How to Do Due Diligence on a Company for Free
You can do a real background check on almost any company without spending a cent, because the records that matter are published by the agencies that hold them. The trick isn't access — it's knowing which record answers which question, and reading each one without fooling yourself. Here's the order a professional works in, the free source for each step, and how a free due diligence tool collapses the whole thing into one search.
Two habits make the difference between a real check and a false sense of security. Work in sequence, because each step depends on the one before it — you can't screen the right entity for lawsuits until you've confirmed the entity. And keep the source for every fact you record, so a finding can be re-checked later instead of taken on faith.
Before you start: what you actually need
Gather the basics that let you tell one company from another: the exact name as it appears on official documents, the state or country of registration, and the names of the people who run or own it. Brand names and website copy are a starting point, not an identifier.
Decide upfront how deep the check needs to go, because that governs how much time each step deserves. Vetting a small vendor is a lighter pass than diligence on an acquisition, and the scope of a due diligence review should match the size of the decision it supports.
1. Confirm the company is who it says it is
Start with identity, because everything downstream keys off the correct legal entity — not the brand on the homepage. For a U.S. public company, the SEC's EDGAR gives you the exact registrant, its filings and its current standing for free. For a private company you're usually in state Secretary-of-State records, which are free but slower. Get the legal name and any parent or subsidiaries straight before you go further; our corporate due diligence module pulls this from EDGAR automatically.
2. Read a few years of financials
One good quarter proves nothing. Public companies file audited annual numbers in their 10-K and unaudited quarterly figures in their 10-Q, and those same documents include the risk factors management is legally required to disclose — often the most revealing page in the filing. Pull three or four years so you're reading a trend, not a snapshot. The financial module charts the multi-year figures and links every source filing.
3. Verify the intellectual property
If what you're evaluating is a technology or a brand, confirm the company actually owns it. Patents and trademarks are searchable free at the USPTO, and the quiet deal-killer is chain of title — an assignment that was never recorded, or a registered owner whose name doesn't match the seller. The full set of traps is in our IP due diligence checklist.
4. Check litigation and restricted-party lists
Search U.S. federal dockets for suits, judgments and bankruptcies — the free RECAP archive at CourtListener mirrors much of PACER, and each case's "nature of suit" code tells you at a glance whether it's routine. Then screen the company and its principals against government watchlists: OFAC's sanctions lists, Commerce's export lists, State's debarments. In regulated industries this step isn't optional, and the rules can bite even for accidental violations — our sanctions screening guide explains what each list means.
5. Scan adverse media
Some of the most important facts — an investigation, a fine, a founder's lawsuit — never appear in an official filing. Adverse-media screening looks for them in the news, bounded by date and tied back to real sources so one blog post doesn't outweigh a Reuters story.
Read the results with a skeptical eye. Match each story to your specific entity rather than a company with a similar name, weigh the credibility of the outlet, and note whether an allegation was ever resolved. A single unverified claim is a lead to run down, not a conclusion.
6. Check security, privacy and data practices
If the company will touch your systems or your customers' data, its security and privacy posture is part of diligence too. Much of this is publicly visible: a published privacy policy, disclosed breach history, and any regulatory action over data handling all tell you how seriously the company treats the obligation.
For a deeper look, ask whether the company holds recognized security certifications and how it documents its controls. Our modules for information security and privacy due diligence frame the questions worth asking before you connect anything or sign a data-processing agreement.
7. Compile the findings into one report
A check is only useful if someone can act on it, so pull the six steps into a single document rather than leaving notes scattered across tabs. Organize it the way you gathered it — entity, financials, IP, litigation, sanctions, adverse media, security — with the source link beside each finding.
Call out what you could not confirm as clearly as what you could. Gaps, stale records and unresolved allegations belong in the write-up, because the reader needs to know the edges of the check as well as its conclusions.
Doing it even faster
If reading filings by hand isn't how you want to spend an afternoon, free AI due diligence does the fetching and drafting for you from these same sources. Either way, remember what a free check is and isn't: public records are only as current as their last update, some sources throttle automated access, and a watchlist match is a lead to confirm, not a verdict. It's a fast, well-sourced first pass that shows you where to dig — and, to be clear, not legal advice. For the definitions behind each step, see what due diligence is.