attribution. Gather from the tuned source list without alerting the subject or tipping off that monitoring is occurring, preserving each item with its source, URL, and capture timestamp.
- Corroborate before elevating. Require independent confirmation from at least two sources before a signal becomes a finding; a single unverified post or listing should never drive a security decision on its own.
- Analyze for credibility, not just content. Weigh capability, intent, proximity, and pattern — not just whether something sounds alarming — and label every conclusion with an explicit confidence level.
- Disseminate to the right decision-maker. Route the finding to whoever owns the decision it informs — a protective detail lead, general counsel, HR, or law enforcement — in a form they can act on immediately.
- Feed the outcome back into the cycle. Update the baseline and the collection plan based on what happened, so the next cycle starts smarter than the last one.
Every one of these steps is doing real work. Skip the baseline step and a program cannot recognize an anomaly. Skip corroboration and a program is one bad tip away from acting on disinformation. The methodology is what separates a defensible program from a collection of screenshots with a cover memo.

What a Real Deliverable Looks Like
A vague PDF of screenshots is not a deliverable; it is raw material. A mature protective-intelligence program produces one of a small number of distinct, purpose-built products, each with a different structure and audience. A baseline exposure report establishes what is publicly discoverable about a principal or organization at a point in time, scored by risk category, and is typically produced before any monitoring begins so there is a documented starting point. A continuous monitoring brief is a recurring, dated summary covering the monitoring period, flagged items with confidence levels, and any recommended action, delivered on a fixed cadence so that a “quiet” period is documented, not assumed. An incident-triggered deep dive is a rapid, focused product built around a single concerning event — a threatening message, a doxxing incident, an activist campaign — that traces attribution where possible, assesses credibility, and recommends a specific next step. A board or executive briefing translates the technical findings into a decision memo for people who need the conclusion and the recommended action, not the underlying methodology. Every one of these should show its sourcing, its confidence levels, and its date — a finding without a documented source and date is not usable in a legal or insurance context and should not be treated as reliable internally either.
Ethics and Legal Limits: What OSINT and Protective Intelligence Cannot Do
The legal boundary is the single most important thing a corporate security leader should confirm before engaging any provider. OSINT, by definition, does not include unauthorized access to a computer system or account — doing so risks violating the federal Computer Fraud and Abuse Act and equivalent state statutes, regardless of the justification. It does not include pretexting — impersonating someone to trick a third party (a bank, a phone carrier, a records custodian) into disclosing private information — which is separately restricted under the Gramm-Leach-Bliley Act’s safeguards for financial information and is a criminal offense in many contexts on its own. It does not include social engineering an individual to obtain non-public information they did not intend to share. And a program conducting background investigations that touch employment, tenancy, or credit decisions must operate within the Fair Credit Reporting Act’s framework regardless of how the underlying data was sourced.
Licensing matters as much as method. In most states, including Arizona, investigative work conducted on behalf of a third party for compensation requires a private investigator license, and a corporate security program that outsources OSINT or protective-intelligence work to an unlicensed provider is taking on exposure it likely does not realize it has. A legitimate provider should be able to state its license number, describe exactly how it corroborates a finding before acting on it, and explain in plain terms what it will not do — not just what it can.
Proportionality is the ethical companion to legality. Collection should be scoped to a documented, legitimate security purpose — not indiscriminate surveillance of everyone in a principal’s orbit, and not collection on family members, employees, or third parties without a specific, articulable reason tied back to an actual threat indicator. A program that cannot explain why it is looking at a specific person is a program that has drifted past its legitimate purpose, and that drift is exactly what turns a defensible security function into a privacy liability for the organization that commissioned it.
What Separates an Elite Program From a Mediocre Vendor
A mediocre provider sells a report. An elite provider runs a program: a documented methodology, a named analyst who can answer questions about sourcing and confidence, corroboration standards applied consistently rather than skipped under time pressure, and a clear, pre-agreed escalation path for the moment a finding crosses from “monitor” to “act.” Ask any prospective provider three questions before engaging them: how do you corroborate a finding before you elevate it, what will you refuse to do regardless of the fee, and who on your team is licensed to conduct this work in the jurisdiction where the subject is located. A provider that cannot answer all three specifically is not running protective intelligence — it is running a search engine with a letterhead.
A Representative Scenario
Consider a representative case: a publicly traded company’s general counsel requests a pre-event exposure check ahead of a contentious shareholder meeting where an activist group has signaled it will attend. A properly scoped OSINT collection maps the group’s public statements, prior event conduct at comparable companies, and any coordination visible on public platforms, while a parallel check establishes whether the CEO’s home address or family details are currently exposed through data-broker listings. Corroborated findings — not raw screenshots — are delivered to the general counsel and the venue security lead forty-eight hours before the event, with a specific recommendation on venue posture and a documented rationale the board can review afterward. Nothing in that deliverable involves a named real client or a guaranteed outcome; it illustrates how the methodology functions under time pressure.
How Honeybadger Solutions Runs Protective Intelligence and OSINT
Our protective intelligence, OSINT, digital forensics, cybersecurity, financial investigations, and background-intelligence work is handled in-house and delivered nationwide, remotely and by design — a corporate client in Chicago or a family office in Miami receives the same methodology, corroboration standard, and licensed oversight as a client in Phoenix. Where a finding calls for physical protective response, our own in-house, licensed agents in Arizona execute directly from home command, and outside Arizona we direct a commanded, vetted-partner network with established theaters in California, Texas, and Florida and other regions served on a mandate basis — the intelligence standard travels with the principal regardless of who executes the physical posture.
About Honeybadger Solutions
Honeybadger Solutions is a veteran- and law-enforcement-led, Arizona-licensed security and investigations firm headquartered in Casa Grande, with additional offices in Phoenix and Oro Valley. Protective intelligence, OSINT, digital forensics, cybersecurity, financial investigations, and background-intelligence services are delivered in-house nationwide and internationally, corroborated to a documented methodology and staffed by licensed personnel. Physical and executive-protection services are delivered by our own in-house agents in Arizona and, beyond it, through a commanded, vetted-partner network directed from our Arizona command. To scope a protective-intelligence engagement, an OSINT assessment, or a corporate security program with our team, call 602-725-2818.
Sources and further reading
- FinCEN — Legal Authorities — The Bank Secrecy Act, USA PATRIOT Act and Anti-Money Laundering Act authorities that govern financial and virtual-asset reporting.
- FBI Internet Crime Complaint Center — Annual Reports — Annual and state-level internet crime statistics, including dedicated reports on cryptocurrency fraud and elder fraud.
Honeybadger Solutions delivers Blockchain Forensics, Blockchain Consulting and Cyber Investigations from its Arizona office for clients across the United States and internationally. This casework is performed remotely under Arizona licensure, so there is no geographic limit on where a client can be based.