Evidence-backed triage,
not a black-box score.

Investigate any indicator — domain, IP, URL, hash, or CVE — with a structured pipeline that traces every finding back to the raw source artifact that produced it.

The Evidence Pipeline
Artifact
Raw API responses fetched concurrently from OSINT sources
Parser
Structured evidence extracted from each raw artifact
Evidence
Typed, normalised facts stored against the investigation
Analyzer
Domain-specific rules applied to evidence bundles
Finding
Labelled claims with severity and confidence score
Score
Weighted sum composited into a final risk score
01 — Traceability
The Evidence Ledger
Every finding is backed by an itemised chain of evidence — Artifact → Parser → Evidence → Analyzer → Finding → Score. The final risk score is never opaque.
02 — Speed
Concurrent Ingestion
Artifacts are fetched in parallel from industry OSINT sources, minimising extraction time without sacrificing coverage.
03 — Extensibility
Analyzer Library
Domain-specific analyzers convert raw evidence into standardised, actionable findings across all target types.