See the stars

ShellScan Specification

Home / ShellScan / ShellScan Specification

ShellScan

From shell to source.


Open Source Corporate Ownership, Financial Network, and Transparency Intelligence Specification

Specification Overview

ShellScan is an open-source specification for a comprehensive corporate ownership, financial institution, shell company, executive history, regulatory intelligence, and financial network transparency platform.

ShellScan is designed to identify, organize, connect, analyze, and visualize publicly available and legally accessible information about companies, financial institutions, ownership structures, officers, directors, boards, regulatory relationships, corporate histories, financial networks, and cross-border entities.

ShellScan transforms fragmented corporate and financial information into connected, searchable, historically aware intelligence while preserving source provenance, evidence quality, analytical transparency, and human review.

ShellScan does not automatically equate complex ownership, offshore structures, nominee arrangements, shell companies, unusual financial relationships, or corporate opacity with illegal activity. Analytical findings are indicators that require supporting evidence and appropriate human or institutional review.

The specification is designed for investigative researchers, journalists, regulators, financial analysts, compliance professionals, policymakers, academics, watchdog organizations, and members of the public seeking greater financial transparency.

Core Principles

  • Open source
  • Public-interest transparency
  • Evidence-based analysis
  • Source provenance
  • Historical preservation
  • Corporate ownership transparency
  • Financial network visibility
  • Explainable analysis
  • Human review
  • False-positive awareness
  • Privacy protection
  • Legal and ethical data use
  • Vendor neutrality
  • Interoperability
  • Reproducibility
  • Auditability
  • Versioned intelligence
  • Cross-border visibility
  • Public accountability

Core Modules

Corporate Entity Intelligence

ShellScan shall maintain comprehensive profiles for corporate entities identified through legally available information.

Capabilities shall include:

  • Legal company name
  • Former company names
  • Trade names
  • Doing-business-as names
  • Registration identifiers
  • Jurisdiction of incorporation
  • Formation date
  • Dissolution date
  • Status
  • Registered addresses
  • Principal addresses
  • Mailing addresses
  • Registered agents
  • Parent companies
  • Subsidiaries
  • Affiliates
  • Related entities
  • Business classifications
  • Industry classifications
  • Corporate purpose
  • Corporate event history
  • Regulatory relationships
  • Publicly reported financial information
  • Source documentation
  • Evidence confidence
  • Historical snapshots

Financial Institution Intelligence

ShellScan shall maintain profiles and relationships for financial institutions throughout the financial sector.

Coverage shall include:

  • Banks
  • Credit unions
  • Mortgage lenders
  • Mortgage brokers
  • Broker-dealers
  • Investment advisers
  • Asset managers
  • Hedge funds
  • Private equity firms
  • Venture capital firms
  • Insurance companies
  • Reinsurance companies
  • Fintech companies
  • Payment companies
  • Money services businesses
  • Trust companies
  • Custodians
  • Clearing organizations
  • Securities firms
  • Consumer finance companies
  • Digital asset companies
  • Other regulated or publicly documented financial entities

The module shall connect financial institutions to their ownership structures, officers, directors, subsidiaries, affiliates, regulatory records, enforcement history, and other documented relationships.

Ownership Intelligence

ShellScan shall map corporate ownership structures and changes over time.

Capabilities shall include:

  • Direct ownership
  • Indirect ownership
  • Parent ownership
  • Subsidiary relationships
  • Beneficial ownership where legally available
  • Controlling interests
  • Minority interests
  • Voting interests
  • Economic interests
  • Cross-ownership
  • Reciprocal ownership
  • Ownership percentages
  • Ownership changes
  • Acquisition events
  • Divestitures
  • Mergers
  • Spin-offs
  • Corporate reorganizations
  • Ownership chains
  • Multi-layer ownership structures
  • Jurisdictional ownership paths
  • Historical ownership snapshots

The system shall distinguish documented ownership from inferred or analytically suggested relationships.

Shell Company Intelligence

ShellScan shall identify characteristics associated with potentially opaque or minimally operational corporate entities.

Potential indicators may include:

  • Limited publicly documented operations
  • Minimal or unclear business activity
  • Shared addresses
  • Shared registered agents
  • Rapid formation and dissolution
  • Complex ownership chains
  • Common officers across numerous entities
  • Unusual jurisdictional structures
  • Frequent ownership changes
  • Dormant or inactive status
  • Limited operational footprint
  • Repeated use of intermediary entities
  • Disproportionate corporate complexity
  • Connections to other high-opacity entities

ShellScan shall not classify an entity as illegal solely because it exhibits these characteristics.

