Skip to Content
Open-source investigation platform

Follow the evidence.Close the case.

Classifyre reads the systems you already run, finds the signals you define, then follows them across sources, like a detective, with an AI autopilot doing the legwork between scans.

No signup. One Docker command. Your data stays with you.
Case file · 042
The Classifyre investigator, a detective cat on a green badge
Exhibit A: the investigatorOn duty
Start here
docker run -d --name classifyre \  -p 3000:3000 \  --shm-size=1g \  -v classifyre-pgdata:/var/lib/postgresql/data \  -v classifyre-data:/var/lib/classifyre \  -v classifyre-uv-cache:/cache/uv \  classifyre/all-in-one:0.6.11
The problem

Every system holds a fact. None of them holds the story.

A shipment went to the wrong address. The ERP knows the order, the support tool knows the complaint, the invoice run knows the money. On its own each is noise. Together they are a case, and today nobody can put them together.

The Classifyre investigator in a trench coat, scratching his head over an unanswerable question mark
Fig. 01: six systems, one story, no line between the facts
  • Field note 01

    Exports don't add up

    Rows lose their joins the moment they leave the database. Six CSVs later the relationships are gone and every question starts the review from zero.

  • Field note 02

    Findings tables dead-end

    A scanner lists 4,000 secrets and stops. Sorting them is still your job, and every rescan quietly adds a few hundred more.

  • Field note 03

    Nobody can say how they knew

    When a regulator, a court or a CFO asks what you knew and when, “the model said so” is not an answer. Evidence without lineage is a rumour.

The problem

It is the same shape every time: someone inside the company leaking a spreadsheet to help it, a counterparty three shell companies deep, a fraud pattern spread across five record systems. Scattered facts. One story.

Read the systems you already runBrowse the source catalogue →
Custom Connector
Sandbox
WordPress
Slack
S3-Compatible Storage
Azure Blob Storage
Google Cloud Storage
PostgreSQL
MySQL
Microsoft SQL Server
Oracle
Apache Hive
Databricks
Snowflake
Dremio
MongoDB
Neo4j
Power BI
Tableau
Confluence
Jira
Jira Service Management
SQLite
Notion
Email
YouTube
Reddit
Delta Lake
Apache Iceberg
Apache Kafka
Elasticsearch
OpenSearch
Meilisearch
Mounted Folder
Microsoft 365
Google Workspace
Dropbox
Hugging Face
Git Repository
Custom Connector
Sandbox
WordPress
Slack
S3-Compatible Storage
Azure Blob Storage
Google Cloud Storage
PostgreSQL
MySQL
Microsoft SQL Server
Oracle
Apache Hive
Databricks
Snowflake
Dremio
MongoDB
Neo4j
Power BI
Tableau
Confluence
Jira
Jira Service Management
SQLite
Notion
Email
YouTube
Reddit
Delta Lake
Apache Iceberg
Apache Kafka
Elasticsearch
OpenSearch
Meilisearch
Mounted Folder
Microsoft 365
Google Workspace
Dropbox
Hugging Face
Git Repository
The method

One thread through every system.

Classifyre is less a business-intelligence tool than an operational data layer: it connects the systems you already run, models the real-world entities and relationships inside them, and keeps one thread from the first hit to the closed case.

  1. 01Read

    Read the systems you already run

    Databases, lakehouses, collaboration tools, storage, streams and public registers. Scans ingest assets on a schedule and everything found lands in one evidence stream.

    Browse the source catalogue →
  2. 02Signal

    Define what matters, in your own words

    Regex and rules for the deterministic things, entity classification with your labels, any Hugging Face model, or a prompt that becomes a detector. Built-in packs cover PII, secrets, code security and content quality from the first scan.

    See the detector packs →
  3. 03Follow

    Follow it across sources

    Fingerprints tie the same fact together wherever it appears. Near-duplicates arrive grouped by cause, and lineage keeps the thread intact from the first hit to the last.

    How fingerprints and duplicates work →
  4. 04File

    Turn findings into a case

    Standing inquiries keep matching fresh evidence. Findings are ranked 0–1 with written reasons. A case collects the evidence, the competing hypotheses, an owner and an audit trail you can hand over.

