Any Input: Files · Pages · Records · Enrichments
Files
Thousands of formats. Content plus metadata, with recursive extraction of embedded files.
Pages
Surface, Deep, and Dark Web via Chrome, Firefox, or TOR. Login sessions and live HTTP scraping, including live capture of an entire site.
Records
Databases, APIs, and structured sets decomposed into independent records, never falsely linked to a container file.
Enrichments
Extracted selectors auto-trigger data-service research on emails, domains, and IPs. Research that runs itself.
Container formats (mailboxes, archives, spreadsheets, databases) decompose into independent records, so intelligence is never falsely linked to a file just because it was the container.Your own holdings, not just the open web: seized media, disclosure sets, exports, and archives process the same way as live sources.
Built on the Ontology for Digital Intelligence
TR3AD is the platform implementation of the Ontology for Digital Intelligence. The ODI supplies three things the platform is built on: a resource-centric model for preserving digital material, a deterministic identity model for resolving intelligence elements across sources, and a discovery-driven analytical framework that replaces keyword search with structured exploration.
An ontology is not a schema you fill in. It is the vocabulary that lets an email address extracted from a spreadsheet, a name read out of a PDF, and a coordinate parsed from an image sit in the same structure and be compared. Everything else on this page depends on it.
Intelligence Types
Twelve top-level classifications that group profiles by fundamental function. Each type contributes standard fields and associations automatically: every Event definition carries temporal fields, because an event is inherently bound by time.
Intelligence Definitions
The schema for a specific kind of intelligence within a type: its fields, matching rules, validation, and permitted associations. Definitions are registered by extensions at startup, so new kinds of intelligence arrive without modifying the core framework.
Intelligence Profiles
Unique instances created from definitions, each one a single resolved element of intelligence in the network, accumulating references and associations as more material is processed.
The twelve Intelligence Types
- Account
- Asset
- Attribute
- Category
- Contract
- Entity
- Event
- Identifier
- Measurement
- Place
- Relationship
- Selector
Because the vocabulary is shared, intelligence extracted in one language from one format is directly comparable to intelligence extracted in another. Resolved intelligence is stored in language-agnostic structures, which is why no translation step is required anywhere in the pipeline.
Discovery, Not Just Search
The streaming intelligence engine: raw resources become Content Frames, extracted elements resolve into Intelligence Profiles, and every link traces to its original source and sentence.

Explore by category, not by query
Search only answers questions you already know to ask. Browse the corpus by IntelType, Definition, and Instance instead.
Content Frames: documents as streams
Documents stream frame by frame, each frame adding connections that accumulate into context.
Triage in minutes, not weeks
What is this about? Who is it about? Answered immediately.
A reading assistant answers one question at a time and forgets the corpus between sessions. Discovery is different: the platform surfaces what the collection actually contains: the people, accounts, places, and events you would never have queried. It keeps that permanently structured, for every question that comes next.
Every core question, answered from evidence
Who, what, when, where, why, and how. Identifying those elements as material is processed is what turns analysis from a search-driven activity into a discovery-driven one: the corpus surfaces the entities, events, places, and relationships an analyst would never have known to query. Each one traces back to the exact source statement it came from.
The Entire Intelligence Lifecycle

Collect
Researchers with one-click multi-source import, specialized Importers for files, websites, and social sources, with streaming Connections on the roadmap.
Analyze
Graph, Locations, Search, and Timelines, usable at 100,000+ nodes.
Evaluate
AI-assisted analysis over the graph; threaded team Discussions for shared assessment.
Visualize
Code-generated Dashboards, AI-drafted Reports, Storyboards, and ETL Publishers.
One product, one graph, end to end, with no stitching a processing engine to a charting tool to a reporting suite.
Products Built for the Evidence, Not a Template
The last stage of the lifecycle is the one most platforms hand back to you as a fixed screen. TR3AD drafts it: reading the content, deciding what would actually explain it, and building that product for the analyst to review.
Import
Bring in everything you have: files, websites from the surface, deep, and dark web, spreadsheets exploded into per-record intelligence, databases, and archives.
Enrich & Resolve
Extracted selectors trigger automated enrichment: emails unmask names and companies, domains unmask infrastructure. Every dot resolves into connected profiles.
Get Briefed
TR3AD generates draft intelligence products from the resolved graph: interactive dashboards, multi-section reports, and narrative storyboards, designed for your data, not filled into templates.
Refine & Publish
The analyst reviews, iterates, and adds products as the investigation develops, then publishes through Publisher extensions: a customized Intelligence Portal, documents and files, external systems and feeds, even other ontologies.