Every analytical classification shall preserve the underlying evidence, indicators, confidence level, methodology, and relevant alternative explanations.

Officer and Director Intelligence

ShellScan shall maintain historical profiles of corporate officers, directors, executives, board members, trustees, and other publicly documented leadership roles.

Capabilities shall include:

  • Full name
  • Known name variations
  • Corporate positions
  • Position start dates
  • Position end dates
  • Companies served
  • Boards served
  • Historical appointments
  • Resignations
  • Executive transitions
  • Shared board memberships
  • Shared corporate affiliations
  • Documented professional relationships
  • Publicly documented geographic or jurisdictional associations
  • Regulatory actions where legally available
  • Enforcement actions
  • Litigation records
  • Bankruptcy relationships
  • Corporate event associations
  • Source provenance

Historical records shall remain available after an individual leaves an organization.

Corporate Relationship Graph

ShellScan shall represent corporate relationships as a connected analytical graph.

Graph relationships may include:

  • Owns
  • Owned by
  • Controls
  • Controlled by
  • Subsidiary of
  • Parent of
  • Affiliate of
  • Shares an officer with
  • Shares a director with
  • Shares an address with
  • Shares a registered agent with
  • Shares a documented intermediary with
  • Acquired
  • Acquired by
  • Merged with
  • Invested in
  • Financed by
  • Regulated by
  • Sued by
  • Sanctioned by
  • Subject to enforcement by
  • Connected through public records
  • Connected through documented financial relationships

The graph shall support historical and temporal relationships.

Ownership Path Analysis

ShellScan shall calculate and display ownership paths between entities.

Capabilities shall include:

  • Direct ownership paths
  • Indirect ownership paths
  • Multi-layer ownership chains
  • Controlling-interest paths
  • Voting-interest paths
  • Beneficial ownership paths where available
  • Shortest relationship paths
  • Longest documented ownership chains
  • Jurisdiction transitions
  • Intermediate entities
  • Ownership concentration
  • Ownership fragmentation
  • Circular ownership structures

Each path shall identify its evidence sources and distinguish documented facts from analytical inference.

Hidden Influence Mapping

ShellScan shall analyze documented relationships that may indicate concentrated or distributed influence across corporate networks.

Capabilities shall include:

  • Common ownership
  • Common executives
  • Common directors
  • Shared intermediaries
  • Repeated service providers
  • Common addresses
  • Investment relationships
  • Financing relationships
  • Control relationships
  • Voting relationships
  • Network centrality
  • Influence pathways
  • Corporate concentration
  • Cross-sector relationships

Influence analysis shall be presented as analytical context rather than definitive proof of control unless control is documented.

Regulatory Intelligence

ShellScan shall integrate publicly available regulatory and governmental information.

Potential sources shall include:

  • SEC records
  • FDIC records
  • FINRA records
  • NMLS records
  • Federal banking records
  • State financial regulatory records
  • State corporate registries
  • State securities regulators
  • Insurance regulators
  • Public enforcement records
  • Government corporate databases
  • Public court records
  • Bankruptcy records
  • Public licensing records
  • Public sanctions information
  • Other legally accessible governmental datasets

The system shall preserve source dates and update histories.

Regulatory and Enforcement History

ShellScan shall connect entities and individuals to documented regulatory actions.

Records may include:

  • Enforcement actions
  • Regulatory orders
  • Fines
  • Settlements
  • Suspensions
  • License actions
  • Regulatory restrictions
  • Public warnings
  • Compliance actions
  • Court judgments
  • Bankruptcy proceedings
  • Public investigations
  • Corporate penalties

The system shall distinguish allegations, investigations, settlements, findings, judgments, and final determinations.

Sanctions and Public Risk Intelligence

Where legally available, ShellScan may correlate corporate entities and individuals with:

  • Sanctions lists
  • Politically exposed person datasets
  • Government watchlists
  • Regulatory warnings
  • Public enforcement actions
  • Public litigation
  • Bankruptcy records
  • Corporate dissolution records
  • License suspensions
  • Public fraud findings

The system shall identify the source and date for each match and provide mechanisms for resolving false or ambiguous matches.

Document Intelligence

ShellScan shall ingest and analyze publicly available corporate and regulatory documents.

