First-party investigation
Every cluster in the index is investigated end-to-end by OilFlow's internal team. We start from an inbound interaction (broker DM, mandate chain, intake form) and walk back the LinkedIn profile, registered company, broker chain, email pattern, and payment-instruction history. We do not include 'name and shame' rumors from compliance Slack channels.
Evidence standards
A cluster reaches 'confirmed' severity when we have at least three independent evidence vectors: (1) traceable false-identity claim, (2) a payment-instruction or mandate-chain artifact in our possession, and (3) cross-reference to a public or first-party investigated prior pattern. 'Likely' and 'suspected' tiers ship with documented evidence gaps.
Redaction protocol
Cluster entries are published under the verified entity's public-domain identity (LinkedIn handle, registered company name). Counterparty victim names (banks, trading houses, insurers) are redacted unless the victim has explicitly authorized publication. Evidence appendices use hashed identifiers for any non-public PII.
Submission to regulators
No cluster has been submitted to any regulator. The index is written so that it could be used as source material for a submission (OFAC SDN candidate intake, FCA financial-crime working examples under SYSC 6.3, MAS Notice 626 typologies, FATF Recommendation 10 working-group papers), but no submission has been made and none will be until there is a legal entity to make it. If that changes, this section will name the body and the date.
Versioning + correction policy
Indexes are versioned semantically (v1.0 → v1.0.1 for typo-grade fixes, v1.1 for material evidence updates). Corrections are listed in a public errata at /intelligence/errata. If you spot a factual error, email [email protected] and we fix and re-issue within five business days.