Court Case / Docket: Data Point Intelligence Guide
Court records are the only open dataset where an adversary is compelled to describe their own conduct under oath. Analysts underuse them badly.
Court records are the only open dataset where an adversary is compelled to describe their own conduct under oath. Analysts underuse them badly.
Understanding the Court Case / Docket as an intelligence artifact
A court case data point is a docketed proceeding identified by court, case number and caption, such as a district civil action or a criminal indictment. The docket is a chronological index of filings: complaints, motions, exhibits, judgments, sanctions and appeals, each carrying a date, an entry number and often the filed document itself. The record binds named parties, their counsel, service addresses and corporate affiliations, and in criminal matters the charging statutes and disposition. It is authoritative, dated and citable in a way that few intelligence sources are.
Formats vary sharply by jurisdiction. United States federal dockets follow a court, year, case-type and sequence pattern; state systems use their own schemes and often lack full-text access. Criminal, civil, bankruptcy and appellate dockets expose different fields, and bankruptcy schedules in particular enumerate assets, creditors and bank accounts. Sealed entries, redactions and terminated-party flags are analytically meaningful gaps rather than noise.
Why it matters
Litigation exposes what no organisation publishes: named beneficial owners, internal correspondence filed as exhibits, breach timelines admitted in pleadings, sanctions histories and asset schedules. Regulatory and criminal filings identify infrastructure, aliases and co-conspirators long before public reporting. A single docket typically yields a dozen new pivots through counsel, registered agents, addresses and companion cases, and a judgment converts an allegation into an adjudicated finding you can cite with confidence.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Named defendants and their aliases, including trading names that link several shell entities back to a single operator.
- Registered agent and service addresses that pivot to corporate registries and to other entities sharing the same address.
- Exhibit sets containing internal correspondence, contracts, wallet addresses or server logs entered into the public record.
- Charging statutes and sentencing documents that establish the scale, dates and jurisdiction of the conduct alleged.
- Counsel of record, whose client list often reveals clusters of related parties across otherwise separate matters.
- Filing cadence and emergency motions marking the point at which an operation was disrupted or assets were frozen.
- Bankruptcy schedules listing creditors, bank accounts, real property and intercompany loans in structured form.
- Settlements and consent orders that define continuing compliance obligations and future breach exposure for a party.
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- CourtListener and RECAP — Free full-text search of millions of United States federal dockets and opinions, with user-contributed PDFs.
- PACER — Authoritative United States federal docket and document access, paid per page but definitive for filings.
- State judiciary case portals — Per-state search covering civil, criminal, family and probate matters absent from federal systems.
- Find Case Law, UK National Archives — Free full-text judgments of the senior courts of England and Wales with stable citations.
- EUR-Lex and CURIA — European Union legislation, sanctions listings and Court of Justice case law including annulment actions.
- SEC EDGAR — Legal proceedings disclosures, litigation releases and enforcement references tied to registered filers.
- DOJ, FTC and regulator press releases — Charging summaries, complaint documents and defendant lists for enforcement actions as they are filed.
- OpenCorporates — Corporate registry data for cross-referencing defendant entities, officers and shared addresses.
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Anchor the identifier — Normalise court, case number and caption and confirm the jurisdiction before collecting, because near-identical numbers exist across districts.
- Pull the full docket — Retrieve every entry with dates and document numbers, explicitly recording sealed or restricted items as known evidentiary gaps.
- Mine the exhibits — Read attachments rather than only the complaint; exhibits carry the addresses, accounts, infrastructure and correspondence worth pivoting on.
- Extract entities — Build a structured list of parties, counsel, agents, addresses and financial identifiers, recording the docket entry where each appeared.
- Find companion matters — Search each extracted name across other courts and regulators for parallel, prior or related proceedings in different jurisdictions.
- Track to disposition — Monitor for judgments, consent orders and appeals, since outcomes change the confidence you may attach to any allegation.