Supported document categories may include:

  • Annual reports
  • Quarterly reports
  • Current reports
  • Securities filings
  • Ownership filings
  • Investment disclosures
  • Corporate registration documents
  • Regulatory filings
  • Enforcement documents
  • Court documents
  • Bankruptcy documents
  • Public licensing records
  • Public corporate disclosures
  • Other legally accessible documents

Document analysis shall extract relevant entities, relationships, dates, ownership information, officers, directors, jurisdictions, financial relationships, and corporate events.

Entity Resolution

ShellScan shall normalize information from different sources into unified entity profiles.

Capabilities shall include:

  • Name normalization
  • Name variation detection
  • Corporate identifier matching
  • Address normalization
  • Officer identity matching
  • Director identity matching
  • Jurisdiction matching
  • Registration matching
  • Historical identity resolution
  • Duplicate detection
  • Relationship reconciliation
  • Conflicting record detection

The system shall retain original source values rather than destroying source-specific information during normalization.

Evidence and Provenance

Every important fact and analytical relationship shall maintain provenance.

Provenance records shall include:

  • Source
  • Source type
  • Source date
  • Retrieval date
  • Original record identifier
  • Relevant document
  • Supporting evidence
  • Extraction method
  • Transformation history
  • Confidence level
  • Verification status
  • Analyst annotations
  • Revision history

Users shall be able to trace analytical findings back to supporting evidence.

Confidence and Verification

ShellScan shall assign evidence and relationship confidence where appropriate.

Confidence classifications may include:

  • Verified
  • Strongly supported
  • Supported
  • Probable
  • Possible
  • Unverified
  • Conflicting
  • Disputed
  • Historical
  • Inactive

Confidence shall never be presented as proof of wrongdoing.

Users shall be able to review the evidence underlying each confidence assessment.

AI Shell Detection

ShellScan may use artificial intelligence to identify patterns associated with potentially opaque corporate structures.

Analytical signals may include:

  • Corporate complexity
  • Ownership layering
  • Shared addresses
  • Shared officers
  • Shared registered agents
  • Rapid entity creation
  • Rapid entity dissolution
  • Dormancy
  • Unusual jurisdiction patterns
  • Repeated intermediary structures
  • Network concentration
  • Unexpected corporate relationships

AI output shall be explainable and accompanied by the indicators contributing to the result.

AI Anomaly Detection

ShellScan shall identify unusual patterns across corporate and financial networks.

Capabilities may include:

  • Unusual ownership changes
  • Unexpected corporate relationships
  • Rapid executive turnover
  • Unusual network growth
  • Sudden jurisdiction changes
  • Unusual entity formation patterns
  • Repeated corporate structures
  • Network fragmentation
  • Network consolidation
  • Abnormal regulatory activity

Anomalies shall be treated as signals for investigation rather than conclusions.

Graph Analysis

ShellScan shall provide analytical tools for examining complex networks.

Capabilities shall include:

  • Network centrality
  • Community detection
  • Relationship clustering
  • Influence pathways
  • Ownership concentration
  • Network density
  • Network fragmentation
  • Bridge entities
  • Highly connected entities
  • Isolated entities
  • Relationship strength
  • Temporal graph analysis

Fraud Pattern Recognition

ShellScan may identify patterns associated with known corporate fraud indicators.

Potential patterns may include:

  • Rapid corporate restructuring
  • Repeated related-party relationships
  • Unusual ownership transfers
  • Circular transactions where publicly documented
  • Repeated executive overlap
  • Sudden asset movement where publicly documented
  • Repeated corporate failures
  • Unusual corporate succession
  • Regulatory warning patterns

Results shall remain analytical indicators and shall not be represented as findings of criminal conduct without appropriate evidence.

Network Evolution Analysis

ShellScan shall analyze how corporate networks change over time.

Capabilities shall include:

  • Entity formation
  • Entity dissolution
  • Ownership changes
  • Leadership changes
  • Acquisitions
  • Mergers
  • Divestitures
  • Network expansion
  • Network contraction
  • Jurisdiction migration
  • Relationship creation
  • Relationship termination

Historical snapshots shall allow users to compare network states across time.

Predictive Risk Analysis

ShellScan may provide predictive models that identify possible future network conditions based on historical patterns.

