INDEPENDENT INTELLIGENCE. CONNECTED.

The signal before
the damage.

Follow the money. Understand the threat. Connect onchain exposure and offchain intelligence in a private desktop workspace built for the people protecting digital assets.

macOS desktop appNo card required
GROUNDTRUTH WORKSPACE / ILLUSTRATIVE INVESTIGATIONONE CONNECTED INVESTIGATION
groundtruth / investigation 001 PRIVATE WORKSPACE
Cross-chain investigationCASE 001 · CROSS-CHAIN EXPOSURE
Under review
ILLUSTRATIVE PRODUCT PREVIEW
fundsbridge deposittransfersFunding source0x7e2…41awallet 01wallet 02wallet 03Bridge routeCross-chain entryReview target0x9c4…e72Related walletETHEREUM / BASE · FICTIONAL SCENARIO
COMMON SOURCE

An unexpected connection.

01/03
Many networks. One connected investigation.Explore the workflow
FROM FIRST SIGNAL TO DEFENSIBLE INTELLIGENCE
DetectInvestigateExplain
THE QUESTIONS BEHIND THE SIGNAL

More data is easy.
A clearer decision takes context.

01

Where did the funds come from?

Trace the immediate counterparties. Keep transaction references close to the question you are trying to answer.

02

What else is connected?

Look beyond an isolated address. Review contract relationships, infrastructure, and the intelligence sources relevant to the case.

03

Can someone else review the finding?

Preserve the evidence, record your reasoning, and give the next analyst a useful starting point.

THE INVESTIGATION WORKSPACE

A transaction is a fact.
A pattern is intelligence.

Move from raw activity to a structured investigation. Explore relationships, preserve the source context, and document what deserves a closer look.

DESKTOP WORKFLOW / SIGNAL DISCOVERYCONCEPT
Unusual patternFOCUS: CONNECTED ECOSYSTEMS
01

Give your attention a direction.

A focused queue of signals, with the context to decide what deserves a closer look.

A connected workflow, from the first observation to a reviewable evidence package.Explore the platform
THE INTELLIGENCE FOUNDATION

A wider field of view.
A precise starting point.

Begin with the public record. Expand the investigation through the relationships, source context, and analyst knowledge that give it meaning.

THE PUBLIC RECORD

Onchain evidence

Wallet activity, native balances, deployed code, and contract metadata. A reproducible snapshot at a specific block.

AddressesTransactionsContracts
THE WIDER PICTURE

Threat context

An investigation model for connecting wallet leads with actor reporting, campaigns, and technical indicators from licensed sources.

ActorsCampaignsInfrastructure
THE HUMAN JUDGMENT

Analyst knowledge

Case notes, review status, saved watchlists, and evidence packages. Keep the reasoning with the record.

HypothesesSource referencesHandoffs

Direct network reads, public explorer context, and a consistent record across ecosystems.

Explore the coverage model
BUILT AROUND THE WORK

Different mandates.
The same need for clarity.

From the first suspicious transfer to a considered ecosystem review, give every investigation a method and every handoff a usable record.

SECURITY OPERATIONS / INCIDENT RESPONSE

Give an incident a clear evidence trail.

A suspicious address is a starting point. Capture its state, review the indexed activity, and turn the strongest leads into a case another analyst can pick up.

THE STARTING POINT
An address associated with a reported exploit or suspicious transfer.
Explore this team’s solution
INVESTIGATION PLAYBOOK / 01
  1. 01

    Capture the address and relevant network snapshot.

  2. 02

    Inspect counterparties, contract context, and source references.

  3. 03

    Record the hypothesis, unresolved questions, and follow-up actions.

THE DELIVERABLE

Incident evidence brief

An incident brief with transaction references and a clear investigation scope.

Address → counterparties → source record
INTELLIGENCE YOU CAN EXPLAIN

The finding matters.
So does the reasoning.

When a case moves between teams, the context should move with it. GroundTruth keeps the source record, the analyst’s interpretation, and the next question together.

01

Observe

Capture what the source actually reports, with the network, block, and time that put it in context.

02

Interpret

Describe the relationship and record your hypothesis. Keep uncertainty and alternative explanations visible.

03

Review

Save the rationale, mark the case’s review state, and export a record the next person can examine.

Explore the evidence package
GROUNDTRUTH / EVIDENCE RECORD
ILLUSTRATIVE CASE BRIEF

Treasury counterparty review

One record. Enough context for the next decision.

Review scope
Counterparty activity on Ink
Evidence basis
RPC snapshot + indexed activity
Source references
Network, block, transaction, timestamp
Analyst record
Hypothesis, rationale, open questions
Review state
Analyst reviewed
ANALYST NOTE

Review the funding relationship in context. A shared counterparty is an observation; the case records the evidence needed to assess its significance.

