Master Architecture 1.0

Turn fragmented evidence into defensible intelligence.

IntelFortes is a defensive OSINT, exposure-intelligence, threat-intelligence, investigation, and digital-forensics search platform designed for security researchers, investigation teams, enterprises, and MSSPs.

Evidence-backed Tenant-isolated Policy-controlled collection Auditable
INTELFORTES / INVESTIGATION READY
SEARCH security@example.org EMAIL
FIRST SEEN 2025-11-20
LAST SEEN 2026-09-01
CONFIDENCE HIGH
Evidence #IF-EXAMPLE-01 PUBLIC

Sanitized demonstration record. Production results attach source, provenance, collection time, and evidence context.

Result policy applied tenant • redaction • entitlement • audit
One platform. One evidence model.

OSINT search is only the beginning.

IntelFortes organizes intelligence around Documents → Selectors → Observations, then builds cases, correlations, alerts, entities, graph relationships, enrichment, and AI-assisted investigation on top of traceable evidence.

Platform capabilities

Built for investigation, monitoring, and evidence-driven analysis.

Feature availability is controlled by deployment, plan entitlements, organization policy, and provider configuration.

01

Universal Selector Search

Search normalized intelligence by email, phone, domain, IP, CIDR, URL, username, hostname, file hash, ASN, crypto address, certificate fingerprint, organization, and supported text.

02

Historical Intelligence

Distinguish First Seen, Last Seen, Collected, Indexed, Published, and Source Updated dates so historical context remains precise and auditable.

03

Cases & Evidence

Organize searches, notes, evidence, timelines, graph views, alerts, and reports into investigations with source provenance and tenant-scoped collaboration.

04

Correlation & Graph

Pivot from exact selector overlap to weighted correlations and evidence-backed graph relationships without presenting inference as identity proof.

05

AI Investigator

Evidence-grounded investigation assistance can summarize entities, build timelines, explain relationships, and generate reports using authorized IntelFortes tools and cited evidence.

06

Alerts & Watchlists

Event-driven monitoring for selectors, domains, infrastructure, organizations, brands, and watchlist assets with deduplicated notifications.

07

Deep Enrichment

Plugin-based enrichment for supported providers such as VirusTotal, Shodan, Censys, DNS/RDAP, and DeHashed where contractually and operationally permitted.

08

Enterprise Exchange

REST API, signed webhooks, STIX 2.1, TAXII, and SIEM integrations for security operations and threat-intelligence workflows.

09

Privacy & Audit Controls

HMAC-based redaction directives, role masking, tenant isolation, immutable audit trails, retention policy, and export-time policy enforcement.

Intelligence lifecycle

From permitted source to evidence-backed result.

Collection and query paths are separated so ingestion, customer access, and compliance controls can scale independently.

01

Discover

Registered sources and authorized imports create collection targets.

02

Policy

Source, tenant, retention, rate, and collection policy are evaluated first.

03

Collect

Approved adapters fetch through Direct, Managed Proxy, or Tor egress.

04

Normalize

Documents and selectors are parsed, normalized, deduplicated, and classified.

05

Index

Evidence is archived and indexed as Documents, Selectors, and Observations.

06

Investigate

Search, alerts, graph, cases, enrichment, and AI operate over authorized evidence.

CONTROL PLANE PostgreSQL users • tenants • sources • cases • audit
SEARCH Elasticsearch / OpenSearch documents • selectors • observations
OBJECT STORE S3 / MinIO raw evidence • imports • exports • reports
ASYNC Redis / Celery → Kafka jobs today • durable events at scale
Search Access Plane

Customer search is isolated from the master intelligence plane.

Search & Export and other narrowly scoped products can query a dedicated read-only projection containing only fields allowed by that entitlement.

  • Independent read-only credentials
  • Entitlement-specific fields
  • Server-enforced result caps
  • User, organization, API-key, and WAF rate controls
  • Tenant filtering, redaction, and audit still apply
MASTER INTELLIGENCE PLANE Documents • Selectors • Observations Ingestion / indexing
↓ projection events
READ-ONLY PROJECTION Entitlement-safe fields No write access to master stores
SEARCH ACCESS SERVICE Policy • Quotas • Redaction • Audit API Gateway / WAF / User
Deployment choice

One platform architecture. Four deployment models.

CLOUD

IntelFortes Cloud

IntelFortes-hosted search, cases, alerts, graph, AI, API, and billing with strict tenant isolation.