Potential uses include:

  • Ownership change scenarios
  • Corporate restructuring scenarios
  • Network expansion
  • Network fragmentation
  • Regulatory exposure
  • Concentration risk
  • Systemic relationship risk
  • Corporate distress indicators

Predictions shall be clearly identified as forecasts rather than facts.

Financial Network Intelligence

ShellScan shall connect publicly documented financial relationships across corporate networks.

Capabilities may include:

  • Investments
  • Financing relationships
  • Debt relationships
  • Equity relationships
  • Publicly documented lending relationships
  • Securities relationships
  • Fund relationships
  • Asset management relationships
  • Insurance relationships
  • Derivative exposure where publicly documented
  • Corporate guarantees where publicly documented
  • Publicly disclosed counterparties

ShellScan shall not imply access to private bank transaction records unless such information is legally available through an authorized source.

Cross-Border Intelligence

ShellScan shall support international corporate and financial relationships.

Capabilities may include:

  • International company registries
  • Cross-border ownership
  • Offshore jurisdictions
  • International subsidiaries
  • Foreign directors
  • Foreign officers
  • Jurisdiction transitions
  • Cross-border corporate structures
  • International regulatory actions
  • International sanctions
  • International litigation
  • Multi-jurisdiction entity resolution

The system shall identify jurisdictional uncertainty and incomplete registry coverage.

Geographic Intelligence

ShellScan shall map corporate relationships geographically.

Capabilities shall include:

  • Incorporation locations
  • Registered addresses
  • Corporate headquarters
  • Officer geographic associations where publicly documented
  • Director geographic associations where publicly documented
  • Financial institution locations
  • Regulatory jurisdictions
  • Ownership jurisdictions
  • Cross-border pathways
  • Corporate concentration by location

Geographic information shall be presented according to the source’s level of reliability.

Corporate History

ShellScan shall maintain a longitudinal corporate timeline.

Timelines may include:

  • Formation
  • Name changes
  • Address changes
  • Ownership changes
  • Officer appointments
  • Board appointments
  • Acquisitions
  • Mergers
  • Divestitures
  • Regulatory actions
  • Litigation
  • Bankruptcy
  • Dissolution
  • Reorganization
  • Other documented corporate events

Users shall be able to reconstruct the documented history of an entity.

Real-Time Monitoring

ShellScan shall support continuous monitoring of selected entities and networks.

Monitoring may include:

  • Ownership changes
  • New corporate registrations
  • Officer changes
  • Board changes
  • Regulatory actions
  • Enforcement actions
  • Litigation
  • Bankruptcy events
  • Sanctions changes
  • Corporate status changes
  • New related entities
  • Network relationship changes
  • Relevant news events

Alerts

Users shall be able to create configurable alerts.

Alerts may be triggered by:

  • Ownership changes
  • New officers
  • Officer departures
  • Board changes
  • New subsidiaries
  • New parent relationships
  • Regulatory actions
  • Enforcement actions
  • Litigation
  • Bankruptcy
  • Sanctions matches
  • Significant network changes
  • Changes in analytical risk indicators

News and Media Correlation

ShellScan may correlate corporate intelligence with publicly available news and media sources.

Capabilities may include:

  • Company mentions
  • Executive mentions
  • Corporate event detection
  • Regulatory event correlation
  • Acquisition reporting
  • Litigation reporting
  • Bankruptcy reporting
  • Investigative reporting
  • Event timelines
  • Source comparison

News reports shall remain distinguishable from verified regulatory or corporate records.

Whistleblower and Public Submission Intelligence

ShellScan may support legally collected public submissions and whistleblower information.

Capabilities shall include:

  • Public submissions
  • Supporting documents
  • Evidence attachments
  • Source classification
  • Verification workflows
  • Anonymous public submissions where legally appropriate
  • Investigator review
  • Status tracking
  • False-information reporting
  • Correction mechanisms

Unverified submissions shall never be presented as established facts.

Crowdsourced Verification

Users may contribute verification and contextual information.

Capabilities shall include:

  • Evidence submissions
  • Corrections
  • Entity annotations
  • Relationship annotations
  • Source suggestions
  • Historical information
  • Dispute reporting
  • Verification votes
  • Expert review
  • Moderator review

Community contributions shall retain provenance and verification status.

Investigative Workspace

ShellScan shall provide tools for structured investigations.

Capabilities may include:

  • Saved entities
  • Saved networks
  • Investigation timelines
  • Evidence collections
  • Notes
  • Relationship maps
  • Source collections
  • Report generation
  • Collaborative investigations
  • Research annotations
  • Investigation history

Natural Language Investigation

ShellScan shall allow users to ask questions about corporate networks using natural language.

