Every capability,
in one operational console.
28 distinct capabilities across 6 intelligence domains — each with documented inputs, outputs and source provenance. The full operational surface of SENTINEL GIP, in plain English.
Maritime
5 capabilitiesAIS ↔ SAR Correlation
Spot vessels that switch off their AIS by matching radar signatures from Sentinel-1.
Cross-references live AIS broadcasts with Sentinel-1 SAR detections over the same time-window. Vessels visible on radar but absent from AIS are surfaced as candidate dark-fleet contacts with confidence scoring.
- AIS feed
- Sentinel-1 SAR acquisitions
- Bounding-box query
- Unmatched SAR contacts
- Confidence score per contact
- Re-acquisition hints
STS Transfer Detection
Flag ship-to-ship transfers happening outside designated anchorages — the #1 sanction-evasion vector.
Continuously scans vessel-pair proximity, relative speed and dwell-time outside designated anchorage zones. Triggers an STS event when two AIS tracks rendezvous at sea, with draft-mismatch and cargo-class context.
- AIS positions
- Designated anchorage polygons
- Vessel cargo class
- STS event ledger
- Vessel-pair dossiers
- Draft-mismatch flags
Dark-Fleet Flagging
Continuously score every vessel for shadow-fleet behaviour and surface the riskiest hulls.
Composite risk score combining AIS gaps, flag-hopping cadence, ownership obfuscation, sanction proximity and STS history. Each component is auditable and traceable to its source.
- AIS history
- Flag-change log
- Ownership chain
- Sanctions overlay
- Composite risk score (0–100)
- Sub-score breakdown
- Time-series volatility chart
Chokepoint Intelligence
Live transit watch on Hormuz, Bab-el-Mandeb, Malacca, Suez and Panama.
Aggregates vessel transits through each chokepoint with cargo class, flag distribution and sanctioned-hull share. Anomaly alerts when transit volume or composition deviates from a 28-day baseline.
- AIS feed
- Chokepoint polygons
- Cargo class taxonomy
- Hourly transit ledger
- Anomaly alerts
- Flag/Cargo break-downs
Sanctions Screening (7 regimes)
Cross-check every vessel, aircraft, person and company against OFAC, EU, UK, UN, Swiss, Canadian and Australian lists daily.
Daily refresh of all 7 sanctions regimes via OpenSanctions + direct authoritative pulls. Fuzzy-match on MMSI, IMO, name, AKA and ownership chain. Every hit is sourced to the original list and entry date.
- Identifier (MMSI/IMO/name/UBO/etc.)
- Hit list with regime + entry date
- Source URL
- Aliases matched
Aerial
3 capabilitiesMilitary Flight Tracking
Track military aircraft including blocked tail numbers — using uncensored ADS-B feeds.
Ingests uncensored ADS-B Exchange data plus OpenSky academic feed. Military hex-codes (NATO, RU, IL, etc.) are classified by ICAO 24-bit, callsign convention and known operator base. Patterns of training, deployment and ferry flights are baselined.
- ICAO hex
- Operator class
- Bounding box / route
- Live track
- 90-day replay
- Anomaly events vs baseline
Private-Jet Pattern of Life
Baseline an operator’s recurring flights and surface the rare anomalies.
Builds a statistical baseline per tail number — typical airports, frequency, time-of-week, route shape. Alerts when a new destination, unusual hour or ADS-B-off event breaks the pattern.
- Tail number / ICAO hex
- Window
- Baseline footprint
- Anomaly events
- Operator network graph
ADS-B Blackout Detection
Catch the moments aircraft go dark — across routes, time-windows and operators.
Detects ADS-B transponder dropouts inconsistent with terrain, altitude or operator profile. Cross-references with traffic-control planned routes when available to separate maintenance noise from intentional dark legs.
- ADS-B raw track
- Planned route
- Blackout segments
- Reconnection point
- Operator history of blackouts
Satellite
2 capabilitiesOn-Demand Satellite Acquisition
Order Sentinel-2 (optical) or Sentinel-1 (SAR) over any coordinate, any date.
Queries the Copernicus Data Space Ecosystem for the freshest cloud-free Sentinel-2 acquisition or all-weather Sentinel-1 SAR over a target. Async pipeline handles large mosaics and side-by-side compare.
- Bounding box
- Date / range
- Cloud cover threshold
- GeoTIFF / preview JPEG
- Acquisition metadata
- Compare-ready pair
Change Detection / Before-After
Two acquisitions, one verdict — see exactly what changed between two dates.
Side-by-side compare with synchronized scroll, opacity blend and difference overlay. Annotate, export and embed in a court-ready dossier.
- Acquisition A
- Acquisition B
- AOI polygon
- Change overlay
- Annotation layer
- Exportable mosaic
Investigation
9 capabilitiesUBO Resolver
Trace the ultimate beneficial owner of any vessel, asset or counter-party in seconds.
Combines OpenCorporates, OpenSanctions, SEC EDGAR, Companies House and Equasis. Builds the ownership chain, surfaces shell-company patterns and flags jurisdictional opacity. Each hop is sourced.
- Company name
- Registry ID
- Vessel IMO
- Ownership chain (n-hops)
- Shell-company flags
- Jurisdictional risk score
Entity Resolution
Collapse duplicate records that refer to the same vessel, person, company or aircraft.
Probabilistic match on identifiers, aliases, ownership chain and behavioural fingerprint. Builds a canonical entity ID and tracks every alias, mistyping and historical name.