HYBRID

IntelFortes Hybrid

Private local intelligence combined with explicitly permitted cloud queries. Private data is not uploaded to IntelFortes Cloud by default.

MSSP

IntelFortes MSSP

Parent organizations manage isolated customer tenants using explicit delegated access without implicit cross-customer visibility.

POLICY-CONTROLLED EGRESS SOURCE AUTHORIZED
Collector
Source Policy
DIRECT normal permitted HTTP(S)
PROXY POOL datacenter • residential • mobile
TOR SOCKS5h permitted .onion sources

Proxy type is a transport capability. Routing does not authorize access and is not used to defeat authentication, CAPTCHAs, rate restrictions, or source blocking.

Collection & egress

Network-aware without making routing the authorization layer.

Every acquisition request passes source policy before IntelFortes selects Direct, Managed Proxy, or Tor transport. Proxy pools track health, geography, session capability, concurrency, and cost without hard-coded provider credentials.

  • Source Registry + Source Policy Engine
  • Modular adapters for public web, authorized APIs, STIX/TAXII, imports, and Tor
  • Health-scored proxy pools with secret-manager credentials
  • SOCKS5h for permitted .onion workflows
  • Blocked sources move to operations/policy review
Search by selector

Normalize the data point. Preserve the evidence.

EMAILuser@example.com
PHONE+1 202 555 0147
DOMAINexample.org
IP / CIDR203.0.113.0/24
URLhttps://example.net/path
USERNAMEsample_user
HOSTNAMEhost.example.org
FILE HASHsha256:…
ASNAS64500
CRYPTO[sanitized address]
CERTIFICATEfingerprint:…
ORGANIZATIONExample Organization
Sanitized query preview

See historical context without putting real sensitive data in marketing.

The preview below is synthetic and demonstrates the result shape, temporal fields, redaction behavior, and evidence confidence labels.

INTELFORTES_QUERY_PREVIEW SYNTHETIC DATA
Source Identifier Secondary First Seen Last Seen Confidence
example.org/security security@example.org +1 202 555 0147 2025-11-20 2026-09-01 High
[sanitized .onion source] analyst@example.net [REDACTED] 2026-01-08 2026-08-27 Medium
example.com/archive [HIDDEN] 203.0.113.42 2024-06-02 2026-07-16 High
Enrichment Plugin Manager

Add intelligence providers without rewriting core search logic.

Provider adapters are entitlement-aware, quota-aware, timeout-protected, and circuit-breaker controlled. Results are normalized into a unified intelligence profile.

VirusTotal Shodan Censys DNS / RDAP DeHashed* STIX / TAXII
*Where commercial terms, provider policy, and the customer's entitlement permit. IntelFortes uses defensive exposure metadata rather than presenting reusable credentials/session material as a normal product output.
ShodanIP enrichment
READY
VirusTotaldomain / IP / file intelligence
READY
Censyshost / certificate enrichment
READY
Organization BYOKprovider credentials isolated by tenant
POLICY
Defense in depth

Protect the evidence, the platform, and the access path.

Identity & Access

Argon2id, MFA, JWT/refresh rotation, scoped API keys, RBAC + ABAC, SSO/SCIM path.

Tenant Isolation

Global intelligence + current tenant visibility only; cross-tenant tests block deployment.

Redaction Everywhere

Ingestion, search, rendering, graph, AI, cache, API, reports, and exports.

Search Isolation

Read-only projections separate lower-privilege/high-volume search from master intelligence stores.

Abuse Controls

Rate limits, result caps, export entitlements, WAF controls, anomaly scoring, re-auth, and suspension workflow.

Auditable Operations

Sensitive searches, exports, admin actions, licensing events, and policy changes generate audit events.

Designed for intelligence workflows

More than a point-lookup or sales-directory experience.

GENERAL DIRECTORY / POINT LOOKUP
  • Primarily current-record retrieval
  • Limited evidence provenance
  • Little or no case workflow
  • Limited historical correlation
  • Minimal relationship analysis
INTELFORTES
  • Historical First Seen / Last Seen context
  • Document → Selector → Observation evidence model
  • Cases, alerts, watchlists, and timeline
  • Correlation and evidence-backed graph
  • Private, Hybrid, Cloud, and MSSP deployment models
  • Policy-controlled enrichment and AI investigation
Plans & entitlements

Choose the access model that fits your investigation workflow.

Pricing shown below matches the current public offering. Exact quotas and capabilities should be rendered from the IntelFortes plan catalog, not hard-coded in production templates.

