Ground-truth intelligence for global security.

High-stakes operations demand verified facts, not approximations. Power your security and compliance workflows with corporate data verified directly at the government source.

Two listed parties. Neither controls it. The licence is still required.

Under the Affiliates Rule, holdings by listed parties aggregate. A supplier named on nothing, held 15% by one listed party and 35% by another, carries the same licence requirement as its owners. And the calculation resets at every level below it.

15%35%50%Listed party A · BIS Entity ListENTITY LISTListed party ABIS Entity List · holds 15% of the supplierListed party B · BIS Military End User ListMILITARY END USER LISTListed party BBIS MEU List · holds 35% of the supplierSupplier C · unlisted, licence requiredUNLISTED SUPPLIERLICENCE REQUIREDSupplier CNamed on no list · registry filings resolve the holdings50% in aggregateSubsidiary D · also caught, calculation resets hereDOWNSTREAM SUBSIDIARYALSO CAUGHTSubsidiary DHeld 50% by Supplier C · the calculation resets hereUnder the rule of most restrictiveness, the strictest requirement of any owner governs, whatever the size of its stake.
Aggregation

Holdings by separate listed parties add together. Neither owner needs a controlling stake, and neither needs to appear in the same programme.

Reset at each level

Once an entity is caught, its own 50% holdings are caught in turn. A clean tier-one supplier can sit above a restricted tier three.

Red Flag 29

Being unable to determine an ownership percentage is itself a red flag under EAR Know Your Customer guidance, to be resolved before the export proceeds.

Your exposure sits three tiers below the contract you signed.

Primes hold a supplier list. The risk sits in who owns the suppliers of those suppliers, in jurisdictions where the prime has no commercial relationship and no visibility. Registry filings are the only record that reaches that far down.

See supply chain risk
01

The supplier you contracted

Named in the agreement

Legal entity verified against the register, ownership resolved to its ultimate parent, filing history and registered status confirmed.

02

Their suppliers

No contract with you

Resolved from the tier-one group structure outward. Shared directors, shared addresses and common ownership surface links that no supplier declaration would show.

03

Component and material sources

Usually invisible to the prime

Where sub-tier entities file, the chain continues. Where a jurisdiction does not publish, the gap is shown as a gap rather than filled with an estimate.

ALL

Ownership and control

Applied at every tier

Aggregate holdings tested against listing regimes at each level, so a restriction two tiers down is visible before it reaches a shipment.

Six functions reading one source of record.

01Trade compliance

Export control and licensing

Counterparty ownership resolved against Entity List, MEU and SDN designations, with aggregate holdings calculated at each level of the chain.

Whether a licence is required before the item moves.

02Procurement

Supplier assurance

Entity verification, ultimate ownership, foreign control, financial filings and adverse events across the whole supplier base and its sub-tiers.

Whether a supplier can be onboarded, and on what terms.

03Corporate development

Investment screening

Acquirer ownership traced to ultimate beneficial owners across jurisdictions, for mandatory and voluntary national security notifications.

What has to be notified, and what the filing must disclose.

04Financial crime

Counter-proliferation

Procurement networks mapped through shared officers, addresses and ownership, with incorporation and dissolution patterns across jurisdictions.

Which counterparties sit inside a network rather than alone.

05Third-party risk

Government contracting

Standing due diligence across subcontractors, resellers and distributors, with changes in control surfaced when they are filed.

Whether the assurance given at award still holds.

06Analysis

Research and open source

Corporate structures across 200+ countries as a documented research input, with every field traceable to the filing it came from.

Findings that hold up when the working is checked.

Global Database provides corporate registry and ownership records for compliance, procurement and research. It is company information, not a capability directed at individuals.

Several regimes. One test: who owns it.

Each of these turns on who owns a counterparty rather than what it is called, and none of them can be closed out with a screening list.

RegimeJurisdictionWhy it reaches ownership dataStatus

BIS Affiliates Rule

US · 90 FR 47201

Extends Entity List, MEU and certain SDN licence requirements to entities owned 50% or more in aggregate by listed parties, with the strictest owner's requirement governing and the calculation resetting at each level below.