Queries may include requests to:

  • Identify ownership chains
  • Find common officers
  • Find shared directors
  • Trace corporate relationships
  • Identify related financial institutions
  • Compare corporate networks
  • Find historical relationships
  • Identify changes over time
  • Summarize documented regulatory activity
  • Trace relationships across jurisdictions

Natural-language results shall link back to the underlying evidence.

Transparency Scoring

ShellScan shall calculate configurable transparency and opacity indicators.

Potential factors may include:

  • Availability of corporate information
  • Ownership complexity
  • Ownership disclosure
  • Jurisdictional complexity
  • Historical record completeness
  • Executive disclosure
  • Regulatory transparency
  • Relationship transparency
  • Evidence completeness
  • Network complexity

Scores shall disclose the factors and methodology used.

Sector Transparency Intelligence

ShellScan shall provide aggregate transparency analysis across industries.

Capabilities may include:

  • Sector comparisons
  • Industry concentration
  • Ownership complexity
  • Regulatory activity
  • Corporate network density
  • Common ownership patterns
  • Executive network overlap
  • Transparency trends

Geographic Transparency Intelligence

ShellScan shall provide aggregate analysis by:

  • Country
  • State
  • Territory
  • Jurisdiction
  • Regulatory region
  • Financial center
  • Corporate registration region

Policy and Regulatory Analysis

ShellScan shall provide tools for analyzing the potential effects of policy and regulatory changes.

Capabilities may include:

  • Regulatory change tracking
  • Policy impact analysis
  • Corporate exposure analysis
  • Sector exposure
  • Jurisdiction exposure
  • Ownership disclosure analysis
  • Scenario comparison
  • Historical policy comparisons

Policy Simulation

Users may model hypothetical policy changes and analyze potential effects on documented corporate networks.

Possible scenarios include:

  • Ownership disclosure requirements
  • Regulatory changes
  • Reporting requirements
  • Financial institution rules
  • Corporate transparency requirements
  • Sanctions changes
  • Cross-border restrictions

Simulation results shall be clearly identified as models rather than predictions of actual government action or market outcomes.

Systemic Risk Analysis

ShellScan may analyze interconnected corporate and financial networks for concentration and propagation risk.

Capabilities may include:

  • Network concentration
  • Common counterparties
  • Common ownership
  • Shared financial institutions
  • Sector dependencies
  • Geographic dependencies
  • Relationship clusters
  • Cascading scenario analysis
  • Network vulnerability
  • Potential points of concentration

Cascading Event Simulation

ShellScan may simulate hypothetical network disruptions.

Examples include:

  • Corporate failure
  • Financial institution failure
  • Regulatory restriction
  • Ownership disruption
  • Supply disruption
  • Market shock
  • Sector contraction

Simulation outputs shall clearly distinguish hypothetical scenarios from observed events.

Supply Chain Intelligence

ShellScan may connect corporate ownership intelligence with publicly available supply chain information.

Capabilities may include:

  • Suppliers
  • Customers
  • Manufacturers
  • Distributors
  • Logistics relationships
  • Corporate ownership
  • Geographic dependencies
  • Trade relationships
  • Supply chain concentration

Trade Intelligence

Where legally available, ShellScan may analyze public trade and customs information.

Capabilities may include:

  • Import relationships
  • Export relationships
  • Trading entities
  • Product categories
  • Trade jurisdictions
  • Corporate relationships
  • Supplier relationships
  • Customer relationships

Debt and Exposure Mapping

ShellScan may map publicly disclosed debt and financial exposure.

Capabilities may include:

  • Debt issuance
  • Credit facilities
  • Publicly documented lenders
  • Bond relationships
  • Guarantees
  • Publicly disclosed counterparties
  • Debt maturity events
  • Refinancing events
  • Exposure concentration

Digital Asset Intelligence

Where legally available and appropriate, ShellScan may connect corporate entities with publicly documented digital asset activity.

Capabilities may include:

  • Digital asset companies
  • Token issuers
  • Public blockchain relationships
  • Smart contract associations
  • Public wallet associations
  • Corporate token holdings where disclosed
  • DeFi relationships
  • Exchange relationships
  • Regulatory actions involving digital assets

Public blockchain associations shall not automatically establish ownership or control.

