A solid foundation
Run investigations on a durable graph core that stays stable while your tooling comes and goes.
Flowsint is an open-source graph analysis and intelligence platform. Collect entities, run enrichment flows and read every relationship your investigation depends on - all in one graph.
Google sign-in, Stripe billing, no credit card for the free credits in your account.
OSINT tools evolve, appear and disappear. What never changes is the need to see, exploit and analyse data clearly. Flowsint gives your investigations a durable base, and turns tooling into extensions you can plug in or remove at any time.
Instead of juggling fragile scripts and siloed services, centralise what you know in one graph. Add a new source, swap an API, change a schema - the case stays intact and your insight keeps compounding.
Run investigations on a durable graph core that stays stable while your tooling comes and goes.
Connect or replace OSINT collectors in minutes through Python, REST or n8n. No lock-in.
Centralise, link and visualise entities and relationships instead of juggling scripts and spreadsheets.
Add fields and entity types as the case evolves without breaking the data you already collected.
Create a flow, run it against the entities in your case, then read the result in the graph. Nothing here needs a schema migration or a deploy.
Choose the entity type that should trigger work and chain the enrichers you need.
Executions stream their logs back to the workbench, so you watch each enrichment land.
Follow the relationships in the graph, pivot on neighbours, and export the case when it closes.
Flowsint is designed around a stable core and a wide edge: entity exploration, schema modelling and enrichment all stay independent of each other.
An interactive graph UI to explore, edit and expand entities and their relationships. Expand neighbours by hop, filter by type and follow the path that matters.
Define how your data is structured with dynamic schemas. Strongly typed fields, rich relations and validation keep the graph clean as the investigation grows.
Write enrichment steps as simple Python or REST webhooks, then run them by hand or chain them into flows that keep the graph current.
Flowsint plugs into n8n workflows (or any other webhook connector) to reach more than 500 services. Build automation that keeps the graph enriched while you work the case.
Collect and enrich data from public sources as soon as new entities land in the case.
Trigger alerts in Slack or Teams when indicators of compromise appear in the graph.
Generate and distribute case reports to email or cloud storage at every milestone.
Search multiple platforms for one entity and merge the new connections back into the graph.
Flowsint is built for professionals who have to explain how people, infrastructure, money and content connect.
Investigate threats, analyse attack patterns and map threat actor relationships.
Gather and analyse open-source intelligence from many sources in one graph.
Uncover connections, trace relationships and build stories that hold up.
Monitor the competitive landscape and map business relationships.
Track emerging technologies, patents, papers and the people behind them.
Map, enrich and navigate interconnected data without writing a platform first.
Planned capabilities that make Flowsint more powerful for investigation work. The core stays open source.
Model any domain with your own types instead of a fixed set of entities.
Ship a maintained catalogue of enrichers next to the platform itself.
Import and export full STIX 2.x objects for cyber threat intelligence workflows.
Every plan opens the same workbench. Choose monthly or yearly billing, and upgrade when your investigations grow.
300 credits a month, one investigation at a time.
1,000 credits, saved views and scheduled flows.
3,000 credits, team seats and priority support.
Monthly and yearly subscriptions run through Stripe. See the full comparison on the pricing page.
Short answers about the platform, the data it works with and how billing fits together.
Flowsint is an open-source graph analysis and intelligence platform. It centralises entities and relationships in one graph, so enrichment tools can be plugged in, replaced or chained without losing the investigation.
Any source you can reach from a Python or REST webhook: DNS and WHOIS records, certificate transparency, breach datasets, public registries, social platforms or your own internal systems.
The workbench is point and click. Enrichers are the developer surface: they are small Python or REST handlers, and flows can also be orchestrated from n8n without touching the platform schema.
Monthly and yearly subscriptions: Starter, Pro and Premium. Every plan opens the same workbench and differs in credits, saved cases and support. Billing runs through Stripe and can be cancelled at any time.
Accounts use Google sign-in only, so there is no extra password to manage. The header button checks your account and subscription, then takes you to the workbench or to the pricing page.
No. Every entity, relationship and graph on this site is dummy data, and no scanning or data collection has been performed on any person or organisation.
Sign in with Google, pick a plan and start enriching your first entities today. The core is open source, so you can also run it yourself.
Signed-in accounts keep their cases and credits between sessions.