- Cite precisely — Record court, case number, docket entry and page for every assertion so a reader can verify it independently.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Collected by these disciplines
- Legal Intelligence — Law, Litigation, and Regulatory Intelligence
- Criminal Intelligence — Intelligence Supporting Criminal Investigation
- Human Intelligence — Information from People, Ethically Obtained
- Corporate Intelligence — Understanding Companies, Structure, and Control
- Social Media Intelligence — Intelligence from Social Platforms and Networks
- Financial Intelligence — Following Value Through the Financial System
- Geospatial Intelligence — Intelligence Derived from Place
- Identity Intelligence — Resolving and Verifying Who Someone Is
- Accounting Intelligence — Financial Statements and Accounting Analysis
- Threat Actor Intelligence — Tracking Adversary Groups Over Time
Investigated in these domains
- Insider Threat
- Organized Crime
- Human Trafficking
- Gangs & Street Crime
- Counterfeiting & IP Crime
- Art & Antiquities Trafficking
- Forced Labour & Modern Slavery
- Corruption & Governance
Pivots to these data points
- Real Property / Parcel — A land or building record — deeds, title, valuation, and ownership history.
Inside the platform: where Court Case / Docket lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
datapoint.php?dp=dp_court_case— Data point hubdomain.php?d=insider— Insider Threat dashboarddomain.php?d=org— Organized Crime dashboardhuman-trafficking.php— Human Trafficking dashboarddomain.php?d=gangs— Gangs & Street Crime dashboardsearch.php— Advanced search, filter and pivotcorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Enrichment Runner
- Enrichment → Local
- Correlate Infrastructure
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Anchor the identifier is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Mine the exhibits turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Cite precisely feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Court Case / Docket
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Defence analysts use litigation records mainly for supply chain assurance, contractor vetting and adversary financial mapping rather than for tactical questions. A defence contractor's civil docket exposes performance failures, export control violations, subcontractor disputes and sanctions histories that never appear in a capability statement. Criminal indictments and forfeiture actions against procurement networks identify front companies, freight forwarders and shipping routes used to divert controlled goods. Products include supplier risk annexes, counter-proliferation network diagrams and force protection assessments where a local partner is under investigation. Constraints: dockets are open source and unclassified, so mixing them into classified products imposes handling obligations, and allegations in a complaint must never be reported as adjudicated fact.
🕵 National intelligence
National intelligence treats court records as a high-yield open source that answers requirements about ownership, control and intent with documentary authority. Indictments, forfeiture complaints and civil discovery expose corporate structures, correspondence, financial flows and named intermediaries that would otherwise require sensitive collection. Litigation also reveals what another government has already established evidentially, which is useful for corroboration and for calibrating confidence in existing reporting. Handle with discipline: the source is unclassified and citable, so record it as such and resist the tendency to over-classify derived analysis. Dissemination should distinguish pleading, admitted fact, and judicial finding, using standard confidence language so consumers can weight the material correctly.
👮 Law enforcement
For investigators the docket is both a lead source and a chain-of-custody problem. Certified copies from the issuing court are the evidential article; a PDF from an aggregator is a lead. Obtain court-certified or authenticated copies where a filing will be tendered, and note that access to sealed, expunged or juvenile material generally requires a court order regardless of whether a copy has leaked. Dockets support charging decisions by establishing prior conduct, identifying co-conspirators and service addresses, and surfacing companion proceedings in other districts. Cross-border filings usually need mutual legal assistance for authenticated copies. Record court, case number, docket entry and date for every assertion placed before a prosecutor.
🔍 Private investigation and corporate security
Private investigators and corporate security use dockets for pre-transaction due diligence, litigation support, insider risk and asset tracing. Bankruptcy schedules, matrimonial filings and judgment enforcement records are the highest-yield sources of asset detail available without compulsion. A private actor may not obtain sealed records, use pretext to induce a clerk or party to release restricted material, access PACER accounts belonging to others, or pay for data obtained in breach of a protective order. Consumer-reporting law constrains how litigation records may be used for employment, tenancy and credit decisions in several jurisdictions, and non-compliance creates direct liability for the client as well as the investigator.