Corporate Influence Analysis

ShellScan may identify documented relationships between corporate networks and broader institutional networks.

Capabilities may include:

  • Board overlaps
  • Executive overlaps
  • Investment relationships
  • Lobbying records where publicly available
  • Political activity records where legally available
  • Industry organizations
  • Trade associations
  • Public policy relationships

The system shall distinguish documented activity from inferred influence.

Explainable AI

All significant AI-generated findings shall provide understandable explanations.

Explanations may include:

  • Contributing evidence
  • Detected indicators
  • Relevant relationships
  • Model confidence
  • Historical context
  • Alternative explanations
  • Data limitations

Users shall be able to inspect the information underlying AI-generated findings.

AI Auditability

AI-generated results shall maintain:

  • Model version
  • Analysis date
  • Input data references
  • Output
  • Confidence
  • Explanation
  • Relevant evidence
  • Revision history

Data Quality Management

ShellScan shall continuously evaluate data quality.

Capabilities shall include:

  • Duplicate detection
  • Missing-data detection
  • Conflicting-record detection
  • Stale-data detection
  • Source reliability indicators
  • Record completeness
  • Data freshness
  • Entity resolution confidence
  • Correction workflows

Versioned Intelligence

ShellScan shall preserve historical versions of important records.

Users shall be able to determine:

  • What information was known at a particular time
  • When a relationship was added
  • When a relationship changed
  • When a source was updated
  • When an analytical assessment changed
  • Why an assessment changed

Historical Snapshots

Users shall be able to view corporate and financial networks as they existed at previous points in time.

Historical views shall support:

  • Ownership
  • Officers
  • Directors
  • Corporate status
  • Regulatory status
  • Relationships
  • Network structure
  • Geographic structure

Search and Discovery

ShellScan shall provide comprehensive search across:

  • Companies
  • Financial institutions
  • Officers
  • Directors
  • Boards
  • Ownership relationships
  • Addresses
  • Jurisdictions
  • Regulatory records
  • Litigation
  • Bankruptcy
  • News
  • Networks
  • Historical records

Public API

ShellScan may provide an API for authorized access to publicly available ShellScan data.

API capabilities may include:

  • Entity queries
  • Relationship queries
  • Historical queries
  • Ownership queries
  • Officer queries
  • Network queries
  • Regulatory queries
  • Evidence queries
  • Search
  • Export
  • Change monitoring

API access shall respect licensing, privacy, security, and source restrictions.

Data Export

ShellScan shall support structured exports where appropriate.

Potential formats include:

  • CSV
  • JSON
  • GraphML
  • HTML
  • Other interoperable formats

Exports shall preserve source and provenance information whenever practical.

Investigative Reports

ShellScan shall generate structured reports containing:

  • Executive summary
  • Entity profiles
  • Ownership chains
  • Corporate relationships
  • Officer histories
  • Board histories
  • Regulatory history
  • Evidence
  • Timeline
  • Network visualization
  • Analytical indicators
  • Confidence levels
  • Data limitations

Reports shall distinguish facts, sourced claims, analytical conclusions, and unresolved questions.

Transparency Reports

ShellScan shall support publication-ready transparency reports for:

  • Companies
  • Financial institutions
  • Corporate networks
  • Industries
  • Jurisdictions
  • Regulatory events
  • Ownership changes

Interactive Visualization

ShellScan shall provide visual representations of complex networks.

Visualization capabilities may include:

  • Ownership graphs
  • Corporate relationship graphs
  • Officer networks
  • Board networks
  • Geographic maps
  • Timelines
  • Historical graph views
  • Regulatory timelines
  • Network clusters
  • Relationship pathways

Temporal Visualization

Users shall be able to observe corporate networks changing over time.

Temporal visualization shall support:

  • Entity creation
  • Entity dissolution
  • Ownership changes
  • Leadership changes
  • Regulatory events
  • Network expansion
  • Network contraction
  • Relationship creation
  • Relationship termination

Immersive Visualization

Optional interfaces may provide advanced three-dimensional or immersive representations of large corporate networks.

Immersive visualization shall remain an interface layer and shall not alter the underlying evidence model.

Public Transparency Interface

ShellScan shall support interfaces designed for members of the public.

