Skip to content
PROTOWORKS DEFENCE

NOMINAL

Request a briefing
LIVE/ENTITY RESOLUTION
34.05°S 18.42°E · 14:22:07Z/GRAPH-INTEL
// GRAPH-INTEL / ENTITY-RESOLUTION

Sightings become entities.
Entities become a network.
The network stays accountable.

Resolve selectors — ICAO-hex, MMSI, callsign, plate, a name spelled six ways — to named actors, then map how they connect. Ownership webs, laundering typologies and co-travel patterns render as legible graph shapes; named algorithms and a graph neural network propose, an analyst decides. Organised crime becomes a network you can read — case-bound, mandate-expiring, covered by a court-ready audit.

Request a walkthroughBack to live ops

RESOLVE QUEUE

AUTO ≥ 0.97
ENTITIES
612K
EDGES
3.4M
LINEAGE
SEALED

MERGES · LIVE

CA-19-BX TRK-0529
PLATE → SUBJECT
0.98
503·1147 VESSEL-114
MMSI → VESSEL
0.97
SAA214 FLIGHT-88
CALLSIGN · HOLD
0.91
ENTITIES 612K
EDGES 3.4M
RESOLVES TODAY 1,284
CONFIDENCE 0.97
LINEAGE SEALED
01 / RESOLVE THE SELECTOR

Thirty records, one actor.

One person or hull arrives under a hex address, an MMSI, a callsign, a plate, a phone, an IBAN, an email, and a name spelled six ways. Resolution folds them into one canonical entity — scored, banded, and reviewable rather than automatic.

RESOLVING
6 RECORDS → 1 CANONICAL PERSON · 4 JOIN · 1 HELD · 1 REJECTED
STRONGdeterministic key · auto
MERGEscored · high confidence
REVIEWheld for an analyst
DISTINCTrejected · not the same
CANONICALPERSON4 RECORDSPHONE · E.164+27·82·xxxSTRONG · 1.00ID NUMBER88…0827STRONG · 1.00NAMESipho NdlovuMERGE · 0.91HANDLEsndlovuMERGE · 0.88NAME · isiZuluS. NdlelaREVIEW · 0.62HELDPLATECA·19·BXDISTINCT · 0.24REJECTED
  • Blocking narrows an astronomically large pair space to a handful of candidates; a calibrated scorer then rates each pair as a probability in [0,1], and the score routes to a band rather than merging on its own.

  • Deterministic strong keys — a normalised E.164cellphone, an exact ID number — short-circuit to the Strong band, while orthography-aware name indexes co-bucket pairs that plain trigram matching drops across isiZulu, isiXhosa and Afrikaans spellings.

  • A person-class entity is never auto-merged, even on a perfect deterministic key; the pair is queued for an analyst with both surface forms and the shared address shown.

  • Every merge is written as a reversible event that re-homes each source record onto the canonical person with provenance intact — an unmerge restores both aggregates losslessly.

SEE ALSO

Selectors arrive already normalised and provenanced from OSINT

Resolution signature
BLOCKING → SCORED MATCHING
BANDS: STRONG / MERGE / REVIEW / DISTINCT
PERSON-CLASS NEVER AUTO-MERGED
ZA ORTHOGRAPHIES: isiZulu / Afrikaans / isiXhosa
MERGE REVERSIBLE — NO ASSERTION DESTROYED
Worked example — four records, one person
STRONGA shared E.164 cellphone and an exact ID number tie two records instantly — the deterministic short-circuit.
REVIEWNdlovu vs Ndlela co-bucket only through the isiZulu name index; scored 0.62, queued with both surface forms and the shared street address.
MERGEThe analyst confirms three of four as one person; the platform re-homes every source record onto the canonical entity.
DISTINCTThe Ndlela plate is rejected as a different household — and if a merge is ever wrong, an unmerge restores both aggregates losslessly.
02 / FOLLOW THE OWNERSHIP

People, companies, and the address that ties them.

Assets sit behind companies, trusts, and nominees; registry linkage turns a name list into an ownership picture. Eleven close corporations at one Umhlanga address, four sharing a director who resolves to a PEP’s relative, seven incorporated in one six-week window with no returns filed — apparent independent bidders collapsing into a single beneficial-ownership cluster.

OWNERSHIP GRAPH
  • Juristic entities — Person / Company / Trust / Address / Bank account — are first-class nodes, joined to people by typed directorship / shareholding / trustee edges.

  • Shared-attribute edges — a shared registered office, a shared director, a shared bank account — are what a spreadsheet cannot hold and the graph makes obvious.

  • Linking to the company registry (CIPC) resolves who ultimately controls an entity and which entities move together — a controller reads as one actor no matter how many shells front for it.

  • Incorporation dates, filing gaps and shared registration details are structural tells the ownership graph surfaces directly, without a name in common.