Generated dashboard: 261 nodes, 298 edges, drafted from an imported collection. Dashboards
Drafted, not configured. Interactive HTML dashboards designed and coded from the graph's content, reviewed and refined by the analyst, exportable, standalone, and shareable outside the platform.

Drafted report, eleven pages, open two-up in the viewer. Reports
Drafted from evidence. Full-length, multi-section draft reports built from provenance content, every statement traceable to the exact source sentence, ready for analyst review. Output to Word, PDF, HTML, or text.

Generated equity chain: 30 entities across 27 jurisdictions, 14 flagged. Storyboards
The narrative, assembled. Timelines, presentations, and interactive storyboards generated from graph content and shaped by the analyst, exportable to interactive HTML and PowerPoint.
Publishers are extensions on a full ETL engine: they can reduce (filter, summarize), expand (generate whole products), or transform (map to other ontologies and systems) the graph's content. The flagship example: a customized Intelligence Portal generated for the investigation: the analyst's chosen dashboards, reports, storyboards, and interactions alongside standard TR3AD interfaces, so consumers of the intelligence explore a finished product, not a raw tool. But the same pipeline publishes to documents, feeds, external platforms, and downstream systems. Tailored Intelligence Triage, end to end: minutes after import the analyst is reading a briefing built from their own evidence; when they're done, their audience gets it in whatever form the mission requires.
The Same Thing, Resolved the Same Way Every Time
The hardest problem in intelligence is not connecting the dots. It is deciding that two references are the same dot. Resolution is the mechanism that answers that question consistently, so identity does not depend on who happened to search for what.
Identity is deterministic rather than probabilistic. Each profile's designated match fields are normalized, concatenated in a fixed order, and hashed. Two references to the same thing produce the same match hash every time, regardless of when, where, or how often they are encountered, and match fields are immutable after creation because changing them would redefine what the profile is.
Resolvers are the match conditions attached to a profile, and they function as an index rather than a search: a read-first, no-scan check of whether a match condition exists. A profile can be reachable through several of them at once. An aircraft is discoverable by its Mode S code, its N-number, or its serial number, and every one of them arrives at the same profile. Resolvers are either defined explicitly by an analyst or inferred by the platform, and each carries a weight so competing conditions resolve predictably.
Twelve resolver types cover it: name parts, address parts, words, characters, regular expressions, hashes, geo-fences, temporal ranges, measurements, numerics, named fields, and the presence of other intelligence. The Word resolver is the one that carries multilingual work: define a concept once and it matches across translations, acronyms, abbreviations, misspellings, and fuzzy variants, in every language in the corpus.
Evidence You Can Defend
Intelligence is only useful if it survives scrutiny: in court, in an inspector-general review, in an assessment. TR3AD stores everything the way it will be examined.
- Air-gapped AI
- Full-platform intelligence processing on a disconnected laptop.
- No context ceiling
- Every resource analyzed in its own bounded session.
- The same dot, found first
- Deterministic identity across sources, formats, and languages.
- Provenance to the sentence
- Every conclusion traces to the exact source statement.
Forensic copies, not references
The original resource is preserved in the graph. Links rot; TR3AD can produce an exact copy of the source on demand.
Cryptographic verification
Every resource verified unique with SHA256 plus a block of common hashes for cross-matching.
Provenance on every fact
Conclusions trace through sentence-level links back to the exact source statement.
Full transaction log
Every change flows through a logged request pipeline. The complete history is auditable.
Every change flows through a logged request pipeline, so the complete history of a case is auditable, not just its conclusions.
See It on Your Own Material
Demonstrations run on your data, in your environment, including fully offline.
