Drishti
दृष्टि — Every Signal. One Picture.
Cross-domain entity fusion, real-time decision intelligence, and court-admissible evidence.
Built for national security. Auditable to a security examiner.
Seven Domains. One Knowledge Graph.
Watch how entities are resolved, merged, and fused across seven intelligence domains — with real-time alerts and court-admissible evidence bundles.
Maritime
AIS vessel tracking, IMO registry, dark gap detection exceeding 2-hour threshold, ship-to-ship transfer alerts, strategic port pattern recognition.
Aviation
ADS-B transponder data, DGCA registry integration, rogue UAV detection without transponder or flight plan, geofence violation monitoring.
Procurement
Government e-Marketplace, CPPP, IREPS, MoD eProcure, MCA company registry. Beneficial ownership chains traced through shell company layers.
Financial
Sanctions screening, crypto intelligence, cross-border transaction pattern detection. Ownership chains traversed for sanctions exposure.
Social Media
Telegram, X, Instagram, LinkedIn monitoring. Account clustering via shared identifiers. Geotagged posts cross-referenced with restricted facility geofences.
Sanctions
Global sanctions lists, Indian enforcement actions, PEP screening, watchlist matching. Ownership chains identify exposure through intermediary entities.
Cyber
MISP, OTX, VirusTotal threat indicators. Malware intelligence, vulnerability feeds, dark web monitoring. Indicators linked to entity graph.
Seven Intelligence Domains. One Unified Graph.
AIS vessel tracking, IMO registry integration, dark gap detection exceeding 2-hour threshold in EEZ, ship-to-ship transfer alerts, strategic port combination pattern recognition.
ADS-B transponder data merged with DGCA registry. Rogue UAV detection fires when aircraft operates without transponder, flight plan, or inside prohibited geofence.
Government e-Marketplace, public tenders, defence procurement, company registries, beneficial ownership chain tracing through shell company layers.
Sanctions screening, crypto intelligence, cross-border transaction pattern detection. Ownership chains traversed for hidden sanctions exposure.
Telegram, X, Instagram, LinkedIn monitoring. Account clustering via shared identifiers. Geotagged posts cross-referenced with restricted facility geofences.
Global sanctions lists, Indian enforcement actions, PEP screening, watchlist matching. Ownership chains identify exposure through intermediary entities.
Threat indicators from MISP, OTX, VirusTotal. Malware intelligence, vulnerability feeds, dark web monitoring. Indicators linked to entity graph for correlation.
From Raw Signal to Court-Ready Evidence
INGEST
13 connectors collect from all 7 domains. Raw data written to immutable storage. Every byte preserved for chain of custody.
NORMALIZE
Domain-specific normalizers convert raw data to canonical event schemas. Schema registry enforces contracts. Breaking changes blocked at the wire level.
RESOLVE
Entity resolver matches and merges entities across domains. Phone match = auto-edge. Username = analyst review. Confidence-based: ≥0.95 auto-merge, 0.75-0.94 review queue.
FUSE
Knowledge graph builds. Ownership chains, relationship edges, cross-domain connections materialize. The graph is the intelligence product.
ALERT
11 rules fire on every entity update. Event-driven, sub-second latency. CRITICAL alerts require confirmation from ≥2 independent intelligence domains.
EVIDENCE
Immutable SHA-256 signed evidence bundles. Alert record + entity snapshots + all raw objects via evidence reference chain. Designed to comply with Indian Evidence Act Section 65B requirements.
See It in Action
These are illustrative operational scenarios. Agency names are used to demonstrate capability relevance — they do not represent actual engagements or endorsements.
"Operation Phantom Procurement" — Shell Company Network Mapping
Intelligence analysis suspects a network of shell companies is systematically winning defence procurement contracts. Manual investigation has identified 2 companies but suspects there are more.
- Phase 1 — Entity resolution traces the 2 known companies through phone numbers, director names, and registered addresses. Discovers 5 more companies sharing directors.
- Phase 2 — Procurement records show all 7 companies won contracts at 4 sensitive defence facilities. Systematic access pattern detected.