SEE ALSO

Registry records and sanctioned-entity data enter already sourced through OSINT

Ownership signature
NODES: PERSON / COMPANY / TRUST / ADDRESS / BANK ACCOUNT
EDGES: DIRECTORSHIP / SHAREHOLDING / TRUSTEE
SHARED-ADDRESS & SHARED-DIRECTOR RINGS
COMPANY-REGISTRY (CIPC) LINKAGE
11 SHELLS → 1 CONTROLLER
03 / READ THE MONEY AS SHAPE

Layering, structuring, and the loop that closes.

Laundering hides a controller behind movement, and every typology has a graph shape. Accounts are nodes, payments are amount-and-time-stamped directed edges — so a scheme that looks innocuous one transaction at a time renders as one legible subgraph.

TYPOLOGY WATCH
  • A layering chain is a long thin path: value moves hop by hop through personal accounts, each keeping a slice, before landing in an asset.

  • A structuring fan-out credits many accounts just under the reporting line, each drained in cash before any per-account rule can accumulate.

  • A circular flow is a cycle: remittances route back upstream of the controller, closing a loop a linear transaction monitor never joins up.

  • A pass-through node balances in and out over hours; a mule hub shows high out-degree over a short window — structure exposes what any per-transaction rule is blind to.

SEE ALSO

Transaction and beneficial-ownership feeds arrive sourced and normalised via OSINT

Worked model — one controller, three shapes
CHAINR2.4m · 9 hops · 70h from source to dealership sink.
FAN31 mule accounts credited <R49.5k, each withdrawn in cash within a day.
LOOPTwo mules remit back two hops upstream — the cycle closes on the controller.
HUBThe controller carries low throughput but the highest centrality — the node worth a warrant.
Typology signature
LAYERING = LONG THIN PATH
CIRCULAR FLOW = CYCLE
STRUCTURING / SMURFING FAN-OUT
PASS-THROUGH: IN ≈ OUT OVER HOURS
MULE HUB: HIGH OUT-DEGREE / SHORT WINDOW
04 / CORRELATE THE FOOTPRINT

One operator behind many aliases.

A fraudulent site or scam network leaves an identity-and-infrastructure footprint separate from any legal name. Each reused selector is a weak tie — inconclusive alone, conclusive fused — and the graph draws the aliases, the infrastructure, and the physical selectors that converge on a single operator.

FOOTPRINT WATCH
  • Weak ties — a reused email alias, a handle stem recycled across platforms, a device fingerprint on two accounts — are each inconclusive alone; the graph fuses them into one strong attribution.

  • Shared infrastructure — a hosting address, a reused TLS certificate, a sibling domain — ties five bank-impersonating phishing domains to one operator.

  • A single cellphone number appearing in both a domain registration and a legitimate second-hand-car listing is the edge that bridges the anonymous infrastructure to a real name.

  • Every edge is labelled by what links it — shared-cert, reused-handle, shared-phone — so the reach from a phishing domain to a person is auditable edge by edge.

SEE ALSO

Infrastructure and identity selectors are collected and sourced upstream in OSINT

Worked model — phishing domain to a person
SEEDA domain impersonating a bank; its registration email reuses the handle stem sbsaverify.
INFRAShared hosting and a reused TLS certificate tie four sibling bank-impersonating domains.
HANDLEThe same stem recurs across two messaging platforms and a classifieds account.
BRIDGEA registration cellphone also on a car listing resolves the cluster to a named individual.
Footprint signature
EMAIL ALIASES → ONE OPERATOR
REUSED HANDLES / PHONES ACROSS PLATFORMS
SHARED HOSTING / CERTIFICATE / DOMAIN
DEVICE & SELECTOR REUSE
ANONYMOUS INFRA → NAMED PERSON
05 / THE GRAPH MATH

Community, centrality, path, prediction.

The pictures above are outputs of named graph algorithms run over the governed store. None of them assert; they scope, rank, and propose — and an analyst confirms every result against source.

COMMUNITY · LOUVAIN / LEIDEN

Partitions a large graph into densely-connected clusters by optimising modularity; Leiden guarantees well-connected communities stable over millions of nodes.

Ring discovery — draws the boundary of the forty-node ring out of a hairball

CENTRALITY · PAGERANK / BETWEENNESS

Scores every node by its importance to network flow — degree, the brokers every path crosses, and importance propagated from important neighbours — over the whole graph.

Finding the controller — the hub worth a warrant, not the disposable edge node

PATHFINDING · BOUNDED k-HOP BFS

Finds the shortest typed-edge chain between two entities, or everything within k hops, via a bounded bidirectional search that meets in the middle and stays fast on a dense graph.

