Resources · Legal framework
OSINT, practised by the book
Seeing into the web's corners is lawful when done with method. Here are the principles that frame our licences and our engagements, and what we refuse to do.
What the regulation requires of you
None of these texts names the dark web
They require something else: detect anomalous activity, gather threat intelligence, monitor your providers, test how effective your measures are. Dark web monitoring serves those four requirements directly. Every article below was checked against the text, and links to its source at the foot of this page.
DORA
Regulation (EU) 2022/2554. Financial entities, since 17 January 2025.
Art. 10
Detection
You must have mechanisms in place to promptly detect anomalous activities. One of your credentials put up for sale is an anomalous activity that shows before the intrusion, not after.
Art. 13(1)
Learning and evolving
You must have the capabilities and staff to gather information on vulnerabilities and cyber threats. The text requires the capability, not a particular source.
Art. 26 and 27
Threat-led testing
TLPT is to be carried out at least every three years. The threat intelligence feeding it must come from an external, independent provider: that requirement sits in the technical standard adopted under Article 26(11), not in the Article itself.
Art. 28
ICT third-party risk
Chapter V requires you to manage the risk your IT providers carry, throughout the relationship. Their exposure becomes yours.
NIS2
Directive (EU) 2022/2555. Essential and important entities. A directive takes effect through national transposition.
Art. 21(2)(a)
Risk analysis and information system security
The first of the minimum measures required. It assumes you know your exposure, including what has already leaked beyond your walls.
Art. 21(2)(b)
Incident handling
Spotting a credential leak before it is used moves the work from response to anticipation.
Art. 21(2)(d)
Supply chain security
The text expressly covers the relationships between the entity and its direct suppliers or service providers.
Art. 21(2)(e)
Vulnerability handling and disclosure
Security in acquisition, development and maintenance, vulnerability disclosure included.
GDPR
Regulation (EU) 2016/679. Every controller and every processor.
Art. 32(1)(d)
Test effectiveness, regularly
The text requires “a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing”. Looking for whether personal data you answer for is already circulating is a direct way to evaluate that effectiveness.
What the law says
Looking is not an offence
Clear, deep and dark web are not legal concepts
These terms match no existing legal concept in French or European law. The deep web means the sites mainstream engines do not index; the dark web, those reachable only through specific protocols or anonymising networks. Both are an integral part of the internet, a technologically neutral network: only what people do with it can constitute an offence.
Tools built for anonymity, used both ways
Anonymising networks protect users' identity and encrypt their communications. They serve legitimate actors as much as cybercriminals: journalists, human rights campaigners, privacy advocates. The technology does not choose; the use does.
A search engine is an intermediary service
The European Digital Services Act defines an online search engine as an intermediary service, in its article 3(j). Before it, European and French case law already treated search engines as hosting providers, across many rulings.
No general monitoring obligation
Article 8 of the DSA is explicit: providers of intermediary services are under no general obligation to monitor the information they transmit or store, nor to actively seek facts indicating illegal activity.
Liable only where we knew, specifically
Recital 28 of the regulation places search engines among the services that benefit from the attenuated hosting liability regime, whose conditions are set out in article 16. A search engine operator therefore only becomes liable for illegal content it references if it had case-by-case knowledge of it and failed to remove it promptly. Recital 22 adds that such knowledge cannot be general: knowing that a service also stores illegal content is not enough.
What we refuse to do
Offensive searching also exposes whoever buys it
This is the substantive difference with other providers, and it is not a matter of preference: it is a matter of criminal law.
We index, we force nothing
Aleph only indexes and references websites, that is, information deliberately made public. We do not offensively search for information reachable because of a security flaw or an exploited vulnerability. There is no legitimate ground for scanning internet-connected machines, accessing them and extracting data.
Those practices are offences, not options
Under French law, fraudulently accessing and remaining within an automated data processing system carries three years' imprisonment and a €100,000 fine, rising to five years and €150,000 as soon as data is altered or deleted (art. 323-1 of the criminal code). Fraudulently extracting, reproducing or transmitting that data carries five years and €150,000 (art. 323-3). An attempt alone carries the same penalties (art. 323-7), and for a legal entity the fines are multiplied by five (art. 131-38).
