Cross-source OSINT aggregation

One identifier in, one reconciled view out.

CrossTrace takes a single seed — an email, a username, a phone number, a domain — fans it across every OSINT API you hold a key for, and merges what comes back. Not three lists side by side: one deduplicated set of accounts, one identity profile with every value attributed to the source that asserted it, and a map that draws exactly as much precision as the source actually offered.

Bring your own API keys. AES-256-GCM at rest, scoped to your account, never shared between accounts.

Recorded run

one seed identifier · two APIs · measured, not modelled

raw account records returned72
distinct accounts after merge44
of which 15 corroborated by two or more sources
fields previously fetched, then dropped at render — now shown92

01Corroboration

Two APIs agreeing is the strongest signal you get

Three lists side by side leave the reconciling to you, and reconciling is where mistakes live. Accounts are keyed on what the account is — platform plus identity — so when two sources find the same one you get a single card that says both found it.

G

github

OSI, Opsis
@JasonDraper01
username✓✓JasonDraper01
user id✓✓10000001
name✓✓Jason Draper
location✓✓IL, US
One card. Two APIs found it; the amber chip says so.

02Pivoting

A search ends in the next search

Everything discovered becomes a term you can run, ranked by how many sources reported it. Pick a batch, see what it will cost across your keys, then run it — in the same view, not a second tab.

discovered terms6 total6 available · 0 searched · 0 unsearchable0 queries spent · 0 results
OSI 2 · Dehashed 2 · Opsis 1upper bound — cached and rejected queries cost nothing

available to search (6)

ranked by how many sources corroborate the term
Two terms selected. The cost of running them is shown before you commit.

03Location

A country-level claim is a country-shaped claim

Precision is parsed, never assumed. A city gets a point, a state gets the state outline, a timezone gets its real IANA boundary — because geocoding all of them to a pin invents precision the source never offered.

what the source said

  • Springfield, IL

    city → a point

  • US, IL

    region → the state outline

  • Raw: United States

    country → the country outline

  • America/Chicago

    timezone → the IANA zone boundary

Geocoding every one of these to a point would put the country claim somewhere in Kansas — and say the subject was there.

The same subject, drawn at four different precisions.

04Footprint

One consensus view of the whole footprint

Name, username, email, location — assembled from every source at once, each value carrying who asserted it. Where two disagree you are shown the disagreement rather than a winner picked on your behalf.

identity

name
Jason DraperOSI, Opsis
username
JasonDraper01OSI, Opsis
email
[email protected]OSI, Opsis, Dehashed
location
Springfield, IL, USOSI, Opsis
Every value carries the sources that asserted it.

05Detail

Ordered by what you can do next

Pivotable identifiers first, then security posture, then everything else — not by which API answered, and not by the order the bytes arrived. Nothing is dropped, only folded.

A

adobe

OSI, Opsis
email hintj *** 1@e *** e.com
phone hint*** 4471
mfanone
passwordyes
statusactive
Pivotable identifiers first, then security posture.

06Keys

Your keys, your credits

Bring your own credentials for the providers you already pay for. They are encrypted at rest with AES-256-GCM, scoped to your account, and never returned to the browser once saved. The result cache is scoped the same way, so nobody else's search is served from your credits.

Point it at one identifier and read what every source says at once.

You will need a key for at least one supported provider. Add it in Settings; the first search takes a few seconds.