
Intelligence you can defend.
Every finding graded to NATO standard, with an honest record of what it could not reach. 115 graded collectors, 63 live modules, one platform.
What do you need to find out?
Describe the job, or paste a domain, email, company name or wallet.
63
Intelligence modules
115
Graded collectors
A–F
Source grading
24/7
Autonomous watch
The difference
Everyone shows you a confidence score.
Ask where the number came from.
Blackout grades every finding to NATO STANAG 2511 and ICD 203 — the standards real intelligence services are held to. Source reliability A–F. Information credibility 1–6. Graded independently, because they are independent.
Every other platform
94%
confident
- Confident based on which source?
- Corroborated, or a single reading?
- What did they fail to reach?
Blackout
OFAC sanctions screening — DESIGNATED
This address is designated: YAN, Xiaobing
- Programme
- SDNTK
- Source grade
- A · Completely reliable
- Credibility
- 1 · Confirmed by other sources
Almost certain (96–100%), with high confidence in the sourcing — Admiralty A1.
Two sources didn't answer — and we tell you which. “Six of twelve refused” is a different finding from “nothing found”.
Worked example of the output format. Not a real subject, and not a case we have worked.
Nobody else asks this
What should be here — and isn't?
Real identities accrete. They are old, uneven and messy — abandoned accounts, a breach from 2013, archived pages nobody meant to keep.
Constructed ones are manufactured in a window. Recent. Uniform. Tidy. Conspicuously free of a decade's debris.
Legend Analysis reads the gaps, not just the hits — and shows the evidence for authenticity alongside the doubts.
Legend analysis
Strong constructed-identity indicators
Worked example of the output format — not a real subject.
No history predating the last 12 months
Oldest verifiable record is 40 days old
Origin dates tightly clustered
4 records all originate within 6 days of each other
Same handle claimed across 11 platforms
Uniformity at scale suggests a single reservation pass
Graded Admiralty D — an indicator, never a conclusion. A new business is legitimately new, and the panel says so.
The register
115 collectors. Every one graded.
Not a logo wall. Grade A is reserved for the body that issues the fact — being excellent isn't enough. Every grade carries a written rationale you're invited to challenge.
Issuing authority
OFAC · Companies House · SEC · RDAP · GLEIF
Direct records
DNS · Certificate Transparency · Wikidata · on-chain
Scanning & aggregation
Shodan · breach corpora · Wayback · blocklists
Derived & inferred
Behavioural profiling · lookalike generation
Verifiable evidence
Don’t take our word for it. Check it.
Every report this platform produces carries a cryptographic seal over its findings. The person who needs to trust it — a bank, a regulator, the other side of a dispute — can verify it here with no account, no key and no contact with us.
Below is a real seal, issued by the same code that seals a customer’s findings. Verify it, then alter a value and verify again.
A seal proves a document has not changed since it was issued. It does not, and cannot, prove the findings are correct — that is what the source grading is for.
No account, no card
Don't take our word for it. Run one.
Type any domain. This is the real collector, hitting live sources right now — the same one behind the paid tiers, not a recording.
Domains only in the public preview — no personal data, deliberately. Username, email, company and image lookups need a free account.
Live now · free tier
The world, as the platform is seeing it
Not a screenshot and not a recording. This is the Live Operations module — one of the three that cost nothing — collecting from USGS, NASA EONET and OpenSky while you read.
—
Events tracked
—
Aircraft in the air

This board is free forever. A free account adds the filters, the full event history and the other two free modules.
Open the full boardThe platform
Engineered like an intelligence agency, priced for everyone.
Secure by design
Server-verified subscriptions, an AES-256 encrypted key vault and row-level data isolation. Access is never gated by client JavaScript.
Your queries stay yours
We do not sell, share or resell what you look up. Provider keys are yours, held encrypted, and billed to you — never pooled across customers.
Defensible by default
Every finding carries its source grade, its credibility rating and the record of which collectors answered. Export it and the reasoning travels with it.
