| Continuous monitoring | Scout runs persistent feeds and collectors against configured entities, profiles, pages, domains, locations, keywords, risk scenarios, and authorized customer inputs. Chatter scopes the same intelligence stream through watchlists, reusable filters, story clusters, analytics, alerts, and reports. | Documented Continuous dark-web monitoring and real-time alerting are explicit current capabilities; PenLink also describes continuous monitoring of open, deep, and dark sources for event intelligence. |
|---|
| Investigation and analysis | Scout supports monitored and ad hoc search workflows; Nexus Early Access adds graph canvas analysis, path finding, transforms, document extraction, entity resolution, correlation, and secure reports. The buyer can combine those tools with persistent monitoring rather than choosing investigation or monitoring as separate products. | Documented Search, analysis, visualization, digital investigations, evidence, and network-oriented workflows are core platform strengths. |
|---|
| Source model | Scout uses proprietary first-party collection for core public-source monitoring rather than depending on third-party APIs. Web, social, news, forums, dark web, RSS, monitored pages and profiles, domains, breach and PII sources, location data, email, webhooks, syslog, browser capture, APIs, and authorized customer records can enter one normalized pipeline. | Documented PenLink explicitly describes surface, deep, and dark-web intelligence and integrated sources. |
|---|
| AI and threat detection | DARIA detects scenario-level events, signals, and impacts; Chatter adds velocity, anomaly, novelty, story, cross-risk, entity, and geographic context. This creates a transparent structured record before alerts, analytics, or narratives are produced. | Documented AI-assisted automated threat detection and illicit-activity identification are documented in the OSINT platform. |
|---|
| Enterprise security use cases | One taxonomy and evidence model can be applied across executives, facilities, products, workforce, suppliers, brands, domains, credentials, infrastructure, locations, and customer data, with the selected product lines and workflows scoped to the buyer. | Documented Enterprise DRP, breach detection, physical protection, executive protection, situational awareness, and reputation analysis are publicly marketed. |
|---|
| Alerting and context | The same domain, severity, geography, keyword, entity-list, and map-area filters drive the feed, saved profiles, alerts, watchlists, analytics, and reports. Analysts can see the source preview, extracted entities, coordinates, clusters, triage state, and related activity behind an alert. | Documented Real-time alerts, contextual insights, and continuous monitoring are documented. |
|---|
| Primary operating model | DigitalStakeout joins targeted collection, scenario detection, investigation, analytics, and report production in one program. Scout is generally available; Nexus and Command add graph and governed multi-customer operations in Early Access when the requirement needs them. | Documented A digital-intelligence and investigation platform serving law-enforcement, defense, national-security, and enterprise-security use cases. |
|---|
| Buying path | The quote builder scopes Scout capacity, relevant product lines, customer-data inputs, Nexus or Command Early Access where appropriate, reporting, integrations, service responsibility, mitigation support, and complete commercial terms. | Qualified Public product and demo information is available; dollar pricing was not published in the official materials reviewed. |
|---|