Master Architecture 1.0

Searchable intelligence infrastructure for evidence-driven investigation.

Search domains, emails, IPs, phones, URLs, hashes, CVEs and other indicators across a continuously growing intelligence corpus. Trace historical evidence, correlate relationships, monitor authorized assets, and investigate from IntelFortes Cloud or infrastructure you control.

Evidence-backedUniversal selector searchTenant-isolatedAuthorized monitoringPrivate / Hybrid ready
INTELFORTES / UNIVERSAL SEARCH READY
SEARCH security@example.org EMAIL
FIRST SEEN 2025-11-20
LAST SEEN 2026-09-01
CONFIDENCE HIGH
Evidence #IF-EXAMPLE-01 PUBLIC

Synthetic demonstration record. Production results trace each observation to its document, source, collection event and preserved evidence context.

Evidence trace preserved observation • document • source • fetch
One platform. One evidence model.

Search the corpus. See the history. Follow the evidence.

IntelFortes continuously collects permitted intelligence, normalizes it into Documents → Selectors → Observations, preserves source provenance and history, then builds correlation, monitoring, cases, graph analysis, enrichment and evidence-grounded AI on top of that evidence model.

Platform capabilities

Built for investigation, monitoring, and evidence-driven analysis.

Feature availability is controlled by deployment, plan entitlements, organization policy, and provider configuration.

01

Universal Selector Search

One search experience for normalized email, phone, domain, hostname, IP, CIDR, URL, file hash, CVE, ASN, username, organization and supported text selectors.

02

Historical Evidence

See First Seen, Last Seen, Collected, Published, Indexed and source-update context; preserve record versions so current state never silently overwrites what IntelFortes previously observed.

03

Correlation & Relationships

Pivot from a selector to evidence-backed emails, phones, subdomains, IPs, ASNs, URLs, certificates, entities and related observations. Correlation is shown as evidence, not identity proof.

04

Authorized Exposure Monitoring

Continuously monitor customer-controlled assets only after authorization. Domain monitoring uses proof-of-control; an ordinary search never becomes a permanent monitoring request.

05

Cases & Evidence

Turn a search into an investigation with referenced evidence, notes, timelines, relationships, graph views, collaborators, alerts and reports without copying away source provenance.

06

Watchlists & Alerts

Event-driven watchlists surface new observations and meaningful changes for permitted selectors and verified assets with deduplicated notifications and auditable state.

07

Evidence-Grounded AI Investigator

AI assistance works through authorized IntelFortes tools and cited evidence, distinguishing observed facts, correlations, inferences and hypotheses rather than presenting model output as fact.

08

Enrichment & Enterprise Exchange

Optionally enrich stored intelligence with authorized providers such as Shodan, Censys, VirusTotal, DNS/RDAP and DeHashed, plus REST API, webhooks, STIX 2.1, TAXII and SIEM workflows.

09

Privacy, Audit & Deployment Controls

Tenant isolation, HMAC-backed redaction, retention controls, audit trails, entitlement enforcement, and Cloud, Private, Hybrid or MSSP deployment from one platform architecture.

Intelligence lifecycle

From permitted source to searchable, historical intelligence.

IntelFortes builds the corpus before and between customer searches. Collection, evidence preservation, customer search and monitoring are separate control paths so each can be governed and scaled independently.

01

Discover

Registered public-security feeds, permitted public-web sources, public onion sources, authorized APIs and customer imports create candidate collection targets.

02

Policy

Source, tenant, authorization, retention, collection cadence and risk policy are evaluated before acquisition.

03

Collect

Approved adapters fetch through Direct, managed commercial proxy, or internal Tor transport according to source policy.

04

Normalize

Each feed record becomes its own document; selectors are normalized, evidence is deduplicated, and identity remains source-scoped.

05

Archive & Index

Raw evidence is content-addressed and searchable Documents, Selectors and Observations are indexed with First Seen / Last Seen history.

06

Investigate

Customers search the accumulated corpus, follow evidence, correlate relationships, monitor verified assets, enrich selectively and build cases.

