Trace Wallets. Map Identities.
Aletheia consolidates 30+ intelligence sources — crypto tracing, identity OSINT, attack-surface recon and continuous monitoring — into one AI-correlated workspace. Follow the money from a wallet to a human, and prove every step.
Crypto Investigation
Follow the money from wallet to human — what free explorers can't do and Chainalysis charges $40k/yr for.
Wallet tracing & counterparties
Paste a BTC or ETH address and instantly map every wallet it transacted with, ranked by volume and direction — rendered as a live money-flow graph, not a wall of hex.
Multi-hop money flow
Follow funds across several hops (victim → thief → intermediary → exchange) automatically, so an entire laundering path becomes one connected graph.
Address attribution & sanctions
Counterparties are labelled against the live US Treasury OFAC sanctions list plus known mixers — so you instantly see when funds touch a red-line address.
"Funds hit an exchange" alerts
The single most actionable signal in fraud: when traced funds reach an exchange or mixer, Aletheia flags it loud — because an exchange can identify the account holder under subpoena.
Wallet mention discovery
Find the social and forum accounts that publicly reference a wallet — the bridge from a pseudonymous address to a real human identity you can pivot on.
ENS resolution
Resolve name.eth ↔ 0x address in both directions, turning a wallet into a human-readable handle to chase across social platforms.
Identity & Social OSINT
Map a person's whole digital footprint from a single identifier.
Username & profile correlation
Enumerate accounts for a handle across hundreds of platforms and discover the surrounding ecosystem of linked services.
Email breach exposure
Check an email against known public breach datasets to surface exposed credentials and the services it's registered to.
Telegram channel discovery
Find public Telegram channels referencing a target — where crypto fraud and scam operations actually coordinate (SerpAPI-powered).
People & corporate records
Resolve names against public knowledge graphs, SEC EDGAR filings and the global GLEIF legal-entity registry for due-diligence leads.
Reverse image & visual intel
Run reverse image search and facial cross-referencing on a subject photo, and extract EXIF metadata (time, GPS) from uploaded images.
Vehicle registry & LPR
Look up a plate, or upload a vehicle image to run AI-powered plate OCR and pull registry details.
Infrastructure & Attack Surface
See what an organisation or target exposes to the internet.
Domain & DNS reconnaissance
WHOIS history, passive DNS, hosting and registrar footprints for any domain.
Certificate-transparency subdomains
Enumerate real hosts from public CT logs — surfacing infrastructure that DNS brute-forcing and search engines never reveal.
Exposure score
A graded attack-surface report for a domain: email hygiene, subdomain sprawl, open ports and impersonation risk in one letter grade.
IP, ASN & host intelligence
Geolocation, network ownership, open ports and CVEs, and scanner/threat reputation for any IP address.
AI Correlation & Graph
The engine that connects the dots across everything you've found.
Persistent entity graph
Every identifier collapses into one canonical node across all your cases, so the same wallet or email found in five investigations becomes a single, correlatable entity.
Cross-case correlation
Instantly see when an identifier in this case also appears in your other cases — the overlaps a spreadsheet would never catch.
Link analysis
Shortest-path between two entities ("how are these connected?"), hub detection via centrality, and automatic clustering of related entities.
Autonomous agent
Point the agent at a target and it plans, executes and pivots on its own across many steps — resumable and running in the background.
AI dossiers & extraction
LLM synthesis turns raw findings into a structured, cited dossier, extracting typed entities and the relationships between them.
Confidence & timeline
Every finding carries a corroboration-weighted confidence score, and events plot onto a chronological timeline and geospatial map.
Monitoring & Alerting
Turn one-off lookups into continuous watch.
Watchlists
Monitor a wallet, domain, email, username or IP on an hourly/daily/weekly cadence and get alerted only when something genuinely new appears.
Wallet monitoring
Watch an address and be alerted when funds move to a new counterparty or a new account starts talking about it.
Portfolio command view
One screen showing every monitored target, its status and open alerts — built for teams and MSPs watching many targets at once.
Slack, Discord & SIEM alerts
Pipe alerts straight into Slack or Discord (auto-formatted) or any SIEM/SOAR endpoint via signed webhooks.
Collaboration & Governance
The defensibility layer serious teams and legal review require.
Teams & access control
Organisations with per-case roles (owner / editor / viewer), so a team shares an investigation without sharing everything.
Immutable audit trail
An append-only record of who viewed, exported or acted on what — the governance evidence enterprise and compliance buyers ask for first.
Evidence provenance
Every exhibit is SHA-256 hashed at ingestion, so any later tampering is detectable and the chain of custody holds.
Court-ready reports
Export a defensible, white-labelled dossier with per-exhibit hashes, capture timestamps and a chain-of-custody and methodology statement.
Deep Investigation Pivoting
Manual target footprinting requires constant copying, pasting, and keeping track of separate files. Aletheia turns entity discovery into a recursive, multi-threaded intelligence loop.
Discovery & Extraction
Primary scans automatically extract candidate assets—including usernames, domains, emails, and crypto wallets. These are highlighted as clickable nodes in your live Identity Graph.
One-Click Traversal
Click any discovered entity node to instantly deploy a nested child investigation. No manual search setups, no context loss. The scan inherits the parent case query contexts.
Stitched Relationship Graphs
The database links cases via self-referential relations. Discovered assets are plotted in a force-directed network, allowing you to trace target footprints across multiple hops.