READ-ONLY ACCESS PLANE

Search & Export

Narrowly scoped intelligence lookup with isolated read-only access.

$97/month
  • Email, phone, domain & supported selector search
  • Read-only intelligence projection
  • Temporal First Seen / Last Seen context
  • CSV / JSON export subject to entitlement
  • Server-enforced rate and result limits
  • Redaction, tenant policy & audit
Create Search Account
TEAM / ENTERPRISE

Enterprise

For security teams, regulated organizations, and advanced investigations.

From $600/month
  • Multi-user organization access
  • Full graph entitlement & advanced correlation
  • Higher/custom search and enrichment quotas
  • API, STIX/TAXII, SIEM & SSO options
  • Executive / white-label reporting where enabled
  • Cloud, Private, Hybrid or MSSP architecture
Request / Order Enterprise
AUTO-UPDATE ENTITLEMENT $59/mo

Feature updates, connector patches, and security fixes according to license terms.

MANAGED VPS $45/mo

Turnkey infrastructure option for supported deployment sizes.

PROFESSIONAL INSTALLATION $99 one-time

Deployment assistance for supported customer infrastructure.

Plan limits are enforced through the entitlement engine and may vary by contract, deployment, provider quotas, and risk policy. “Unlimited” is not used as an operational promise.

SIGNED LICENSE Ed25519 verified deployment_id: if-deploy-•••••••• installation_id: ••••••••
ACTIVE DEPLOYMENT
Private deployment licensing

Signed licensing with a real migration path.

IntelFortes Private uses signed licenses, deployment IDs, optional attestation, update entitlements, and audited migration/reset workflows instead of brittle permanent MAC/CPU locking.

  • Local Ed25519 signature verification
  • Optional first-run online activation
  • Deployment and installation IDs
  • Optional entitlement heartbeat + offline grace period
  • Audited migration/reset workflow
FAQ

Questions security teams ask before deployment.

What is IntelFortes?

IntelFortes is a defensive OSINT, exposure-intelligence, threat-intelligence, investigation, and digital-forensics search platform built around traceable Documents, Selectors, and Observations.

Is IntelFortes only self-hosted?

No. Master Architecture 1.0 supports Cloud, Private, Hybrid, and MSSP deployment models from the same platform architecture.

Does Search & Export query the master production intelligence database directly?

No. The architecture uses a dedicated read-only Search Access Plane projection for narrowly scoped or high-volume access. It contains only fields permitted by the user's entitlement and remains subject to tenant, redaction, rate, and audit controls.

How does IntelFortes collect data?

Registered source adapters pass through a Source Policy Engine before a permitted request is routed through Direct, Managed Proxy, or Tor SOCKS5h transport. Routing is not authorization and is not used to defeat access controls or source blocking.

What external intelligence providers can be integrated?

The Plugin Manager supports provider adapters such as VirusTotal, Shodan, Censys, DNS/RDAP, and DeHashed where provider terms and IntelFortes policy permit. Organization-specific BYOK credentials can also be supported.

How are privacy and redaction handled?

Redaction is enforced across ingestion, search, rendering, graph, AI retrieval, APIs, cache, reports, and exports. HMAC-based selector tokens and auditable redaction workflows prevent a search-only blacklist from being the sole control.

Does IntelFortes claim to be automatically “GDPR compliant”?

IntelFortes provides privacy, redaction, retention, access-control, and audit capabilities that can support an organization's compliance program. Actual legal compliance depends on the operator's data sources, lawful basis, configuration, jurisdiction, policies, and use.

How are Private licenses tied to a deployment?

Signed licenses use deployment and installation IDs with optional attestation and online entitlement checks. IP/country changes can be treated as risk signals, while legitimate VPS or hardware migrations use an audited migration workflow.

Build your intelligence environment

Deploy IntelFortes around your evidence, policy, and investigation workflow.

Choose a plan, request an Enterprise deployment, or contact MediaXtreme about Private, Hybrid, MSSP, integrations, or implementation.

✓ Tenant-isolated ✓ Evidence-backed ✓ Policy-controlled ✓ Auditable ✓ Extensible ✓ Deployment-flexible
Talk to us

Tell us what you are investigating.

Send us your deployment model, data-handling constraints, and the workflow you need to support. A MediaXtreme engineer replies with a scoped answer — not a generic brochure.

  • Private, Hybrid and MSSP deployment scoping
  • Entitlements, redaction policy and audit requirements
  • API, STIX/TAXII and SIEM integration questions
  • Existing licence, billing and account support
We reply to business enquiries within one business day.