Live now · multi-source fusion running continuously

Intelligence you can defend.

Every finding graded to NATO standard, with an honest record of what it could not reach. 115 graded collectors, 63 live modules, one platform.

What do you need to find out?

Describe the job, or paste a domain, email, company name or wallet.

63

Intelligence modules

115

Graded collectors

A–F

Source grading

24/7

Autonomous watch

The difference

Everyone shows you a confidence score.
Ask where the number came from.

Blackout grades every finding to NATO STANAG 2511 and ICD 203 — the standards real intelligence services are held to. Source reliability A–F. Information credibility 1–6. Graded independently, because they are independent.

Every other platform

94%

confident

  • Confident based on which source?
  • Corroborated, or a single reading?
  • What did they fail to reach?

Blackout

OFAC sanctions screening — DESIGNATED

This address is designated: YAN, Xiaobing

A1
Programme
SDNTK
Source grade
A · Completely reliable
Credibility
1 · Confirmed by other sources

Almost certain (96–100%), with high confidence in the sourcing — Admiralty A1.

Sources consulted10/12

Two sources didn't answer — and we tell you which. “Six of twelve refused” is a different finding from “nothing found”.

Worked example of the output format. Not a real subject, and not a case we have worked.

Nobody else asks this

What should be here — and isn't?

Real identities accrete. They are old, uneven and messy — abandoned accounts, a breach from 2013, archived pages nobody meant to keep.

Constructed ones are manufactured in a window. Recent. Uniform. Tidy. Conspicuously free of a decade's debris.

Legend Analysis reads the gaps, not just the hits — and shows the evidence for authenticity alongside the doubts.

Legend analysis

Strong constructed-identity indicators

60/100

Worked example of the output format — not a real subject.

  • No history predating the last 12 months

    Oldest verifiable record is 40 days old

  • Origin dates tightly clustered

    4 records all originate within 6 days of each other

  • Same handle claimed across 11 platforms

    Uniformity at scale suggests a single reservation pass

Graded Admiralty D — an indicator, never a conclusion. A new business is legitimately new, and the panel says so.

The register

115 collectors. Every one graded.

Not a logo wall. Grade A is reserved for the body that issues the fact — being excellent isn't enough. Every grade carries a written rationale you're invited to challenge.

A×24

Issuing authority

OFAC · Companies House · SEC · RDAP · GLEIF

B×53

Direct records

DNS · Certificate Transparency · Wikidata · on-chain

C×29

Scanning & aggregation

Shodan · breach corpora · Wayback · blocklists

D×9

Derived & inferred

Behavioural profiling · lookalike generation

Verifiable evidence

Don’t take our word for it. Check it.

Every report this platform produces carries a cryptographic seal over its findings. The person who needs to trust it — a bank, a regulator, the other side of a dispute — can verify it here with no account, no key and no contact with us.

Below is a real seal, issued by the same code that seals a customer’s findings. Verify it, then alter a value and verify again.

A seal proves a document has not changed since it was issued. It does not, and cannot, prove the findings are correct — that is what the source grading is for.

Specimen report

No account, no card

Don't take our word for it. Run one.

Type any domain. This is the real collector, hitting live sources right now — the same one behind the paid tiers, not a recording.

Try

Domains only in the public preview — no personal data, deliberately. Username, email, company and image lookups need a free account.

Live now · free tier

The world, as the platform is seeing it

Not a screenshot and not a recording. This is the Live Operations module — one of the three that cost nothing — collecting from USGS, NASA EONET and OpenSky while you read.

Events tracked

Aircraft in the air

This board is free forever. A free account adds the filters, the full event history and the other two free modules.

Open the full board

The platform

Engineered like an intelligence agency, priced for everyone.

Secure by design

Server-verified subscriptions, an AES-256 encrypted key vault and row-level data isolation. Access is never gated by client JavaScript.

Your queries stay yours

We do not sell, share or resell what you look up. Provider keys are yours, held encrypted, and billed to you — never pooled across customers.