📰 Journalism and OSINT media
Journalists get authority from court records that no anonymous source provides, but the discipline is reading the underlying document rather than the docket text or a press release. Verify that a judgment has not been vacated or a matter dismissed before publishing an adverse finding, and check for appeals. Distinguish allegation from finding in the wording of every sentence, not only in a caveat at the end. Contempt, reporting restrictions and automatic anonymity for minors and complainants apply in many jurisdictions and survive the fact that a document is technically public. Put findings to the named party for right of reply, and be prepared to explain the public interest in identifying private individuals.
🌍 NGO, humanitarian and human rights
Human rights and anti-corruption organisations use litigation records for accountability documentation, strategic litigation research and asset recovery advocacy. Court files establish patterns of conduct with a level of authority that survives denial campaigns. Victim-centred practice matters: filings routinely name complainants, witnesses and survivors, and republishing those names can expose people to retaliation even where the document is public. Redact by default and seek consent where a survivor is identifiable and contactable. Duty of care extends to staff reading traumatic material. Where a case establishes a finding relevant to a mandate, cite the judgment precisely, since accountability work is attacked first at the level of sourcing.
🎓 University and research
Researchers use docket data for empirical legal studies, corporate accountability research and network analysis of enforcement. Methodology must confront coverage bias directly: federal systems are far better digitised than state and non-Anglophone systems, so any cross-jurisdiction claim inherits that skew. Bulk collection through aggregators may breach terms of use, so document your access route and licence. Ethics review is normally required where identifiable individuals, especially criminal defendants, are analysed at scale. Publish the case identifier list, the extraction code and the coding manual so results are reproducible, and cite by court, case number and docket entry rather than by aggregator URL, which changes.
Playbook: working Court Case / Docket end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Frame the legal question
Decide what the docket is expected to establish: prior conduct, corporate control, asset location, or a network of associates. Each drives a different search strategy and a different evidential threshold. Identify jurisdictions likely to hold relevant proceedings, including where the subject is incorporated, banks, holds property and has traded. Write down what would falsify your hypothesis. A good output is a short collection plan naming the courts, the party names and aliases to be searched, and the date range, so gaps in coverage are visible from the start.
Phase 2 — Normalise identifiers and names
Case numbers are only unique within a court, and near-identical numbers exist across districts, so always record court plus number plus year. Build a name variant list covering transliterations, married and maiden names, trading names, abbreviations and common misspellings, because clerk data entry is inconsistent. For entities, obtain the exact registered name and any former names from the corporate registry first. Stop when adding further variants returns no new dockets. The output is a normalised search key set you can rerun as new proceedings are filed.
Phase 3 — Search across systems
Run the key set against federal, state and appellate systems, bankruptcy courts, regulatory tribunals and foreign judgment databases relevant to the jurisdictions identified. Aggregators are for discovery; the issuing court is for confirmation. Record every system searched and the date, including those that returned nothing, because a documented negative is analytically valuable and prevents repeat work. Where a system has no full-text search, search party name indexes and, if necessary, request a clerk search. Good output is a candidate docket list with a confidence flag on identity matching.
Phase 4 — Confirm identity
Before merging any docket into a subject profile, corroborate with at least two identifiers beyond the name: date of birth, address, corporate registration number, counsel of record, or a co-party already confirmed. Common names produce large volumes of false matches and a single wrong merge contaminates every downstream conclusion. Where identity cannot be confirmed, keep the docket in a separate unresolved file rather than discarding it. Record the corroborating identifiers explicitly so a reviewer can audit the merge decision later.
Phase 5 — Pull the complete docket
Retrieve every entry with date, entry number and document title, not only the headline filings. Note sealed, restricted and stricken entries explicitly as known evidentiary gaps, because a pattern of sealing is itself informative. Download the documents you can access and record which entries were unavailable and why. Where PACER charges apply, budget deliberately: exhibits are usually worth more per page than the complaint. The output is a complete entry index with an availability column, which becomes the audit trail for everything that follows.