Public users may be able to:

  • Search companies
  • Search financial institutions
  • View ownership
  • View corporate histories
  • View documented officers and directors
  • Review regulatory records
  • View network relationships
  • Review evidence
  • Submit corrections
  • Learn about corporate structures

Educational Intelligence

ShellScan may provide educational resources explaining:

  • Corporate ownership
  • Shell companies
  • Beneficial ownership
  • Financial institutions
  • Corporate registries
  • Regulatory systems
  • Corporate structures
  • Financial networks
  • Evidence evaluation
  • Investigative research methods

Investigative Challenges

An optional educational system may provide structured challenges based on public records.

Challenges may teach users how to:

  • Trace ownership
  • Identify relationships
  • Verify sources
  • Analyze corporate histories
  • Compare entities
  • Follow regulatory records
  • Understand network structures

Security and Access Control

ShellScan shall support appropriate access controls for protected functionality.

Capabilities may include:

  • Authentication
  • Authorization
  • Role-based access
  • Administrative controls
  • Audit logs
  • Session controls
  • API access controls
  • Abuse prevention

Privacy Protection

ShellScan shall distinguish public corporate information from personal information requiring additional protection.

Privacy controls shall support:

  • Data minimization
  • Appropriate handling of personal information
  • Removal or correction mechanisms where legally required
  • Source restrictions
  • Access controls
  • Privacy-preserving publication
  • Protection against unnecessary exposure of sensitive personal information

Legal and Ethical Data Governance

ShellScan shall use information in accordance with applicable laws, source terms, licensing requirements, privacy requirements, and ethical research standards.

The platform shall:

  • Respect source restrictions
  • Preserve attribution
  • Preserve provenance
  • Avoid unsupported accusations
  • Distinguish allegations from findings
  • Provide correction mechanisms
  • Support responsible disclosure
  • Identify data limitations

Audit Trail

Important actions and analytical changes shall be auditable.

Audit records may include:

  • Data ingestion
  • Data modification
  • Entity merges
  • Relationship changes
  • Analyst annotations
  • AI analyses
  • Corrections
  • Verification actions
  • Administrative actions
  • Report generation

Correction and Dispute System

ShellScan shall provide mechanisms for correcting inaccurate or disputed information.

Capabilities shall include:

  • Correction requests
  • Evidence submission
  • Dispute status
  • Source review
  • Historical correction records
  • Analyst review
  • Resolution tracking

Corrections shall not erase historical provenance.

Open Research Collaboration

ShellScan shall support collaboration among:

  • Journalists
  • Researchers
  • Academics
  • Regulators
  • Compliance professionals
  • Transparency organizations
  • Civil society
  • Investigators
  • Developers

Collaborative contributions shall preserve authorship, provenance, and revision history.


Optional Plugin Modules

Optional plugins may extend ShellScan without changing the core specification.

International Registry Plugin

Adds expanded integration with international corporate registries and government corporate datasets.

Offshore Jurisdiction Plugin

Adds specialized analysis of offshore jurisdictions, corporate structures, and cross-border ownership relationships.

Global Sanctions Plugin

Adds expanded sanctions and international regulatory intelligence.

PEP Intelligence Plugin

Adds expanded politically exposed person relationship analysis using legally available datasets.

Court and Litigation Plugin

Adds expanded public court, litigation, judgment, and bankruptcy intelligence.

News Intelligence Plugin

Adds expanded news monitoring, event detection, source comparison, and corporate media correlation.

Whistleblower Plugin

Adds controlled workflows for public whistleblower submissions and evidence review.

Investigative Collaboration Plugin

Adds collaborative research workspaces, shared investigations, annotations, evidence collections, and team workflows.

Journalist Workspace Plugin

Adds specialized tools for investigative journalists, including research timelines, source tracking, evidence organization, and report preparation.

Regulatory Compliance Plugin

Adds compliance-oriented monitoring and reporting tools for financial institutions and regulated organizations.

Corporate Due Diligence Plugin

Adds structured corporate due diligence workflows for authorized users.

Investment Intelligence Plugin

Adds investment relationship, fund, portfolio, ownership, and exposure analysis using publicly available information.

Hedge Fund Intelligence Plugin

Adds specialized hedge fund entity, ownership, leadership, investment, and regulatory analysis.

Private Equity Intelligence Plugin

Adds specialized private equity firm, fund, portfolio company, ownership, and executive relationship analysis.

Insurance Intelligence Plugin

Adds specialized insurance and reinsurance corporate network analysis.

Mortgage Intelligence Plugin

Adds specialized analysis of mortgage lenders, mortgage brokers, licensing, ownership, officers, directors, and regulatory relationships.