CONTROL PLANE PostgreSQL users • tenants • sources • cases • audit
SEARCH Elasticsearch / OpenSearch documents • selectors • observations
OBJECT STORE S3 / MinIO raw evidence • imports • exports • reports
ASYNC Redis / Celery → Kafka jobs today • durable events at scale
Search Access Plane

Customer search stays read-only and separate from collection.

Search & Export and other customer-facing search paths query a dedicated read-only projection containing only fields allowed by the user’s entitlement and tenant policy. Searching a third-party domain is a question; it does not register, verify or monitor that domain.

  • Independent read-only credentials
  • Entitlement-specific fields
  • Server-enforced result caps
  • User, organization, API-key, and WAF rate controls
  • Tenant filtering, redaction, and audit still apply
  • Search does not create monitoring jobs or organization-domain ownership
MASTER INTELLIGENCE PLANE Documents • Selectors • Observations Ingestion / indexing
↓ projection events
READ-ONLY PROJECTION Entitlement-safe fields No write access to master stores
SEARCH ACCESS SERVICE Policy • Quotas • Redaction • Audit API Gateway / WAF / User
Deployment choice

One platform architecture. Four deployment models.

CLOUD

IntelFortes Cloud

IntelFortes-hosted search, cases, alerts, graph, AI, API, and billing with strict tenant isolation.

HYBRID

IntelFortes Hybrid

Customer-controlled private intelligence combined with explicitly permitted cloud intelligence and enrichment. Private data is not uploaded to IntelFortes Cloud by default.

MSSP

IntelFortes MSSP

Parent organizations manage isolated customer tenants using explicit delegated access without implicit cross-customer visibility.

POLICY-CONTROLLED EGRESS SOURCE AUTHORIZED
Collector
Source Policy
DIRECT normal permitted HTTP(S)
PROXY POOL datacenter • residential • mobile
TOR SOCKS5h permitted .onion sources

Proxy type is a transport capability. Routing does not authorize access and is not used to defeat authentication, CAPTCHAs, rate restrictions, or source blocking.

Collection & egress

Collect through policy-controlled Direct, managed proxy and Tor transport.

Every acquisition request passes the Source Policy Engine before transport is selected. Direct is the normal clear-web route; contracted proxy pools provide approved routing capabilities; internal Tor handles permitted public .onion sources. Transport never creates authorization.

  • Source Registry + Source Policy Engine
  • Modular adapters for public web, authorized APIs, STIX/TAXII, imports, and Tor
  • Health-scored proxy pools with secret-manager credentials
  • SOCKS5h for permitted .onion workflows
  • Blocked sources move to operations/policy review
Search by selector

One search box. Many selector types. Every result tied to evidence.

EMAILuser@example.com
PHONE+1 202 555 0147
DOMAINexample.org
IP / CIDR203.0.113.0/24
URLhttps://example.net/path
USERNAMEsample_user
HOSTNAMEhost.example.org
FILE HASHsha256:…
ASNAS64500
CVECVE-2026-1234
CERTIFICATEfingerprint:…
ORGANIZATIONExample Organization
Sanitized query preview

See the result shape: source, history, confidence and evidence.

The preview remains synthetic. Production search should show where a result came from, when it was first and last observed, how it is related, and why IntelFortes considers a relationship relevant.

INTELFORTES_QUERY_PREVIEW SYNTHETIC DATA
Source Identifier Secondary First Seen Last Seen Confidence
example.org/security security@example.org +1 202 555 0147 2025-11-20 2026-09-01 High
[sanitized .onion source] analyst@example.net [REDACTED] 2026-01-08 2026-08-27 Medium
example.com/archive [HIDDEN] 203.0.113.42 2024-06-02 2026-07-16 High
Live platform telemetryMeasured from IntelFortes — never hard-coded.
CONNECTING
Documents
Selectors
Observations
Active Sources
Last Corpus Update

Production requirement: populate from a read-only public telemetry endpoint. If unavailable, show unavailable — never substitute marketing estimates.

Enrichment Plugin Manager

Stored intelligence first. Live enrichment when it adds value.

