IntegrityFile.org public-source due diligence reports for NGOs, UN agencies and grant makers
Due diligence for humanitarian and development actors
NGO partner, vendor, grantee and subcontractor due diligence service
For the partner you are about to select, get the public-source due diligence file your team can document, review, and keep.
IntegrityFile helps NGO, UN, donor, and grant teams document public-source due diligence on preferred partners, vendors, grantees, and subcontractors before award, agreement signing, or onboarding.
Not bulk surveillance. Not automatic exclusion. Reports are generated for specific selection, procurement, grant, or monitoring decisions and are intended for human review. IntegrityFile complements existing screening systems by documenting public-source risks that are often missed, under-documented, or hard to standardize: rebranding risk, governance issues, safeguarding concerns, political exposure, conflicts of interest, donor/audit history, local-language adverse media, and public-source reputation signals.
Most screening tools answer narrow questions: is there a list match, a sanctions hit, or a known database record? IntegrityFile is built for the harder NGO and grant-making review: the public-source risk story around the entity, its aliases, its leadership, and the context in which your team is about to award, sign, onboard, renew, or monitor.
Reputation and adverse mediaLocal-language allegations, public controversies, community concerns, media patterns, and issues that never become a formal list record.
Political exposure and neutralityPEP links, state-connected boards, party roles, government proximity, politically exposed relatives, and conflict-sensitive operating contexts.
AML, terrorism-financing and aid diversion signalsRestricted-party proximity, diversion allegations, financial crime references, cash-flow red flags, high-risk intermediaries, and source-quality checks before escalation.
Governance, ownership and conflictsBoard overlap, related-party links, beneficial ownership signals, shared addresses, procurement conflicts, signatory risk, and leadership continuity.
Rebranding and identity historyFormer names, dormant entities, splinter organizations, acronym collisions, registration continuity, and attempts to outrun old public-source problems.
Donor, audit and safeguarding historyQuestioned costs, grant terminations, corrective actions, PSEA and safeguarding concerns, regulator records, and donor/audit references that need file notes.
A finding is not a conclusion. IntegrityFile turns public-source signals into a structured file for human review, clarification, escalation, or dismissal as a false positive.
What you receive
An audit-ready file, not just a search result
The deliverable is a structured due diligence report for the partner or vendor file. Every section is designed to be filed, reviewed, and exported.
Risk category summaryClear, reviewed by category
Evidence tableExportable source log
Source links and datesEvery finding referenced
Search terms usedFull audit trail of what was checked
False positive logDismissed results documented
Follow-up questionsSuggested for management review
Reviewer notes fieldAnnotate and record decisions
PDF and Word exportReady for the partner file
Who is reviewed
Organizations and the people behind them
Each report covers the organization and its key officials. You can name directors, signatories, and board members for targeted individual review. Where names are not provided, IntegrityFile.org conducts best-efforts public-source searches to identify and include relevant associated individuals.
The organization
Legal name and registrationAliases and former namesRegistration statusDonor and audit historySanctions exposureRebranding riskGovernance concerns
Key officials
Named by you, or identified by best-efforts search
Directors and foundersBoard membersAuthorized signatoriesPEP and political exposureBeneficial ownership linksConflict of interest signalsMoney laundering risk
Reviews of individuals are conducted only where there is a legitimate due diligence purpose. The tool can review directors, board members, signatories, owners, senior managers, and key project personnel.
Risk coverage
Every check your partner file needs
Reports group findings by category, so reviewers know what was searched, what was found, and what needs follow-up.
Allegations of trafficking, abuse, forced labor links
Reputation and media
Adverse media, whistleblower reports, public controversy
Human review
Built for review, not automatic decisions
The system identifies and organizes public-source risk signals. Every finding requires human review before any decision is made. Users control what is included, marked, and filed.
The report does not label an organization or individual as guilty, sanctioned, affiliated, or unsuitable. It identifies public-source information that may require review, clarification, escalation, or documentation.
How false positives are handled
What was found
Assessment
Risk area
Suggested action
Same name, different country and sector
Likely false positive
None
Log and dismiss
Same name, different organization
Possible false positive
Review
Confirm identity before dismissing
Same organization, same director
Possible relevant match
Governance / integrity
Request clarification from partner
Same name, confirmed same entity
Relevant finding
Per finding type
Document, escalate if required
Users can mark each result as relevant, irrelevant, false positive, needs clarification, or escalation required. Final conclusions remain with your organization.
Methodology
Not just search. A documented review trail.
Each report follows a structured open-source due diligence methodology. We review multiple categories of public information and record what was checked, what was found, and what needs human follow-up.
Each report documents:
Entity name, country and identifiers reviewed
Known aliases, acronyms and former names
Officials searched or identified
Search terms and risk terms used
Sources reviewed by category
Relevant findings by risk category
False positives and dismissed results
Source links, dates and summaries
Suggested follow-up questions
Reviewer notes and decision fields
Exportable evidence table
Source type
What we use it for
Official organization registries
Confirm legal name, registration status, former names, address, activity status and identity mismatches
Company and beneficial ownership registries
Identify directors, officers, persons with significant control, related entities and ownership links
Charity and NGO registries
Check registration status, trustees, areas of operation, public filings and regulator notes
Identify adverse media, scandals, allegations, public controversies and reputational risk signals
Local-language public sources
Search names, acronyms and risk terms in relevant local languages where possible
Organization websites and public documents
Check leadership, board members, former names, annual reports and public claims
Social and web footprint
Identify inactive entities, rebranding, misleading affiliation claims or public complaints
The methodology draws on official and public-source records, including sources such as the UN Security Council Consolidated List, OFAC sanctions tools, EU sanctions resources, the UK Sanctions List, selected national asset-freeze sources, World Bank and multilateral development-bank debarment records, national company registries such as Companies House, charity regulators such as the UK Charity Commission, and public inspector-general and audit records such as USAID OIG reports, where available.
