Compliance and open data in the defence sector

Compliance and open data in the defence sector: Tools for defence business resilience and risk mitigation

YouControl analysts explain how open-data-based tools can help prevent a wide range of risks

Text size

A
Small
A
Medium
A
Large
10 min
Обкладинка: YouControl

The rapid growth of the defence sector is being accompanied by radical and often inconsistent changes in government policy regarding open data, analysts from the YouControl platform write in a column for Defender Media. In their view, Ukraine has now developed a somewhat chaotic and decentralised system of information concealment that poses more risks than it provides real protection. The sudden disappearance of data from open registries effectively “highlights” defence companies for the enemy.

This is not the only compliance and security challenge facing Ukraine’s defence sector. Using real cases, YouControl analysts demonstrate how open-data-based tools can help prevent financial and reputational risks, information leaks, and exposure of sensitive data to hostile actors.

Today, Ukraine’s defence-industrial complex is demonstrating a pace of development that has drawn the attention of global analysts and investors. Research by KSE Institute, conducted in cooperation with Brave1 and Defence Builder, shows that Ukraine’s defence tech market reached approximately $6.8 billion in 2025. The most notable growth came in high-tech segments: UAV production (+137%), ground robotic systems (+488%), and EW systems (+215%).

The rapid progress of the defence sector has made transparency of ownership structures among manufacturers a critical issue. Professional compliance is becoming an essential operational standard, with the reputational “cleanliness” of partners becoming as strategic an asset as the technologies themselves. The expansion of the ecosystem through new contracts and investments creates additional channels for hidden hostile influence or technology leaks, requiring businesses to move beyond intuitive trust toward deep verification of every link in the supply chain.

At the same time, Cabinet of Ministers Resolution No. 1257, adopted in 2025, which allows defence companies to restrict access to their data, has created additional barriers for KYC/AML procedures and the attraction of international capital.

To scale the sector and establish joint ventures with Western partners, a hybrid compliance model is required in which automated OSINT analytics ensures UBO verification and sanctions resilience despite restricted access to state registries.

The transparency paradox: data closure as an additional compliance and security challenge

The rapid expansion of the defence sector is being accompanied by radical but often inconsistent changes in state open data policy. Ukraine has now developed a somewhat chaotic and decentralised information concealment system — one that creates more risks than actual protection.

At the level of individual business initiatives, selective depublication is taking place. Under Cabinet of Ministers Resolution No. 1257 dated 3 October 2025, defence companies were granted the right to independently choose which electronic information resources should restrict access to their data. More than 250 companies have already used this mechanism by sending official requests to the Ministry of Defence to temporarily limit access to information in their YouControl profiles. At the same time, YouControl analysts found that information about these companies remains publicly accessible through a number of other resources. Such an approach appears inconsistent and dangerous.

At the level of systemic legislative “blackouts” of registries, the situation is becoming more complicated due to the following processes:

  • The Unified State Register of Legal Entities, Individual Entrepreneurs and Public Organisations remains only partially open. Under Law No. 4576-IX, defence companies are entitled to register contact addresses instead of actual locations.
  • Since 18 November 2025, the State Register of Property Rights, under Law No. 4576-IX, has restricted access to cadastral numbers related to property rights and encumbrances, as well as property addresses down to the settlement level. According to information published on the official website of the National Information Systems state enterprise, an exception is made only for banks, which receive access under service agreements with the technical administrator. This creates an information gap: banks can see the data, while investors and partners are left with “blank spots”.

Despite intentions to protect the defence-industrial complex, such fragmented and inconsistent depublication creates a “beacon effect”: Russian intelligence can identify priority targets by comparing archived and current databases. The sudden disappearance of a company from YouControl, while its data remains visible in less popular registries or archived versions of the state register, becomes a direct marker of strategic importance.

In addition to security risks, data closure creates several operational challenges:

  • Property opacity and raiding risks. Restricted access to the State Register of Property Rights (since 18 November 2025), where property addresses are hidden at the administrative-unit level, makes it impossible to verify a counterparty’s assets, increasing corruption risks and the threat of covert property seizures.
  • Financing barriers. For international investors, the “invisibility” of a company makes KYC (Know Your Customer) and AML (Anti-Money Laundering) procedures impossible or significantly more difficult, resulting in refusals to cooperate and blocked currency transactions.
  • Loss of budget oversight. The absence of public information eliminates journalistic and public oversight over the use of state funds in the sector.

Restrictions on access to public registries in Ukraine do not eliminate the need for deep compliance — on the contrary, they transform it into a complex analytical challenge. In an environment of closed or “masked” data, standard due diligence becomes impossible, requiring the use of professional OSINT tools. Only solutions capable of working with historical archives, indirect links and international databases can verify partners in a “semi-closed” information environment where direct evidence may be hidden.

Strategic сompliance: From OSINT шntelligence to systemic automation

In the context of hybrid warfare, traditional auditing is no longer sufficient: identifying hidden affiliations concealed within “matryoshka-style” structures has become a priority. Deep verification of ultimate beneficial owners (UBOs) creates three key safeguards: financial hygiene (blocking aggressor-linked money flows), technological resilience (protecting developments from leaks), and global compliance necessary for cooperation with Western partners.

In the professional compliance environment, partner reliability is never determined by a single indicator — it is always the result of intersecting legal, financial, sanctions and reputational data.

