The situation
Open-source investigation work mixes separate paid tools, hand-run searches and hand-built reports, and a guess can pass for a finding unless something checks it.
What I did
I built an investigation operating system the investigator directs in plain English, like writing an email to an intern investigator. Under the hood: search engines queried in parallel, over 55 social-platform collectors, and domain, archive, and threat-intelligence lookups, all feeding one case file.
The collection is not the point. The discipline is:
- No account is tied to a person without two independent crosslinks. Uncorroborated items are flagged, never silently dropped.
- A challenge step, using structured analytic techniques from the intelligence community, is required before findings are written and before any report. It is a rule, not a lock: when one report skipped it, a second read caught four claims stronger than the evidence.
- Every piece of evidence is captured at collection time with a cryptographic hash and archive submission, so chain of custody holds.
- Reports generate as branded Word documents straight from the case file.
The number
22 delivered cases have run through the system, every fact tied to a numbered evidence item that was hashed and archived when it was collected. The invoices come from a script reading the same case records.
Every number is from the case records.
An investigator's tools should argue with them. If your team's work product depends on judgment nothing checks, the assessment week shows where the same discipline belongs in your process.
Book a 30-minute callMore work: the analyst that refuses to guess · the pipeline that failed 95 times silently · the research desk that runs itself