- Phase 3 — Financial domain reveals crypto transactions between 3 of the companies.
- Phase 4 — Ownership graph shows ultimate beneficial owner is a foreign national. Complete network mapped.
Complete shell network mapped in under 2 hours — manual investigation had taken 4 months for the first 2 companies. Evidence bundle links 7 companies, 12 directors, 4 facilities, and 1 foreign beneficial owner. Prosecution-ready.
"Operation Sea Shield" — Ship-to-Ship Transfer Network Documentation
Repeated suspected ship-to-ship transfers in a specific zone of the Arabian Sea. The Coast Guard has satellite imagery showing two vessels in proximity but cannot confirm the pattern or identify the network.
- Day 1 — STS detection rule identifies 4 suspected transfer events in the past 90 days. Vessel identifiers resolved against IMO registry.
- Day 2 — Ownership chains traced. 2 of 4 vessels linked by common beneficial ownership.
- Day 3 — Sanctions screening flags previous port calls at sanctioned ports. Social media finds crew Telegram group with location-tagged photos confirming proximity.
- Day 5 — Entire STS network documented. Coast Guard interdicts the next scheduled transfer.
Entire STS transfer network documented with 4 events, 6 vessels, 3 ownership chains, 1 sanctions link, and social media confirmation. Coast Guard interdicts the next scheduled transfer with prosecution-ready evidence.
"Operation Digital Fortress" — Rogue UAV Operator Identification
A rogue UAV is detected operating near a sensitive research facility without a transponder or filed flight plan. Physical security reports visual sighting but cannot identify the operator.
- T+0 — Geofence violation rule fires immediately. Aviation registry queried for nearby registered UAVs — no match found.
- T+5 min — Procurement records show a company purchased commercial UAVs matching the visual description.
- T+10 min — Company director's phone number matches a Telegram account. Social media reveals geotagged photos near 3 other sensitive facilities.
- T+20 min — UAV operator identified. 6-month surveillance pattern across 4 facilities documented.
UAV operator identified and linked to a company conducting unauthorized surveillance of 4 sensitive facilities. 6-month pattern established through multi-domain fusion. Evidence bundle covers aviation, procurement, social media, and geo domains.
"Operation Sanctions Web" — Joint Venture Sanctions Exposure Assessment
India's delegation to a multilateral forum needs to verify whether a proposed joint venture partner has sanctions exposure. The entity operates across maritime shipping, procurement, and financial services in the Indo-Pacific.
- Hour 1 — Entity resolver finds matches across maritime registry (3 vessels), procurement filings (2 contracts), and financial domain.
- Hour 2 — Financial domain reveals flagged crypto transactions. Sanctions screening identifies parent company on EU sanctions list.
- Hour 3 — Ownership chain shows 2 layers of shell companies between sanctioned parent and proposed JV partner.
- Hour 4 — Complete sanctions exposure report delivered. Evidence bundle shared as diplomatic dossier.
MEA delegation receives a complete sanctions exposure report within 4 hours. The proposed JV is rejected. Without Drishti, this analysis would require coordination across 4 ministries and 2+ weeks.
Architectural Defences
Critical architectural rules are enforced by code structure, not documentation. Violations are physically impossible, not just prohibited.
CRITICAL alerts require confirmation from 2+ independent intelligence domains. Single-source alerts are rejected at system startup.
Immutable, SHA-256 signed evidence bundles with write-once storage. Defensible under Indian Evidence Act Section 65B.
Every entity update triggers rule evaluation in sub-second latency. No polling, no batch processing, no lag.
Every data flowing through the system conforms to strictly versioned schemas. Breaking changes are blocked at the wire level.
Every domain normalizer passes a comprehensive automated test suite before deployment. Quality is enforced, not hoped for.
Zero Foreign Dependencies
Every component runs on Indian infrastructure. Intelligence data never leaves the deployment boundary.
Production-Grade Infrastructure
Every component is open-source and self-hostable. No foreign SaaS in the pipeline.