Source availability varies by country and entity type. Every report shows which sources and search terms were used. The report presents public-source risk signals for human review. It does not make automatic eligibility decisions and does not replace formal sanctions screening, legal advice, investigation, or required internal approval processes.
Safeguards and control
Controlled by your team
Reports are tools for human reviewers, not automated systems. Your team controls what is submitted, how findings are marked, and what conclusions are reached.
No automatic blacklisting
No finding produces an automatic decision. Human review is always required before any action.
Source-linked findings only
Every finding is referenced to a public source with a link, date, and summary.
User-controlled annotations
Mark findings as relevant, irrelevant, false positive, needs clarification, or escalation required.
Exportable audit trail
Download the complete evidence record for the partner, procurement, or grant file.
Sensitive categories handled carefully
Political affiliation, PSEA, and human rights findings are signals for review, not labels or conclusions.
Periodic monitoring option
Re-check selected partners, vendors, and individuals periodically and document any new signals.
Data protection by design
You decide which organization names and individual names to submit
Reports are generated for documented due diligence purposes only
Access to reports is controlled within your team
Individual findings are presented only with public-source references
Exports can be managed and deleted from your records
How it works
Four steps to a pre-award file
1
Preferred partner identified
The team has a candidate partner, vendor, grantee, consortium member, or subcontractor under consideration before award, agreement signing, onboarding, or renewal.
2
Report generated
IntegrityFile checks public-source signals across fraud, safeguarding, aid diversion, political exposure, conflicts of interest, rebranding risk, governance, legal issues, donor/audit history, and reputation.
3
Findings reviewed
The user marks findings as relevant, irrelevant, false positive, needs clarification, or escalation required.
4
Report filed
The final output goes into the partner, vendor, procurement, or grant file as the documented public-source due diligence record.
Who it's for
Where teams use it
Partner selection
Vendor onboarding
Grant due diligence
Subcontractor review
Consortium partner review
Periodic partner monitoring
Procurement file preparation
Audit and donor file support
Common questions
What UN and NGO teams ask
No. IntegrityFile.org supports the public-source due diligence record and may reference sanctions, restricted-party, debarment and exclusion sources where relevant. It does not replace required sanctions screening, vendor eligibility checks, legal review, investigation, or internal approval processes.
Findings are treated as risk signals, not conclusions. The report separates relevant findings from possible false positives and always requires human review before any decision.
No. The report identifies public-source information that may require review, clarification, escalation, or documentation. All conclusions remain with your team.
Yes, where there is a legitimate due diligence purpose. The tool can review directors, board members, signatories, owners, senior managers, and key project personnel associated with the organization being assessed.
Sources may include official registries, charity and NGO registers, company and beneficial ownership databases, sanctions and restricted-party sources, procurement and debarment sources, court and regulator records, donor and audit records, organization websites, media archives, local-language sources, and other public records. Source availability varies by country and entity type. See the sanctions-list reference page.
Yes. Users can mark each finding as relevant, irrelevant, false positive, needs clarification, or escalation required. Reviewer notes and decision fields are included in the exported record.
Yes. Optional periodic monitoring lets teams re-check selected partners, vendors, and associated individuals and document any new public-source signals that emerge.
Intake details
Run a report on a selected partner
Add the entity details and any known key officials. IntegrityFile will use this information to prepare a pre-award public-source due diligence report for human review.
First report free for each organization. Most reports are available within 24 hours. Paid plans are available for additional reports, monitoring, and team access.
First report free
Create your IntegrityFile account
Create an organization account to submit the selected entity for public-source due diligence review. One free report is available per organization so your team can assess the report format before subscribing.
Already created an account?
Plans
Choose how your team will use IntegrityFile
Start with one selected partner or choose a monthly plan for ongoing partner, vendor, grantee and subcontractor review.
Dashboard
Your due diligence reports
Loading your dashboard...
Admin
Research handoff
Use the admin token to download each paid request as JSON. After research and report generation, upload the completed report JSON to publish it to the user dashboard and send an email notification.
Admin requests will appear here.