- Identifier(s)
- Source dataset
- Canonical entity ID
- Alias history
- Confidence per match
Pattern of Life (Maritime + Aerial)
Baseline normal — then catch every deviation.
For any vessel or aircraft, compute the statistical baseline of recurring movements over a configurable window. Anomalies are scored and ranked; the system explains why each one stands out.
- Entity ID
- Window
- Baseline visual
- Ranked anomalies
- Explainer notes per anomaly
Threat Scoring
A composite score that summarises everything we know about an entity, with full transparency.
Combines sanctions hits, dark-fleet behaviour, ownership opacity, breach exposure and network proximity to known bad actors. Every sub-score is auditable — no black-box ML.
- Entity ID
- 0–100 score
- Sub-score breakdown
- Source citations
AI Intelligence Analyst (ICA)
A Claude Sonnet 4.5 analyst that reads the entire graph and writes the brief.
Operates strictly on the data already loaded into the investigation. Generates source-cited briefs, drafts recommendation memos and answers natural-language questions. Refuses to speculate when evidence is thin.
- Investigation graph
- Natural-language prompt
- Source-cited brief
- Recommendation memo
- Action checklist
Cross-Investigation Correlation
Spot the entity that appears in two of your active investigations — automatically.
When the same vessel, company, hex or phone number surfaces in multiple investigations, you get a notification. Lets a team of analysts triangulate without sharing notes manually.
- Active investigation list
- Shared-entity alerts
- Cross-investigation graph
Timeline Reconstruction
Every event, every move, every transaction — on one chronological axis.
Merges AIS tracks, ADS-B segments, sanctions actions, port calls, ownership changes and breach events into one auditable timeline. Filter, zoom, annotate and export.
- Entity ID
- Time range
- Interactive timeline
- Annotated milestones
- PDF / PNG export
Court-Ready Reports
Every claim is sourced. Every signature is HMAC-verifiable.
Dossiers ship as PDF with every figure linked to its raw source, every screenshot timestamped, every claim citation-annotated. The PDF itself is HMAC-signed for tamper detection.
- Investigation snapshot
- Signed PDF dossier
- Citation appendix
- HMAC verification key
OSINT
5 capabilitiesParallel Search Agents
Fan out a single query across 30+ OSINT sources in parallel — one normalised result set.
A single search is dispatched to Shodan, Censys, OpenCorporates, OpenSanctions, HIBP, IntelX, GDELT and others in parallel. Results are normalised, deduplicated and ranked by relevance.
- Query (identifier / freeform)
- Unified result set
- Per-source telemetry
- Latency report
Breach & Credential Intelligence
Score exposure across HIBP, IntelX, DeHashed and LeakCheck — without leaking your query.
Aggregates exposure data on identifiers (email, phone, username). Queries are k-anonymised where the upstream API supports it. Surfaces re-used passwords, dump dates and corroborating sources.
- Identifier
- Exposure score
- Per-source citation
- Recommended actions
Dark-Web Monitoring
Continuous watch on paste sites, dark-web marketplaces and threat-actor disclosures.
Indexed via IntelX and partner feeds. Alerts on entity mentions, leaked datasets and ransomware-blog posts referencing the watched keyword set.
- Watchlist (entities / keywords)
- Live mention feed
- Citation snapshots
- Threat-actor attribution
Real-Time Alerts
Webhook, email or in-platform — fire the moment a watched entity moves.
Per-entity, per-event-type alerts: AIS gap, port-call, sanctions hit, breach mention, social spike. Webhook payloads are HMAC-signed for downstream integration trust.
- Watchlist + trigger spec
- Webhook / Email / In-platform alert
- Signed payload
Operations
4 capabilitiesBatch Intelligence Import
Drop a CSV of identifiers — get a full screen, dossier and pivot graph back.
Upload up to thousands of MMSI/IMO/IATA/ICAO/email/company-name rows at once. Each row is screened against sanctions, dark-fleet, breach and corporate sources in parallel. Status is reported per row.
- CSV / Excel
- Per-row dossier
- Aggregated risk view
- Downloadable enriched CSV
Crisis Broadcast
Embed a public, HMAC-signed feed of geopolitical events on any newsroom dashboard.
GDELT + ACLED + curated incident feed, packaged as an embeddable widget with HMAC signing. Powers the public crisis broadcast on the SENTINEL home page.
- Topic / region filter
- Embed token
- HMAC-signed live feed
- Embeddable iframe / WebSocket
Evidence Cold-Storage (2-year retention)
Every raw signal is archived for 2 years — verifiable, replayable, auditable.
AIS, ADS-B, satellite acquisitions and dossier snapshots are written to cold storage and replayable on demand. Lets you reconstruct any past event with the data we had at the time.
- Date range
- Entity / AOI
- Replay timeline
- Original raw payload
- Provenance hash
Programmatic API & Webhooks
Wire SENTINEL GIP into your existing stack — REST + webhooks, HMAC-signed.
Full programmatic access to screening, search, batch import, alerting and dossier-generation endpoints. Every webhook payload is HMAC-signed for downstream zero-trust integration.
- API key + signed request
- JSON response
- HMAC-signed webhooks
Built for analysts who can’t afford to miss a signal.
All capabilities are operational from day one. Free tier available, full unlock from $29.99/month.
Social Intelligence
Index public X, Telegram and Reddit content tied to monitored entities.
Public-only collection via partner APIs (SocialData for X). No private chats. Posts are timestamped, hashed and linked back to the entity graph for pivot.