Your environment, your keys, your evidence.

Run {{PRODUCT_NAME}} on Kubernetes or Docker Compose in your own environment, with single sign-on, workspace roles, a full audit trail and credentials in your vault.

Sign-in screen: continue with single sign-on through your identity provider, or use a username and password, under a notice that every action is audited.

Product screen with fictional data

Deployed in your environment, not ours.

{{PRODUCT_NAME}} installs on Kubernetes or Docker Compose and connects to the identity provider, vault, storage and models you already run.

  1. The boundary is yours

    Install with Kubernetes manifests, a Helm chart or Docker Compose, on infrastructure you control.

  2. Your services, by reference

    Point it at your identity provider, secrets vault, database, object storage and model server. Credentials stay where they are.

  3. One governed way out

    Outbound traffic is denied by default. Collection reaches sources only through the egress profiles a workspace allows.

Your environmentKubernetes or Docker Compose

OIDCIdentity providerSingle sign-on for every person
By referenceSecrets vaultSource logins, egress and model keys
REST APIYour toolsAlerts by webhook, every action by API
{{PRODUCT_NAME}}
  • Collection
  • Evidence
  • Analysis
  • Search
  • Alerts
Self-managedStorageRecords, sealed captures, search index
LocalModel serverOr self-hosted, or a provider you choose

Outbound traffic denied by default

Egress profilesChosen per source

  • Tor
  • VPN
  • Proxy
Authorized sourcesForums, closed communities, onion services and leak sites
Diagram: {{PRODUCT_NAME}} runs inside your environment, connected to your own services, and reaches authorized sources only through approved egress.

Access decided by role, per workspace.

People sign in through your identity provider. Each workspace isolates its sources, alerts and evidence, and every member holds one role in it.

  1. Workspaces keep teams apart

    Every request carries its workspace. The API refuses data from any other one, so teams and clients never see each other’s evidence.

    Workspaces screen: the EU financial sector workspace, whose identity section explains that the API refuses data from any other workspace.
  2. Members come from your provider

    Add a person by the subject your identity provider issues, choose a role and give a reason. The change is logged with your name.

    Add member dialog: the subject issued by the identity provider, a role, and a required reason logged to the audit trail.
  3. Four roles, nothing implicit

    Viewers read. Analysts triage, search and export within policy. Operators run collection. Admins change policy and members.

    Member actions menu: change role to viewer, analyst, operator or admin, each with what it allows.
  4. Every change carries a reason

    Changing a role or removing a member asks for a reason and lands in the audit trail. Past actions stay attributed.

    Role change confirmation for a member, from viewer to analyst, with a required reason recorded in the audit trail.
Workspaces screen: the EU financial sector workspace, whose identity section explains that the API refuses data from any other workspace.

Product screen with fictional data

Sign-in that fails safe

Sign-in screen with the notice that the identity provider did not answer and the password was not checked.
Provider not answeringWhen your identity provider does not answer, sign-in stops and says why. The password is not checked anywhere else.
Sign-in screen with the notice of too many sign-in attempts and the wait before the next one.
Too many attemptsRepeated failures make the account wait before the next try, and the form shows how long.
High-impact actions
Deleting evidence, changing retention or retiring a source asks for explicit confirmation, and multi-factor sign-in when your provider reports it.
Kept sessions
Keep me signed in saves the session and username in that browser, never the password.

Product screen with fictional data

Workspace policy screen: allowed sources, exports and classification, retention per data class with legal hold, interaction and AI analysis, evidence access, legal basis and purpose.
Save confirmation for the workspace policy: raw page retention shortened from 90 to 60 days, a warning that older raw pages will be deleted, and the reason for the change.

Product screen with fictional data

Workspace policy on a phone: sources, exports, retention per data class, legal hold, AI analysis and evidence access.

Retention and legal hold, set by you.

Each workspace has its own policy: sources, exports, retention and what AI may do. The API enforces it, and every change is audited.