The connection question — returns the chain, every edge typed, sourced, re-walkable

LINK PREDICTION · RANKED LEADS

Scores not-yet-connected node pairs for how likely a real edge is, from shared neighbours and structural proximity, and ranks the proposals the data has not yet drawn.

Surfacing the hidden tie — a ranked look-here list an analyst confirms, never a conclusion
06 / AN UNTRUSTED RISK SIGNAL

What the network learns, a human decides.

A graph convolutional network refines each node by aggregating its neighbours’ features — one message-passing step per hop — so after several hops a node’s representation carries the character of its whole neighbourhood. It is deliberately untrusted: the model says this neighbourhood resembles risk; the analyst decides what it means.

MODEL · UNTRUSTED
Graph convolution · per layer
1
GATHER
Pull the feature vector of every direct neighbour.
2
AGGREGATE
Combine them — a mean or an attention-weighted sum — into one message.
3
UPDATE
Fold that message into the node's own representation.
4
REPEAT ×K
Each layer widens the receptive field one more hop, so after K layers a node carries the character of its whole K-hop neighbourhood.
THE REPRESENTATION FEEDS TWO HEADS
NODE CLASSIFICATION→ ENTITY RISK
LINK PREDICTION→ HIDDEN EDGES
Untrusted · thresholded · routed to review · model vX.Y stamped · never an accusation
  • The representation feeds two heads: node classification risk-scores an account or entity from the company it keeps, and link prediction proposes probable hidden edges.

  • A score can flag a laundering-shaped neighbourhood without any single rule firing — which is exactly why it is treated as untrusted, thresholded and routed to review rather than acted on.

  • Every run is stamped with model name and version; the output is never an authoritative accusation and never an automatic action against a person.

SEE ALSO

Why a model signal can never merge a person or act unreviewed is set out under GOVERNANCE

Model signature
MESSAGE-PASSING OVER NEIGHBOURS × HOPS
NODE CLASSIFICATION = ENTITY RISK SCORE
GNN LINK PREDICTION
UNTRUSTED FEED — ANALYST-REVIEWABLE
MODEL NAME/VERSION STAMPED PER RUN
07 / ONE GRAPH, MANY LENSES

Three networks. One graph. Five questions.

The infrastructure, the identities and the ownership ring are not three cases — they are one graph, fused by a few weak ties. Run a different algorithm over it and it answers a different question. Select a lens and watch the same network re-read itself.

ONE GRAPH · MANY QUESTIONS
INTERNET-FACING
FAKE IDENTITY
BENEFICIAL OWNERSHIP
RESOLVED PERSON
COMMUNITY · LEIDEN / LOUVAIN
WHAT IT SHOWS
Which nodes belong together — it colours the graph into the groups that talk to themselves more than to anyone else.
HOW IT WORKS
It keeps moving each node into whichever neighbouring group raises the overall density of within-group edges, until no single move helps. The three intelligence sub-networks fall out as three colours.
ON THIS GRAPH · FINDING
Three dense clusters — infra, identity, ownership — with four weak inter-cluster ties holding them together.
MODULARITY PARTITION → 3 COMMUNITIES
INFRA · IDENTITY · OWNERSHIP
WEAKLY-CONNECTED = 1 COMPONENT
FUSED BY 4 BRIDGE EDGES
CUT A BRIDGE → GRAPH SPLITS IN TWO
  • Three clusters that most tools keep in three tools — internet-facing infrastructure, fabricated usernames, accounts and IDs, and CIPC beneficial ownership — are one store here, so a lead in one becomes a lead in all three.

  • A handful of weak ties fuse them: a phone on both a WHOIS record and a car listing, a handle reused as a domain registrant, a controller signing in from a known device. Each is a bridge— cut it and the graph splits back into islands.

  • The picture never changes; the question does. Community detection draws the boundaries, centrality ranks the hubs, bounded pathfinding returns the typed chain, link prediction proposes the undrawn edge, and the GNN lights a risk field — five reads of one layout.

  • None of the five asserts. They scope, rank, propose and flag; every edge stays typed and sourced, and an analyst confirms the result against the record before it means anything.

What the merge buys
THREE SUB-NETWORKS → ONE COMPONENT
WEAK TIES = LOAD-BEARING BRIDGES
SAME LAYOUT · FIVE ALGORITHMS
PARTITION · RANK · PATH · PREDICT · SCORE
EVERY EDGE TYPED, SOURCED, RE-WALKABLE
ALGOS SCOPE — ANALYSTS CONFIRM
08 / SCREEN THE NEIGHBOURHOOD

Sanctions and PEP, one hop out.

A resolved entity and its immediate neighbours are screened against a consolidated sanctions and politically-exposed-person set — OFAC, UN, EU, national lists, plus PEP and beneficial-ownership data. What a flat name-list check misses, the neighbourhood surfaces.

