Platform

One investigative pipeline, from identifier to evidence package.

An investigation can start from a name, company number, email, phone, username, domain, IP, certificate, wallet, identity document or asset identifier. From there the platform verifies, collects, extracts, resolves, graphs, scores and keeps watching.

(a)

KYC and identity verification

Verification

  • Identity-document acquisition and authenticity checks
  • OCR and field extraction from documents
  • Consistency checks against submitted information
  • Biometric and liveness verification via licensed providers
  • Address, telephone and email verification

Screening and lifecycle

  • Sanctions, PEP and watchlist screening
  • Adverse-media screening
  • Aliases and alternative spellings
  • Duplicate-account and synthetic-identity detection
  • Source-of-funds support, refresh and expiry management

INFRA integrates licensed providers for document authentication, biometrics and authoritative sanctions data rather than reproducing every regulated verification technology internally.

(b)

KYB and corporate intelligence

Structure

  • Company-registry verification and incorporation history
  • Directors, shareholders and authorised representatives
  • Ultimate beneficial-owner identification
  • Parent, subsidiary and affiliate mapping
  • Cross-border structure reconstruction

Signals

  • Nominee directors and shared addresses
  • Shell-company indicators
  • Insolvency, liquidation and litigation signals
  • Procurement, grant and public-contract records
  • Regulatory licences and enforcement actions
(c)

Real business, or an individual behind a company name?

A registered company is not proof of a business. This check separates a genuine operating company from a shell, a dormant vehicle or a single individual trading behind a corporate name — and states which one it is, with the evidence for it.

Existence & activity

  • Registry status, incorporation age and filing history
  • Filed accounts, turnover and audit trail — or their absence
  • VAT, tax and social-security registration
  • Declared employees and payroll footprint
  • Licences and permits required for the stated activity

Physical & operational footprint

  • Registered address: real premises, virtual office or mass-registration hub
  • How many other companies share the same address, agent or telephone number
  • Website and domain age, hosting, reused or cloned content, stock imagery
  • Trading traces: reviews, listings, job adverts, deliveries, customers, media
  • Bank, invoicing and counterparty patterns consistent with the claimed volume

Who is actually behind it

  • Directors and shareholders resolved to real, verified individuals
  • Nominee, proxy and formation-agent indicators
  • One-person control: sole director, sole signatory, personal contact details
  • Prior struck-off, insolvent or phoenix companies of the same people
  • Whether the individual — not the entity — carries the risk that matters
Operating business

Substance, staff, filings and trading history all corroborate.

Owner-operated

Genuine activity, but effectively one individual — treat as such.

Dormant / pre-trading

Registered, no evidence of activity yet. Not yet verifiable.

Shell or front

Corporate form without substance. Escalate before onboarding.

Where the answer is “an individual”, the file switches to individual KYC — identity, screening and source of funds on the person — rather than continuing to assess a company that only exists on paper.

(d)

Dark web and leak investigations

Controlled collection across underground sources, run lawfully and without participation: nothing is bought, no access is brokered and no criminal service is engaged.

What is searched

  • Ransomware and extortion leak sites, including countdown listings
  • Criminal forums, marketplaces and access-broker adverts
  • Paste sites, breach dumps and credential combolists
  • Closed messaging channels and fraud-as-a-service offerings
  • Stolen document, identity and card-data listings

What it establishes

  • Exposure of a company, brand, domain or its people
  • Compromised credentials, mailboxes and remote-access paths
  • Identity data offered for sale, indicating impersonation or synthetic identity risk
  • Fraud infrastructure and reuse across previous schemes
  • Early warning of a supplier or counterparty about to be disrupted

Underground claims are intelligence leads, never accepted facts. Source reliability is assessed, each claim is cross-referenced against independent evidence, and provenance is preserved so a finding can be reviewed or withdrawn.

(e)

Sources and provenance

Official record

  • Public and government registers
  • Beneficial-ownership registers
  • Court and insolvency records
  • Procurement and grant databases

Open web

  • News and specialist media
  • Public social and professional profiles
  • Websites and archived pages
  • Domain, DNS, certificate and infrastructure data

Restricted & internal

  • Dark web forums, markets and paste sites
  • Public leak and breach indicators
  • Blockchain transaction data
  • Internal customer, fraud and transaction data

Every record keeps its original source, collection time, relevant excerpt, content hash and retrieval method — so findings stay traceable, reproducible and reviewable.

(f)

Entity resolution and graph

Resolved on

  • Names and transliterations
  • Dates of birth, addresses, telephone numbers
  • Emails, usernames and company positions
  • Shared infrastructure, documents and photographs
  • Cryptocurrency transactions, temporal and geographic consistency

Every match is graded

  • Confirmed match
  • Probable match
  • Possible association
  • Contradictory evidence
  • Unverified allegation
(g)

Multi-agent investigation

Agent 01

Orchestration agent plans the investigation

Agent 02

Collection agents search source categories

Agent 03

Registry agents retrieve corporate information

Agent 04

Dark web agents monitor underground sources

Agent 05

Blockchain agents trace wallets and transactions

Agent 06

Cyber-intelligence agents analyse domains and infrastructure

Agent 07

Entity-resolution agents correlate identities

Agent 08

Verification agents challenge unsupported conclusions

Agent 09

Reporting agents generate structured findings

Machine-generated statements require source attribution and a confidence score, and stay visibly separated from observed fact.

(h)

Architecture and deployment

L1
Data acquisition

Connectors, crawlers, APIs, licensed feeds and controlled dark web collectors.

L2
Normalisation & provenance

Common schemas, language processing, deduplication, timestamps, content hashes.

L3
Entity intelligence

Entity resolution, knowledge graph, timelines and relationship analysis.

L4
AI & risk engine

Multi-agent orchestration, policy rules, anomaly detection, explainable scoring.

L5
Applications & integration

Investigator workspace, KYC portal, monitoring dashboards, reports and APIs.

SaaSMulti-tenant · fastest to first check
Private cloudIsolated tenancy · data residency · custom feeds
On-premisesLocal models · no investigative data leaves your estate