IntelFortes searches its accumulated corpus first. Optional provider adapters can add fresh infrastructure, malware, reputation, DNS/RDAP or exposure context without making every search dependent on an external API.

VirusTotal Shodan Censys DNS / RDAP DeHashed* STIX / TAXII
*Where commercial terms, provider policy, and the customer's entitlement permit. IntelFortes uses defensive exposure metadata rather than presenting reusable credentials/session material as a normal product output.
ShodanIP enrichment
OPTIONAL
VirusTotaldomain / IP / file intelligence
OPTIONAL
Censyshost / certificate enrichment
OPTIONAL
Organization BYOKprovider credentials isolated by tenant
OPTIONAL
Defense in depth

Protect evidence, tenant boundaries, authorized monitoring and the access path.

Identity & Access

Argon2id, MFA, short-lived sessions, scoped API keys, permission-based RBAC/ABAC, and SSO/SCIM where entitled.

Tenant Isolation

Global intelligence plus current-tenant or explicitly delegated intelligence only. Cross-tenant visibility regression tests are deployment gates.

Redaction Everywhere

Redaction and policy apply across ingestion, search, history, correlation, graph, AI, cache, API, reports and exports.

Search ≠ Monitoring

A customer search does not create ownership or collection. Continuous domain monitoring requires registration, DNS proof-of-control and an explicit monitoring switch.

Abuse & Export Controls

Rate limits, result caps, export entitlements, WAF controls, anomaly/risk signals, re-authentication and suspension workflows protect the search plane.

Auditable Operations

Sensitive searches, exports, monitoring authorization, admin actions, licensing events, policy changes and redaction workflows produce audit events.

Designed for intelligence workflows

Search + corpus + history + correlation + monitoring — with deployment choice.

POINT LOOKUP / DIRECTORY MODEL
  • A query is primarily a current-record lookup
  • Little or no preserved evidence chain
  • Limited historical change context
  • Relationships may be shallow or unexplained
  • Usually tied to the provider’s hosted data model
INTELFORTES INTELLIGENCE MODEL
  • Continuously growing searchable intelligence corpus
  • Document → Selector → Observation evidence chain
  • First Seen / Last Seen and version-aware historical context
  • Evidence-backed correlation, graph and case workflows
  • Authorized monitoring plus Cloud, Private, Hybrid and MSSP deployment
  • Optional enrichment and evidence-grounded AI investigation
Plans & entitlements

Choose the access model that fits your investigation workflow.

Plans define entitlements, quotas and deployment eligibility. In production, names, prices, quotas and capabilities must come from the IntelFortes plan catalog/API rather than being authorization logic in this template.

READ-ONLY ACCESS PLANE

Search & Export

Narrowly scoped intelligence lookup with isolated read-only access.

$97/month
  • Universal search across supported selectors in the read-only access plane
  • Read-only intelligence projection
  • Historical First Seen / Last Seen evidence context
  • CSV / JSON export subject to entitlement
  • Server-enforced rate and result limits
  • Redaction, tenant policy & audit
Create Search Account
TEAM / ENTERPRISE

Enterprise

For security teams, regulated organizations, and advanced investigations.

From $600/month
  • Multi-user organization access
  • Full graph entitlement & advanced correlation
  • Higher/custom search and enrichment quotas
  • API, STIX/TAXII, SIEM & SSO options
  • Executive / white-label reporting where enabled
  • Cloud, Private, Hybrid or MSSP architecture
Request / Order Enterprise
AUTO-UPDATE ENTITLEMENT $59/mo

Feature updates, connector patches, and security fixes according to license terms.

MANAGED VPS $45/mo

Turnkey infrastructure option for supported deployment sizes.

PROFESSIONAL INSTALLATION $99 one-time

Deployment assistance for supported customer infrastructure.

Plan limits are enforced through the entitlement engine and may vary by contract, deployment, provider quotas, and risk policy. “Unlimited” is not used as an operational promise.

SIGNED LICENSE Ed25519 verified deployment_id: if-deploy-•••••••• installation_id: ••••••••
ACTIVE DEPLOYMENT
Private deployment licensing

Signed licensing with a real migration path.

