Enhanced Due Diligence

Screen a company against public registry, sanctions and technical sources. The report says what was checked, what it found, and — just as plainly — what it could not see.

This screens companies, not people, and reports only what a named public source says. A finding is a reason to ask a question, not a conclusion that anyone did anything wrong.

Sanctions screening is running, against the consolidated lists published by the US Treasury (OFAC), the European Commission and HM Treasury (OFSI). Those are primary government sources, so a finding from them is graded Official.

Two things it does not do. It does not screen for politically exposed persons — designation lists carry no PEP status and there is no free authoritative PEP dataset, so a clean sanctions result says nothing about political exposure. And its name matching compares Latin-script names and close variants: it does not transliterate between scripts, and covers those three lists rather than the hundred-odd smaller regimes. A party listed only under a Cyrillic, Arabic or Chinese spelling would not be found. Both limits are recorded as gaps in every report.

The registered legal name works best. A trading name may still find it, but is more likely to return several candidates for you to choose between.

If you have it, this is the surest way to identify the right company — an exact match skips the “which one do you mean” step entirely. Accepts an LEI, a national register number, an EU VAT or tax number, a BIC, an ISIN, a US SEC CIK or ticker, or a country/number pair. Check digits are validated where the format has them, so a typo is caught before anything is searched.

An ISO country code — lt for Lithuania, es for Spain, gb for the UK, or us-de for a US state. Leave it blank to search globally, which works but returns more candidates for you to choose between.

Enables the cyber checks: DNS and mail authentication (DMARC, SPF, DKIM), DNSSEC and registration detail. Without it the cyber pillar is recorded as unassessed.

What this screen covers today

Entity identification and registry status, group and parent structure, cyber posture, and sanctions screening against the three consolidated government lists. The remaining pillars — adverse media, ABAC, political exposure, financial indicators, litigation and ESG — need research that is not built yet, and every report lists them as open gaps rather than quietly leaving them out.

A screen makes live requests to a company registry and to public DNS. Results are held in memory for 30 minutes so the report and its download agree, then dropped — nothing is written to disk. Clear them sooner with the button on the report.

The report appears here once the screen completes.

How to read this report

Every statement carries two labels. The evidence label says what kind of source it came from — official (a registry, court or regulator), published (a company disclosure or reputable press), observed (a technical check EVULNABLE ran itself), estimated (an inference), or client-supplied. The confidence grade says how well established it is — verified, corroborated, reported, or unverified.

Anything below verified is a lead for enquiry, not an established fact. A denial confirms an allegation was made; it does not make it true, and it does not make it false.

The overall rating is not an average. A high rating in sanctions or bribery-and-corruption stands on its own; a high rating anywhere else needs a second pillar to corroborate it. Averaging is deliberately not used, because it lets a data gap read as reassurance.