SCREENING WALK
  • Screening runs on the canonical entity, not a surface name, so a spelling variant cannot slip a list.

  • The walk reaches one hop out to the immediate neighbourhood — a director, a co-signatory, a spouse, a trustee — and is bounded so it stays proportionate.

  • A clean company surfaces a director who resolves through an isiXhosa variant to a national PEP, and a co-director two hops from an OFAC-listed entity through a shared trust — neither matches the company’s own name.

  • Every hit returns ranked, with its connecting path shown, for an analyst to confirm or dismiss — never an automatic accusation; the list version is written to the audit spine.

SEE ALSO

Sanctions, PEP and registry sources are ingested and version-stamped in OSINT

Screening signature
SCREEN THE CANONICAL ENTITY
CONSOLIDATED SANCTIONS + PEP SET
NEIGHBOUR HITS ONE HOP OUT
CONNECTING PATH SHOWN PER HIT
LIST VERSION WRITTEN TO AUDIT
09 / CO-TRAVEL AND PATTERN-OF-LIFE

Coincidence, or a relationship.

Under a lawful mandate, link analysis over accumulated sightings turns time-stamped points into behaviour: repeated co-occurrence separates coincidence from relationship. Rendezvous land on one timeline, the shared route on one map — and when the mandate expires the correlation stops and the retention clock starts.

MANDATE-BOUND
SUBJECTCO-TRAVEL VEHICLE3-WEEK WINDOW · ANPR READS01·07h02·07h03·07h04·07h05·07h06·07hMANDATEEXPIRESSIX MORNINGS · SAME STATION → ONE KEEPERSUBJECT · plate ACO-TRAVEL · plate BFILLING STN · 10-MIN WINDOWKEEPER · 2 HOPSresolved in graph
  • Co-occurrence— two subjects, or a subject and a vehicle, at the same place inside the same short window, repeatedly — is the signal a pair of separate position lists can never show.

  • It is descriptive of what was observed, never a prediction of intent and never a behavioural score on a person; every point carries its sensor, timestamp, and authorising mandate.

SEE ALSO

The ANPR reads and sightings the temporal read leans on originate in SENSORS

Worked model — six mornings, one relationship
MANDATEAuthorises tracking one vehicle by plate — scope, subject, lawful basis, expiry.
CO-TRAVELA second plate coincides within a 10-minute window on six separate mornings.
RESOLVEThe second keeper sits two hops from the subject already in the entity graph.
EXPIREOn expiry the correlation stops and the retention clock starts — descriptive, never predictive.
Pattern signature
CO-OCCURRENCE = SAME PLACE / SAME WINDOW
RECURRING RENDEZVOUS ON ONE TIMELINE
CO-TRAVEL PAIR → ENTITY GRAPH
DESCRIPTIVE, NOT PREDICTIVE
MANDATE-BOUND / EXPIRES / RETENTION CLOCK
10 / GOVERNED BY CONSTRUCTION

Every edge lawful, every read logged.

None of this is capability without governance, and the governance is structural, not policy. The four guarantees below hold by construction — they are how the graph operates, not rules layered on top.

Mandate · subject-of-interest
38DAYS
SUBJECTscope-bound · in mandate
BASISPOPIA · authorising officer
EXPIRY≤ 90 days · automatic
LAPSEstops resolving on expiry
Red line · persons enter only under an authorising mandate
Audit spine · hash-chained
TAMPER-EVIDENT
READentity · neighbourhood walk9f3a…c1
↓ links prior hash
MERGEanalyst-confirmed · reversible4b7e…8d
↓ links prior hash
SCREENlist v2026.07 · hit confirmeda1c9…52
↓ links prior hash
MODELGNN score · routed to reviewe6d0…7f
  • A person enters the graph only under a mandate carrying subject, scope, lawful basis, and a hard expiry capped at ninety days the system enforces automatically.

  • Every access — read as well as write — writes a hash-chained, tamper-evident audit row, so who saw what, and when, is answerable end to end.

  • Model output is an untrusted feed the analyst confirms; a merge, a screening hit, and a pattern are all analyst-confirmed and reversible — and person risk-scoring is excluded by construction.

  • A query that would cross a tenant boundary or run without a lawful basis does not execute — governance the graph cannot express its way around.

Governance signature
MANDATE-GATED / EXPIRY ≤ 90 DAYS
POPIA LAWFUL BASIS AT THE BOUNDARY
HASH-CHAINED AUDIT OVER READS + WRITES
ANALYST-CONFIRMED, REVERSIBLE MERGES
NO LAWFUL BASIS → DOES NOT EXECUTE
ENGAGEMENT

Resolve the selector, map the network, keep the audit.

Talk to our team about a Graph Intelligence walkthrough — entity resolution over your selectors, link analysis across your area of operations, and a governance review against POPIA.

Request a walkthroughBack to live ops