Everything you need to run CARIO INTEL — from sign-in to signed PDF dossiers.
CARIO INTEL is an OSINT (Open-Source Intelligence) workstation. You enter a target — email, domain, IP, wallet, username, phone, or organisation — and the platform fans out across dozens of lawful public collectors in parallel to build a complete intelligence dossier with risk scoring, entity graphs, timelines, and a tamper-evident chain of custody.
Every action you take is recorded against a case file. Cases hold evidence, analyst notes, custody events, and exportable PDF reports.
Roles: admin manages operators and access requests; analyst uses every investigative module.
What runs against each target type:
The /investigate module is the workspace for active cases.
All cases are also browsable as a flat index at /cases with evidence and note counts.
Every mutation (case created, evidence added/tagged/deleted, note added, status changed, scan run, export) appends a custody event. Each event is hashed against the previous one, forming a tamper-evident chain.
The case header shows a CHAIN VERIFIED or CHAIN BROKEN badge. The full ledger is in the Chain of Custody tab.
/graph renders all entities discovered for the current scan as an interactive node-link diagram. Click any node to inspect it on the dashboard's right rail.
Every stored case also has its own investigation graph. Open a case from the Scan Vault and switch to the Graph view to add entities manually, search for entities close to the one you investigated, and ask the graph AI assistant to expand a node or explain a cluster.
Every scan you run is stored permanently against your account in the Scan Vault — nothing is lost when you close the tab, and cases sync across devices.
Choose your default workspace profile (9 industry presets) in /settings.
The copilot does more than answer questions — it investigates. In any case chat it synthesises the collected evidence, proposes the next pivots, and tells you when a line of enquiry is a dead end.
Claims are labelled as hypothesis vs. corroborated fact. AI messages consume credits from your plan; extra credit packs can be bought at /pricing.
One person may hold a dozen usernames, several emails, multiple companies, wallets and domains. Identity resolution clusters everything a case discovered into canonical identities.
Each cluster shows a verdict (same identity, likely same, uncertain), a confidence score, the supporting evidence, and any conflicts that argue against the merge. Entities that can't be attributed are listed as ungrouped.
Cross-checks self-reported claims against primary records and flags field-level conflicts — for example a profile claiming "CEO" when the official registry shows a directorship resigned three years ago.
Each contradiction lists both sources, the conflicting values, and a severity so you know which ones actually matter.
Trust score (0–100, higher is better) is simply 100 − risk score. It is the single headline number on a subject profile and answers: "how much adverse public evidence exists about this subject?" It is not a credit score, a legal judgment or a prediction of behaviour.
Risk score (0–100, higher is worse) starts from a clean baseline of 3 and only rises when a source returns an actual hit. A collector that simply ran successfully, or returned zero results, adds nothing. That is why a clean subject stays in the very high nineties on trust.
Points come from five capped categories, each with diminishing returns so one noisy category can never dominate:
Severity floors. Adverse evidence also sets a minimum risk, so a documented criminal record can never be diluted by clean infrastructure: corroborated tier-A coverage forces risk to at least 72 (trust ≤ 28), tier B to at least 48, tier C to at least 22.
The same collector output always produces the same score — the model never invents the number. Every subject profile shows a "How this score was calculated" strip listing each scoring category, the points it cost and the exact evidence line behind it, so any figure can be traced back to a source.
Confidence (0–100%) is a separate question: not "is this subject risky?" but "are we sure these findings are about this subject, and can we rely on them?" It combines four sub-scores shown in the confidence panel:
Before the search runs, very common names ("John Smith") and generic handles are detected deterministically and the console asks for narrowing details — city, employer, birth year, a known email — rather than producing a dossier that blends several people. You can always proceed anyway; the resulting confidence will reflect the ambiguity.
Findings also carry a verification tier: confirmed (primary source), supported (3+ independent sources), likely (2), possible (1 or inference), unverified, or contradicted. A high trust score with low confidence means "we found little bad — but we are also not certain we found the right person": narrow the search with DOB, location, employer or contact details before drawing conclusions.
A 300–850 exposure score for the subject, graded across five categories: breach exposure, social presence, infrastructure, financial signals and metadata leakage.
Each category comes with the evidence behind the grade and concrete remediation advice.
Paste a company name to generate a one-click dossier: ownership graph, subsidiaries, executives and board, lawsuits, patents, sanctions exposure, suppliers, technology stack, acquisitions and hiring trends.
Business Intel filters let you narrow by industry, geography, ownership/UBO and board or C-suite role to find chairmen and key people fast. Dossiers export as Markdown or into the case PDF.
/threat-simulation answers "what is this company's biggest cyber risk?" using only passive public sources.
It evaluates exposed services, leaked credentials, attack surface, vulnerable technologies and public infrastructure, then returns a ranked defensive assessment with severity, confidence, evidence, coverage gaps and next steps. It is defensive only — no active probing is performed.
Probabilistic forward assessments — bankruptcy risk, exit-scam probability, phishing-campaign likelihood, account-takeover and infrastructure-abandonment risk.
Each assessment states a probability, a confidence level, a time horizon, the supporting and counter evidence, assumptions and watch indicators. These are estimates, not certainties — treat them as leads, never conclusions.
Results can be pushed into the active case and appear in the one-click Case Brief with evidence strength, confidence gaps and recommended next steps.
An infinite visual workspace inside each case. Drag people, companies, phones, domains, wallets, screenshots, PDFs and notes onto the board and connect them into a link chart.
Anything you drop is hashed and recorded with provenance, so canvas artifacts count as real evidence rather than sketches.
Every artifact — uploaded, collected or canvas-dropped — carries a SHA-256 hash, a collection timestamp, its source, the collection method and a full audit history.
Run a verification pass at any time to confirm nothing has been altered since collection. Results feed the case's chain-of-custody badge and the signed PDF dossier.
Where the graph shows structure, the heatmap shows strength. Connections are banded from coincidental through weak to very likely connected, with a percentage on each pair so you can prioritise the links worth chasing.
/timeline shows every dated event the collectors surfaced — breach dates, registration dates, on-chain activity, archived snapshots — in chronological order, colour-coded by severity.
/threats aggregates severity-ranked findings across all active cases.
/monitor streams the public-source firehose (Hacker News, Wikipedia recent changes, GitHub public events) plus collector health probes. Use the Pause button to freeze the feed for review.
You can also put specific targets under watch — email, company, domain, wallet, phone, person or username. An hourly sweep re-probes each target with free public sources and notifies you on change: new breach, new company role, sanctions listing, lawsuit, new domain, GitHub leak or media mention. The number of watched targets is capped by your plan.
/geo plots geolocation data from the most recent scan (IP geo, ASN regions, organisational addresses).
/sources lists every collector with its current health, latency, and HTTP status. Toggle a source to scope it out of future scans.
Three places can export a signed PDF dossier:
PDFs are generated locally from structured data — they do not leave your browser until you save them, and they render correctly regardless of theme.
/assistant is a conversational copilot trained on the current case context. Ask it to summarise findings, draft narrative paragraphs, or suggest next collection steps.
/team lists the operators who have access to this workspace.
Users with the administrator role get an /admin link in the sidebar to:
/settings holds workspace preferences and integration toggles.