Phase 6 — Mine exhibits and attachments
The complaint states a theory; the exhibits contain the evidence. Read attachments for contracts, internal correspondence, bank records, wallet addresses, server logs, shipping documents and organisation charts entered into the public record. Declarations and expert reports often summarise investigative findings that were never published elsewhere. Extract every identifier into a structured list with the docket entry and page reference recorded against it. Stop when you have covered every attachment on the entries relevant to your question rather than every entry in the case.
Phase 7 — Extract and structure entities
Build a normalised table of parties, counsel, registered agents, service addresses, financial accounts, corporate affiliates and asset descriptions, each carrying its docket entry and page citation. Distinguish assertions by a party from findings by the court and from documents produced in discovery, because their evidential weight differs sharply. Resolve corporate parties to registry records to obtain officers and ownership. The output is a structured entity set ready for graph analysis, not a set of highlighted PDFs.
Phase 8 — Find companion and parallel matters
Search every extracted name, address, agent and counsel across other courts, regulators and foreign systems. Counsel of record is an underused pivot, because specialist firms cluster related parties across otherwise separate matters. Look for prior proceedings that pre-date the conduct at issue, parallel regulatory action, and enforcement in other jurisdictions. Bankruptcy and receivership filings frequently consolidate information from many earlier cases. Stop when new searches return only matters you have already indexed.
Phase 9 — Track to disposition
Monitor each matter through judgment, settlement, consent order, dismissal or appeal, because outcome determines the confidence you may attach to any allegation. Set docket alerts where the system supports them. Record vacated judgments and successful appeals prominently, since secondary databases rarely propagate reversals and stale adverse records circulate for years. The output is a disposition field on every case record, updated on a defined cycle rather than only when someone asks.
Phase 10 — Assess reliability and weight
Grade each extracted fact by its source within the file: judicial finding, admitted fact, sworn declaration, party pleading, or unverified exhibit. A settlement without admission of liability is not a finding of wrongdoing and should never be described as one. Note where a court expressly declined to reach an issue. Where filings conflict, present both and say which is better supported. This grading is what separates a defensible product from a summary of one side's litigation position.
Phase 11 — Publish with precise citation
Cite court, case number, docket entry and page for every assertion, and archive the source document with a hash. Use language that matches evidential status: alleged, admitted, found, ordered. Apply data minimisation for private individuals named incidentally, including witnesses, minors and complainants. Where a subject is named adversely, offer right of reply where the product will be published. Record the date of the docket snapshot, because a case that was pending at publication may have resolved by the time a reader checks.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| CourtListener | Open | Free full-text search over millions of United States federal and selected state opinions, dockets and oral arguments. | Primary discovery layer for locating dockets by party name, counsel or text before pulling authoritative copies. |
| RECAP Archive | Open | Crowd-sourced repository of PACER documents contributed by users of the RECAP browser extension. | Free access to filings and exhibits already purchased by others, avoiding duplicate PACER charges. |
| PACER | Registration | Authoritative United States federal docket and document system covering district, bankruptcy and appellate courts. | Definitive retrieval of complete dockets and filings, including entries absent from free mirrors. |
| United States Courts | Open | Official portal for federal judiciary information, court locator, rules and case management guidance. | Confirms court identity, jurisdiction and local rules that govern sealing and access. |
| Find Case Law, The National Archives | Open | Official free repository of judgments and decisions from courts and tribunals of England and Wales. | Authoritative citable judgments for United Kingdom proceedings, with stable neutral citations. |
| EUR-Lex | Open | Official European Union legal database covering legislation, sanctions instruments and case law. | Identifies designations and legal bases referenced in litigation, and links to Court of Justice proceedings. |
| CURIA | Open | Case law database of the Court of Justice of the European Union including annulment actions by designated persons. | Tracks challenges to sanctions listings and the evidence the Council relied on. |
| SEC EDGAR | Open | Filings by registered issuers including legal proceedings disclosures, litigation releases and enforcement actions. | Cross-references corporate defendants to disclosed proceedings, contingencies and regulatory settlements. |
