Data & Privacy
OSIRIS is a front end over public data sources. It does not hold an intelligence database of its own: nearly every panel answers by querying somebody else's service in real time. That has a consequence worth stating plainly, because it is easy to miss.
YOUR QUERY LEAVES THIS INSTANCE
When you look up an email address, domain or IP, that value is forwarded to the upstream provider that answers the lookup. The provider sees what you searched for, and the search itself can reveal what you are investigating. Self-hosting OSIRIS changes who operates the front end β it does not stop these outbound queries. If the subject of an investigation is sensitive, treat every lookup as disclosed to the provider listed below.
AUTOMATIC IP GEOLOCATION
Three seconds after the dashboard loads, the browser calls /api/geo. The server reads your apparent IP address from the usual proxy headers and asks an external geolocation provider where it is, so the map can open near you rather than on the middle of the Atlantic. Interacting with the page before that β a click, a key press β cancels the request and the map stays where it is. Nothing about the result is written to your account, because there are no accounts.
WHERE DATA GOES
| Service | What is sent | When |
|---|---|---|
| ipapi.co, freeipapi.com, ip-api.com | Your apparent IP address | As the dashboard loads, to fly the map to your city |
| api.xposedornot.com | The email address you search | Breach lookups |
| cavalier.hudsonrock.com | The email or domain you search | Infostealer lookups |
| internetdb.shodan.io, stat.ripe.net, rdap.org, dns.google | The host, IP or domain you search | Infrastructure lookups |
| crt.sh | The domain you search | Certificate transparency lookups |
| api.github.com | The username you search | GitHub account lookups |
| otx.alienvault.com, cve.circl.lu, cveawg.mitre.org | The indicator or CVE you search | Threat and vulnerability lookups |
| Google Gemini | The feed context you submit for analysis, including Live Alerts headlines | AI briefing, analysis and overview requests, when the instance has a Gemini key |
| Telegram (cdn*.telesco.pe) | Your IP address, as with any image request | When you expand a Live Alert that has a photo or video preview |
| NOAA nowCOAST (nowcoast.noaa.gov) | Your IP address and the part of the map in view, as with any map tile | Only while the Live Clouds layer is switched on |
| DigitalDon (widget.digitaldon.net) | The token you search, and your IP address, as with any page you open. No referrer or site name is sent | Only when you run a DonBot token scan, in Markets β Crypto or RECON β DonBot. Its page runs sealed in its own frame, and counts its own usage there |
| The AI provider you choose for OI (OpenAI, Anthropic, Google, OpenRouter, Groq, DeepSeek, xAI, Mistral or Alibaba Cloud) | Your API key; for a forecast, your question and any data you add (pasted text, or the text of files you attach, read in your browser), with the OSIRIS headlines picked for it; for OI Assist, the conversation, where the map is looking, which layers are on, and what OI found on the map for you. Sent from the OSIRIS server, not your browser, so the provider sees our address, not yours | Only when you run an OI forecast, talk to OI Assist, check a key, or question the panel, on the key you supplied |
| GDELT (api.gdeltproject.org), Wikipedia (en.wikipedia.org) and the news sites they point to | A few search keywords drawn from your forecast question, and requests for the articles found. Sent from the OSIRIS server, not your browser | When you run an OI forecast with research and live intelligence switched on |
| photon.komoot.io, nominatim.openstreetmap.org | The place name searched. Sent from the OSIRIS server, not your browser | When you search for a place, or OI Assist looks one up to take you there |
| Your browserβs speech recognition (in Chrome and Edge, a Google or Microsoft service) | Your voice, while the microphone is on. OSIRIS never receives the audio, only the words it becomes, which you then send to OI | Only when you press the microphone in OI Assist. Firefox has no speech recognition, so the button does not show there |
Each service applies its own privacy policy and retention to what it receives. OSIRIS does not control, and cannot undo, what an upstream provider keeps.
AI FEATURES
Briefings and correlation are produced by Google Gemini from the feed context the request carries. Do not paste confidential source material into them. A briefing is a language model's summary of its input: fluent prose is not verification, and the claims inside still need checking against the underlying feeds.
OI runs on your own key. It stays in your browser (only this tab, unless you ask to be remembered on the device) and goes to OSIRIS in a request header when you start a run, check a key or question the panel. The server passes it to the provider you chose for that request and holds it only while your run is going: it is not written to disk, logged or shown back. A run itself is not private: anyone with its link can watch it, and it is kept in memory for three hours after it ends. Its forecast is a simulation by language models, not a prediction anyone stands behind.
OI Assist keeps the conversation in your browser tab, and only for as long as the tab is open. Each time it thinks, the conversation so far goes to OSIRIS and on to your provider; the server does not keep it. What OI does on the map (where it flies, which layers it switches, what it marks) happens in your browser. Replies read aloud use your browser's own voice, on your device.
SCANNING
Active scans are rate limited, restricted to a safe subset, and blocked against private and reserved address space. That is a safety floor, not permission: scanning infrastructure you are not authorised to test may be unlawful where you or the target are located, and authorisation remains yours to obtain.
Last reviewed against the codebase: 17 September 2026.