← OSIRIS

Data & Privacy

OSIRIS is a front end over public data sources. It does not hold an intelligence database of its own: nearly every panel answers by querying somebody else's service in real time. That has a consequence worth stating plainly, because it is easy to miss.

YOUR QUERY LEAVES THIS INSTANCE

When you look up an email address, domain or IP, that value is forwarded to the upstream provider that answers the lookup. The provider sees what you searched for, and the search itself can reveal what you are investigating. Self-hosting OSIRIS changes who operates the front end β€” it does not stop these outbound queries. If the subject of an investigation is sensitive, treat every lookup as disclosed to the provider listed below.

AUTOMATIC IP GEOLOCATION

Three seconds after the dashboard loads, the browser calls /api/geo. The server reads your apparent IP address from the usual proxy headers and asks an external geolocation provider where it is, so the map can open near you rather than on the middle of the Atlantic. Interacting with the page before that β€” a click, a key press β€” cancels the request and the map stays where it is. Nothing about the result is written to your account, because there are no accounts.

WHERE DATA GOES

ServiceWhat is sentWhen
ipapi.co, freeipapi.com, ip-api.comYour apparent IP addressAs the dashboard loads, to fly the map to your city
api.xposedornot.comThe email address you searchBreach lookups
cavalier.hudsonrock.comThe email or domain you searchInfostealer lookups
internetdb.shodan.io, stat.ripe.net, rdap.org, dns.googleThe host, IP or domain you searchInfrastructure lookups
crt.shThe domain you searchCertificate transparency lookups
api.github.comThe username you searchGitHub account lookups
otx.alienvault.com, cve.circl.lu, cveawg.mitre.orgThe indicator or CVE you searchThreat and vulnerability lookups
Google GeminiThe feed context you submit for analysis, including Live Alerts headlinesAI briefing, analysis and overview requests, when the instance has a Gemini key
Telegram (cdn*.telesco.pe)Your IP address, as with any image requestWhen you expand a Live Alert that has a photo or video preview
NOAA nowCOAST (nowcoast.noaa.gov)Your IP address and the part of the map in view, as with any map tileOnly while the Live Clouds layer is switched on
DigitalDon (widget.digitaldon.net)The token you search, and your IP address, as with any page you open. No referrer or site name is sentOnly when you run a DonBot token scan, in Markets β†’ Crypto or RECON β†’ DonBot. Its page runs sealed in its own frame, and counts its own usage there
The AI provider you choose for OI (OpenAI, Anthropic, Google, OpenRouter, Groq, DeepSeek, xAI, Mistral or Alibaba Cloud)Your API key; for a forecast, your question and any data you add (pasted text, or the text of files you attach, read in your browser), with the OSIRIS headlines picked for it; for OI Assist, the conversation, where the map is looking, which layers are on, and what OI found on the map for you. Sent from the OSIRIS server, not your browser, so the provider sees our address, not yoursOnly when you run an OI forecast, talk to OI Assist, check a key, or question the panel, on the key you supplied
GDELT (api.gdeltproject.org), Wikipedia (en.wikipedia.org) and the news sites they point toA few search keywords drawn from your forecast question, and requests for the articles found. Sent from the OSIRIS server, not your browserWhen you run an OI forecast with research and live intelligence switched on
photon.komoot.io, nominatim.openstreetmap.orgThe place name searched. Sent from the OSIRIS server, not your browserWhen you search for a place, or OI Assist looks one up to take you there
Your browser’s speech recognition (in Chrome and Edge, a Google or Microsoft service)Your voice, while the microphone is on. OSIRIS never receives the audio, only the words it becomes, which you then send to OIOnly when you press the microphone in OI Assist. Firefox has no speech recognition, so the button does not show there

Each service applies its own privacy policy and retention to what it receives. OSIRIS does not control, and cannot undo, what an upstream provider keeps.

AI FEATURES

Briefings and correlation are produced by Google Gemini from the feed context the request carries. Do not paste confidential source material into them. A briefing is a language model's summary of its input: fluent prose is not verification, and the claims inside still need checking against the underlying feeds.

OI runs on your own key. It stays in your browser (only this tab, unless you ask to be remembered on the device) and goes to OSIRIS in a request header when you start a run, check a key or question the panel. The server passes it to the provider you chose for that request and holds it only while your run is going: it is not written to disk, logged or shown back. A run itself is not private: anyone with its link can watch it, and it is kept in memory for three hours after it ends. Its forecast is a simulation by language models, not a prediction anyone stands behind.

OI Assist keeps the conversation in your browser tab, and only for as long as the tab is open. Each time it thinks, the conversation so far goes to OSIRIS and on to your provider; the server does not keep it. What OI does on the map (where it flies, which layers it switches, what it marks) happens in your browser. Replies read aloud use your browser's own voice, on your device.

SCANNING

Active scans are rate limited, restricted to a safe subset, and blocked against private and reserved address space. That is a safety floor, not permission: scanning infrastructure you are not authorised to test may be unlawful where you or the target are located, and authorisation remains yours to obtain.

Last reviewed against the codebase: 17 September 2026.