IntelFortes Private uses signed licenses, deployment IDs, optional attestation, update entitlements, and audited migration/reset workflows instead of brittle permanent MAC/CPU locking.

  • Local Ed25519 signature verification
  • Optional first-run online activation
  • Deployment and installation IDs
  • Optional entitlement heartbeat + offline grace period
  • Audited migration/reset workflow
FAQ

Questions security teams and investigators ask before using IntelFortes.

What is IntelFortes?

IntelFortes is searchable intelligence infrastructure for evidence-driven security, exposure, threat-intelligence and investigation workflows, built around traceable Documents, Selectors, and Observations.

Is IntelFortes only self-hosted?

No. Master Architecture 1.0 supports Cloud, Private, Hybrid, and MSSP deployment models from the same platform architecture.

Does Search & Export query the master production intelligence database directly?

No. The architecture uses a dedicated read-only Search Access Plane projection for narrowly scoped or high-volume access. It contains only fields permitted by the user's entitlement and remains subject to tenant, redaction, rate, and audit controls.

How does IntelFortes collect data?

Registered source adapters pass through a Source Policy Engine before a permitted request is routed through Direct, Managed Proxy, or Tor SOCKS5h transport. Routing is not authorization and is not used to defeat access controls or source blocking.

What external intelligence providers can be integrated?

The Plugin Manager supports provider adapters such as VirusTotal, Shodan, Censys, DNS/RDAP, and DeHashed where provider terms and IntelFortes policy permit. Organization-specific BYOK credentials can also be supported.

How are privacy and redaction handled?

Redaction is enforced across ingestion, search, rendering, graph, AI retrieval, APIs, cache, reports, and exports. HMAC-based selector tokens and auditable redaction workflows prevent a search-only blacklist from being the sole control.

Does IntelFortes claim to be automatically “GDPR compliant”?

IntelFortes provides privacy, redaction, retention, access-control, and audit capabilities that can support an organization's compliance program. Actual legal compliance depends on the operator's data sources, lawful basis, configuration, jurisdiction, policies, and use.

How are Private licenses tied to a deployment?

Signed licenses use deployment and installation IDs with optional attestation and online entitlement checks. IP/country changes can be treated as risk signals, while legitimate VPS or hardware migrations use an audited migration workflow.

Does searching a domain cause IntelFortes to monitor it?

No. Search, registration, verification and monitoring are separate operations. Searching an arbitrary domain queries existing intelligence; it does not create an organization-domain claim, collector job or permanent watch.

How is continuous domain monitoring authorized?

Customer domains must be registered and verified through proof-of-control before monitoring can be enabled. DNS TXT verification is the default control path. Monitoring can be turned off immediately.

Is external enrichment the IntelFortes corpus?

No. IntelFortes builds and searches its own accumulated evidence corpus. Authorized providers such as Shodan, Censys, VirusTotal, DNS/RDAP or DeHashed can optionally supplement a result with fresh enrichment where terms, policy and entitlements allow.

Does IntelFortes treat public information as public-domain information?

No. Public accessibility and public-domain legal status are different concepts. Source policy, provider terms, retention, redaction and applicable legal obligations remain part of the collection and use decision.

Build your intelligence environment

Start with search. Scale into a complete intelligence environment.

Choose Search & Export, deploy Researcher, or request an Enterprise, Private, Hybrid or MSSP environment built around your evidence, retention, integration and investigation requirements.

Designed for cybersecurity, threat intelligence, corporate security, fraud investigation, digital forensics, exposure monitoring, incident response and authorized research.

✓ Universal search ✓ Historical evidence ✓ Evidence-backed correlation ✓ Authorized monitoring ✓ Tenant-isolated ✓ Deployment-flexible
Talk to us

Tell us what you are investigating.

Send us your deployment model, data-handling constraints, and the workflow you need to support. A MediaXtreme engineer replies with a scoped answer — not a generic brochure.

  • Private, Hybrid and MSSP deployment scoping
  • Entitlements, redaction policy and audit requirements
  • API, STIX/TAXII and SIEM integration questions
  • Existing licence, billing and account support
We reply to business enquiries within one business day.