JSONCSVMARKDOWN
THE PARTNER PROGRAMME

Every ecosystem.
A wider
perspective.

Independent exchanges, asset services, and security teams see different parts of the same threat. GroundTruth brings those perspectives into a common investigation approach, shaped around each partner’s priorities.

Explore ecosystem partnerships
ECOSYSTEM INTELLIGENCE
EXCHANGES / SERVICES / ECOSYSTEMS
01

See the ecosystem as a whole.

Give the team a shared starting point for reviewing protocols, counterparties, and emerging patterns.

02

Bring context to the response.

Trace a lead from the first alert to a source-backed case the right team can act on.

03

Help good builders move forward.

Make diligence more repeatable, with evidence that can be checked and questions that can be answered.

ONE PLATFORM. MULTIPLE ECOSYSTEMS.
THE INTELLIGENCE ECOSYSTEM

Onchain. Offchain.
One connected case.

Follow the funds with blockchain intelligence. Understand the actors with threat intelligence. Bring the infrastructure and the evidence into the same picture.

INTELLIGENCE SOURCESChainalysisFlashpointRecorded FutureTRM LabsVirusTotal

Follow the exposure.

Chainalysis, TRM Labs, and Elliptic. Wallet screening, transaction context, and entity attribution, attached to the case that needs them.

BLOCKCHAIN INTELLIGENCE

Understand the adversary.

Flashpoint and Recorded Future. Bring deep and dark web reporting, threat-actor context, and indicator relationships into the investigation.

THREAT INTELLIGENCE

Connect the infrastructure.

VirusTotal and GreyNoise. Put domains, URLs, file hashes, and IP activity beside the onchain trail, with a source for every lead.

TECHNICAL CONTEXT

Make the handoff count.

MISP, OpenCTI, Splunk, and Microsoft Sentinel. Intelligence exchange and security operations workflows, with reviewed findings and the supporting source context.

TEAM WORKFLOWS

Commercial sources require appropriate API access and licensing. Data entitlements and network coverage vary by provider.

Explore all 11 integrations
FIT THE WAY YOUR TEAM WORKS

Your workspace.
Your environment.

Work with a local case store or connect the desktop app to a GroundTruth server in your environment. Choose the data boundary that fits the investigation.

THE ANALYST

GroundTruth workspace

Investigations · Notes · Evidence

THE INVESTIGATION LAYER

Private case store

Local or connected workspace

THE SOURCE RECORD

Network & explorer

Public data · Source references

Local workspace

A bundled backend and a case database on your Mac. Work with saved investigations, keep your notes close, and query public providers when a new snapshot is needed.

LOCAL CASE FILES / NO SEPARATE SERVER SETUP

Connected workspace

Keep your casework in a connected GroundTruth workspace. Sign in with your account, preserve the same investigation workflow, and manage deployment within your organization.

INDIVIDUAL ACCESS / PERSISTENT CASEWORK
THE PRACTICAL DETAILS

Evaluate with
the right questions.

Which investigations is GroundTruth designed for?

GroundTruth supports address and contract investigations, incident triage, counterparty reviews, and ecosystem diligence. Begin with a public address, inspect the available evidence, and preserve the reasoning behind your next decision.

Which networks can my team investigate?

Address investigations cover Ink, Ethereum, Base, Arbitrum, and Optimism. GroundTruth combines a block-specific network snapshot with available explorer context. Indexed activity, source coverage, and provider limits are kept in context so your team can assess the evidence appropriately.

How does GroundTruth keep a finding reviewable?

A case keeps the address, network, snapshot context, source references, and analyst notes together. Observed relationships remain separate from your conclusions. Review status and exported briefs help the next analyst understand both the evidence and the open questions.

Can we work with our own intelligence sources?

Integration scope starts with your existing provider licenses, API access, and operational requirements. Blockchain analytics, threat-actor reporting, infrastructure intelligence, and security operations tools each contribute a different kind of context. Data entitlements and coverage are assessed source by source.

How do we hand an investigation to another team?

Export a structured JSON evidence package, a CSV transaction worksheet, or a Markdown case brief. The saved analyst notes and source references travel with the relevant case export, giving reviewers a record they can inspect in their own workflow.

Can GroundTruth fit our own operating environment?

Use a local workspace with a case database on your Mac, or connect to a GroundTruth server with account-scoped access. The Security page explains the storage, session, and network boundaries so your team can evaluate the deployment against its requirements.

THE NEXT CONNECTION IS THE ONE THAT MATTERS.
MANY ECOSYSTEMS / ONE CONNECTED PICTURE

Connect the dots.
Own the investigation.

A wider view of the threat.
A clearer next move.

Register for the desktop trialEvaluate the workspace · No card required