| United States Department of Justice press releases and case documents | Open | Charging announcements, indictment summaries and enforcement action documents by district and division. | Rapid identification of newly filed criminal matters and the defendants and entities named in them. |
| Federal Trade Commission cases and proceedings | Open | Complaints, consent orders and administrative proceedings on consumer protection and competition matters. | Surfaces conduct findings and continuing compliance obligations attached to corporate respondents. |
| OpenCorporates | Open | Aggregated company registry data covering officers, addresses, filings and jurisdictions worldwide. | Resolves corporate defendants and registered agents to officers, affiliates and shared addresses. |
| OCCRP Aleph | Registration | Searchable archive of registries, leaks, court records and investigative documents across many jurisdictions. | Locates foreign proceedings and documents not indexed by national court search systems. |
| OpenSanctions | Open | Consolidated dataset of sanctions listings, politically exposed persons and regulatory watchlists. | Checks whether litigation parties are designated, which changes handling and reporting obligations. |
| World Bank Stolen Asset Recovery guidance | Open | Practitioner guidance on asset recovery, mutual legal assistance and cross-border enforcement. | Frames what a foreign judgment or forfeiture order can practically achieve in another jurisdiction. |
| Federal Judicial Center research resources | Open | Empirical studies, case statistics and reference materials on the United States federal courts. | Supplies baselines for how common a filing type or outcome is, preventing over-reading of one docket. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Court Case / Docket. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- CourtListener and RECAP — Full-text federal docket search with free document copies. Limitation: coverage depends on what users have purchased, so gaps are common in low-profile cases.
- PACER with a managed billing account — Authoritative document retrieval across federal courts. Limitation: per-page charges make broad exploratory pulls expensive and encourage under-collection of exhibits.
- Docket alerting services — Notify on new entries in tracked cases and new filings naming a party. Limitation: coverage outside federal courts is patchy and alerting lags for paper-filed matters.
- Optical character recognition pipelines — Make scanned exhibits and older filings text-searchable. Limitation: quality collapses on poor scans, handwriting and non-Latin scripts, silently losing content.
- Entity extraction and graph tooling — Pulls names, addresses and identifiers from filings into a link chart. Limitation: legal boilerplate generates enormous false-positive entity noise without tuned rules.
- OpenCorporates and registry lookups — Resolve corporate parties to officers, agents and affiliates. Limitation: registry data quality and beneficial ownership disclosure vary enormously by jurisdiction.
- OCCRP Aleph — Cross-jurisdiction document search spanning registries, leaks and court files. Limitation: mixed provenance means documents need independent authentication before citation.
- Document management with hashing — Stores retrieved filings with hashes, retrieval dates and citation metadata. Limitation: useless unless the citation fields are populated at retrieval rather than later.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Enrichment Runner — Walks the indicator set through a chosen provider in time-boxed, cursor-based batches that resume rather than restart.
- Enrichment → Local — Materialises enrichment into the local store so dashboards render from your own database instead of a live third-party call.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Read the exhibits, not the complaint. A pleading is a lawyer's theory drafted to survive a motion to dismiss; the attachments contain the contracts, correspondence and account numbers that actually pivot to new intelligence.
- Counsel of record is the most underused pivot in litigation research. Specialist firms cluster related parties across separate matters, and a shared attorney frequently reveals a relationship no corporate filing discloses.
- A settlement with no admission of liability is not a finding of wrongdoing. Describing it as one is the single most common way litigation-derived products get retracted and sued over.
- Sealing patterns are analytically meaningful. A civil case where the substantive exhibits are sealed while the procedural entries are open usually indicates trade secret or cooperation material worth pursuing through other routes.
- Absence from an aggregator means the aggregator lacks the data, not that the subject has a clean record. State-level, tribunal and non-Anglophone coverage is poor, and negative findings must be scoped to systems actually searched.
- Track dispositions on a schedule rather than on demand. Vacated judgments and successful appeals almost never propagate to secondary databases, and stale adverse records are a liability that compounds quietly.