Sample partner due diligence report for Sahel Community Development Network, Mali
Sahel Community Development Network (SCDN)
Mali · Public-source due diligence report · Generated 26 Jun 2026
Medium risk, review required
2
High-priority findings
3
Findings for review
8
Categories clear
4
False positives logged
Entity profile
Full registered nameSahel Community Development Network
Acronym / trading nameSCDN
Country of registrationMali
Registration numberNGO-ML-2014-0447
Registration statusActive (verified Jun 2026)
Year established2014 (formerly 2011, see finding F-02)
SectorFood security, WASH, livelihoods
Websitescdn-mali.org
Prior names reviewedSahel Aid Initiative (2011-2013)
Review contextSubgrant partner, food security program
Associated people reviewed
AM
Amadou Maiga
Executive Director & Founding Member
See F-01, F-02
FK
Fatoumata Kouyate
Finance Director
Clear
IB
Ibrahim Ba
Board Chair
PEP, see F-03
MT
Mariam Toure
Program Manager
Clear
Risk category summary
Integrity, fraud and misuse of funds
High
Entity continuity and rebranding risk
Review
Political exposure and neutrality risk
Review
Donor and audit history
Review
Safeguarding and PSEA
Clear
Aid diversion and sanctions exposure
Clear
Conflict of interest and related-party risk
Clear
Governance and registration concerns
Clear
Human rights and protection concerns
Clear
Procurement and vendor performance
Clear
Legal, regulatory and financial distress
Clear
Reputation and public controversy
Clear
Conflict of interest, individual (Maiga)
High
Sanctions, restricted-party and debarment sources checked
UN Security Council Consolidated List
Clear
UN Security Council Consolidated List Search
Clear
OFAC Sanctions List Search
Clear
OFAC Sanctions List Service
Clear
EU sanctions resources / EU financial sanctions data
Clear
UK Sanctions List
Clear
Canada consolidated sanctions list
Clear
Australia DFAT Consolidated List
Clear
World Bank Debarred Firms and Individuals
Clear
ADB sanctions and debarment list
Clear
AfDB debarred and sanctioned firms
Clear
IDB sanctioned firms and individuals
Clear
EBRD ineligible entities
Clear
AIIB debarment list
Clear
SAM.gov exclusions
No U.S. federal nexus noted
EU EDES public exclusion records
No public match found
Sample statuses show how the report records source-by-source checks. A clear status means no relevant public match was identified from the listed source for the names reviewed on the report date. It is not a legal sanctions-clearance certificate.
Findings
Integrity · Conflict of interest, F-01 · High priority
Executive director holds ownership stake in a vendor active in the program area
Public business registry records (Direction Nationale des Domaines) show Amadou Maiga as 40% shareholder of Bamako Logistics SARL, a transport company. Procurement records published by a prior UN agency partner show Bamako Logistics received service contracts in the same geographic area as SCDN's current programming. No public disclosure of this interest was identified in SCDN's filing materials or website. This relationship requires clarification before any award involving procurement of transport or logistics services.
Entity continuity · Rebranding, F-02 · High priority
SCDN shares founding leadership with a dissolved predecessor entity that had a grant dispute
A 2013 NGO Ministry report (published on the Malian government portal) lists "Sahel Aid Initiative" (SAI) as an entity whose registration was suspended following a complaint from a bilateral donor relating to unspent grant funds and incomplete reporting. Amadou Maiga is named as founder and director of SAI. SCDN was registered in 2014 under the same address and director. The connection between SAI and SCDN is not disclosed on SCDN's website or in their registration summary. The donor complaint outcome is not publicly documented. Follow-up required with SCDN management and possible inquiry to the original donor.
Political exposure, F-03 · Review
Board chair is a former deputy minister, potential neutrality and PEP consideration
Ibrahim Ba served as Deputy Minister of Agriculture in Mali (2016-2018), per archived government records and local press reporting. He joined SCDN's board in 2020. His PEP status requires standard disclosure and assessment of whether his government role during the period of any past grants creates a conflict or neutrality concern. No adverse media found relating to Ba personally. Standard PEP declaration and disclosure review recommended prior to award.
Donor and audit history, F-04 · Review
USAID OIG published a mention of SCDN in a broader 2022 West Africa audit report
A 2022 USAID Office of Inspector General audit of West Africa food security programming includes a footnote referencing SCDN as a subpartner whose financial documentation was incomplete at time of review. The audit does not name SCDN as the subject of a finding. It is cited in a list of subpartners with documentation gaps. The prime partner was asked to follow up. No public repayment demand or debarment found relating to SCDN. Reviewer should consider requesting SCDN's own account of this audit period and any correspondence with the prime.
Aid diversion · Sanctions, Clear
No sanctions, debarment or diversion-related media found
Searches conducted against core sanctions and restricted-party references including OFAC sanctions tools, EU sanctions resources, the UN Security Council Consolidated List, the UK Sanctions List, and public World Bank and multilateral development-bank debarment sources. No matches for SCDN, Sahel Aid Initiative, or any of the four individuals reviewed. No media found linking the organization or individuals to armed groups, aid diversion, or terrorism-financing allegations.
False positive log, 4 dismissed results
Results dismissed as unrelated
1. "Sahel Development Network" (Burkina Faso), different country, different registration, no shared leadership. Dismissed.
2. "Amadou Maiga" (Senegalese politician), different person, different country. Name is common in West Africa. Dismissed.
3. 2019 AFP article referencing "SCDN" in the context of a Sahel climate coalition, refers to "Sahel Climate and Desertification Network," a distinct entity. Dismissed.
4. USAID contractor debarment list reference to "Sahel Community Services" (Niger, 2020), different name, different country, no shared leadership or registration. Dismissed.
Suggested follow-up questions for SCDN
1
Can SCDN provide documentation of the relationship between SCDN and Sahel Aid Initiative, and confirm the outcome of the 2013 Ministry registration suspension and any associated donor complaint?
2
Does Amadou Maiga hold any current or recent ownership, directorship, or financial interest in any vendor, supplier, or service provider that has worked or may work in SCDN's program areas? Has this been declared to the board?
3
Can SCDN provide its correspondence or internal records relating to the 2022 USAID OIG audit period, including any response submitted to the prime partner?
4
Can Ibrahim Ba complete a standard PEP declaration and confirm there is no conflict between his prior government role and SCDN's current or proposed donor relationships?
