The Greyline Verification Standard

Technology

The named tool stack behind Greyline's analysis, and the platform layer, Greyline Sentinel, live today, and the Greyline Intelligence Cloud, on our roadmap.

Method · Technology

Named tool stack, and the platform layer: Greyline Sentinel and the Greyline Intelligence Cloud.


Tooling as Enabler, Not Replacement

Greyline’s analysts work with a defined stack of licensed OSINT, forensic, and monitoring tooling. These tools accelerate collection and cross-referencing. They do not replace analyst judgement, and they do not sign off findings.

Every tool in the stack is selected and maintained to the evidential standard described throughout this section. If a tool cannot produce output that meets our chain-of-custody and reproducibility requirements, we do not use it for evidential work.


The OSINT and Investigation Stack

Our analysts use a curated set of licensed platforms and tools for:

We do not rely on free tools for evidential work where a licensed, auditable alternative exists. The provenance of our tooling matters as much as the provenance of our evidence.


Forensic and Capture Tooling

For digital evidence collection, we use:

All forensic tooling is maintained, version-controlled, and documented. If a court asks what tool produced a given image and how it works, we can answer.


Greyline Sentinel

Greyline Sentinel is our internal platform for structured collection and case management. It is the system our analysts use today to:

Sentinel is not a client-facing platform. It is the operational backbone that ensures the standard is met on every engagement.


Greyline Intelligence Cloud

Greyline Intelligence Cloud is on our product roadmap. It is a planned extension of Sentinel for clients who want ongoing, structured visibility into a live monitoring engagement.

What it is not: It is not yet built. It is not available to instruct. We are naming it here so the direction of travel is transparent, not to describe a live capability or a plan a client can currently sign up to.

What it is intended to be: A client-accessible layer for ongoing engagements, threat monitoring, brand surveillance, executive protection, where the client needs real-time visibility into what we are seeing and how we are assessing it.

When Intelligence Cloud moves from roadmap to live product, this page will be updated with full technical and security specifications.


AI and Automation: Our Position

We use AI-assisted tools in two contexts:

  1. Collection assistance: Pattern-matching, candidate surfacing, large dataset triage. The AI flags; the analyst verifies.
  2. Synthetic intelligence detection: Probabilistic detection of AI-generated content, deepfakes, and synthetic media. Findings are worded as consistent with synthetic generation, not proof of it.

In both cases, the analyst’s verification is mandatory and documented. We do not use generative AI to write findings, to draft reports, or to reach analytical conclusions. The accountability chain runs from the evidence, through the analyst, to the named signatory. AI is not in that chain.


Data Security and Jurisdiction

All case data is held on UK-jurisdiction infrastructure. Data is:

We do not store client data on cloud infrastructure outside UK or EEA jurisdiction without explicit client consent and a documented legal basis.


What This Means for the Client

You engage a firm where:

See the Standard Applied

Explore the rest of our method.