SECURITY & DATA HANDLING

Know the boundaries.
Trust the process.

Your team should know where a case lives, which sources an investigation reaches, and how access is controlled. These are the boundaries behind the GroundTruth workspace.

Explore deployment options
Account-scoped accessDefined data boundariesPreserved source context
THE OPERATING MODEL

Specific controls.
Clear responsibilities.

Choose a deployment, document its scope, and apply the security controls appropriate to your environment.

01

Case storage

Local workspaces keep case files in a SQLite database on your Mac. Connected workspaces keep them on the chosen GroundTruth server. Local and server case stores are separate.

Device and server disk policies determine protection at rest. Apply your organization’s access, retention, and backup policies to the environment you operate.

02

Identity and sessions

Server workspaces use individual accounts with salted password hashes and revocable sessions. Case reads and writes are scoped to the account that owns the case.

Your desktop sign-in is separate from the website. Persisted desktop credentials use the operating system’s secure-storage facility when available.

03

Network boundaries

The bundled backend binds to the local loopback interface. Remote workspaces use an HTTPS server origin; authenticated writes include origin checks.

Live investigations send the selected public address to configured network RPC and explorer providers. Saved analyst notes are stored with the case, rather than included in those public-source queries.

04

Read-only investigation

GroundTruth queries public evidence. It does not ask for wallet private keys or seed phrases, and the investigation workflow does not sign blockchain transactions.

Review outputs support an analyst’s decision. The identity, attribution, and implications of a relationship remain matters for evidence-based assessment.

05

Source integrity

Network reads retain their block context. Indexed activity, source references, and provider gaps remain part of the investigation record.

Exports carry the saved case context and data mode. Illustrative sample cases retain their sample label when exported.

FOLLOW THE DATA

Three boundaries.
No ambiguity about the case.

Public source queries, stored casework, and exported evidence have different purposes. Treat each according to the information it contains.

01

Public source query

Network + public address

Used to retrieve blockchain state and explorer context. Provider terms and infrastructure determine their logging and retention.

02

Case record

Evidence + analyst notes

Stored in your selected workspace. On a server, access follows the owning GroundTruth account and the deployment’s infrastructure controls.

03

Evidence export

A copy you choose to share

Written to the location you select. Your team controls recipients, storage, and onward distribution of the exported material.

Evaluate GroundTruth against your own operating and procurement requirements.

THE NEXT CONNECTION IS THE ONE THAT MATTERS.
MANY ECOSYSTEMS / ONE CONNECTED PICTURE

Connect the dots.
Own the investigation.

A wider view of the threat.
A clearer next move.

Register for the desktop trialEvaluate the workspace · No card required