Search terms and name variations used
"Sahel Community Development Network" Mali
"SCDN" Mali NGO
"Sahel Aid Initiative" Mali
"Amadou Maiga" Mali NGO fraud corruption
"Ibrahim Ba" Mali minister
SCDN Mali audit donor suspension
SCDN Mali sanctions OFAC
SCDN Mali debarred ineligible excluded
scdn-mali.org
Reviewer decision
Decision
This is a sample illustrative report. All organizations, individuals, and findings are fictitious and shown for format demonstration only. The report supports due diligence and partner review. It does not replace formal sanctions screening, legal advice, investigation, or internal approval processes. Findings are public-source risk signals for human review, not automatic conclusions.
Legal center
IntegrityFile.org legal and data protection documents
These documents explain how IntegrityFile.org provides structured public-source due diligence reports, how reports should be used, how personal data is handled, and what safeguards apply.
IntegrityFile.org is designed to complement existing screening, procurement, grant, vendor, partner-selection, and approval processes. It does not replace sanctions screening, vendor eligibility checks, legal review, investigations, management decisions, or required internal approvals.
IntegrityFile.org focuses on the public-source risk signals that are often hard to find, under-documented, or missed in standard database checks. Reports may cover adverse media, fraud and integrity concerns, safeguarding and PSEA issues, aid diversion, political exposure, conflicts of interest, rebranding and entity-continuity risk, governance concerns, legal and regulatory issues, donor or audit history, and reputational signals.
Findings are presented as public-source signals for human review. Reports do not label any person or organization as guilty, sanctioned, unsuitable, affiliated, ineligible, or disqualified.
Last updated27 June 2026
OperatorIntegrityFile.org
Legal contactlegal@integrityfile.org
Privacy contactprivacy@integrityfile.org
Terms
Terms of Service
1. Use of IntegrityFile.org
IntegrityFile.org provides structured public-source due diligence reports for organizations and associated key individuals. Reports are intended to support partner, vendor, grantee, subcontractor, procurement, grant, and monitoring workflows.
Reports may help users identify, organize, review, and document public-source information relevant to due diligence. Reports are not legal advice, investigation findings, sanctions determinations, eligibility decisions, exclusion decisions, or recommendations to approve or reject any organization or individual.
Users remain responsible for final decisions, approvals, escalations, partner engagement, vendor review, follow-up questions, documentation, and compliance with their own policies and applicable law.
2. Complementary role
IntegrityFile.org is designed to complement existing systems and controls. It does not replace:
sanctions screening
anti-money laundering checks
counter-terrorism financing checks
vendor eligibility checks
procurement approval
legal review
safeguarding investigation
audit or assurance review
management decision-making
donor-required approval processes
any required internal clearance or escalation process
The service supports the open-source and adverse-media due diligence step by creating a structured record of public-source risk signals, reviewed findings, dismissed false positives, source links, and user notes.
3. Authorized users and accounts
Customers are responsible for ensuring that only authorized personnel access their workspace. Users must keep login credentials secure and must not share accounts.
Customers are responsible for managing user roles, access rights, exports, internal sharing, and retention of reports within their organization.
IntegrityFile.org may suspend access where there is suspected misuse, security risk, unlawful use, non-payment, or breach of these terms.
4. Permitted use
Users may use IntegrityFile.org only for legitimate organizational due diligence, monitoring, procurement, grant, compliance, audit, risk management, or partner-review purposes.
Permitted use includes review of:
implementing partners
local NGOs and CSOs
vendors and suppliers
grantees
subcontractors
consortium members
downstream partners
directors, officers, board members, signatories, owners, senior managers, and other relevant associated individuals
Users must have a legitimate due diligence purpose before submitting information about individuals.
5. User responsibilities
Users are responsible for:
entering accurate names, countries, identifiers, and context
limiting searches to relevant organizations and individuals
reviewing findings before relying on them
documenting false positives
considering source reliability, date, context, and severity
giving partners or vendors an opportunity to clarify findings where policy permits
following their organization's policies and applicable law
ensuring that reports are not used for unlawful discrimination, harassment, retaliation, political targeting, or public shaming
6. Report limitations
IntegrityFile.org reports are based on available public-source information, user-submitted information, third-party search infrastructure, and automated or human-assisted classification.
Public-source information may be incomplete, outdated, mistranslated, inaccurate, duplicated, or unavailable in some countries or languages. A missing finding does not mean that no issue exists. A finding does not mean that the allegation is true or that the organization or individual is unsuitable.
Source availability varies by country, language, entity type, and public-record environment.
7. Human review required
Reports are signals, not conclusions. Users must not make automatic adverse decisions solely on the basis of an IntegrityFile.org report.
Before taking action, users should assess:
identity match
source reliability
publication date
country and language context
seriousness of the issue
whether the source is official, media, third-party, or user-submitted
whether the finding relates to the same organization or person
whether the matter has been resolved, disproven, appealed, or explained
whether escalation, clarification, or legal review is required
8. Associated individuals
Where reports include individuals, searches should be limited to persons relevant to the due diligence purpose, such as directors, officers, signatories, owners, senior managers, board members, key project personnel, procurement contacts, finance officials, or other associated persons relevant to the review.
Users must not submit names for personal curiosity, stalking, harassment, political targeting, or unrelated background checks.
9. Source references and public information
Reports may include source links, publication dates, short summaries, public records, official registry references, adverse-media references, organization websites, donor or audit references, regulator records, court records where available, and other public-source material.