The offensive provider's client is exposed too
This is the part few people weigh: using a provider that searches offensively also engages the client's criminal liability. They can be prosecuted for holding or using data fraudulently taken from an automated processing system, five years and €150,000 under art. 323-3, and as an accomplice, punished as the perpetrator (art. 121-6).
That is why our method is slower, and sustainable
Forcing nothing means collecting more widely and indexing more deeply to find what is already exposed. It is an expensive technical choice, and the only way to hand a client material they can use without putting themselves at risk.
Leak search
Lawful, on four conditions
A client's legitimacy alone does not make a leak search lawful. Its lawfulness depends on its purpose and on how it is carried out.
- 01A purpose that concerns you
- The search must target leaks concerning the client, with keywords tied to information about them. It must not be used to look for leaks affecting third parties, a competitor for instance.
- 02No breach of any system
- Only information reachable without circumventing security is analysed. No exploiting a vulnerability, no bypassing a protection mechanism.
- 03What does not concern you is set aside
- Even with relevant keywords, a search returns false positives. As soon as it appears that data does not concern the client, it is neither extracted nor kept, and reading it stops.
- 04The GDPR, and the data protection authority's guidance
- The client only copies evidence of leaks coming from their own information system, and minimises the collection of personal data.
What we guarantee
The rules we hold ourselves to
The mandate, when we step in ourselves
A mandate is only required when Aleph takes human part in a leak search. It formalises the authorisation to act on the client's behalf and for their account, records their explicit consent, and protects both sides. It is not needed when the client uses our tools on their own.
GDPR compliance
Personal data processing follows the GDPR: legal basis, minimisation, retention limits, data-subject rights. Our method is documented and auditable.
Aligned with NIS2 and DORA
Our products and services help organisations under these frameworks document the threat monitoring they require, with usable evidence.
A responsible use
Every licence and every engagement comes with clear terms of use. Our tools serve security and legitimate investigation, not mass surveillance.
Data sovereignty
Collection and hosting in France, with no third-party data supplier: your queries and monitoring perimeters never leave the European legal framework.
The texts
References
This page follows the legal opinion delivered to Aleph by the law firm Shift Avocats on 4 September 2025, answering the eight most common questions about our services. The penalties quoted are those of the versions in force, and every reference links to the text itself. It sets out the main principles, for licences and engagements alike; the full contractual terms come with your contract.
- DORA, arts. 10, 13, 26, 27 and 28
Regulation (EU) 2022/2554 of 14 December 2022: detection of anomalous activity, gathering information on vulnerabilities and threats, threat-led testing, and ICT third-party risk.
- NIS2, art. 21(2)
Directive (EU) 2022/2555 of 14 December 2022: the minimum risk-management measures, including risk analysis (a), incident handling (b), supply chain security (d) and vulnerability disclosure (e).
- GDPR, art. 32(1)(d)
Regulation (EU) 2016/679 of 27 April 2016: the duty to regularly test, assess and evaluate the effectiveness of security measures.
- DSA, art. 3(j)
Regulation (EU) 2022/2065 of 19 October 2022: definition of an online search engine.
- DSA, art. 8
No general obligation to monitor transmitted or stored information, nor to actively seek out illegal activity.
- DSA, recital 28
Online search engines are among the services that benefit from the regulation's liability exemptions.
- DSA, art. 16
The attenuated liability regime: no liability without actual knowledge, prompt removal once aware.
- DSA, recital 22
Knowledge of illegal content must be specific: knowing in general that a service also stores illegal content is not enough.
- CJEU, 23 March 2010
Case C-236/08, Google France v Louis Vuitton Malletier: case law already treated search engines as hosting providers before the DSA.
- Criminal code, art. 323-1
Fraudulent access to and presence in an automated data processing system: three years and €100,000, five years and €150,000 where data is altered.
- Criminal code, art. 323-3
Fraudulently extracting, holding, reproducing, transmitting or modifying data from such a system: five years and €150,000.
- Criminal code, art. 323-7
An attempt carries the same penalties.
- Criminal code, art. 121-6
An accomplice to an offence is punished as its perpetrator.
- Criminal code, art. 131-38
For a legal entity, the fine incurred is five times the one set for a natural person.
- GDPR
Regulation (EU) 2016/679: legal basis, minimisation, retention limits, data-subject rights.
- CNIL, RIFI
The French data protection authority's guidance on searching the internet for information leaks.