Returns 10 Nov 2026

Entity List and MEU List

US · EAR

Named-party licence requirements that apply today under the legally distinct standard, with red flags to be resolved where an unlisted subsidiary may divert to a listed parent.

In force

OFAC 50 Percent Rule

US · OFAC guidance

Entities owned 50% or more in aggregate by blocked persons are themselves blocked whether or not listed. The rule turns on ownership rather than control, so it can only be applied against resolved holdings.

In force

Ownership and control test

UK · OFSI

Ownership turns on more than 50% of shares or voting rights, or the right to appoint or remove a majority of the board, with a separate control limb. OFSI closed a call for evidence on the test in June 2026.

Under review

National Security and Investment Act

UK · NSIA 2021

Mandatory notification for qualifying acquisitions in specified sensitive sectors, which requires the acquirer’s ownership chain to be traced and disclosed. Confirm current sector definitions with counsel.

In force

Foreign investment screening

US CFIUS · EU 2019/452

National security review of foreign acquisitions turns on who ultimately controls the acquirer. Scope and procedure vary by member state and are subject to revision.

In force

Export licensing

UK ECJU · US ITAR, EAR

Licence applications and end-user assurances require the corporate identity and ownership of the consignee and end user to be established and evidenced.

In force

The Affiliates Rule was suspended as part of a trade agreement and remains a live policy instrument. Treat the November date as current rather than settled, and re-check it before relying on it.

A supplier cleared at award can be caught by lunchtime.

Every entity in your supplier base stays under watch after onboarding, with changes surfaced on the day they are filed rather than at the next scheduled review.

Supplier base watch2,418 entities · 41 jurisdictions--:--:-- UTC
SanctionsShareholder added to the BIS Entity ListKESTREL MACHINING LTD
BIS Entity List
0s
ThresholdAggregate holding by listed parties reaches 50%KESTREL MACHINING LTD
Companies Registry
43s
PEPDirector matched to a politically exposed personVANTOR SYSTEMS LTD
PEP sources
1m
ControlTier-two supplier acquired by a new parentALTREN COMPOSITES GMBH
Handelsregister
2m
SanctionsOwnership crosses the OFAC 50 percent thresholdMERIDAX TRADING PTE
OFAC SDN sources
2m
OwnershipNew beneficial owner recorded above a subcontractorNORTHGATE PRECISION B.V.
UBO register
3m
PEPBeneficial owner holds a state officeNORTHGATE PRECISION B.V.
PEP sources
4m
SAMPLE STREAMSelect a row to see the filing behind it

Everyone cites something. We cite the registry.

A licence decision, a notification or a refusal has to survive an audit years later. What matters is not that a field has a source, but where that source resolves to.

Chain of custody · single fieldSAMPLE
The field
Ultimate parent

One value on one supplier record. Everything to the right of it is what you can put in front of an auditor, a licensing officer or a regulator without asking us for anything.

Registry
Companies House, United Kingdom
Filing it was read from
PSC01 · persons with significant control
Filed by the company
11 March 2026
Retrieved by us
28 July 2026
06:14:11 UTC
A derived provider returnsVendor company file, an internal record identifier and a refresh cycle. The filing is not carried through, so re-checking the value means going back to the vendor rather than to the register.

400+ registries. Here are twenty-four of them.

Every record on this page comes from a named government source.

Companies HouseUnited Kingdom
Companies Registration OfficeIreland
Registre du commerce et des sociétésFrance
HandelsregisterGermany
KVK HandelsregisterNetherlands
Banque-Carrefour des EntreprisesBelgium
Registre de Commerce et des SociétésLuxembourg
Registro MercantilSpain
Registro ImpreseItaly
Registo ComercialPortugal
FirmenbuchAustria
Zefix · HandelsregisterSwitzerland
Krajowy Rejestr SądowyPoland
BolagsverketSweden
BrønnøysundregistreneNorway
Det Centrale VirksomhedsregisterDenmark
Patentti- ja rekisterihallitusFinland
Registrar of CompaniesCyprus
Secretaries of State · SEC EDGARUnited States
Corporations CanadaCanada
ACRASingapore
Companies RegistryHong Kong
ASICAustralia
Ministry of Corporate AffairsIndia
Twenty-four shown. The full list runs to 400+ across 200+ countries.See the full coverage list

Then it has to clear third-party risk, not just the demo.