IntegrityFile.org does not guarantee that third-party links will remain available or unchanged. Users should retain reports and evidence according to their own file-retention requirements.
10. AI-assisted features
IntegrityFile.org may use AI-assisted tools to summarize sources, classify findings, identify possible risk categories, detect aliases or former names, suggest follow-up questions, and organize report sections.
AI-assisted outputs may contain errors and must be reviewed by users. AI-assisted classifications are not findings of fact, legal conclusions, or eligibility decisions.
11. Customer content and reports
Customers retain responsibility for the information they submit, upload, annotate, export, or share through the service.
IntegrityFile.org may process customer-submitted data to provide the service, generate reports, maintain audit logs, support monitoring features, provide customer support, improve reliability, and meet legal or security obligations.
12. Confidentiality
IntegrityFile.org will use reasonable measures to protect non-public customer workspace data and reports. Customers are responsible for controlling who within their organization can access, export, download, or share reports.
Exports should be treated as sensitive due diligence records.
13. Intellectual property
IntegrityFile.org and its templates, workflow design, report structure, software, interface, classifications, and documentation are owned by IntegrityFile.org or its licensors.
Customers may use generated reports for their internal due diligence, compliance, procurement, grant, audit, and partner-review files, subject to these terms.
14. Fees and subscriptions
If paid plans are offered, pricing, billing period, report limits, monitoring limits, user limits, and cancellation terms will be described at checkout or in an order form.
Fees are non-refundable unless required by law or stated in the applicable order form.
15. Service changes
IntegrityFile.org may update features, report formats, source coverage, search logic, risk categories, AI-assisted functions, pricing, subprocessors, or these terms as the service develops.
Material changes will be posted in the Legal Center or notified to customers where required.
16. No warranties
IntegrityFile.org is provided on an "as is" and "as available" basis. IntegrityFile.org does not warrant that reports will identify every relevant issue, that all public sources are complete or accurate, that links will remain available, or that a report is sufficient for any specific donor, regulator, court, procurement, or internal policy requirement.
17. Limitation of liability
To the maximum extent permitted by law, IntegrityFile.org is not liable for decisions made by customers, actions taken against partners or vendors, missed findings, false positives, third-party source errors, public-source inaccuracies, loss of data caused by customer actions, or unauthorized sharing of exports by customer users.
Any liability cap should be set out in the applicable order form or subscription agreement.
18. Indemnity
Customers agree to use IntegrityFile.org lawfully and responsibly. Customers are responsible for claims arising from misuse of the service, unlawful submissions, unauthorized searches, discriminatory use, public accusations, or actions taken without human review and required internal approval.
19. Governing law
These terms are governed by the laws of the jurisdiction specified in the applicable order form or customer agreement, unless otherwise required by applicable law or agreed in a separate written agreement.
20. Contact
Questions about these terms may be sent to: legal@integrityfile.org.
Privacy
Privacy Notice
1. Overview
IntegrityFile.org processes personal data to provide structured public-source due diligence reports for legitimate organizational review purposes.
This privacy notice explains what data we process, why we process it, how we use it, who we share it with, how long we retain it, and what rights may apply.
2. Who we are
IntegrityFile.org is operated by Alfa SUS (France).
Contact: legal@integrityfile.org Privacy contact: privacy@integrityfile.org Postal address: 88 avenue de France, Nice, 06000, France
3. Personal data we process
IntegrityFile.org may process the following categories of personal data:
Account and user data
name
work email address
organization
role or job title
login and authentication information
workspace membership
usage logs
support communications
Customer-submitted due diligence data
organization names
registration numbers
countries
websites
aliases and former names
names of associated individuals
job titles or roles
country or region information
user notes
review decisions
uploaded files or source links, if enabled
Generated report data
public-source references
source links
publication dates
source summaries
risk categories
relevance indicators
false-positive notes
suggested follow-up questions
reviewer notes
monitoring status
report metadata
audit logs
Technical and security data
IP address
device and browser information
session logs
access logs
security events
cookie identifiers
product usage events
4. Sources of personal data
We may receive personal data from:
customer users
organization uploads
public websites
official registries
company and charity registers
regulator records
court or legal records where publicly available
donor, audit, or inspector-general publications
news and media sources
publicly available organization documents
third-party search or AI infrastructure used to generate reports
5. Purposes of processing
We process personal data to:
create and manage user accounts
generate due diligence reports
identify public-source risk signals
summarize and categorize public-source findings
document search terms, sources, and review decisions
allow users to export reports
support monitoring and re-checking features
maintain audit logs
provide customer support
improve product reliability and security
prevent misuse
comply with legal, contractual, and security obligations
6. Lawful basis
Where GDPR, UK GDPR, or similar laws apply, the lawful basis may depend on the processing activity and the customer's use case.
Possible lawful bases may include:
performance of a contract for account administration and service delivery
legitimate interests for organizational due diligence, fraud prevention, compliance, procurement, grant management, partner review, security, and service improvement
legal obligation where processing is required to comply with applicable law
consent where required for optional cookies or certain optional communications
Customers are responsible for identifying their own lawful basis for submitting individuals for due diligence review.
7. Legitimate interests
Where legitimate interests are relied upon, those interests may include:
responsible partner and vendor due diligence
fraud, corruption, safeguarding, procurement, and reputational risk management
protection of donor, grant, procurement, and public-interest resources
documentation of public-source review steps
security, abuse prevention, and service reliability
Processing should be proportionate, limited to relevant individuals, and subject to human review.
