FAQ

Frequently Asked Questions about Vestigo OSINT

Everything you need to know about OSINT investigation, username search, IP geolocation, phone lookup, GitHub intelligence and pricing.

Understanding OSINT
What is OSINT and why does it matter?

OSINT (Open Source Intelligence) is the practice of collecting and analyzing information from publicly accessible sources: social media profiles, websites, public records, forums, and open databases — without hacking, without unauthorized access.

It is used daily by investigative journalists to verify sources, HR professionals for background checks, cybersecurity experts during penetration testing reconnaissance, law enforcement, private investigators, and academic researchers.

The digital footprint of a person — their complete online presence — can reveal employment history, social connections, geographic patterns, email addresses, and links between different online identities.

How does Vestigo search 2,004 platforms simultaneously?

Vestigo builds platform-specific URLs by inserting the target username into each platform's profile URL pattern (e.g., github.com/{username}, twitter.com/{username}).

50 async workers send requests in parallel. A profile is marked Confirmed only when: (1) the server returns HTTP 200, AND (2) the username appears in the page title, canonical URL, or Open Graph metadata. This dual-check minimizes false positives from platforms that return 200 for "profile not found" pages.

Active enrichers then automatically fetch profile photos, real names, bios, follower counts, and recent posts for confirmed profiles on supported platforms.

Legality & Privacy
Is Vestigo legal in the US, UK and Europe?

Yes. Vestigo only accesses publicly available information — profiles that anyone can view without logging in. It does not exploit security vulnerabilities, does not bypass authentication, and does not access private data.

The legality depends on what you do with the information, not the collection itself. Vestigo is designed for legal use cases: journalism, professional identity verification, cybersecurity auditing (with authorization), academic research.

Using results for harassment, stalking, or unauthorized commercial data collection violates the Terms of Service and may constitute a criminal offense under applicable law.

Is Vestigo GDPR compliant?

Yes. Vestigo does not store your search results (found profiles, IP data, phone analysis) in its database. Only account data required for service delivery — email address, subscription status, daily quota — is retained. You can request complete account and data deletion at any time via account settings.

How Vestigo Works
What is automatic cross-referencing?

When an enricher discovers that the target uses a real name different from their username (e.g., username "dark_wolf99" but GitHub shows "James Miller"), Vestigo automatically generates derived username variations: jamesmiller, james.miller, j.miller, james_miller.

These derived usernames are then checked against remaining unchecked platforms — significantly increasing discovered profiles. This OSINT technique, typically done manually by investigators, is fully automated in Vestigo.

How accurate is IP geolocation?

Vestigo cross-references multiple geolocation databases (MaxMind GeoIP2, ip-api, ipinfo.io) for maximum accuracy. Typical precision: country (>99%), region/state (~90%), city (~75%). Mobile IPs are often localized to regional level only. VPN/proxy/Tor detection uses reputation lists updated daily.

How does the Facebook phone lookup work?

Meta's "Forgot password" recovery flow accepts a phone number and reveals partial account information: first name and last initial, partial email address, profile photo. Vestigo uses this official, public Meta feature — no security exploit involved. The result links a phone number to a real identity when the person has a Facebook account registered to that number.

What emails can GitHub OSINT reveal?

Git stores the committer's email with every commit in the repository history. Developers using different machines (work laptop, home computer) may expose both their professional email and personal email in the commit history of a single public repository — even if these emails aren't displayed on their GitHub profile page.

Comparison & Pricing
Vestigo vs Sherlock — what's the real difference?

Sherlock: ~400 platforms, CLI only (Python required), no enrichers, no IP/phone/GitHub modules, free. Vestigo: 2,004 platforms, professional web interface, automatic enrichments (photo, real name, stats), IP + phone + GitHub modules included, Facebook detection, cross-referencing. Cost: €9.90/week or €15/month.

For developers who are comfortable with CLI tools: Sherlock is great for quick username checks. For professionals who need complete digital footprint investigation with no setup: Vestigo is the better choice.

How many searches are included in each plan?

Weekly Plan (€9.90/week): 50 searches per day. Monthly Plan (€15/month): 100 searches per day. Each search covers all 2,004 platforms. The daily quota resets at midnight UTC. Unused searches do not roll over. There are no overage charges — access is paused until the next day.

Can I cancel my subscription anytime?

Yes. Cancel in one click from your account settings (Account → Subscription → Cancel). Access remains active until the end of the paid period. No cancellation fees, no minimum commitment. Stripe invoices are available for download for expense reporting.

Ready to start your OSINT investigation?

Join journalists, investigators and cybersecurity professionals who use Vestigo every day.

Create account — €9.90 See all features