Set out before your security, privacy and procurement teams ask for it.

Control areaWhat we provide
Certification and compliance

Certification

ISO/IEC 27001 certified information security management, independently audited against the standard.

Data protection

UK and EU GDPR. Registered with the UK Information Commissioner's Office. Data processing agreement with standard contractual clauses and the UK addendum, and a named data protection contact.

Lawful sourcing

Records collected from public government registers under the terms each registry publishes. Provenance retained at field level.

Security controls

Hosting and residency

EU and UK hosting options. Encrypted in transit and at rest. Residency fixed in the contract rather than handled as an exception.

Access control

Single sign-on over SAML, role-based permissions, enforced multi-factor authentication, retained access logs.

Availability

Contracted uptime target with a published status page, and named support contacts for production incidents.

Resilience

Backups, documented recovery objectives and a restoration procedure that is tested rather than described.

Security testing

Independent penetration testing on a fixed cadence, with continuous vulnerability management between tests.

Supply chain and documentation

Sub-processors

Published list with advance notice before any change, so your own vendor register stays accurate.

Vendor pack

Completed due diligence questionnaire, certificates, insurance and financials, released when your assessment opens.

How to access the data.

Seven routes into the same primary, government-sourced dataset. Pick the one that fits your stack.

Platform

Search, screen and export company records from the web application.

API

Query any company by registry identifier. Documented endpoints, JSON responses, provenance on every field.

Bulk data feeds

Full datasets and scheduled deltas, delivered to your warehouse on your cadence.

CRM

Enrich and verify accounts inside Salesforce, HubSpot and Microsoft Dynamics 365.

MCP

Connect the dataset to any MCP-compatible agent or tool.

Assistant connectors

Pull registry data straight into the assistant your teams already use.

Regis AI

Ask questions in natural language across the dataset and get answers with their sources attached.

If yours is not here, put it to the team directly.

Contact the team

The questions a compliance committee asks first.

Where does the data come from?

Directly from the government registry holding the record, across 400+ registries in 200+ countries. Each field carries the registry, the filing reference and the retrieval timestamp, so a licensing decision made today can be reconstructed years later.

We already screen against the Consolidated Screening List. Why does this matter?

Because once the Affiliates Rule returns, the Consolidated Screening List stops being an exhaustive answer. An entity caught by aggregate ownership appears on no list at all. Establishing that requires resolved holdings from registries, which is a different product from a list match.

How far does ownership resolve?

Through to natural persons wherever the jurisdiction publishes it, with each link carrying the filing it came from and the date. Where a chain runs into a jurisdiction that does not publish, the gap is shown as a gap rather than filled with an estimate.

Can it calculate aggregate holdings across a chain?

Holdings are returned as resolved values with their sources, level by level, so your own logic can apply whichever threshold and aggregation rule the relevant regime requires. We supply the evidenced ownership; the licensing determination stays with you and your counsel.

Does it cover sanctions and designations?

Screening runs against consolidated sanctions and PEP sources across the resolved group rather than the named entity alone, with the decision trail retained for audit.

How does it reach our compliance systems?

By API for checks at the point of a transaction, by bulk delivery for the standing supplier base, and by change feed for anything that moves. Joins are on open identifiers rather than proprietary keys.

What certifications do you hold?

ISO/IEC 27001 for information security management, and registration with the UK Information Commissioner's Office, which is checkable on the public register. The full vendor pack is released under NDA when your assessment opens.

How do we test it before committing?

Send a sample of your supplier base. We return the resolved entities, the ownership chains and the gaps against what you currently hold, so the evaluation runs on your own data rather than a curated demo set.