8. Sensitive data
IntegrityFile.org is not designed for users to upload unnecessary sensitive personal data.
Public-source findings may sometimes include sensitive or high-risk information, such as allegations related to criminal proceedings, political exposure, safeguarding, sanctions exposure, human rights issues, or other reputational matters.
Users should submit only the data necessary for the due diligence purpose and should avoid uploading sensitive data unless legally permitted, necessary, and authorized under their organization's policies.
9. Children's data
IntegrityFile.org is not intended for searching or processing children's data. Users must not submit children's personal data unless legally required, specifically authorized by customer policy, and supported by an appropriate lawful basis.
10. How reports present personal data
Individual findings are presented with public-source references, dates, summaries, and review context where available. Reports should be used as review materials, not as automatic conclusions.
Users should assess relevance, identity match, accuracy, source reliability, severity, and context before taking action.
11. Sharing and disclosure
We may share personal data with:
authorized users within the customer workspace
service providers and subprocessors supporting hosting, storage, authentication, email delivery, monitoring, analytics, AI/search infrastructure, and security
professional advisers where necessary
authorities where legally required
successor entities in connection with a merger, acquisition, restructuring, or asset sale
We do not sell personal data.
12. International transfers
Where personal data is transferred internationally, IntegrityFile.org will use appropriate transfer mechanisms where required, such as standard contractual clauses, adequacy decisions, contractual safeguards, or other lawful transfer mechanisms.
Specific transfer mechanisms may depend on the customer location, service providers selected, and applicable law.
13. Retention
Report retention should reflect customer grant, procurement, legal, audit, monitoring, and file-retention requirements.
IntegrityFile.org may retain:
account data while the account remains active
reports according to customer configuration or subscription terms
audit logs for security and accountability purposes
backups for a limited period
billing and legal records as required by law
Customers may request deletion or export subject to legal, security, audit, contractual, and backup limitations.
14. Security
IntegrityFile.org uses administrative, technical, and organizational safeguards designed to protect personal data, including access controls, encryption in transit, encryption at rest where supported, audit logging, backups, restricted administrative access, and incident response processes.
No service can guarantee absolute security.
15. Individual rights
Depending on applicable law, individuals may have rights to:
access personal data
correct inaccurate data
request deletion
object to processing
restrict processing
request portability
challenge automated decisions
complain to a supervisory authority
Where IntegrityFile.org acts as processor for a customer, requests may need to be directed to the customer organization. IntegrityFile.org will assist customers with rights requests as required by the applicable agreement and law.
16. Automated decision-making
IntegrityFile.org does not make final eligibility, approval, rejection, exclusion, or adverse decisions about organizations or individuals.
Reports provide public-source signals for human review. Customers must ensure that any decision with legal, contractual, employment, funding, procurement, or similarly significant effects is made through appropriate human review and required internal approvals.
17. Cookies
IntegrityFile.org may use essential cookies for authentication, session security, load balancing, and preferences. Optional analytics or product-improvement cookies are used only where enabled and disclosed through an appropriate consent or preference mechanism where required.
18. Changes to this privacy notice
We may update this privacy notice as the service develops, legal requirements change, or subprocessors are added. The latest version will be posted in the Legal Center.
19. Contact
Privacy questions may be sent to: privacy@integrityfile.org.
Data protection
Data Protection Overview
Due diligence with proportionality and controls
IntegrityFile.org is designed for documented public-source due diligence in organizational contexts. The service should be used proportionately and only where there is a legitimate due diligence purpose.
Core principles
Purpose limitation
Reports should be generated only for legitimate partner, vendor, procurement, grant, monitoring, audit, compliance, or risk-management purposes.
Data minimization
Users should submit only the information needed for the review, such as name, organization, country, role, website, registration number, or other relevant identifiers.
Accuracy and context
Findings are treated as signals requiring confirmation, context, and human review. Users should consider whether a source relates to the same organization or person, whether it is current, and whether the source is reliable.
Human review
Reports do not make automatic decisions. Users must review findings before taking action.
Source transparency
Reports should show source links, dates, summaries, risk categories, and review notes where available.
Retention control
Reports should be retained according to the customer's grant, procurement, legal, donor, audit, and monitoring requirements.
Access control
Reports should be available only to authorized users with a need to know.
Accountability
Customers should document who reviewed the report, what findings were considered, what false positives were dismissed, and what follow-up was required.
Appropriate individuals to review
Individual searches should generally be limited to people relevant to the organization's due diligence purpose, such as:
directors
officers
board members
trustees
owners or beneficial owners
signatories
senior managers
finance officials
procurement officials
key project personnel
authorized representatives
subcontractor or consortium leads
Higher-risk categories
Some findings require special care, including:
safeguarding and PSEA allegations
criminal allegations
sanctions exposure
terrorism-financing concerns
political affiliation
human rights allegations
donor or investigation findings
allegations involving vulnerable persons
Such findings should be reviewed carefully, escalated where required, and not treated as automatic conclusions.
Data subject requests
Requests from individuals should be assessed according to applicable law and the customer's policies. Where IntegrityFile.org acts as processor, the customer normally determines the response.
Recommended customer controls
Customers should maintain:
an internal due diligence purpose statement
a list of authorized users
access controls for reports
report-retention rules
escalation rules for high-risk findings
a false-positive documentation process
a process for partner/vendor clarification where policy permits
a human-review step before decisions
DPA
Data Processing Addendum
1. Purpose
This Data Processing Addendum explains the typical controller and processor roles for IntegrityFile.org. A signed customer DPA or order form may supplement or replace this page for enterprise customers.
