Home/Platform
The platform

One collection core. Every capability on top of it.

A single pipeline from raw collection to an authorised decision, with provenance written at every stage. Analysts work in one console instead of six tools, and every number can be traced back to the source and the classifier version that produced it.

Cycle
15 minutes
Sources
60+ tiers
Languages
25+
Provenance
Every stage
Platform layers inside the sovereignty boundary

Built for the way analysts actually work

Most intelligence tooling fails for an unglamorous reason. It produces a feed that nobody has time to read, alerts that fire so often the team mutes them, and figures that cannot be defended when a senior stakeholder asks a hard question in front of their leadership. The technology is rarely the problem.

The platform is built around three commitments. Nothing arrives without provenance. Nothing alerts without passing an anti-noise test. Nothing is measured without a stated basis. Those constraints slow the demo down and make the system survivable in production.

Architecture

From raw collection to an authorised decision.

Six stages, each writing a record of what it did, which is what makes the output defensible months later when the decision is being reviewed.

01

Collect

Curated source tiers across wire, national press, broadcast transcripts, social platforms, forums, and the open web, on a fifteen minute cycle with circuit breakers and deduplication.

02

Resolve

Entities, people, organisations, and places resolved to a persistent register, so the same actor is the same record whether written in Arabic, Cyrillic, or Latin script.

03

Classify

Rule-based scoring returns instantly and language models refine it asynchronously. Classification prompts are versioned per client, so your definitions are yours.

04

Correlate

Signals join across layers: a narrative spike against a mobility change, a bill against a lobbying network, an account cluster against a broadcast segment.

05

Alert

Triggers with deduplication, cooldown windows, and source-tier gating. An alert that fires at three in the morning has earned it.

06

Decide

Briefs, evidence packs, and recommended options routed to the desk that owns the file. Actions require a named human authorisation and land in the audit log.

Console

Four operating pictures, one surface.

The working console our operators use. Switch layers to see the same collection layer rendered four ways.

LIVE · SYNC 00:00:00
Layer 01Geolocated narrative severity
Engineering

The parts evaluators ask about

What a technical panel usually wants to see before it will sign off on a platform that carries this kind of authority.

01

Tenant isolation

Every read is filtered and every write is stamped with the owning tenant. Cross-tenant access needs an explicit authorisation check, and the build fails if a new endpoint skips it.

02

Capability permissions

Reading a feed and acting on it are separate permissions drawn from a closed allowlist validated when the server starts. A permission that does not exist cannot be granted by accident.

03

Versioned classification

Prompts and rule sets are versioned per client and stored with the results, so any rescoring is reproducible and a definition change is visible in the record.

04

Anti-noise alerting

Deduplication, cooldown windows, and source-tier gating on every trigger, tuned during the operate phase against your own escalation history.

05

Entity register

People, organisations, and places resolved to persistent records with aliases collapsed across scripts and transliterations.

06

Audit trail

Who queried what, which classifier scored it, who approved an action, and when. Exportable for internal, board, or regulatory review.

07

Circuit breakers

A degraded source is isolated rather than allowed to poison a series, and the degradation is recorded so the gap is visible in the data.

08

Deployment tooling

Infrastructure as code, reproducible builds, and a migration path that runs the same way in an air-gapped environment as in a connected one.

Deployment

Three ways to hold it.

The architecture is identical across all three. What changes is where the data sits and who holds the keys.

Fastest to value

Managed enclave

We operate the platform in a dedicated tenancy in a region you nominate, with your encryption keys and your retention policy. Suited to institutions that want capability this quarter without a procurement cycle for hardware.

Stand-up
Two to four weeks
Key custody
Client-held
Operators
Our team, your direction
Most common

Your cloud

The full stack runs inside your nominated cloud region or own data centre. We deploy, integrate with your identity provider, and run alongside your staff through the first two operating cycles before stepping back.

Stand-up
Six to twelve weeks
Key custody
Client-held, in jurisdiction
Operators
Joint, then yours
Highest assurance

Air-gapped

No outbound connectivity. Models, indices, and source corpora are shipped and updated through a controlled diode. Built for defence and intelligence customers whose accreditation does not permit anything else.

Stand-up
Twelve to twenty weeks
Key custody
Client-held, offline
Operators
Cleared client staff
Questions

Platform questions

The ones a technical evaluation panel raises first.

What sources does the platform collect?

Wire services, national and regional press, broadcast transcripts, the major social platforms, forums, and the open web, organised into credibility tiers. Source lists are built with your desks during setup, because the sources that matter in one country are noise in another.

Can it ingest our own data?

Yes. Internal reporting, call centre records, survey series, and statistical office outputs can be joined to the open-source picture, and they usually improve it substantially. Internal data stays inside your boundary and is never used to train anything outside it.

How does it handle a source going down?

A circuit breaker isolates the failing source, the gap is recorded, and any series depending on it is marked rather than silently interpolated. A quiet gap that looks like a real decline is one of the more expensive failure modes in this field.

What does integration with our identity provider involve?

The platform authenticates against your existing identity provider over standard protocols, and permissions map to groups your administrators already manage. No parallel user directory is created.

Contact

Ask for the technical session, not the sales deck.

We will walk your engineers through the architecture, the failure modes, and the parts that are still hard.