OSINT · Resource
A Responsible OSINT Workflow for Cold-Case Research
An ethical, lawful open-source-intelligence workflow for cold-case research: legal collection, source evaluation, documentation, and privacy — without scraping restricted systems.
By Second Trace editorial · Published August 30, 2026 · Updated August 30, 2026 · 8 min read
In short
A responsible OSINT workflow has five steps: define a lawful, specific question; collect only from public sources you are permitted to access; record the source and capture time for everything; evaluate each source's reliability; and stop before private individuals, access-controlled systems, or anything that could harass or endanger someone.
Step 1 — Define the question lawfully
Start with a specific question you have a legitimate, lawful reason to answer — for example, "what was reported publicly about this event in the month it occurred?" A vague mandate ("find everything about this person") drifts quickly into collecting data you have no business holding. Scope the question, and write it down.
Step 2 — Know what counts as open source
Open source means information that is publicly available and that you are permitted to access: published news and media, government records and public databases, public social posts, academic publications, and public archives. It does not mean access-controlled systems, paywalled content you circumvent, leaked private data, or anything obtained by deception. If you would need a password you do not have, it is out of scope.
Step 3 — Collect with a paper trail
For everything you gather, record the source (URL or citation), the exact date and time you retrieved it, and how you obtained it. Capture a copy or screenshot. Months later, you must be able to show where each fact came from and when it was true. This is the same discipline that makes any investigation auditable.
Step 4 — Evaluate the source before you trust it
Distinguish primary from secondary sources, and official records from unofficial commentary. Ask who produced it, when, and why. A screenshot of a public record and a screenshot of a social post are not equally reliable, even if both are "public." Record your reliability assessment alongside the item.
Step 5 — Verify before you rely
A single source is a starting point, not a conclusion. Where you can, corroborate across independent sources. Treat any finding that rests on one unverified source as unconfirmed until it is not. When you cannot verify, say so — "insufficient evidence" is a complete and honest answer.
Step 6 — Respect privacy and avoid harm
Do not publish or collect personal information about private individuals, and never use research to identify, contact, or harass anyone. Presume innocence: describe people neutrally until an authoritative source establishes a role. If a step feels like it could endanger or embarrass an uninvolved person, stop.
Step 7 — Know the boundaries
Responsible OSINT has hard limits: no restricted systems, no circumvented access controls, no private data, no real-time tracking, no vigilante publication. Legal limits vary by jurisdiction and by your intended use. This guide is not legal advice — when your work could have legal consequences, consult a qualified professional.
Sources & further reading
- OSINT Framework — a community-maintained index of open-source intelligence tools and sources.
- Society of Professional Journalists Code of Ethics — standards for verification and minimizing harm in open-source research and reporting.
Frequently asked questions
Is OSINT legal?
Collecting information that is genuinely public — published records, open databases, public media — is generally lawful. What is not is accessing restricted systems, bypassing paywalls or access controls, or collecting and publishing private personal information. Legality also depends on jurisdiction and intended use, so when in doubt, consult a qualified professional.
What is the difference between OSINT and scraping?
OSINT is about using open sources with permission. Scraping is the automated extraction of data from a site, which may violate the site's terms or applicable law and is outside responsible OSINT. Second Trace does not scrape access-controlled services.
How do I archive a page that might change or disappear?
Capture a screenshot, save a copy, and record the URL and the exact date and time you retrieved it. Web archives (such as the Internet Archive) are a useful additional record. The capture time matters because web content changes constantly.
Put this into practice
Second Trace is a workspace for organizing case information with full provenance. These capabilities map directly to the method above:
Related resources
Evidence
Organizing evidence →A practical framework for organizing evidence in large, long-running investigations — provenance, chain of custody, and how to keep thousands of items findable.
Method
Facts, allegations & theories →A working taxonomy for sorting confirmed facts, allegations, testimony, inference, and theory in a case record — and why the distinction must survive export.
Ethics
Ethics of unsolved cases →Ethical principles for researching unsolved cases: presumption of innocence, privacy, avoiding harm, and respect for victims and living people.