Platform overview

Evidence that survives audit, insurer and court.

PhishNet collects fraud and threat signals, links them to brands and customers, preserves the source trail, and exports the proof your board, auditor, insurer or regulator can use. With qualified RFC 3161 timestamps, selected evidence can support court-grade EU workflows for prosecutions, insurance claims and TLPT evidence.

Opening platform pulse...
PhishNet evidence record with finding, source, hash, timestamp and collector fields
source trail preservedeIDAS timestamp-ready
-Searchable evidence corpusopening
-All-time stored findingsopening
-New findings in latest runopening
-Active collection lanesopening
-Live evidence checksopening
Capabilities

Four jobs your team can prove.

Every finding keeps its source trail, confidence, timestamp, review state and evidence links, so the number on a dashboard can always open the rows behind it.

EVIDENCE VAULT

Prove it, keep it, analyse it.

Every finding retains its source, SHA-256 hash, collector run and timestamp trail. Where a qualified RFC 3161 token is attached, the vault preserves eIDAS-qualified proof that can move from audit-grade to court-grade under EU law.

ANALYST SEARCH

Ask the corpus real questions.

Search across phishing journeys, impersonation infrastructure, kits, ransomware claims, exposure signals and evidence artifacts without losing the proof trail.

COLLECTION

EU-only signal across customer harm.

Phishing, smishing, ransomware, credential exposure, public attack surface, sanctions exposure, OT advisories and monitored public channels.

EXPORT CENTER

Citable, defanged, regulator-ready.

Turn findings into partner-safe indicators, regulator packets, board summaries or prosecution-ready evidence packs.

Chain of custody

From first sighting to board file, the source trail stays attached.

Every major counter and report claim should open the supporting rows, source policy, confidence, graph context and evidence record. That is the difference between a feed and a defensible file.

PhishNet chain of custody rail from capture to hash, timestamp and export
Who uses it

Built for the people who have to sign off.

The same evidence supports fraud response, NIS2 files, DORA reporting, insurer discussions, takedown work and executive briefings.

DEFENCE

Analysts and attribution.

Interrogate the corpus and keep attribution-grade provenance entirely inside EU jurisdiction.

REGULATED

Banks and insurers.

Build DORA evidence, fraud case files and claims packets that survive audit, insurer scrutiny and evidentiary challenge.

PARTNERS

MSSPs and research.

Run your own analysis over a feed you do not have to collect yourself, while keeping the export contract intact.

Contact

See the vault and notebooks live.

Book a tour and we will walk a finding from collector capture through the evidence vault to a citable export, including where qualified timestamp proof strengthens the final package.