Workflow
From a single clue to the full picture — in seconds.
No manual transforms, no stitching four tools together. Blackout does the pivoting for you.
Drop in any selector
A domain, email, username or IP — even a partial lead. One field, one click, no setup.
Auto-pivot & fuse
Blackout crawls dozens of live sources and automatically links every related identity, asset and exposure.
Get a scored dossier
A threat-scored profile, relationship graph and an agency-grade PDF — ready to action or share.
Everything it does
The whole platform, in one page.
69 capabilities in 6 groups, 66 of them live today and 3 marked beta or coming. Not a shortlist — this is all of it, laid out the way the product is.
Command & workspace
Run operations, cases and briefings — and everything you produce.
Operation Theatre
Watch an autonomous investigation unfold live — Blackout resolves the identity, expands the network into a constellation, geolocates the infrastructure and scores the threat in real time, then hands you a briefing.
War Room
The live operational command centre — a cinematic global theatre fusing your watchlist threat board, DEFCON posture, recurring entities, live intelligence feed and worldwide operations into one screen.
Priority Requirements
Declare the standing questions that matter to you — geography, keywords and thresholds — and Blackout scores the live world against them continuously, surfacing answers without you going looking.
Blackout Bridgebeta
Connect smart glasses and other Bluetooth hardware directly to Blackout — full service discovery, live event log, capability scan and exportable diagnostics. Desktop Chrome/Edge and Android.
Auto-Investigate
One-click OSINT — enter any target (domain, email, username, IP) and get a live compiled intelligence brief.
Link Analysis
Visual entity-relationship graphs — connect people, orgs, domains, emails and more, then expand with transforms.
Intelligence Graph
Your persistent knowledge base — every entity from every saved case, deduped and linked into one graph that compounds over time and surfaces shared people & infrastructure.
Bulk Investigate
Investigate many targets at once — each fully assessed, threat-scored, ranked, and exported as one combined report.
Watchlist
Continuous monitoring — put any target under watch and get alerted the moment its exposure shifts: new ports, fresh CVEs, breaches, infrastructure moves.
Profile Builder
Automated identity resolution — enter any selector and Blackout auto-pivots across every source, fuses linked identities into one scored subject dossier with a relationship graph, and exports it.
Auto-Pilot
Autonomous investigation — give one target and Blackout resolves the identity, expands the whole connected network, correlates your cases and writes the assessment, hands-free.
Anomaly Detection
Statistical anomaly detection across your watchlist — surfaces exposure-change surges and active-threat spikes against each target’s own baseline, so emerging escalations find you.
Entity Annotations
Pin persistent, live-updating notes to any entity — domain, IP, email, username or case — building shared analyst context that follows the entity across your workspace.
Executive Briefing
Turn a full technical workup into a board-ready narrative — bottom line, key judgements, risk rating and recommendations, in executive prose (AI-authored when an Anthropic key is connected).
Ask Intelligence
Conversational OSINT — ask a question in plain English; Blackout runs live lookups on any domain/IP/email you mention, cross-references your cases, and answers grounded in real data.
Source Reliability
Grade sources and information on the NATO Admiralty System — attach standardised reliability×credibility ratings to every finding and keep a source register, so confidence travels with your intelligence.
Investigation Playbooks
Named, repeatable investigation workflows — chain Blackout’s modules into one automated run (domain due diligence, entity screening, infrastructure threat assessment) with live step-by-step results.
Email Forensics
SOC-grade phishing triage — paste a raw email and Blackout reconstructs the delivery path, verifies SPF/DKIM/DMARC, flags spoofing and extracts every indicator, locally.
Data Extractor
Paste any blob — breach dumps, email headers, logs, chat exports — and Blackout extracts every email, IP, domain, URL, wallet, phone, CVE, hash and key locally, each one-click investigable.
