Your AI-powered hub for faster, smarter investigations.

Internal systems, forensic evidence and open sources in one workspace, from the first entity to the finished report.

Falkor Air cloud delivered
Falkor Enterprise on prem or air gapped

About Falkor

Puts the analyst back in the driver’s seat.

Falkor is supercharging the investigation process, so you can discover, analyse and report crucial insights effortlessly.

Teams and organisations gather and store data inconsistently, which makes it hard to see the full picture. Analysts struggle to identify relevant facts in a sea of data, and tired technology leaves them racing the clock to make intelligent decisions.

Falkor gives analysts a place where they can run investigations effortlessly and collaborate seamlessly. Internal systems, files, forensic evidence and open sources come together in one platform, where entities are enriched, relationships uncovered, evidence analysed, cases managed and comprehensive reports produced.

Falkor supports law enforcement, public safety, national security, corporate security, fraud investigation and digital forensic teams.

LINK ANALYSIS
Falkor link analysis canvas showing entities, relationships and investigator notes
Entities, accounts, locations and relationships on one canvas, with investigator notes attached to the path rather than kept in a separate document.
ISO 27001Information security
GDPRData protection
10+ yrsPer-member experience

The platform

Everything you need to run an investigation.

So what can you actually do with Falkor?

Manage cases
One place to track and manage everything related to your investigation, from objectives and important files to team members assigned to the case. Head to the Case Overview to keep up with outstanding tasks and see the latest updates.
Analyse data
Import new data in almost any format, then dig into it. View it from every angle, on a map, in a table, across a timeline, as a heatmap and more. Find important information faster with powerful search and filtering, and use link analysis graphs to explore connections between entities.
Unlock OSINT insights
Connect to OSINT and SOCMINT sources and enrich your data with new identifiers, associated online accounts, posts and more. Conduct digital profiling and monitor topics of interest in real time.
Collaborate
Work closely together to crack the case with powerful collaboration tools. Assign tasks, share notes and reminders, and keep team members automatically updated every time something changes.
Report findings
Turn insights into actions faster by generating reports rapidly. Compile all of your case's data, notes, conclusions, files and summaries of findings in one report, then edit, download and share with the relevant stakeholders.
Take control of investigations
A bird's-eye view of everything that affects your work, from investigation progress to overall productivity. Custom dashboards for managers and analysts help you find the information relevant to your role faster.
Manage permissions and access
Assign granular permissions according to roles or specific user characteristics, ensuring each user only accesses the data they are allowed to see.
Enhance investigations with AI
Falkor's AI assistant helps analysts move faster without losing context. Ask questions directly inside your investigation to explore leads and generate summaries in seconds. Use OCR to extract text from PDFs and images, and NER to surface people, organisations and locations from raw content.

Falkor Forensic Studio

Every extraction and artifact in one environment.

Evidence becomes searchable, connected and continuously enriched across the entire investigation lifecycle.

A single mobile forensic extraction can contain millions of data points: messages, locations, accounts, applications and behavioural indicators spread across years of activity. Working through that by hand is the bottleneck in most digital forensic units.

Forensic Studio structures, enriches and analyses extraction data automatically, so investigators surface leads dramatically faster. It brings every extraction, artifact and intelligence source into a single operational environment.

Falkor Forensic Studio extraction overview, chat analysis and Ask your data
01
One device, investigated faster

AI models identify entities, objects, text and relationships automatically. Extraction data is enriched with OSINT and internal sources.

Behavioural timelines are reconstructed across applications and devices to reveal patterns investigators would otherwise miss.

02
All evidence, finally connected

The real challenge begins when investigations span multiple devices, people, platforms and timeframes. Falkor correlates entities, communications, locations, accounts and behaviours across the entire forensic repository.

Rather than pivoting manually between systems, the platform uncovers overlapping data points, repeated patterns, shared infrastructure and operational connections across cases and sources.