Defensible by default

Every finding carries its source grade, its credibility rating and the record of which collectors answered. Export it and the reasoning travels with it.

Workflow

From a single clue to the full picture — in seconds.

No manual transforms, no stitching four tools together. Blackout does the pivoting for you.

01

Drop in any selector

A domain, email, username or IP — even a partial lead. One field, one click, no setup.

02

Auto-pivot & fuse

Blackout crawls dozens of live sources and automatically links every related identity, asset and exposure.

03

Get a scored dossier

A threat-scored profile, relationship graph and an agency-grade PDF — ready to action or share.

Everything it does

The whole platform, in one page.

69 capabilities in 6 groups, 66 of them live today and 3 marked beta or coming. Not a shortlist — this is all of it, laid out the way the product is.

Command & workspace

Run operations, cases and briefings — and everything you produce.

27

Operation Theatre

Watch an autonomous investigation unfold live — Blackout resolves the identity, expands the network into a constellation, geolocates the infrastructure and scores the threat in real time, then hands you a briefing.

War Room

The live operational command centre — a cinematic global theatre fusing your watchlist threat board, DEFCON posture, recurring entities, live intelligence feed and worldwide operations into one screen.

Priority Requirements

Declare the standing questions that matter to you — geography, keywords and thresholds — and Blackout scores the live world against them continuously, surfacing answers without you going looking.

Blackout Bridgebeta

Connect smart glasses and other Bluetooth hardware directly to Blackout — full service discovery, live event log, capability scan and exportable diagnostics. Desktop Chrome/Edge and Android.

Auto-Investigate

One-click OSINT — enter any target (domain, email, username, IP) and get a live compiled intelligence brief.

Link Analysis

Visual entity-relationship graphs — connect people, orgs, domains, emails and more, then expand with transforms.

Intelligence Graph

Your persistent knowledge base — every entity from every saved case, deduped and linked into one graph that compounds over time and surfaces shared people & infrastructure.

Bulk Investigate

Investigate many targets at once — each fully assessed, threat-scored, ranked, and exported as one combined report.

Watchlist

Continuous monitoring — put any target under watch and get alerted the moment its exposure shifts: new ports, fresh CVEs, breaches, infrastructure moves.

Profile Builder

Automated identity resolution — enter any selector and Blackout auto-pivots across every source, fuses linked identities into one scored subject dossier with a relationship graph, and exports it.

Auto-Pilot

Autonomous investigation — give one target and Blackout resolves the identity, expands the whole connected network, correlates your cases and writes the assessment, hands-free.

Anomaly Detection

Statistical anomaly detection across your watchlist — surfaces exposure-change surges and active-threat spikes against each target’s own baseline, so emerging escalations find you.

Entity Annotations

Pin persistent, live-updating notes to any entity — domain, IP, email, username or case — building shared analyst context that follows the entity across your workspace.

Executive Briefing

Turn a full technical workup into a board-ready narrative — bottom line, key judgements, risk rating and recommendations, in executive prose (AI-authored when an Anthropic key is connected).

Ask Intelligence

Conversational OSINT — ask a question in plain English; Blackout runs live lookups on any domain/IP/email you mention, cross-references your cases, and answers grounded in real data.

Source Reliability

Grade sources and information on the NATO Admiralty System — attach standardised reliability×credibility ratings to every finding and keep a source register, so confidence travels with your intelligence.

Investigation Playbooks

Named, repeatable investigation workflows — chain Blackout’s modules into one automated run (domain due diligence, entity screening, infrastructure threat assessment) with live step-by-step results.

Email Forensics

SOC-grade phishing triage — paste a raw email and Blackout reconstructs the delivery path, verifies SPF/DKIM/DMARC, flags spoofing and extracts every indicator, locally.

Data Extractor

Paste any blob — breach dumps, email headers, logs, chat exports — and Blackout extracts every email, IP, domain, URL, wallet, phone, CVE, hash and key locally, each one-click investigable.

Case Management

Run investigations as cases — bundle saved reports and evidence, keep a timestamped notes timeline, and track status and priority from open to closed.