Case Management
Run investigations as cases — bundle saved reports and evidence, keep a timestamped notes timeline, and track status and priority from open to closed.
Intelligence Briefings
Automated recurring intelligence digests — watchlist changes, new high-threat findings and case activity compiled on a daily or weekly cadence and emailed to you as a branded PDF.
SITREP
Command center — a live operational picture fusing your watchlist alerts, portfolio threat, recurring cross-case entities and global live events into one posture readout.
Live Operations
Real-time global situational awareness — live earthquakes, aircraft, wildfires, storms and volcanoes plotted on one world map, streaming 24/7.
Maps
Geospatial plotting of entities, movements and areas of interest.
Timeline
Reconstruct chronologies across every piece of collected evidence.
Evidence Locker
Chain-of-custody storage for artefacts, screenshots and exports.
Reports
Generate court-ready intelligence reports from any investigation.
Identity & due diligence
People, companies, sanctions and adverse-media screening.
Adverse Media
Negative-news screening for KYC and due diligence — scan global news coverage of any person or company for fraud, corruption, litigation, sanctions and criminal reporting, categorised.
Corporate Intelligence
Global corporate intelligence with no key required — legal entity identity and ownership hierarchy (GLEIF), US SEC registrant and filing history, French national registry records with officers and filed financials, the Irish register with status and accounts filing history, and the Brazilian register by CNPJ with officers and share capital. Connect a free Companies House key for full UK officer, ownership and filing depth.
Counterparty Check
Pre-engagement due enquiry on a party you are about to advise on, contract with or litigate against — ownership, sanctions and adverse media, all three required, with every concern referred to a fee-earner rather than absorbed. Sealed, so the file can be checked by the other side.
Supplier Check
Procurement due diligence in one pass — ownership, sanctions, adverse media and digital footprint, assessed against your policy. Tells you plainly when a required check could not be carried out, and what changed since last time.
Sanctions Screening
KYC / AML due diligence — screen any person or entity against live sanctions and watchlists with fuzzy name matching, scored candidate matches and programme details.
People Intelligence
Resolve identities from names, aliases and partial data across public records.
Face Recognitionbeta
Match faces against indexed sources and cluster appearances over time.
Digital & infrastructure
Domains, certificates, attack surface, vulnerabilities and crypto.
Threat Attribution
Attribute a target’s exposure profile to known threat actors — Blackout maps the attack surface to ATT&CK techniques, then ranks the APT and cybercrime groups whose playbooks overlap.
ATT&CK Mapper
Map a target to the MITRE ATT&CK matrix — Blackout lights up the adversary techniques its real attack surface enables, and exports a Navigator layer for your SOC.
Infrastructure Correlation
Given a set of entities, determine which of them are the same operation. Shared registrars, nameservers, netblocks, mail infrastructure, account-bound verification tokens and registration timing are weighted by how much each actually narrows the field — so commodity providers used by millions never link strangers.
Attack Surface
External attack-surface management — discover every internet-facing asset an organisation exposes (subdomains, hosts, open ports, services, CVEs) and score it into a single exposure grade.
Vulnerability Intelligence
Assess any CVE with live NVD, EPSS and CISA KEV data — CVSS severity, real-world exploit probability, affected products, and whether it is actively exploited in the wild.
DNS Security Posture
Audit a domain’s DNS and email-authentication hardening — SPF, DKIM, DMARC, MTA-STS, DNSSEC and CAA — graded A–F with every record and a fix for each gap.
Certificate Intelligence
Certificate Transparency reconnaissance — enumerate every subdomain and TLS certificate ever issued for a domain, spot freshly-minted and lookalike certs, and map the issuing CAs.
Image Forensics
Drop any photo to expose GPS capture location, camera and lens, timestamps and authenticity signals — read in your browser. Opt into deep analysis for solar-position verification against the claimed time and place, perceptual fingerprints, C2PA and AI-generator detection, encoder fingerprinting and an exact-copy web search.
