Most investigative work fails in the gaps. Collection happens in a browser, notes live in a document, images sit in a folder, the graph is drawn in a separate tool, and the report is written from memory at the end. Every handover between those tools loses context, and the question an auditor asks months later — why did you accept this as true? — no longer has an answer.
Engramite closes those gaps. It is a single workspace where an investigation is opened, sourced, argued, reviewed and written up, with every step attached to the same case file.
One case file, from question to report
An investigation starts with a question: a subject, a scope, and the result you need. From there, everything you gather belongs to that case — documents, source pages, downloads, images, entities, and the findings drawn from them.
Nothing floats loose. Every item in the case file carries the decision that let it in, so the reasoning behind a conclusion is still there long after the work is finished.
An agent that plans, and an analyst who decides
The Engramite Agent interprets the request, chooses which capabilities to use, and coordinates the work across the case. It breaks a request into steps and reports what comes back from each one.
What it never does is decide alone. You choose how much latitude it has — manual, supervised or automatic — which sets whether each tool run waits for your confirmation. The agent proposes; the investigator accepts, rejects, or asks for more.
Evidence that survives review
Findings are not facts because a machine produced them. Engramite keeps accepted findings separate from uncertain and rejected material, and records why each one landed where it did. A match between two identities is a lead until something exact links them — and the workspace is built to keep that distinction visible rather than quietly collapsing it.
That separation is what makes the final report defensible. Read more in accepted, rejected, and why the difference matters.
It runs on your machine
Engramite is local-first. Collection, models and the case file live on the analyst's own device, and material leaves only when the analyst sends it. For work involving named people, that is not a preference — it is the difference between an investigation you can defend and one you cannot.
See device zero for what that means in practice.
The parts you will actually use
- Archive — the case file itself: sources, documents, downloads, reports.
- Engramite Graph — entities, evidence and relationships as a connected graph.
- Engramite Writer — approved findings turned into a structured report.
- Engramite Map — signals, reports and locations placed in spatial context.
- Engramite Browser — reading sources without exposing the operator.
- Vision — reading images, reverse search, and where a photo was taken.
- Leaks — breach and dark web exposure tied to a subject under review.
- Campaigns — authorized phishing simulations and how people react.
- Plugins — specialist tools added or removed per case.
Frequently asked questions
Is Engramite an OSINT tool? It covers open-source collection, but a collection tool is only part of it. The workspace exists to turn collected material into reviewed findings and a report that holds up.
Who is it for? Investigators, corporate security and due-diligence teams, and analysts who have to show their work.
Does my case data go to a vendor cloud? No. The platform runs on your machine, and material leaves only when you send it.
Want to see it against your own workload? Talk to us.