Intelligence Briefings

Automated recurring intelligence digests — watchlist changes, new high-threat findings and case activity compiled on a daily or weekly cadence and emailed to you as a branded PDF.

SITREP

Command center — a live operational picture fusing your watchlist alerts, portfolio threat, recurring cross-case entities and global live events into one posture readout.

Live Operations

Real-time global situational awareness — live earthquakes, aircraft, wildfires, storms and volcanoes plotted on one world map, streaming 24/7.

Maps

Geospatial plotting of entities, movements and areas of interest.

Timeline

Reconstruct chronologies across every piece of collected evidence.

Evidence Locker

Chain-of-custody storage for artefacts, screenshots and exports.

Reports

Generate court-ready intelligence reports from any investigation.

Identity & due diligence

People, companies, sanctions and adverse-media screening.

7

Adverse Media

Negative-news screening for KYC and due diligence — scan global news coverage of any person or company for fraud, corruption, litigation, sanctions and criminal reporting, categorised.

Corporate Intelligence

Global corporate intelligence with no key required — legal entity identity and ownership hierarchy (GLEIF), US SEC registrant and filing history, French national registry records with officers and filed financials, the Irish register with status and accounts filing history, and the Brazilian register by CNPJ with officers and share capital. Connect a free Companies House key for full UK officer, ownership and filing depth.

Counterparty Check

Pre-engagement due enquiry on a party you are about to advise on, contract with or litigate against — ownership, sanctions and adverse media, all three required, with every concern referred to a fee-earner rather than absorbed. Sealed, so the file can be checked by the other side.

Supplier Check

Procurement due diligence in one pass — ownership, sanctions, adverse media and digital footprint, assessed against your policy. Tells you plainly when a required check could not be carried out, and what changed since last time.

Sanctions Screening

KYC / AML due diligence — screen any person or entity against live sanctions and watchlists with fuzzy name matching, scored candidate matches and programme details.

People Intelligence

Resolve identities from names, aliases and partial data across public records.

Face Recognitionbeta

Match faces against indexed sources and cluster appearances over time.

Digital & infrastructure

Domains, certificates, attack surface, vulnerabilities and crypto.

20

Threat Attribution

Attribute a target’s exposure profile to known threat actors — Blackout maps the attack surface to ATT&CK techniques, then ranks the APT and cybercrime groups whose playbooks overlap.

ATT&CK Mapper

Map a target to the MITRE ATT&CK matrix — Blackout lights up the adversary techniques its real attack surface enables, and exports a Navigator layer for your SOC.

Infrastructure Correlation

Given a set of entities, determine which of them are the same operation. Shared registrars, nameservers, netblocks, mail infrastructure, account-bound verification tokens and registration timing are weighted by how much each actually narrows the field — so commodity providers used by millions never link strangers.

Attack Surface

External attack-surface management — discover every internet-facing asset an organisation exposes (subdomains, hosts, open ports, services, CVEs) and score it into a single exposure grade.

Vulnerability Intelligence

Assess any CVE with live NVD, EPSS and CISA KEV data — CVSS severity, real-world exploit probability, affected products, and whether it is actively exploited in the wild.

DNS Security Posture

Audit a domain’s DNS and email-authentication hardening — SPF, DKIM, DMARC, MTA-STS, DNSSEC and CAA — graded A–F with every record and a fix for each gap.

Certificate Intelligence

Certificate Transparency reconnaissance — enumerate every subdomain and TLS certificate ever issued for a domain, spot freshly-minted and lookalike certs, and map the issuing CAs.

Image Forensics

Drop any photo to expose GPS capture location, camera and lens, timestamps and authenticity signals — read in your browser. Opt into deep analysis for solar-position verification against the claimed time and place, perceptual fingerprints, C2PA and AI-generator detection, encoder fingerprinting and an exact-copy web search.

