One investigative pipeline, from identifier to evidence package.
An investigation can start from a name, company number, email, phone, username, domain, IP, certificate, wallet, identity document or asset identifier. From there the platform verifies, collects, extracts, resolves, graphs, scores and keeps watching.
KYC and identity verification
Verification
- Identity-document acquisition and authenticity checks
- OCR and field extraction from documents
- Consistency checks against submitted information
- Biometric and liveness verification via licensed providers
- Address, telephone and email verification
Screening and lifecycle
- Sanctions, PEP and watchlist screening
- Adverse-media screening
- Aliases and alternative spellings
- Duplicate-account and synthetic-identity detection
- Source-of-funds support, refresh and expiry management
INFRA integrates licensed providers for document authentication, biometrics and authoritative sanctions data rather than reproducing every regulated verification technology internally.
KYB and corporate intelligence
Structure
- Company-registry verification and incorporation history
- Directors, shareholders and authorised representatives
- Ultimate beneficial-owner identification
- Parent, subsidiary and affiliate mapping
- Cross-border structure reconstruction
Signals
- Nominee directors and shared addresses
- Shell-company indicators
- Insolvency, liquidation and litigation signals
- Procurement, grant and public-contract records
- Regulatory licences and enforcement actions
Real business, or an individual behind a company name?
A registered company is not proof of a business. This check separates a genuine operating company from a shell, a dormant vehicle or a single individual trading behind a corporate name — and states which one it is, with the evidence for it.
Existence & activity
- Registry status, incorporation age and filing history
- Filed accounts, turnover and audit trail — or their absence
- VAT, tax and social-security registration
- Declared employees and payroll footprint
- Licences and permits required for the stated activity
Physical & operational footprint
- Registered address: real premises, virtual office or mass-registration hub
- How many other companies share the same address, agent or telephone number
- Website and domain age, hosting, reused or cloned content, stock imagery
- Trading traces: reviews, listings, job adverts, deliveries, customers, media
- Bank, invoicing and counterparty patterns consistent with the claimed volume
Who is actually behind it
- Directors and shareholders resolved to real, verified individuals
- Nominee, proxy and formation-agent indicators
- One-person control: sole director, sole signatory, personal contact details
- Prior struck-off, insolvent or phoenix companies of the same people
- Whether the individual — not the entity — carries the risk that matters
Substance, staff, filings and trading history all corroborate.
Genuine activity, but effectively one individual — treat as such.
Registered, no evidence of activity yet. Not yet verifiable.
Corporate form without substance. Escalate before onboarding.
Where the answer is “an individual”, the file switches to individual KYC — identity, screening and source of funds on the person — rather than continuing to assess a company that only exists on paper.
Dark web and leak investigations
Controlled collection across underground sources, run lawfully and without participation: nothing is bought, no access is brokered and no criminal service is engaged.
What is searched
- Ransomware and extortion leak sites, including countdown listings
- Criminal forums, marketplaces and access-broker adverts
- Paste sites, breach dumps and credential combolists
- Closed messaging channels and fraud-as-a-service offerings
- Stolen document, identity and card-data listings
What it establishes
- Exposure of a company, brand, domain or its people
- Compromised credentials, mailboxes and remote-access paths
- Identity data offered for sale, indicating impersonation or synthetic identity risk
- Fraud infrastructure and reuse across previous schemes
- Early warning of a supplier or counterparty about to be disrupted
Underground claims are intelligence leads, never accepted facts. Source reliability is assessed, each claim is cross-referenced against independent evidence, and provenance is preserved so a finding can be reviewed or withdrawn.
Sources and provenance
Official record
- Public and government registers
- Beneficial-ownership registers
- Court and insolvency records
- Procurement and grant databases
Open web
- News and specialist media
- Public social and professional profiles
- Websites and archived pages
- Domain, DNS, certificate and infrastructure data
Restricted & internal
- Dark web forums, markets and paste sites
- Public leak and breach indicators
- Blockchain transaction data
- Internal customer, fraud and transaction data
Every record keeps its original source, collection time, relevant excerpt, content hash and retrieval method — so findings stay traceable, reproducible and reviewable.
Entity resolution and graph
Resolved on
- Names and transliterations
- Dates of birth, addresses, telephone numbers
- Emails, usernames and company positions
- Shared infrastructure, documents and photographs
- Cryptocurrency transactions, temporal and geographic consistency
Every match is graded
- Confirmed match
- Probable match
- Possible association
- Contradictory evidence
- Unverified allegation
Multi-agent investigation
Orchestration agent plans the investigation
Collection agents search source categories
Registry agents retrieve corporate information
Dark web agents monitor underground sources
Blockchain agents trace wallets and transactions
Cyber-intelligence agents analyse domains and infrastructure
Entity-resolution agents correlate identities
Verification agents challenge unsupported conclusions
Reporting agents generate structured findings
Machine-generated statements require source attribution and a confidence score, and stay visibly separated from observed fact.
Architecture and deployment
Connectors, crawlers, APIs, licensed feeds and controlled dark web collectors.
Common schemas, language processing, deduplication, timestamps, content hashes.
Entity resolution, knowledge graph, timelines and relationship analysis.
Multi-agent orchestration, policy rules, anomaly detection, explainable scoring.
Investigator workspace, KYC portal, monitoring dashboards, reports and APIs.