Key areas of OSINT analysis using YouControl solutions

Initial screening and sanctions control through automated checks across more than 600 due diligence factors on the YouControl platform. The system provides continuous monitoring of international sanctions, PEP (Politically Exposed Person) statuses and their associates (LIPs). The “Express Analysis” feature instantly identifies more than 10 types of potential links to the aggressor state that may be hidden within complex ownership structures.

Additional tools for checking individuals help companies make informed hiring decisions, which is critically important for defence firms. Through name-based matching, the system aggregates data from state registries that may indicate links, debts, court cases or political exposure. This allows key due diligence factors to be assessed quickly using public data.

Case 2025.4.2.4 (State Financial Monitoring Service Typology Studies): The use of the A7A5 stablecoin and the Garantex exchange to circumvent international sanctions.

As described in the Centre for Information Resilience report from June 2025, A7A5 — a stablecoin backed by the Russian rouble — was created by A7 LLC, which helps Russian businesses affected by Western sanctions conduct cross-border payments.

According to Elliptic, A7 was founded by Ilan Shor, who was convicted in 2017 for crimes linked to the theft of $1 billion from three Moldovan banks in 2014. Another major shareholder in A7, holding a 49% stake, is Promsvyazbank (PSB), a Russian state bank specialising in servicing the country’s defence sector. This is a textbook example of a “matryoshka” structure, where financing from a Russian military bank is concealed behind the name “A7 LLC”.

Screenshot from the YouControl system, “Company Profile” section
Screenshot from the YouControl system, “Ownership Structure”

Strategic supplier selection through YC.Market. The tool is based on verified financial stability and market reputation data, enabling companies to scale supply chains securely and avoid toxic affiliations. Public procurement data and tender histories highlight a company’s real production experience as well as specific risks such as collusion or signs of unfair competition.

Example case: “Searching for a supplier for a defence company”

A hypothetical “Company X”, a UAV manufacturer, is searching for a reliable component supplier. Using YC.Market, potential partners can be identified using filters such as relevant business activity codes, absence of links to Russia or Belarus, Diia.City residency, available contacts, and an “A” rating in Express Analysis, meaning no notable risk signals. The system then generates a list of potential partners along with additional data for decision-making.

Screenshot from the YC.Market system, “Market Analysis”

International mapping and beneficiary de-anonymisation through YC World and AI-based extraction tools enable the visualisation of global corporate networks. This makes it possible to uncover “corporate masks” and identify real UBOs from more than 3,000 international corporate groups, even when they are registered in high-confidentiality jurisdictions.

Case: Transit of High Priority Items to Russia

In a recent joint investigation, journalists from Trap Aggressor together with Polish outlet Frontstory uncovered a scheme involving the shipment of products from the Polish factory FAMOT Pleszew to Russia through Turkish intermediaries. The products involved high-precision machine tools (HS codes 8458.11 and 8457.10), classified internationally as High Priority Items. Such equipment is critical to the production of missile systems and UAV components.

Screenshot from the YC World system, “Connection Graph”

Despite the manufacturer’s impeccable reputation within the EU, equipment from FAMOT/DMG MORI worth at least $1.2 million had been delivered to Russia by 30 November 2024. This case demonstrates that traditional auditing focused only on direct counterparties is incapable of identifying complex transit chains. For the defence sector, this means cross-border analysis capable of tracking dual-use goods through intermediaries in third countries is now essential to prevent technological support for the aggressor.

Behavioural auditing and reputational resilience

Behavioural auditing through court records allows companies to reconstruct counterparties’ business histories based on approximately 100 million documents. The system provides access to “archival traces” — court rulings involving corruption disputes or criminal proceedings that may have been deleted from official registries but remain preserved in the database as evidence of a company’s real background.

At the same time, media monitoring helps identify reputational signals such as scandals or investigative reports before they evolve into lawsuits. ESG compliance assessments are also becoming mandatory. ESG has become a marker of sustainable development and effectively a “ticket of entry” for cooperation with Western defence companies and international investors.

Particular attention must also be paid to the dynamic nature of the sanctions landscape. Since assets are often transferred to affiliated individuals immediately after sanctions are imposed, analysing only current sanctions lists creates a false sense of security. Only the combination of historical ownership-change data and оперативе analytics allows the identification of attempts to urgently replace owners and guarantees full compliance.

Ultimately, any analytical architecture requires qualified management. To address this, YouControl has implemented a specialised support programme already covering more than 100 defence enterprises and military structures. Through training, defence-sector specialists learn OSINT intelligence methods, enabling companies to establish their own in-house risk-management competence centres under wartime conditions.

Data transparency as a strategic asset for the defence sector

For Ukraine’s defence technology market, currently undergoing rapid capitalisation and integration into global supply chains, professional compliance has ceased to be merely a legal formality. Under current conditions, it has become a critical element of business survival and scaling.

Through systematic open-data-based analysis, three fundamental objectives can be achieved:

  • Protection of production cycles from hostile capital infiltration, hidden aggressor influence and industrial espionage.
  • Trust from international partners and funds, for whom transparent ownership structures and clean reputations are baseline requirements for providing technology or capital.
  • Compliance with high security standards, opening access to state preferences and special regimes such as Defence City.

Transparency in the defence-industrial sector does not mean exposing sensitive data — it means creating a verified ecosystem where every counterparty is checked and every risk identified in advance. OSINT analysis tools are becoming the “digital armour” that allows Ukrainian defence tech not only to expand production capacity, but also to remain resilient against hybrid threats over the long term.