Advanced Search

Composes advanced search-engine operators — exposed files, misconfigurations, login panels, credentials, social footprint — scoped to the search engine that actually covers the target’s region (Yandex, Baidu, Naver), explained and graded by sensitivity. Opens real, live results in a new tab; nothing is scraped or stored.

Phone Intelligence

Carrier, line type, reputation and linked-account enrichment.

Email Intelligence

Deliverability, disposable/role detection and breach signals (deeper with a Hunter.io key).

Username Intelligence

Sweep 98 platforms from a single handle and get back what can be defended: confirmed accounts with direct links, genuine absences, and an explicit list of the sites that refused to answer — never a refusal reported as an absence.

Domain Intelligence

WHOIS, full DNS, email security, hosting geolocation and certificate-transparency subdomains.

IP Intelligence

Geolocation, ASN, ISP, hosting/proxy detection and reverse DNS for any IP address.

Social Media Intelligence

Cross-platform profile aggregation, network mapping and activity timelines.

Brand Threat Radar

Typosquat & phishing detection — generates look-alike domains for your brand and flags the ones already registered, before they are used against you.

Deep & Dark

Breach, leak & dark-web intelligence — detailed breach analytics and paste exposure for emails, and Tor-index (onion) search for any selector or keyword.

Threat Intelligence

IOC reputation — aggregate live threat signals (Shodan risk tags & CVEs, Tor-exit membership, proxy/hosting, AbuseIPDB via BYOK) for any IP or domain into one verdict.

Crypto Intelligence

Wallet intelligence for Bitcoin & Ethereum — live balance, transaction activity and token exposure from any address.

Blockchain Forensics

Fund-flow tracing for BTC & ETH — map a wallet’s counterparties, inbound/outbound flows and flag known exchange & mixer (Tornado.Cash) interactions.

Geospatial

Map targets and their infrastructure across the world.

5

Geospatial Mapping

Map a target’s real-world infrastructure — resolve its web, mail and nameserver hosts, geolocate every IP, and plot the footprint across the live world map.

Vehicle Enquiry

UK vehicle due diligence from the official DVLA register — make, colour, engine, tax and MOT standing, export and V5C history. Establishes what a vehicle is, never where it has been.

Public camera search

Name a place and see every camera overlooking it, with distances. 3 national networks — road and transport authorities that publish for public viewing. Misconfigured private cameras excluded.

Live air traffic

Aircraft transmitting ADS-B now, military transponders marked. Coverage is thin over oceans and the product says so.

Broadcast news wall

4 international broadcasters live from their own channels, so a story can be read against more than one editorial line.

Developer & integrations

APIs, exports, webhooks and outbound connections.

2

Integrations & Export

Push alerts to Slack, Discord or Microsoft Teams, and export any report as a STIX 2.1 bundle or CSV for your SIEM, TAXII server, MISP or OpenCTI.

Developer API

Issue API keys and webhooks to query Blackout intelligence from your own systems.

Blackout applications

Standalone Blackout apps, embedded inside the OS.

8

Global Intelligence Console

Real-time 3D global console — SIGINT feed, live world events and entity fusion graph.

Operative Platform

Unified operative console — SITREP, live ledger, verification and case management.

Digital Passport

GOV.UK-styled digital identity wallet and verifiable credential issuer.

AgentAudit Trust OS

AI governance & agent assurance terminal — policy builder, controls and audit trails.

BCI-7 Operations

ATLAS terminal, profile builder, deception engine and NEXUS entity graph.

Project Chronos

Temporal intelligence & horizon-scanning workspace for tracking events over time.

Ghostwirebeta

Covert signals & secure-comms intelligence console.

Operations Console

Live multi-source operations feed — global events, seismic, weather and flight tracking.

Start investigating Every capability above is in the product today. Nothing here is a roadmap.

Head to head

Where we are genuinely alone.

These are the capabilities we cannot find in any competing product. Every one is verifiable in ours today.

CapabilityBlackoutMaltegoSpiderFootShodanIntel X
Findings graded to NATO STANAG 2511
ICD 203 probability language
Reports which sources failed to answer
Constructed-identity (legend) analysis
Sanctions screening included, not an add-on
Person + infrastructure in one workspace
Published, challengeable source register
Full Partial / manual Not availableComparison reflects Blackout's assessment of publicly documented capabilities.