Fintech Intelligence Plugin

Adds specialized fintech company monitoring, ownership mapping, regulatory analysis, and financial relationship intelligence.

Digital Asset Intelligence Plugin

Adds expanded analysis of cryptocurrency companies, tokens, exchanges, decentralized finance relationships, and public blockchain activity.

Blockchain Verification Plugin

Adds blockchain-based verification and timestamping for selected public evidence records.

Supply Chain Plugin

Adds expanded supply chain, supplier, customer, logistics, and corporate dependency analysis.

Trade Intelligence Plugin

Adds expanded import, export, customs, and international trade relationship analysis.

Debt Intelligence Plugin

Adds expanded public debt, lending, bond, guarantee, and financial exposure analysis.

Systemic Risk Plugin

Adds advanced network dependency and cascading-event simulations.

Policy Sandbox Plugin

Adds interactive policy and regulatory scenario modeling.

AI Research Assistant Plugin

Adds advanced natural-language investigation assistance while preserving evidence links and explainability.

Predictive Intelligence Plugin

Adds advanced forecasting of corporate network changes and potential risk conditions.

Advanced Graph Analytics Plugin

Adds specialized network science, graph algorithms, community detection, centrality analysis, and temporal network analysis.

Three-Dimensional Visualization Plugin

Adds advanced three-dimensional corporate network visualization.

Immersive Investigation Plugin

Adds optional immersive interfaces for navigating large corporate and financial networks.

Public Education Plugin

Adds educational lessons, tutorials, guided investigations, and interactive learning experiences.

Citizen Investigation Plugin

Adds public research challenges and structured transparency investigations based on legally available information.

Transparency Index Plugin

Adds expanded scoring and comparative transparency indexes for companies, financial institutions, sectors, and jurisdictions.

Corporate Reputation Plugin

Adds structured aggregation of documented public events affecting corporate reputation while maintaining source distinctions.

Data Quality Plugin

Adds advanced source reliability, freshness, conflict detection, duplicate detection, and data completeness analysis.

Evidence Review Plugin

Adds specialized evidence review, verification, source comparison, and dispute-resolution workflows.

Archive Plugin

Adds long-term preservation and historical snapshots of corporate records and relationship networks.

API Gateway Plugin

Adds expanded programmatic access, API management, usage controls, and external integrations.

Research Export Plugin

Adds specialized exports for academic, investigative, regulatory, and analytical workflows.


Specification Branding License (SBL)

Standard

Optional


License & Notice Requirements

ShellScan is released under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).

By contributing to this project, you agree that your contributions will also be released under this license.

Please note the following:

  • All contributions must comply with the AGPL-3.0+ terms.
  • Under Section 7 of the license, all redistributions, forks, and derivative works must preserve attribution to:
    Roxanne Ardary and roxanneardary.com.
  • ShellScan specifications are free to use with attribution. A Specification Branding License can be negotiated upon request.
  • The project’s notice.md file tracks attribution requirements and contributor acknowledgments.
    Any update that adds new contributors or modifies attribution should also update notice.md.
  • When submitting a pull request, ensure that any new files maintain the attribution headers where applicable.
  • Network-deployed versions of this software must also remain fully AGPL-3.0+ compliant, including exposure of source code modifications when applicable under the license.

For full legal details, please refer to the AGPL-3.0+ license and the project’s notice.md file.


Notice – ShellScan

Attribution Requirement: Under Section 7 of the AGPL 3.0+ license, all redistributions, forks, and derivative works, including network-deployed versions of this project, must provide attribution to Roxanne Ardary and roxanneardary.com.

Contributors

This file tracks contributors and their specific contributions to the project.

  • Roxanne Ardary, roxanneardary.com – March 28, 2026
    Created the repository for ShellScan. Developed the initial shell scanning tool for detecting and analyzing shell scripts and potential security issues.
  • [Add other contributors here] – [Date]
    [Describe contribution in one sentence]

License – ShellScan

This repository is licensed under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).

Key Points:

  • You are free to use, modify, and distribute the code.
  • All redistributions, forks, and derivative works or network-deployed versions must also be licensed under AGPL-3.0+ and provide attribution to Roxanne Ardary and roxanneardary.com as required under Section 7 of the license.
  • The software is provided “as is,” without warranty of any kind.

For the full license text, see GNU AGPL-3.0 License.