Advanced Search
Composes advanced search-engine operators — exposed files, misconfigurations, login panels, credentials, social footprint — scoped to the search engine that actually covers the target’s region (Yandex, Baidu, Naver), explained and graded by sensitivity. Opens real, live results in a new tab; nothing is scraped or stored.
Phone Intelligence
Carrier, line type, reputation and linked-account enrichment.
Email Intelligence
Deliverability, disposable/role detection and breach signals (deeper with a Hunter.io key).
Username Intelligence
Sweep 98 platforms from a single handle and get back what can be defended: confirmed accounts with direct links, genuine absences, and an explicit list of the sites that refused to answer — never a refusal reported as an absence.
Domain Intelligence
WHOIS, full DNS, email security, hosting geolocation and certificate-transparency subdomains.
IP Intelligence
Geolocation, ASN, ISP, hosting/proxy detection and reverse DNS for any IP address.
Social Media Intelligence
Cross-platform profile aggregation, network mapping and activity timelines.
Brand Threat Radar
Typosquat & phishing detection — generates look-alike domains for your brand and flags the ones already registered, before they are used against you.
Deep & Dark
Breach, leak & dark-web intelligence — detailed breach analytics and paste exposure for emails, and Tor-index (onion) search for any selector or keyword.
Threat Intelligence
IOC reputation — aggregate live threat signals (Shodan risk tags & CVEs, Tor-exit membership, proxy/hosting, AbuseIPDB via BYOK) for any IP or domain into one verdict.
Crypto Intelligence
Wallet intelligence for Bitcoin & Ethereum — live balance, transaction activity and token exposure from any address.
Blockchain Forensics
Fund-flow tracing for BTC & ETH — map a wallet’s counterparties, inbound/outbound flows and flag known exchange & mixer (Tornado.Cash) interactions.
Geospatial
Map targets and their infrastructure across the world.
Geospatial Mapping
Map a target’s real-world infrastructure — resolve its web, mail and nameserver hosts, geolocate every IP, and plot the footprint across the live world map.
Vehicle Enquiry
UK vehicle due diligence from the official DVLA register — make, colour, engine, tax and MOT standing, export and V5C history. Establishes what a vehicle is, never where it has been.
Public camera search
Name a place and see every camera overlooking it, with distances. 3 national networks — road and transport authorities that publish for public viewing. Misconfigured private cameras excluded.
Live air traffic
Aircraft transmitting ADS-B now, military transponders marked. Coverage is thin over oceans and the product says so.
Broadcast news wall
4 international broadcasters live from their own channels, so a story can be read against more than one editorial line.
Developer & integrations
APIs, exports, webhooks and outbound connections.
Integrations & Export
Push alerts to Slack, Discord or Microsoft Teams, and export any report as a STIX 2.1 bundle or CSV for your SIEM, TAXII server, MISP or OpenCTI.
Developer API
Issue API keys and webhooks to query Blackout intelligence from your own systems.
Blackout applications
Standalone Blackout apps, embedded inside the OS.
Global Intelligence Console
Real-time 3D global console — SIGINT feed, live world events and entity fusion graph.
Operative Platform
Unified operative console — SITREP, live ledger, verification and case management.
Digital Passport
GOV.UK-styled digital identity wallet and verifiable credential issuer.
AgentAudit Trust OS
AI governance & agent assurance terminal — policy builder, controls and audit trails.
BCI-7 Operations
ATLAS terminal, profile builder, deception engine and NEXUS entity graph.
Project Chronos
Temporal intelligence & horizon-scanning workspace for tracking events over time.
Ghostwirebeta
Covert signals & secure-comms intelligence console.
Operations Console
Live multi-source operations feed — global events, seismic, weather and flight tracking.
Head to head
Where we are genuinely alone.