Free, no card

Three modules that cost nothing, and are not a demo

Most platforms in this field give you a locked screenshot and ask for a card. These run in full, against live sources, on a free account — because the fastest way to show the paid tiers are worth paying for is to let you check that the free ones work.

Username Intelligence

98 platforms

One handle, swept across development, social, creative, gaming, music, forum and security platforms in about six seconds.

Verified against a control handle that exists nowhere. Sites that could not tell a real account from an invented one were removed rather than counted.

IP Intelligence

Ports, CVEs, Tor, blocklists

Geolocation, ASN and netblock owner, the abuse contact to serve notice on, exposed services and known vulnerabilities, Tor exit status and screening across three aggregate threat lists.

“Not listed” is only said when every list actually answered. If one is unreachable the result reads inconclusive, because an absence you did not check is not an absence.

Live Operations

The world, right now

Seismic events, aircraft in the air, wildfires, storms, volcanoes, floods and sea ice — plotted live and refreshed continuously.

A feed that stops answering is named on the board. A quiet map is never allowed to look like a quiet world.

All three draw on the same 115 graded collectors the paid tiers use. The difference is how many subjects you can run, not how good the answer is.

Start free

Pricing

Priced per organisation, not per analyst

Seats are included in the plan. Bring your colleagues into the same workspace without the bill changing — then have one of them sign off the work before it leaves.

What does it cost when we add someone?

Nothing. Seats are included in the plan — 5 on Professional, unlimited on Enterprise — and there is no per-user fee. You are billed for the organisation, not per head.

How do we know a report was actually checked?

An analyst cannot approve their own work. The reviewer’s sign-off is sealed inside the document itself, so it travels with the report — and a recipient can verify it without an account, a login, or contacting you.

Who can see whose work, and can we prove it?

Colleagues share a workspace; the database enforces the boundary, not the interface. Deletions and authority changes are recorded, and every member can read that record — not only administrators.

What happens when someone leaves?

Their access ends immediately and their work goes with their account. That is a deliberate choice rather than an oversight — if you need work to survive a departure, keep it in shared cases and sealed reports, which do.

Recon

Free, and genuinely useful

£0/mo

One seat

  • Username sweep across 98 platforms, with false positives verified out
  • Full IP intelligence — geolocation, ASN, open ports, known CVEs, Tor and blocklist screening
  • Live global operations board — seismic, aviation, wildfire, storm, volcano and flood
  • Every finding graded, and every source that did not answer named
  • 1 active investigation
Start free
Explorer

For individual analysts

£29/mo

One seat

  • Everything in Recon
  • Auto-Investigate & Link Analysis
  • Intelligence workbench + Watch globe
  • Full OSINT toolkit — People, Domain, Email, Phone, Social & Crypto
  • Data Extractor, Email & Image Forensics
  • 10 active investigations · Evidence locker (5 GB)
  • Email support
Choose Explorer
Most popular
Professional

For teams and agencies

£99/mo

5 seats included — no per-user fee

  • Everything in Explorer
  • Unlimited investigations
  • Auto-Pilot, War Room & Operation Theatre
  • Attack Surface, ATT&CK, CVE, Sanctions & Adverse Media
  • Case Management, court-ready Reports & chain-of-custody Evidence
  • Scheduled briefings, Slack/Teams integrations & Developer API
  • Evidence locker (100 GB) · Priority support
Choose Professional
Enterprise

Full-spectrum intelligence

£349/mo

Unlimited seats, one workspace

  • Everything in Professional
  • All current & future modules
  • Admin panel & audit logs
  • SSO-ready & role-based access
  • Unlimited seats
  • Dedicated success manager
Choose Enterprise
Encrypted · analyst-grade

Deploy your intelligence OS today.

Join analysts and agencies running full-spectrum OSINT on Blackout Intelligence.

Create your account