03
Built for investigations in the AI era

Forensic analysis, AI, enrichment, operational management and cross-source intelligence in a single platform.

Designed for complex investigations and collaborative forensic environments, where more than one analyst and more than one case are in play at once.

In your environment

Runs on top of what you already have.

Falkor takes what your existing systems and tools produce and makes it one investigation.

Nothing has to be replaced for Falkor to be useful. It integrates and connects information from internal systems, databases, case files and digital forensic tool output, so material that has already been extracted becomes searchable, linkable and mappable alongside everything else on the case.

From there it extends outward. Identifiers already in hand, accounts, handles, numbers, addresses and locations, carry straight into OSINT enrichment, entity profiles, link analysis and timeline and geospatial views. The source tool keeps doing its job; the investigation carries on past it.

For a digital forensics unit that is Forensic Studio’s whole premise. Extractions stop being separate reports read one at a time and become a single searchable repository that correlates across devices, people and cases.

What Falkor takes in

Internal systems and databases. Existing agency records connected in rather than exported and re-keyed.

Case files and documents. Unstructured material read with OCR, extracted and turned into entities.

Digital forensic tool output. Device extractions brought in as structured, searchable intelligence.

Open sources. Social media, messaging platforms, forums, news, and deep and dark web.

Third-party APIs. Breach data, domain and IP records, and account enrichment through Falkor Enrich.

Security and deployment

What procurement will ask about.

Falkor Air and Falkor Enterprise are the two deployment models. OSINT, Geowave and Forensic Studio are modules licensed alongside user seats.

Deployment

Falkor Air is delivered through the cloud. Falkor Enterprise deploys on premises or into an air-gapped environment. Both provide the same secure investigation environment, so the choice is infrastructure rather than capability.

  • Air cloud delivered
  • Enterprise on premises or private cloud
  • Enterprise air gapped
  • Multi-factor authentication, SSO and active directory integration
Security and compliance

Falkor operates an information security management system conforming to ISO/IEC 27001:2013, and complies with the EU General Data Protection Regulation.

  • ISO/IEC 27001:2013 ISMS conformance, certificate available on request
  • GDPR compliant
  • Hosted on AWS across multiple Availability Zones
  • All client traffic encrypted in transit over HTTPS
  • Annual penetration testing at application and infrastructure level by independent auditors
  • Documented incident protocol with escalation, mitigation and post mortem
Data and oversight

Falkor is an analysis environment. Agencies bring data obtained through their own lawful means, and the platform presents entities and relationships for an analyst to evaluate.

  • Granular permissions by role or user characteristic
  • Each user sees only the data they are permitted to see
  • An auditable and visible investigative flow
  • Findings presented for analyst judgement, not automated decision

The ISO/IEC 27001 certificate and further detail on security practices are available on request. Ask us and we will obtain them for you.

Training and support

Falkor Academy, open to non-customers.

Expert-led courses for analyst teams, whether or not the organisation runs Falkor.

The Academy is aimed at analyst teams and organisations doing investigative work in any field, from beginners through to advanced analysts sent by their employer to specialise. Courses build toward roles including crime analyst, forensic analyst, intelligence and threat intelligence analyst, and fraud and anti-money laundering analyst. Falkor system users also have full access to Falkor certification.

01
Open-Source Intelligence (OSINT) Training

Master open-source intelligence skills to uncover valuable information, streamline investigations and enhance decision-making.

02
Cyber Threat Intelligence

Identify, analyse and respond to cyber threats with advanced intelligence techniques, protecting systems and staying ahead of attackers.

03
Falkor Specialized Training

Learn how to use Falkor to make your investigations easier and faster.

Implementation supportDeployment, onboarding and learning resources
Tailored trainingPlus a designated Customer Success Manager
Falkor certificationFull access for Falkor system users

See it against your own casework.Talk to us about Falkor.

The quickest way to judge an investigation platform is to point it at a problem you already have. We can arrange a demonstration built around your sources and your use cases rather than a generic walkthrough.