    How cases work →
  5. 05Work

    Let the autopilot do the legwork

    Between scans, five agents wake in sequence: matching inquiries, opening cases, waking dead sources, drafting the detector you were missing, consolidating memory. Flip observe-only and everything stays a proposal.

    How the autopilot works →
Open the file

This is the part most tools leave to you.

A case, assembling itself
ANALYST LINKDUPLICATE MATCH · SENT FILE = INTERNAL FILECASE #42 · OPENClassified leak via emailHYPOTHESIS 1Sender traced: A. NovakHYPOTHESIS 2214 records exposedEMLIDTAGDUPBY AUTOPILOT
A classified file emailed out: sender traced, impact scoped, duplicate confirmed, every exhibit attributed.
  • EMLThe external email itself: headers, recipient, timestamp
  • IDSender identity resolved across the directory
  • CLASSClassification marking found inside the attachment
  • DUPInternal original confirmed by fingerprint
Walk the real thingshowcase.classifyre.com
Where it lands

The files look different. The method is the same.

Classifyre reads whatever the operation runs on; the sector only decides which signals you define first.

  • Finance · KYC · AMLTypical dataCustomer master, transactions, sanctions, account networksWhat gets followedLayered counterparties, a sanctioned name resurfacing under a new one
  • Healthcare operationsTypical dataAdmissions, transfers, theatre schedules, staffing, inventoryWhat gets followedCapacity leaks, waitlist patterns, inventory drift
  • Energy · utilitiesTypical dataSCADA, sensors, GIS, maintenance, market dataWhat gets followedSensor drift before failure, silent outages, contract anomalies
  • Supply chain · logisticsTypical dataERP orders, inventory, shipments, supplier recordsWhat gets followedShipments to the wrong address, ghost inventory, supplier overlap
  • TransportationTypical dataMaintenance logs, engineering records, ground operationsWhat gets followedDeferred defects, parts provenance, unlogged work
  • TelecommunicationsTypical dataNetwork topology, telemetry, incidents, field workWhat gets followedRoute abuse, SLA breaches before the complaints arrive
  • Retail · POS · SKUTypical dataSales, promotions, inventory, returns, competitor pricesWhat gets followedShrink, promotion abuse, return fraud
  • Law enforcement · civil investigationTypical dataCase records, persons and entities, financial and travel recordsWhat gets followedOne entity under three names, one thread across five record systems
  • Government · public sectorTypical dataProcurement, registers, correspondence, grantsWhat gets followedUndeclared interests, tender patterns, leaked documents
  • Internal audit · complianceTypical dataAccess logs, contracts, expenses, communicationsWhat gets followedThe leak, the conflict of interest, the control that stopped working

Sector data shapes from the published case literature of operational data platforms; outcome figures cited in the category context above are Palantir's published results, used to describe the market, not to claim Classifyre's.

Your move

Open your first case tonight.

Point it at one system you already run and see what the investigator finds. Everything you build carries over when you go remote with Helm.

One command tonight. The same core at scale.

The all-in-one image has the database, the UI and the scan workers in it; everything stays on your machine. The Helm chart runs the same core on Kubernetes when the estate grows.

All-in-one image · free · no signup
docker run -d --name classifyre \  -p 3000:3000 \  --shm-size=1g \  -v classifyre-pgdata:/var/lib/postgresql/data \  -v classifyre-data:/var/lib/classifyre \  -v classifyre-uv-cache:/cache/uv \  classifyre/all-in-one:0.6.11
Helm chart · scales to any size

Or run it on Kubernetes

Ephemeral scan workers scale to zero between runs and fan out as far as your estate goes. Your cluster, your data.

helm install classifyre \
  oci://registry-1.docker.io/classifyre/classifyre-core \
  --version 0.6.11
  1. Tonight, on your machine

    One Docker command. Sources, findings and cases stay local.

  2. At scale, on Kubernetes

    The same core as a Helm chart: scan workers scale to zero between runs.

  3. When it becomes infrastructure

    Enterprise adds SSO, roles, per-workspace authorization, tuned models and our engineers. Until then, this is all you need.

Straight answers

Questions people actually ask.

More detail lives in the docs · docs.classifyre.com