  1. Only the sources you allow

    Crawls, searches and alerts in a workspace use only the sources its policy lists.

  2. Exports on your terms

    Allow exports, block every export during a legal review, and mark shared output with a Traffic Light Protocol classification.

  3. A limit for every kind of data

    Posts, captures, raw pages, attachments and the audit log each keep their own limit. Legal hold suspends every deletion.

  4. Read-only, with AI labelled

    Source interaction stays off unless you allow it. AI output is always marked as derived, never as evidence.

  5. Who opens the evidence

    Choose who can open captures and raw pages, and record the legal basis and purpose next to them.

  6. Shown before anything is deleted

    Saving asks for a reason and shows the difference. A shorter limit warns what tonight’s sweep will delete.

Save confirmation for the workspace policy: raw page retention shortened from 90 to 60 days, a warning that older raw pages will be deleted, and the reason for the change.

Secrets stay in your vault.

Source logins, egress credentials and model keys live in your secrets vault. {{PRODUCT_NAME}} keeps a reference to each one, never the value.

Anatomy of a secret reference
Path, version and presence only

workspacesws_eu_finWorkspacesourcesbasaltSourceloginCredential

Version
3Rotated in the vault
Reference
Resolves
Value
Never sent to the browser

Where a secret never appears

Rotation
Rotate a value in the vault and the console shows a new version, without revealing either value.
Retirement
Retiring a source revokes the secrets it used.
  • Configuration filesSettings hold the vault path, never the value.
  • Logs and metricsRedaction keeps values out of logs, and metric names and labels never carry them.
  • Data backupsBackups carry reference paths only, never secret material.
  • The browserThe console sees path, version and presence. Stored material is never sent to it.
  • The audit trailEvents record what was done and by whom, never the secret itself.

Recovery you rehearse, not assume.

A backup that has never been restored is not trusted. Restore drills run on a schedule and prove each step below.

Restore drillOn a schedule, outside production
  1. Restore the records

    The system of record returns first, from its latest backup or a point in time.

  2. Verify the evidence

    Every capture is checked against its SHA-256 fingerprint before it counts.

  3. Rebuild search

    Search is rebuilt from the records. It is never restored from a dump.

  4. Resume from checkpoints

    Each source picks up from its last durable checkpoint, not from the start.

  5. Prove no duplicates

    Posts processed again are matched to what exists, never counted twice.

  6. Trace the lineage

    Every post links again to its capture and to the run that collected it.

Scheduled drills
Drills run on a schedule outside production. Starting one by hand asks for confirmation.
Objectives per service
Recovery point and recovery time objectives are set for each service you run.
Rehearsed faults
Worker loss, database restarts and network failures are rehearsed, and checkpoints, evidence and search must stay consistent.

Self-hosted threat intelligence, where your evidence stays.

The short answers to the questions a security review asks first.

Security sheetSelf-hosted deployment
Deployment
Kubernetes or Docker Compose, in your environment
Identity
Single sign-on over OIDC through your provider
Roles
Viewer, analyst, operator and admin, per workspace
Isolation
Workspaces enforced by the API on every request
High-impact actions
Explicit confirmation before they run
Audit
Every decision recorded and attributable, refusals included
Retention
A limit per data class, with legal hold
Recovery
Backups and scheduled restore drills
Secrets
In your vault, referenced by path
Network
Outbound traffic denied by default, egress per source
AI models
Local, self-hosted or a provider you choose
Evidence
Captures sealed with a SHA-256 fingerprint
Integration
Versioned REST API and webhooks

Authorized and observe-only.

{{PRODUCT_NAME}} monitors only sources your organization is authorized to access. It never bypasses access controls, compromises accounts or exploits sites.

Leaked data is never downloaded, and AI output is never treated as evidence.

Read the responsible-use policy

See it on your own sources.

Tell us what you need. We will walk you through a live capture, from post to sealed record.

Request a briefing

Prefer email? Write to {{CONTACT_EMAIL}}.