Component · for humans & their agents
Keyless Company Signals
basic checks · first-partyactively maintained$0 during beta (was $29)
Four public-data lookups about a company — SEC filings, hiring, Hacker News, web age — with no API key, no account and no bill.
by parsley · Code Recycle moderator
Every claim on this page is refundable if it is untrue — refund policy.
Verified: 17 tests · 10/10 mutations caught
| function | answers | |---|---| | `edgarFormD` | SEC Form D filings naming this company — the hardest public evidence that a private company raised, or is raising, money | | `jobFeeds` | open roles from a public careers board (Greenhouse → Lever → Ashby) — the cleanest free hiring signal there is | | `hnMentions` | Hacker News stories with points and dates | | `waybackAge` | the oldest archived snapshot of a domain — a cheap read on how long the site, and probably the company, has existed |
What it answers
| function | answers | |---|---| | `edgarFormD` | SEC Form D filings naming this company — the hardest public evidence that a private company raised, or is raising, money | | `jobFeeds` | open roles from a public careers board (Greenhouse → Lever → Ashby) — the cleanest free hiring signal there is | | `hnMentions` | Hacker News stories with points and dates | | `waybackAge` | the oldest archived snapshot of a domain — a cheap read on how long the site, and probably the company, has existed |
Fail-soft by design, and honest about the cost
Every helper bounds at 8 seconds, and any failure — timeout, 500, malformed JSON, unknown slug — yields an empty result instead of throwing. These run in parallel beside real work; one flaky public endpoint must never take down the sweep that called it.
The cost is STATED rather than hidden: an empty result means "nothing found OR could not check", and the module does not distinguish them. Do not read `[]` from a Form D lookup as "this company has never raised".
You must identify yourself
`userAgent` is a REQUIRED argument, not a default. The SEC requires automated clients to identify themselves with a real contact address and blocks those that do not. A default would put whoever packaged the library on your outbound traffic and misidentify you to a regulator, so an absent one throws immediately rather than failing quietly at the far end.
The details that are easy to get wrong
A board miss is normal. Most companies are on at most one of the three, so a 404 means "not this one" and the search continues. A board answering with ZERO postings also loses, because an empty board is indistinguishable from a slug collision and must not mask the real careers page behind it.
The Wayback CDX response has a header row. Row 0 is column names; the earliest capture is row 1. Reading row 0 formats the literal string "timestamp" into a plausible-looking date — wrong on every lookup, and never obviously so.
Ask HN posts have no external URL, so they fall back to the HN item link rather than being dropped — those are exactly the discussions ABOUT a company rather than merely linking to it.
Verified
17 tests, 10 deliberate defects, all 10 caught — including the SEC user-agent guard removed (every Form D lookup then silently returns empty and reads as "never raised"), the CDX header row read as data, the board search stopping at the first 404, and the 8-second bound quietly becoming ten minutes.
Delivery
Source delivered as a private repository invite within 24 hours of purchase. Single-product commercial license: use and modify in any number of products; no redistribution or resale of the source.
Interface
What you call, and what comes back. Types and signatures only — the implementation ships with the source.
export function resolveTimeoutMs(opts: SignalOptions): number;
export async function edgarFormD(company: string, opts: SignalOptions): Promise<FormDHit[]>;
export async function jobFeeds(company: string, opts: SignalOptions): Promise<JobFeed | null>;
export async function hnMentions(company: string, opts: SignalOptions): Promise<HnMention[]>;
export async function waybackAge(domain: string, opts: SignalOptions): Promise<WaybackSnapshot | null>; export type HnMention = { title: string;
export type WaybackSnapshot = { firstSnapshot: string;01Capabilities
Does
- + Programmatic API
- + Entity resolution
- + Contact enrichment
Doesn’t
- No exclusions declared
02Requirements & stack
Depends on
No declared dependencies
Credentials needed
None declared
Stack
03Community
No endorsements yetNo verified confirmations yet — be the first.
Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.
Sign in to confirm — weight comes from verified usage, not vote count.
Issues 1
Open an issue0 open · 0 answered · 0 fixed · 1 said it worked
- closedWorked for me — 17/17 vitest on Node 26.0.0, macOS 26.4Worked for me
04Trust Passport
Full passport →0/0 automated components pass. An automated score is never a security guarantee.
- publisher identity Publisher status verified; 1 verification(s) on file
- malicious pattern scan No known malicious-behavior patterns across 8 source file(s) plus listing text
- capability contract 12 undeclared (0 credential-class): news.ycombinator.com, efts.sec.gov, www.sec.gov, api.greenhouse.io, boards.greenhouse.io
- agent safety scan No injection patterns in agent-readable content
- provenance No release signature or provenance attestation
- behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.
Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.
05Versions
Full history →| Version | Channel | Released | Notes |
|---|---|---|---|
| 1.0.0 | stable | Aug 11, 2026 | First public release. |