We are pleased to provide insights into the compliance framework for D3Prospect, the enterprise data intelligence layer operated by BSPEC INC. This statement outlines our principles regarding Open-Source Intelligence (OSINT) ingestion, artificial intelligence (AI) predictive modeling, information security, and global data privacy standards. We encourage our partners and API consumers to review these practices to understand how we maintain sub-100ms data resolution safely and legally.
Unlike traditional data brokers that strictly rely on scraping and storing historical records, D3Prospect operates as a real-time probabilistic prediction engine. We gather purely technographic and publicly available professional information (such as firmographics, startup funding, domain IT infrastructure, and public professional profiles). Using proprietary machine learning models, D3Prospect analyzes this B2B metadata to calculate statistical probabilities of corporate email syntaxes and entity resolutions.
D3Prospect engages in transparent data orchestration. We strictly prohibit unauthorized access, bypassing security gateways, or using deceptive accounts to aggregate data. Importantly, D3Prospect never accesses or processes any sensitive personal information (SPI)—such as health, racial, or religious data—nor do we gather information from personal, non-work-oriented social media accounts, even if publicly accessible. Our engine maps the public professional sphere exclusively.
Within the scope of D3Prospect’s knowledge graph lies a limited set of publicly available professional data. While many comprehensive U.S. state privacy laws exclude publicly available information from the definition of protected personal data, we recognize that other global regulations (such as the GDPR) may classify inferred or predicted professional data differently.
We place the utmost attention on safeguarding this data. D3Prospect’s outputs—such as predicted corporate emails, job titles, and industry focus—are generated dynamically based on mathematical signals (like Top-Level Domains and corporate IT naming conventions). We do not store or compute any data designated as private by the individual or entity.
To align proactively with global data protection regulations (including CCPA/CPRA and GDPR) and to empower individual data protection rights, BSPEC INC has engineered a highly secure, automated compliance infrastructure:
Identity Verification (Right to Know): Through our public-facing Privacy Portal, individuals can request to see what metadata our AI associates with their professional identity. To prevent data breaches, D3Prospect mandates strict Identity Verification via a secure, time-limited cryptographic token (Magic Link/OTP) before revealing any probabilistic data.
Cryptographic Suppression (Right to Opt-Out/Delete): Due to the continuous ingestion of our OSINT engine, standard data deletion is insufficient. When an individual opts out, D3Prospect utilizes a one-way Cryptographic Suppression List. The individual’s identifiers are hashed (via SHA-256) and stored at the network edge. This guarantees that our Cloudflare Workers and machine learning models will programmatically block the future generation, prediction, or display of that individual’s data across our entire API network in milliseconds.
As an AI-driven data layer, D3Prospect continuously monitors global privacy frameworks, automated decision-making regulations (such as those outlined in the EU AI Act and recent CCPA amendments), and established case law. Legal precedents regarding public data, such as hiQ Labs, Inc. v. LinkedIn Corp., have affirmed that the aggregation of publicly accessible data does not violate the Computer Fraud and Abuse Act (CFAA), provided it does not involve unauthorized access to protected systems. D3Prospect’s strictly public, OSINT-driven approach aligns perfectly with these legal frameworks.
Furthermore, our internal Code of Ethics and Supplier Code of Conduct require all employees, third-party network partners, and API consumers to strictly adhere to ethical business practices, robust information security (AES-256 encryption in transit and at rest), and responsible data stewardship. Our predictive engine is designed solely to facilitate legitimate B2B commerce and cannot be used for discriminatory profiling or automated decision-making that produces legal or similarly significant effects on individuals.
BSPEC INC 1213 Eagle Crest Drive
Lemont, Illinois, 60439
USA