2. Roles
For customer-submitted due diligence data, the customer typically acts as controller and IntegrityFile.org acts as processor.
For account administration, product telemetry, billing, security, abuse prevention, and general service operation, IntegrityFile.org may act as an independent controller.
Roles may vary depending on the customer relationship, jurisdiction, configuration, and agreement.
3. Processing subject matter
The processing subject matter is the generation, storage, display, export, monitoring, and management of public-source due diligence reports.
4. Processing duration
Processing continues for the duration of the customer's account, subscription, report-retention period, or as otherwise required by law, contract, security, audit, or backup obligations.
5. Processing purposes
IntegrityFile.org processes personal data to:
create reports
manage workspaces
display and export findings
maintain audit logs
support monitoring
provide customer support
maintain security
prevent misuse
comply with legal and contractual obligations
6. Categories of personal data
Data categories may include:
organization names
registration numbers
websites
country information
official names
job titles and roles
aliases and former names
user notes
source links
source summaries
report metadata
account details
audit logs
technical logs
7. Categories of data subjects
Data subjects may include:
customer users
partner or vendor officials
directors
officers
signatories
owners or beneficial owners
board members or trustees
key project personnel
subcontractor representatives
public officials or politically exposed persons referenced in public sources
other associated individuals submitted or identified for legitimate due diligence purposes
8. Customer instructions
IntegrityFile.org will process customer-submitted data according to customer instructions, these terms, the applicable order form, and applicable law.
9. Confidentiality
IntegrityFile.org will ensure that personnel authorized to process customer data are subject to confidentiality obligations.
10. Security measures
IntegrityFile.org will maintain appropriate administrative, technical, and organizational measures, including:
workspace-based access controls
role-based permissions
least-privilege administration
encryption in transit
encryption at rest where supported
logging and monitoring
backup controls
vulnerability management
incident response
subprocessor review
access revocation procedures
11. Subprocessors
IntegrityFile.org may use subprocessors for hosting, storage, authentication, email, analytics, monitoring, AI/search infrastructure, and security.
A current subprocessor list will be maintained in the Legal Center. IntegrityFile.org will provide notice of material changes where required by contract or law.
12. Assistance with rights requests
IntegrityFile.org will provide reasonable assistance to customers responding to data subject requests, where required by applicable law and the customer agreement.
13. Deletion or return
Upon customer request or termination, IntegrityFile.org will delete or return customer data according to customer configuration, subscription terms, legal obligations, audit requirements, security needs, and backup retention limits.
14. International transfers
Where required, IntegrityFile.org will use appropriate transfer mechanisms for international data transfers, such as standard contractual clauses, adequacy decisions, or other lawful mechanisms.
15. Audits
IntegrityFile.org will make reasonable information available to demonstrate compliance with this DPA. Enterprise audit rights, if any, should be set out in a signed agreement.
16. Incident notification
IntegrityFile.org will assess suspected security incidents promptly and notify affected customers where required by law or contract.
Security
Security Overview
Administrative, technical, and organizational safeguards
IntegrityFile.org protects reports and submitted data using reasonable safeguards designed for sensitive due diligence records.
Access control
Workspace-based access
User roles for administrators, reviewers, and read-only users
Least-privilege administrative access
Access revocation when users leave a workspace
Restricted production access for authorized operational personnel
Encryption
Encrypted transport using HTTPS/TLS
Encrypted storage where supported by hosting and database providers
Secure handling of authentication tokens and session data
Logging and monitoring
User activity logs
Security event logs
Administrative access logs
Monitoring for service reliability and abuse prevention
Backups and recovery
Secure backups
Recovery procedures
Backup retention according to operational requirements
Vulnerability management
Dependency updates
Security patching
Review of critical vulnerabilities
Remediation based on severity
Incident response
Security incidents are assessed promptly. Affected customers will be notified according to contractual and legal requirements.
Exports
Report exports are sensitive due diligence records. Customers are responsible for controlling exports after download, including storage, sharing, retention, and deletion in their own systems.
Customer security responsibilities
Customers should:
use strong passwords and appropriate account-access controls
restrict access to authorized users
remove users who no longer require access
treat exports as confidential
avoid uploading unnecessary sensitive data
configure retention according to internal policy
report suspected unauthorized access promptly
Subprocessors
Subprocessors
Third-party service providers
IntegrityFile.org may use third-party providers to operate the service. Subprocessors may support hosting, storage, authentication, email delivery, monitoring, analytics, AI/search infrastructure, customer support, and security.
The production subprocessor list should identify each provider, purpose, processing location, and transfer mechanism.
Current subprocessor list
Category
Purpose
Provider
Location
Status
Cloud hosting
Application hosting, storage, backups
Not yet engaged
Not yet applicable
Will be published before production report processing
Database/storage
Report storage and metadata
Not yet engaged
Not yet applicable
Will be published before production report processing
Authentication
User login and access controls
Not yet engaged
Not yet applicable
Will be published before production report processing
AI/search infrastructure
Report generation, source review, summarization support
Not yet engaged
Not yet applicable
Will be published before production report processing
Email service
Notifications and account messages
Not yet engaged
Not yet applicable
Will be published before production report processing
Monitoring/security
Logs, alerts, uptime and security monitoring
Not yet engaged
Not yet applicable
Will be published before production report processing
Analytics
Product improvement and usage metrics, if enabled
Not yet engaged
Not yet applicable
Will be published before production report processing
Payments
Subscription billing, if enabled
Not yet engaged
Not yet applicable
Will be published before production report processing
Changes to subprocessors
IntegrityFile.org may update subprocessors as the service develops. Material changes will be posted in the Legal Center or notified to customers where required.
