Independence
We process no payments. We take no revenue from any party we investigate.
Independence is not a posture on this page. It is the reason the output is usable by a regulator, a scheme and a bank at the same time.
Lawful collection
Payments are capped at the minimum value that clears an operator's cashier. No profit is taken from winnings, and no balance arising from a collection is treated as revenue.
Every transaction carries a full audit trail — funnel, timestamps, cashier state, authorisation and settlement — reproducible by a third party without our narration.
Analyst identity
Our analysts' identities are protected because they are the collection instrument. A named analyst is a burnt analyst.
Naming them would degrade the capability our clients are buying, and expose them to retaliation from the operators under investigation.
Identity protection never extends to the evidence. Artifacts are attributable to a collection and a date; only the person is withheld.
Conflicts
No engagement anywhere in the business is contingent on the outcome of an attribution. A standing conflicts statement is supplied on engagement.
Disclosed clients
Where we work for a party whose interest is adverse to an institution named in a finding, that engagement is disclosed before the finding is filed.
Work produced under any outcome-based fee is never used as regulatory or court evidence, and is marked as such at the point of delivery.
No commercial arrangement anywhere in the business is tied to the outcome of an attribution.
Right of reply
Every party named in a filed attribution receives a right of reply before publication, with a defined window and a defined route.
Replies are recorded and travel with the finding permanently. A correction joins the record rather than replacing it.
Until that window closes, the public layer shows a mask bar, not a name — a rule enforced by the data itself.
Entity
Corporate detail is supplied to a prospective client on request.
Security and data protection
Certifications, sub-processors, data residency, retention, encryption, breach notification and our DPA are supplied to a prospective client on request. Security reports may also be sent to security@birdtold.me.