Find the campaign behind the conversation.
Accounts that register together, post together, and fall silent together are not a coincidence. We map the network, score authenticity at the account level, and hand you evidence that holds up when it is challenged.
- Analysis unit
- Account, not mention
- Media
- Video, voice, image
- Output
- Evidence pack
- Review
- Legal and press ready
Coordination leaves a signature
Manufactured consensus is a logistics problem for whoever runs it, and logistics leave traces. Accounts get created in batches. Posting schedules cluster in a way organic behaviour does not. Phrasing repeats with small mutations. Follower graphs overlap far past chance.
We look for those signatures together rather than one at a time, because any single indicator produces false positives. A registration burst alone might be a marketing agency onboarding staff. A registration burst plus near-identical bios plus synchronised first posts plus a shared amplification target is a network.
The unit of analysis is the account rather than the mention. That distinction decides what you can say afterwards. Mention-level analysis tells you a narrative is loud. Account-level analysis tells you whether four thousand people believe something or forty accounts said it a hundred times each.
Attribution, stated honestly
Attribution is where this field earns or loses its credibility. We grade every finding on a stated confidence scale and we publish the reasoning behind the grade, including the indicators that argue against our own conclusion.
Technical indicators such as infrastructure overlap, timing, and language artefacts support an assessment. They rarely prove a state sponsor on their own, and we will say so in the brief rather than letting a headline imply more than the evidence carries. Overclaiming attribution once costs a government more credibility than the original campaign did.
Synthetic media
Cloned voice in a leaked call, a fabricated video of a minister, an image of an event that never happened.
Detection runs on the media file and on its distribution pattern together, because a fabricated clip usually arrives through a path that looks nothing like organic sharing. You get the detection result, the artefacts behind it, and the propagation history.
Inside an evidence pack
The parts of this capability a technical evaluator will want to interrogate before a procurement decision.
Narrative timeline
First appearance, the accounts that carried it into each community, and the moment it crossed into mainstream media.
Account dossiers
Registration data, behavioural fingerprints, network position, and authenticity scoring for every account named.
Reach assessment
Genuine exposure separated from inflated engagement, so response is proportionate to actual spread.
Confidence statement
What we assess, at what confidence, on what basis, and what would change the assessment.
Asked in most evaluations
Answers we would give in the room, written down so you can circulate them without a meeting.
Can you attribute a campaign to a specific state?
Sometimes, at a stated confidence level, and never on technical indicators alone. We present what the evidence supports and mark the boundary where inference begins. A government that overclaims attribution once spends years paying for it.
Do you monitor the domestic population?
We monitor public content against a scope you define in the contract, and we build detection and measurement capability rather than covert operations. Where a jurisdiction restricts collection on its own citizens, that restriction is configured in the system and enforced in code.
How fast is detection?
Collection runs on a fifteen minute cycle and coordination scoring runs continuously against it. A network of any size usually surfaces within hours of becoming active. The limiting factor is almost always the volume of collection you licence, not the analysis.
What happens after a network is identified?
You get the evidence pack and the options. Publication, platform referral, diplomatic action, or nothing at all are all legitimate choices, and the right one depends on your context. We do not run response operations on a client's behalf.
Adjacent capability
Each capability runs on the same collection and classification core, so evidence gathered for one is available to the others.
Sentiment and buzz measurement
We separate what gets collected from what gets measured. A monitor names a query, a subject, and the ideas you want test...
Open-source intelligence
Collection across press, broadcast, social, forums, registries, imagery, maritime and aviation data, fused against a per...
Legislative intelligence
We track bills, committee movement, and rapporteur language across the jurisdictions that matter to you, score each item...
Bring us the question your last briefing could not answer.
Tell us the jurisdiction and the mandate. We will tell you within a week whether we are the right people for it.