Lead intelligence & OSINT
What the automatic checks tell you about a lead, and how to run the manual tools for a suspicious one.
The rule
We verify that a lead is real and reachable; we do not build profiles of people. Automatic checks only ever send an email address or number to an accountable provider (Telnyx, Vonage, Gravatar as a hash, Have I Been Pwned) or a handful of silent registration probes. Nothing that would notify the person is ever used, and nothing from social profiles is stored.
Automatic — the Lead intelligence card
| Signal | Meaning |
|---|---|
| Gravatar | public avatar and display name for the email; 'name matches' confirms identity |
| Registered on … | silent checks: does the email have an account on X/Twitter, Spotify, Adobe |
| Email history | Have I Been Pwned: an address seen in breaches since e.g. 2014 has existed for years — a real person, not a fresh fake (needs the HIBP key) |
| Company | for business emails: site title, logo, Companies House link |
| HLR | Vonage: phone reachable right now, roaming, ported, network |
| Search buttons | Google, LinkedIn, Facebook, Instagram, Companies House pre-filled with the name — you look, nothing is stored |
Older leads often have no social accounts at all; that alone barely moves the score. What matters is the combination: real mobile number, email with history, name that matches, answered a call.
Manual — for one suspicious lead
On the server a manager can run two commands (one lead at a time, by hand): osint-email <email> lists the services the address is registered on; osint-user <handle> checks whether a username exists on public sites. Paste the result into the lead's notes. Do not batch these over lists.
Automated bulk profiling of individuals is not something the system does, by design: it breaks constantly (Meta bans it), and under UK GDPR it is processing people never agreed to.