When you are investigating a suspicious seller name, a recycled brand string, or a domain that only shows up in secondary reporting, the first job is identity: which legal entities exist, who is listed as legal representative, which websites and registries attach to the name, and what you can independently confirm. Legal dossier is built for that workflow. You enter a website, ads ID, company/seller name, or registry ID; DecryptAds assembles entities, people, domains, and connection edges from public registers and research, then lists the sources so you can open the primary material yourself.
Recently an article from Brian Krebs, Read This Before You Buy That TV Streaming Stick, raised some questions about a suspicious Chinese company. We took that example company to showcase our new tool.
Walkthrough video
The video below uses the company-name query Zhejiang Fengwo IoT Technology Ltd — the same path you would take when a report or sellers scrape only gives you an English brand string and no tax ID yet. A first run usually takes 2–3 minutes (registries + research); keep the tab open until the dossier finishes. While it works you see a step-by-step progress screen:
What you see in this example
From the company name alone, the dossier treats the input as a
company_name lookup and resolves a primary operating site,
fwgcloud.com, via ICP and registry research. On the results page you can work
through several panels investigators actually use:
-
Legal entities — bilingual mainland names with Unified Social Credit Codes
(e.g. IoT operating company
91330106MA2H16649G, holding company91330102MABY1MHG2H), registered addresses in Hangzhou, and a same-brand Hong Kong company number when the research pass surfaces one. Confidence and notes call out which hits are high-confidence operating entities versus candidate / same-brand shells. - People — legal representative / chairman roles (e.g. 徐恩德 / Xu Ende on both the IoT and holding companies), plus inventors from CNIPA patents assigned to the IoT entity. Roles cite whether they come from a registry filing or a public event / about page.
-
Domains & contacts — primary and related
fwgcloud.comhosts, ICP filing references, and contact strings found in aggregators or WHOIS/RDAP context. - Connections / identity graph — shared officers between holding and operating companies, people linked to addresses, and other multipartite edges so you can see how the dossier stitches entities without treating every edge as proven ownership.
- Summary & investigation notes — a short narrative of what resolved, what was rejected as a weak name collision, and where aggregator addresses or legal-rep listings disagree so you know what still needs primary confirmation.
In this particular run the DecryptAds sellers.json / ads.txt pivots were empty at start (name-only query), so identity comes from registries, ICP, patents, and cited research — which is exactly when source links matter most.
Sources: confirm before you rely on it
Every dossier includes a Sources list with titles and URLs. For the Fengwo example that means you can jump straight to material such as:
- The company site and ICP history for
fwgcloud.com - Chinese company cards that publish USCC, legal representative, and address
- CNIPA / Google Patents assignee pages for the IoT company
- Hong Kong company registry mirrors when a same-brand HK entity appears
- Independent research write-ups that motivated the lookup (open those and re-check claims)
Use the dossier as an investigation map, not a verdict. Automated correlation across open sources can be incomplete, stale, or wrong — especially on officer titles, address history, and third-party attribution. Open the linked sources, prefer primary registries over aggregators when they conflict, and document what you verified. Corrections: corrections@decryptads.com.
Other query shapes
The same tool accepts:
- Website / hostname
- Ads ID —
pub-…orsystem,seller_id - Company / seller name — as in the video
- Registry / tax / LEI ID — when you already have a USCC, VAT, CIK, UEI, LEI, etc.
When the corpus already knows the seller, you also get ad-supply crosswalk rows (sellers.json / ads.txt / app-ads.txt). When it does not, you still get the legal identity assembly and the source list.
Where to run it
Tools → Legal dossier
(decryptads.com/legal_dossier)
· deep link /legal_dossier/<query>
· API GET /api/analytics/legal_dossier?q=…
· MCP legal_dossier(q, …) (one query at a time)
Access is limited to researcher and enterprise
accounts. Free-tier users see a locked menu entry and receive 403 from the API / MCP.
Pair with analytical features, API, and MCP when you want hostname risk scoring or agent-driven lookups beside the identity dossier.