Ground-truth intelligence for global security.
High-stakes operations demand verified facts, not approximations. Power your security and compliance workflows with corporate data verified directly at the government source.
Two listed parties. Neither controls it. The licence is still required.
Under the Affiliates Rule, holdings by listed parties aggregate. A supplier named on nothing, held 15% by one listed party and 35% by another, carries the same licence requirement as its owners. And the calculation resets at every level below it.
Holdings by separate listed parties add together. Neither owner needs a controlling stake, and neither needs to appear in the same programme.
Once an entity is caught, its own 50% holdings are caught in turn. A clean tier-one supplier can sit above a restricted tier three.
Being unable to determine an ownership percentage is itself a red flag under EAR Know Your Customer guidance, to be resolved before the export proceeds.
Your exposure sits three tiers below the contract you signed.
Primes hold a supplier list. The risk sits in who owns the suppliers of those suppliers, in jurisdictions where the prime has no commercial relationship and no visibility. Registry filings are the only record that reaches that far down.
See supply chain risk →The supplier you contracted
Named in the agreementLegal entity verified against the register, ownership resolved to its ultimate parent, filing history and registered status confirmed.
Their suppliers
No contract with youResolved from the tier-one group structure outward. Shared directors, shared addresses and common ownership surface links that no supplier declaration would show.
Component and material sources
Usually invisible to the primeWhere sub-tier entities file, the chain continues. Where a jurisdiction does not publish, the gap is shown as a gap rather than filled with an estimate.
Ownership and control
Applied at every tierAggregate holdings tested against listing regimes at each level, so a restriction two tiers down is visible before it reaches a shipment.
Six functions reading one source of record.
Export control and licensing
Counterparty ownership resolved against Entity List, MEU and SDN designations, with aggregate holdings calculated at each level of the chain.
Whether a licence is required before the item moves.
Supplier assurance
Entity verification, ultimate ownership, foreign control, financial filings and adverse events across the whole supplier base and its sub-tiers.
Whether a supplier can be onboarded, and on what terms.
Investment screening
Acquirer ownership traced to ultimate beneficial owners across jurisdictions, for mandatory and voluntary national security notifications.
What has to be notified, and what the filing must disclose.
Counter-proliferation
Procurement networks mapped through shared officers, addresses and ownership, with incorporation and dissolution patterns across jurisdictions.
Which counterparties sit inside a network rather than alone.
Government contracting
Standing due diligence across subcontractors, resellers and distributors, with changes in control surfaced when they are filed.
Whether the assurance given at award still holds.
Research and open source
Corporate structures across 200+ countries as a documented research input, with every field traceable to the filing it came from.
Findings that hold up when the working is checked.
Global Database provides corporate registry and ownership records for compliance, procurement and research. It is company information, not a capability directed at individuals.
Several regimes. One test: who owns it.
Each of these turns on who owns a counterparty rather than what it is called, and none of them can be closed out with a screening list.
BIS Affiliates Rule
US · 90 FR 47201Extends Entity List, MEU and certain SDN licence requirements to entities owned 50% or more in aggregate by listed parties, with the strictest owner's requirement governing and the calculation resetting at each level below.
Returns 10 Nov 2026Entity List and MEU List
US · EARNamed-party licence requirements that apply today under the legally distinct standard, with red flags to be resolved where an unlisted subsidiary may divert to a listed parent.
In forceOFAC 50 Percent Rule
US · OFAC guidanceEntities owned 50% or more in aggregate by blocked persons are themselves blocked whether or not listed. The rule turns on ownership rather than control, so it can only be applied against resolved holdings.
In forceOwnership and control test
UK · OFSIOwnership turns on more than 50% of shares or voting rights, or the right to appoint or remove a majority of the board, with a separate control limb. OFSI closed a call for evidence on the test in June 2026.
Under reviewNational Security and Investment Act
UK · NSIA 2021Mandatory notification for qualifying acquisitions in specified sensitive sectors, which requires the acquirer’s ownership chain to be traced and disclosed. Confirm current sector definitions with counsel.
In forceForeign investment screening
US CFIUS · EU 2019/452National security review of foreign acquisitions turns on who ultimately controls the acquirer. Scope and procedure vary by member state and are subject to revision.
In forceExport licensing
UK ECJU · US ITAR, EARLicence applications and end-user assurances require the corporate identity and ownership of the consignee and end user to be established and evidenced.
In forceThe Affiliates Rule was suspended as part of a trade agreement and remains a live policy instrument. Treat the November date as current rather than settled, and re-check it before relying on it.
A supplier cleared at award can be caught by lunchtime.
Every entity in your supplier base stays under watch after onboarding, with changes surfaced on the day they are filed rather than at the next scheduled review.
Everyone cites something. We cite the registry.
A licence decision, a notification or a refusal has to survive an audit years later. What matters is not that a field has a source, but where that source resolves to.
One value on one supplier record. Everything to the right of it is what you can put in front of an auditor, a licensing officer or a regulator without asking us for anything.
400+ registries. Here are twenty-four of them.
Every record on this page comes from a named government source.
Then it has to clear third-party risk, not just the demo.
Set out before your security, privacy and procurement teams ask for it.
✓Certification
ISO/IEC 27001 certified information security management, independently audited against the standard.
✓Data protection
UK and EU GDPR. Registered with the UK Information Commissioner's Office. Data processing agreement with standard contractual clauses and the UK addendum, and a named data protection contact.
✓Lawful sourcing
Records collected from public government registers under the terms each registry publishes. Provenance retained at field level.
✓Hosting and residency
EU and UK hosting options. Encrypted in transit and at rest. Residency fixed in the contract rather than handled as an exception.
✓Access control
Single sign-on over SAML, role-based permissions, enforced multi-factor authentication, retained access logs.
✓Availability
Contracted uptime target with a published status page, and named support contacts for production incidents.
✓Resilience
Backups, documented recovery objectives and a restoration procedure that is tested rather than described.
✓Security testing
Independent penetration testing on a fixed cadence, with continuous vulnerability management between tests.
✓Sub-processors
Published list with advance notice before any change, so your own vendor register stays accurate.
✓Vendor pack
Completed due diligence questionnaire, certificates, insurance and financials, released when your assessment opens.
How to access the data.
Seven routes into the same primary, government-sourced dataset. Pick the one that fits your stack.
API
Query any company by registry identifier. Documented endpoints, JSON responses, provenance on every field.
Bulk data feeds
Full datasets and scheduled deltas, delivered to your warehouse on your cadence.
CRM
Enrich and verify accounts inside Salesforce, HubSpot and Microsoft Dynamics 365.
Assistant connectors
Pull registry data straight into the assistant your teams already use.
Regis AI
Ask questions in natural language across the dataset and get answers with their sources attached.
If yours is not here, put it to the team directly.
Contact the team