- Bankruptcy schedules are the closest thing to a compelled asset declaration available in open source. Investigators focused on criminal dockets routinely miss them, and they list accounts, property and intercompany loans in structured form.
- Grade every extracted fact by its position in the file. Judicial finding, admitted fact, sworn declaration and unverified exhibit carry different weight, and collapsing them into a single narrative is how analysts overstate a case.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Court Case / Docket is producing anything, and they are worth baselining before you change process or tooling.
- Proportion of subject profiles where litigation checks were run against a documented list of jurisdictions rather than a single aggregator.
- Rate of identity-merge errors detected in quality assurance review, tracked toward zero as corroboration rules are enforced.
- Median time from a new filing naming a monitored entity to it appearing in an analytical product.
- Share of published assertions carrying court, case number, docket entry and page citation that a reviewer verified independently.
- Number of stale adverse findings corrected through scheduled disposition review, which should fall as monitoring matures.
- New pivots per docket exploited, measuring whether exhibits are being mined or only complaints are being read.
- Percentage of retrieved filings archived with hash and retrieval date, supporting later verification if a document is amended or sealed.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- A complaint is an allegation, not a finding; copying pleading language into intelligence products misrepresents its evidentiary weight.
- Coverage is deeply uneven, so absence of a case from an aggregator usually indicates missing data rather than a clean record.
- Common names produce false matches; corroborate with dates of birth, addresses or counsel before merging identities.
- Sealed, expunged and juvenile records may be legally restricted from use even when a copy has leaked publicly.
- Docket text is written by clerks and is often abbreviated or simply wrong; the underlying document is the authority.
- Dismissals and vacated judgments frequently never propagate to secondary databases, leaving stale adverse records in circulation.
Legal and ethical considerations
Court records are public in most jurisdictions but not unconditionally. Sealed filings, expunged matters, juvenile proceedings and mandated redactions carry restrictions that survive accidental publication. In Europe, republishing identified defendants can engage data-protection and erasure obligations. Cite the docket, distinguish allegation from adjudicated fact, and never present a pending or dismissed matter as proven. Where a subject is named, apply proportionality and publish only what supports the finding rather than the whole file.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Court Case / Docket, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 10 intelligence disciplines, 8 mission domains, 1 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
Can I report what an indictment says as fact?
No. An indictment is an accusation supported by probable cause, not a finding. Report it as what it is: prosecutors allege the following conduct in a named case. The same applies to civil complaints, which are drafted to survive dismissal rather than to state proven facts. What you may report as established are judicial findings, admitted facts, jury verdicts, guilty pleas and the existence and terms of orders. Track the case to disposition, because a substantial share of filed matters are dismissed, settled without admission, or reversed, and the original allegation continues circulating long after it ceased to be accurate.
The docket says sealed. Can I use a copy that leaked?
Usually not, and rarely without advice. Sealing orders bind parties and, in some jurisdictions, anyone with notice of the order; publishing sealed material can amount to contempt regardless of how you obtained it. Expunged and juvenile records carry statutory restrictions that survive leakage entirely. For law enforcement, access generally requires an application to the sealing court. For journalists, there may be a public interest argument, but that is a decision for counsel rather than an analyst. At minimum, record that the entry is sealed as a known gap and pursue the underlying facts through other lawful routes.
How do I stop common-name false matches contaminating a profile?
Require at least two corroborating identifiers before merging any docket into a subject file: date of birth, address, corporate registration number, counsel of record, or a co-party already confirmed. Keep unresolved matches in a separate holding file rather than discarding them, since later evidence often resolves them. Record the corroborating identifiers on the merge so a reviewer can audit the decision. In entity work, obtain the exact registered name and former names from the corporate registry first, because trading names and abbreviations generate most of the noise.
What can I get from a foreign court that I cannot get from an aggregator?