These are the capabilities we cannot find in any competing product. Every one is verifiable in ours today.
| Capability | Blackout | Maltego | SpiderFoot | Shodan | Intel X |
|---|---|---|---|---|---|
| Findings graded to NATO STANAG 2511 | |||||
| ICD 203 probability language | |||||
| Reports which sources failed to answer | |||||
| Constructed-identity (legend) analysis | |||||
| Sanctions screening included, not an add-on | |||||
| Person + infrastructure in one workspace | |||||
| Published, challengeable source register |
Free, no card
Three modules that cost nothing, and are not a demo
Most platforms in this field give you a locked screenshot and ask for a card. These run in full, against live sources, on a free account — because the fastest way to show the paid tiers are worth paying for is to let you check that the free ones work.
Username Intelligence
98 platforms
One handle, swept across development, social, creative, gaming, music, forum and security platforms in about six seconds.
Verified against a control handle that exists nowhere. Sites that could not tell a real account from an invented one were removed rather than counted.
IP Intelligence
Ports, CVEs, Tor, blocklists
Geolocation, ASN and netblock owner, the abuse contact to serve notice on, exposed services and known vulnerabilities, Tor exit status and screening across three aggregate threat lists.
“Not listed” is only said when every list actually answered. If one is unreachable the result reads inconclusive, because an absence you did not check is not an absence.
Live Operations
The world, right now
Seismic events, aircraft in the air, wildfires, storms, volcanoes, floods and sea ice — plotted live and refreshed continuously.
A feed that stops answering is named on the board. A quiet map is never allowed to look like a quiet world.
All three draw on the same 115 graded collectors the paid tiers use. The difference is how many subjects you can run, not how good the answer is.
Start freePricing
Priced per organisation, not per analyst
Seats are included in the plan. Bring your colleagues into the same workspace without the bill changing — then have one of them sign off the work before it leaves.
What does it cost when we add someone?
Nothing. Seats are included in the plan — 5 on Professional, unlimited on Enterprise — and there is no per-user fee. You are billed for the organisation, not per head.
How do we know a report was actually checked?
An analyst cannot approve their own work. The reviewer’s sign-off is sealed inside the document itself, so it travels with the report — and a recipient can verify it without an account, a login, or contacting you.
Who can see whose work, and can we prove it?
Colleagues share a workspace; the database enforces the boundary, not the interface. Deletions and authority changes are recorded, and every member can read that record — not only administrators.
What happens when someone leaves?
Their access ends immediately and their work goes with their account. That is a deliberate choice rather than an oversight — if you need work to survive a departure, keep it in shared cases and sealed reports, which do.
Free, and genuinely useful
One seat
- Username sweep across 98 platforms, with false positives verified out
- Full IP intelligence — geolocation, ASN, open ports, known CVEs, Tor and blocklist screening
- Live global operations board — seismic, aviation, wildfire, storm, volcano and flood
- Every finding graded, and every source that did not answer named
- 1 active investigation
For individual analysts
One seat
- Everything in Recon
- Auto-Investigate & Link Analysis
- Intelligence workbench + Watch globe
- Full OSINT toolkit — People, Domain, Email, Phone, Social & Crypto
- Data Extractor, Email & Image Forensics
- 10 active investigations · Evidence locker (5 GB)
- Email support
For teams and agencies
5 seats included — no per-user fee
- Everything in Explorer
- Unlimited investigations
- Auto-Pilot, War Room & Operation Theatre
- Attack Surface, ATT&CK, CVE, Sanctions & Adverse Media
- Case Management, court-ready Reports & chain-of-custody Evidence
- Scheduled briefings, Slack/Teams integrations & Developer API
- Evidence locker (100 GB) · Priority support
Full-spectrum intelligence
Unlimited seats, one workspace
- Everything in Professional
- All current & future modules
- Admin panel & audit logs
- SSO-ready & role-based access
- Unlimited seats
- Dedicated success manager
Deploy your intelligence OS today.
Join analysts and agencies running full-spectrum OSINT on Blackout Intelligence.
Create your account