Cookies
Cookie Notice
Essential and optional cookies
IntegrityFile.org uses cookies and similar technologies to operate the website and service.
Essential cookies
Essential cookies are required for:
secure login
session management
authentication
account security
load balancing
fraud and abuse prevention
user preferences needed for service operation
These cookies cannot be disabled through the service because they are necessary for the product to function.
Preference cookies
Preference cookies may remember user choices such as interface settings, language, or workspace preferences.
Analytics cookies
Analytics cookies may be used to understand product performance, improve features, and diagnose issues. Where required, analytics cookies are used only after consent or through a preference mechanism.
Managing cookies
Users may control cookies through browser settings or the cookie preference tool where available. Blocking essential cookies may prevent the service from working properly.
Acceptable use
Acceptable Use Policy
Responsible and lawful use
Users must use IntegrityFile.org only for legitimate organizational due diligence, monitoring, audit, grant, procurement, compliance, or risk-management purposes.
Prohibited uses
Users must not use IntegrityFile.org for:
stalking
harassment
doxxing
public shaming
political targeting
personal curiosity searches
unlawful discrimination
retaliation
surveillance unrelated to organizational due diligence
automated adverse decisions without human review
generating defamatory or misleading accusations
searching children's data without legal authorization
uploading malicious content
scraping or reverse engineering the service
bypassing access controls
sharing reports with unauthorized persons
using reports outside their documented due diligence purpose
High-risk use restrictions
Users must not use reports as the sole basis for decisions that may significantly affect a person or organization, including exclusion from funding, contract termination, employment action, public accusation, referral to authorities, or denial of opportunity.
Such decisions require human review, context assessment, escalation, and required internal approval.
Misuse
IntegrityFile.org may suspend or terminate access if it reasonably believes the service is being misused or used unlawfully.
Human review
Human Review Policy
Reports are signals, not conclusions
IntegrityFile.org reports organize public-source information for review. They do not label any person or organization as guilty, sanctioned, unsuitable, affiliated, ineligible, excluded, or disqualified.
Required human review
Before taking action, users should review:
whether the finding relates to the same person or organization
whether identifiers match
whether the source is reliable
whether the source is current
whether the allegation is proven, unresolved, disputed, or historical
whether the matter is relevant to the specific due diligence purpose
whether the partner or vendor should be asked for clarification
whether legal, safeguarding, procurement, or management escalation is required
False positives
False positives must be documented and dismissed where appropriate. Reports should record the reason a result was dismissed, such as different country, different person, different organization, outdated information, unrelated acronym, or insufficient match.
Relevant findings
Relevant findings should be assessed for:
severity
recency
source reliability
identity confidence
program relevance
donor or policy implications
whether the concern is resolved or ongoing
whether follow-up questions are required
Partner or vendor clarification
Where policy permits, partners or vendors should be given an appropriate opportunity to clarify relevant findings before an adverse decision is made.
Final decisions
Final decisions remain with the customer organization and its approval processes. IntegrityFile.org provides structured public-source information to support review; it does not make decisions.
Methodology
Methodology Notice
How reports are generated
IntegrityFile.org uses a structured public-source due diligence methodology. Reports may combine user-submitted information, public-source search, official registries where available, organization websites, donor and audit references, regulator records, court or legal records, media sources, local-language search terms where possible, and AI-assisted summarization or classification.
Source types reviewed may include
official organization registries
company and beneficial ownership registries
charity and NGO registries
sanctions, restricted-party and asset-freeze source references
debarment and ineligibility sources
government and regulator records
court and legal records where publicly available
donor, audit, and inspector-general records
organization websites and public documents
annual reports and project pages
news and media archives
local-language public sources
social and web footprint indicators
Sanctions and restricted-party references may include public UN, OFAC, EU, UK, national asset-freeze, World Bank, multilateral development-bank, and public exclusion sources where relevant and available. See the sanctions-list reference page.
Risk categories
Reports may organize public-source signals into categories such as:
integrity, fraud, and misuse of funds
safeguarding, PSEA, and misconduct
aid diversion, sanctions exposure, and terrorism-financing concerns
political exposure and neutrality risk
conflict of interest and related-party risk
entity continuity and rebranding risk
governance and registration concerns
human rights and protection concerns
procurement and vendor performance risk
legal, regulatory, and financial distress
donor, audit, and investigation history
reputation and public controversy
No guarantee of completeness
Public-source coverage varies. Reports may not identify all relevant information. A clean report does not guarantee that no risk exists.
Review record
Each report is intended to document:
the entity reviewed
associated names reviewed
search terms used
risk categories checked
sources reviewed
relevant findings
false positives
source links
review notes
suggested follow-up
report date
user decision fields
Responsible use
Responsible Use Statement
IntegrityFile.org exists to help organizations conduct more consistent, documented, and proportionate due diligence. The service should be used to strengthen fairness, transparency, accountability, and review quality.
It should not be used to replace human judgment, make unsupported accusations, or bypass the rights of partners, vendors, grantees, or individuals.
The correct use of IntegrityFile.org is to identify public-source risk signals, document what was reviewed, separate relevant findings from false positives, and support responsible follow-up through the customer's established processes.