Authenticated copies, complete dockets including entries that were never digitised, and access to files that require a local application. Many civil law jurisdictions do not publish first instance dockets at all, so the aggregator gap is structural rather than incidental. Practical routes are local counsel or an agent making a court file inspection, official gazette and insolvency registers, and for law enforcement mutual legal assistance. Budget time: file inspection in some jurisdictions takes weeks and may require demonstrating a legitimate interest in the proceeding.
Is bulk collection of court records lawful?
Access is usually lawful; bulk automated collection often breaches the terms of the system providing it, and in the European Union the resulting dataset engages data protection law because criminal proceedings data is specially protected. PACER has explicit limits, several state systems prohibit scraping outright, and aggregator licences restrict redistribution. The defensible pattern is to use official bulk data products where they exist, respect published rate limits, document your access route, and hold personal data under a stated lawful basis with a retention period rather than accumulating dockets indefinitely.
How should I handle names of witnesses and victims in filings?
Redact by default. Court files routinely name complainants, minors, witnesses and third parties who have no role in your finding, and republishing those names can expose them to retaliation and, in several jurisdictions, breach automatic anonymity provisions. Publish only what is proportionate to the conclusion you are drawing. Where a survivor is identifiable and contactable and their account is central, seek informed consent. Keep the unredacted material under access control in your evidence store so the underlying citation remains verifiable without the names appearing in the product.
Which filings give the best return on time invested?
Exhibits attached to summary judgment and preliminary injunction motions, because both require parties to put their best documentary evidence on the record. Bankruptcy schedules and statements of financial affairs, which enumerate assets, accounts and creditors under penalty of perjury. Forfeiture complaints, which describe investigative findings in narrative detail. Sworn declarations from investigators and expert reports, which frequently summarise analysis that was never published elsewhere. Sentencing memoranda, which set out scale, dates and roles. The docket text itself is written by clerks and is the least reliable part of the file.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- Rules of civil and criminal procedure in the relevant jurisdiction, which govern what is filed publicly, what is sealed, and how documents are authenticated.
- Rules of evidence on authentication and self-authenticating public records, which determine whether a court copy can be tendered without a custodian witness.
- Mutual legal assistance treaties and letters rogatory, the lawful route for obtaining authenticated foreign court records for evidential use.
- Fair Credit Reporting Act and equivalent consumer reporting regimes, which restrict use of litigation records in employment, tenancy and credit decisions.
- UK GDPR and EU GDPR Article 10, which restrict processing of personal data relating to criminal convictions and offences to defined lawful bases.
- Contempt of court and reporting restriction regimes, including automatic anonymity for minors and complainants in many jurisdictions.
- ICD 203 analytic standards on source characterisation and expression of confidence, applied when litigation material enters intelligence products.
- Open Government and public records legislation, which defines the baseline right of access to judicial records and the exceptions to it.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- CourtListener and the RECAP Archive — Free Law Project. Open database of United States court opinions, dockets and contributed filings.
- Public Access to Court Electronic Records — Administrative Office of the United States Courts. Authoritative federal docket and document access system.
- Find Case Law — The National Archives, United Kingdom. Official free archive of judgments from courts and tribunals of England and Wales.
- EUR-Lex — Publications Office of the European Union. Official database of European Union law, sanctions instruments and case law.
- Court of Justice of the European Union case law database — Court of Justice of the European Union. Judgments and pending proceedings including challenges to sanctions designations.
- EDGAR full-text search — United States Securities and Exchange Commission. Issuer filings including legal proceedings and contingency disclosures.
- OpenCorporates — OpenCorporates. Aggregated corporate registry data used to resolve litigation parties to officers and affiliates.
- Aleph — Organized Crime and Corruption Reporting Project. Cross-jurisdiction archive of registries, court files and investigative documents.
- OpenSanctions — OpenSanctions. Consolidated sanctions, watchlist and politically exposed person dataset.
- Federal Judicial Center — Federal Judicial Center. Research and statistics on federal court caseloads and procedure.
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: links docketed proceedings to entities, addresses and infrastructure so litigation becomes a live intelligence feed. Explore the platform, or browse the rest of the library by following any tag above.