Sources that count
Four kinds of material can fill a field in a record. A document published by the brand itself, such as terms, a privacy notice or a footer line naming a company. An entry in a public register maintained by a company registry or a financial supervisor. A notice published by a regulator. And a payment record showing the name of a receiving entity.
Everything else is context, not evidence. Forum posts, affiliate pages, video testimonials and screenshots without provenance can point us at something worth checking, and they never fill a field on their own.
The order of checks
The sequence matters, because each step depends on the one before it.
- Fix the name. Record the exact string as it appears in the source, including punctuation, capitalisation and any numerals or symbols, plus the variants seen elsewhere.
- Find the operator. Look for a company name in the footer, in the terms and in the privacy notice, and check that all three agree.
- Search the register. Take the company name and number to the registry of the country named, and to the financial supervisor of that country if an authorisation is claimed.
- Test the claim, not the brand. If an authorisation is asserted, compare legal name, permission status, permission scope and registered trading names.
- Search the warning lists. Run the brand string through public indexes of unauthorised firms, in every spelling variant recorded at step one.
- Follow the payee. Where a payment record is available, note the receiving entity and its country.
- Write the row. Fill only what the preceding steps support, and leave the rest visibly empty.
Most records stop at step two, and that is the finding rather than a failure of effort.
What the statuses mean
The verdict card carries one of four statuses, and each is defined narrowly.
Unverified is the default. It means we could not establish an operator, an authorisation, or both, and it is neither an accusation nor a clearance.
No red flags found means the checks above ran to completion and returned nothing adverse. It is a statement about our searches on a given date, not a guarantee about a company.
High risk and Avoid are reserved for records where a specific public regulator document naming the brand exists and is cited in the record. We do not assign either status on the strength of an impression, a complaint thread or a pattern resemblance.
The checked date
Every card shows the date the record was last checked. That date moves only when a check was actually performed, never to make an entry look fresh. Anything that happened after it is outside what the record asserts.
Limits we accept
We cannot see private agreements, ownership chains held in jurisdictions without public registers, or the internal arrangements of any company. We cannot confirm that a page we read is the page a given visitor was shown, since campaigns of this type are routinely routed by country. And we cannot prove a negative: an empty register search shows that a claim is unconfirmed, not that a company does not exist somewhere.
Naming those limits is part of the method. A directory that pretended to see everything would be less useful than one that marks its own edges.
Corrections
Records are rewritten when documents arrive, and only then. Send them through the contact page; we check each against its original source before a field changes, and we date the change.