FLOWSINT
OSINT Investigation Graph
Transform OK Β· 924 nodes ← ClearGlass
Investigation Β· Sketch #13434 Β· 924 nodes

Map the
infrastructure.

Flowsint turns a single domain or IP into a living entity graph. Run transforms to resolve neighbors, pivot across hundreds of nodes, and watch infrastructure relationships surface in real time β€” domains, IPs, subdomains and the links between them.

πŸ•Έ Open an investigation See the surface β–Έ
0
Nodes in sketch
0
Neighbors resolved
5
Entities selected
∞
Transforms / pivot
The surface
Every entity, every edge, one canvas.

Pick an entity on the left, watch it light up in the graph, read its full resolution on the right. Transforms run in the console below.

Flowsint Investigation / Sketch #13434
β Ώ ⚑ ☰ ⇄ β—Ž
Entities Β· 924 nodes 5 sel
11:36:48COMPLETEDTransform completed successfully.
11:36:48INFOTransform execution log finalized Β· 169 neighbors.
12.34.56.78
TypeIP address
CountryN/A
Address12.34.56.78
CityN/A
ISPN/A
LatitudeN/A
169 neighbor(s)
akamaiβ†’ resolves12.34.5…
gridlogβ†’ resolves12.34.5…
githubβ†’ resolves12.34.5…
inferenceβ†’ resolves12.34.5…
incontrolβ†’ resolves12.34.5…
What it does
From one seed to the whole footprint.
🌐

Domain β†’ IP resolution

Drop a domain and Flowsint resolves it, maps its subdomains, and pulls every IP it touches into the graph.

⚑

Transforms on demand

Run a transform on any node to expand its neighbors. Each run is logged to the console with a finalized execution record.

πŸ”—

Neighbor resolution

A single IP surfaced 169 neighbors β€” every domain resolving to it, ranked and pivot-ready in the detail panel.

⇄

Pivot across entities

Select up to many entities at once and pivot β€” Flowsint redraws the graph around the shared infrastructure between them.

πŸ“

Geo + ISP enrichment

Country, city, ISP and coordinates fill in as enrichment transforms complete β€” N/A today, mapped tomorrow.

πŸ—‚

Sketches that persist

Every investigation is a saved sketch β€” 924 nodes in #13434 β€” so you can return, re-run, and keep building the case.

Authority lattice
Flowsint is the OSINT node in the ClearGlass command grid.

This page now acts as an investigation cluster waypoint: it routes discovery traffic into the intelligence pillar, laterally into cyber defense and agent orchestration, and forward into a governed engagement path without adding noisy or random links.

1 Β· Site linking strategy

Home remains the authority hub; pillar pages hold category intent; cluster pages prove depth; blog posts expand topical relevance; service pages convert qualified demand. Each link is a controlled signal path from discovery to trust to conversion.

5 Β· Service-page links

Service pages should point back to proof and process: Security Quick-Audit to cyber defense, hardening to SMB trust, PHIPA to ClearPulse, procurement work to government readiness, and all high-intent routes to pricing or booking.

6 Β· Blog pillar links

Blog posts should reinforce a pillar, one sibling cluster, and one conversion next step. OSINT posts route to Flowsint and Intelligence; agent-governance posts route to PERCIVAL and AI Operator; security posts route to Cyber Defense Console.

7 Β· Footer and CTA structure

The footer stays minimal: ClearGlass hub, intelligence pillar, service booking, pricing, privacy, and terms. CTAs stay specific: open an investigation, request a security briefing, see pricing, or browse engagements.

8 Β· Implementation order

Maintain the graph in tools/internal_links.py, regenerate generated blocks, add contextual links only where they improve intent, validate with the bot, then review changed pages for visual and crawl integrity.

Defensive OSINT, by ClearGlass Inc

See the graph
before they do.

Flowsint is built for authorized investigations, attack-surface mapping, and infrastructure intelligence. Part of the ClearGlass intelligence stack alongside Sentinel and the Ontario OSINT deck.