This work joins two disciplines that have never been joined
Set out that way the gap is narrow and specific. External discovery ends at the operator. Ownership resolution begins at a company name. Between them sits the step almost nobody takes: carrying an observed host through to the company behind the operator, and on to its owners and the law that governs what it does with your data.
Observing an application rather than trusting its vendor list is the founding premise of an entire category of tooling, and has been for years. The contribution here is what happens after the observation, and even that is borrowed rather than invented: the same know-your-customer and beneficial ownership tradecraft that regulated firms run every day, applied to a starting point that discipline has never used.
Ownership and jurisdiction answer a specific set of questions. How concentrated a dependency really is, once separate names collapse into common owners. Whether a provider sits under a legal regime that changes what your data is exposed to. Whether any party in the chain carries sanctions or control exposure you would not knowingly have accepted. They are not a prediction of whether a provider will be breached, and a method that claimed otherwise would deserve the skepticism such claims usually attract.