Cross-source OSINT aggregation
One identifier in,
one reconciled view out.
CrossTrace takes a single seed — an email, a username, a phone number, a domain — fans it across every OSINT API you hold a key for, and merges what comes back. Not three lists side by side: one deduplicated set of accounts, one identity profile with every value attributed to the source that asserted it, and a map that draws exactly as much precision as the source actually offered.
Bring your own API keys. AES-256-GCM at rest, scoped to your account, never shared between accounts.
Recorded run
one seed identifier · two APIs · measured, not modelled
01Corroboration
Two APIs agreeing is the strongest signal you get
Three lists side by side leave the reconciling to you, and reconciling is where mistakes live. Accounts are keyed on what the account is — platform plus identity — so when two sources find the same one you get a single card that says both found it.
02Pivoting
A search ends in the next search
Everything discovered becomes a term you can run, ranked by how many sources reported it. Pick a batch, see what it will cost across your keys, then run it — in the same view, not a second tab.
available to search (6)
ranked by how many sources corroborate the term03Location
A country-level claim is a country-shaped claim
Precision is parsed, never assumed. A city gets a point, a state gets the state outline, a timezone gets its real IANA boundary — because geocoding all of them to a pin invents precision the source never offered.
what the source said
Springfield, ILcity → a point
US, ILregion → the state outline
Raw: United Statescountry → the country outline
America/Chicagotimezone → the IANA zone boundary
Geocoding every one of these to a point would put the country claim somewhere in Kansas — and say the subject was there.
04Footprint
One consensus view of the whole footprint
Name, username, email, location — assembled from every source at once, each value carrying who asserted it. Where two disagree you are shown the disagreement rather than a winner picked on your behalf.
05Detail
Ordered by what you can do next
Pivotable identifiers first, then security posture, then everything else — not by which API answered, and not by the order the bytes arrived. Nothing is dropped, only folded.
06Keys
Your keys, your credits
Bring your own credentials for the providers you already pay for. They are encrypted at rest with AES-256-GCM, scoped to your account, and never returned to the browser once saved. The result cache is scoped the same way, so nobody else's search is served from your credits.
Point it at one identifier and read what every source says at once.
You will need a key for at least one supported provider. Add it in Settings; the first search takes a few seconds.