Galactic Automation BV · Belgium

European fraud and risk intelligence.

See the threat, decide the response, and prove the work. Eight commercial surfaces on one EU-sovereign platform with audit-grade provenance.

GDPR-native EU-hosted EN · NL · FR output
PHISHNET / LIVE SIGNAL ENGINE snapshot-first
332evidence artifacts
93kit captures
239observations
10global source packs
Phishing
feeds
Malware
hashes
Ransom
victims
Infra
DNS/TLS
Opening live intake chart...
Evidence · intake movementlive + snapshot contract
Live intake

New evidence is moving now.

Public-safe counters from the running platform. Raw URLs, victims, and sensitive evidence stay behind the authenticated workspace.

Opening live snapshot…
Current feed corpus
New in latest run
All-time corpus
Active source modules
Verified live
What the platform does

Three jobs, one evidence spine.

PhishNet is not another disconnected feed. It turns collector evidence into decisions, actions, reports, and product-specific workspaces without losing provenance.

01

See the threat

Early warning across phishing, smishing, sanctions, credential exposure, ransomware, attack surface, and OT advisories.

02

Decide the response

AI briefs, lifecycle state, source health, risk scores, and human-approved action paths for the people who own the decision.

03

Prove the work

Raw artifacts, SHA-256 provenance, citations, run lifecycle metadata, export profiles, and evidence packets for audit and prosecution.

Structural moat

One finding propagates everywhere.

When a collector adds a sanctions hit, a lookalike app, a KEV advisory, or a regulator warning, the platform resolves the entity once and fans out entitlement-safe summaries to the surfaces that need it.

Federated products

Sentinel, Cyber Risk, Institution workspaces, Cases, Action Queue, Brand and Reports all read from the same resolved event.

Evidence by design

Every claim links back to a collector run, a raw artifact hash, source URI, parse state, timestamp, and confidence score.

Collector → registry → surfaces
OFAC SDNcollector event
Enrichmentresolve legal entity
SentinelMLRO alert
Cyber Riskunderwriting flag
Raw artifactsha256 keyed
Evidencerole-gated vault
Reportscitation ready
Casespriority bump

Public intelligence

Daily dashboard cutfresh
Research notescitable
Live intake counterspublic-safe
Raw evidence boundaryrestricted
Opening dashboard chart...
Research and public trust

Public outputs remain useful, defanged, and citable.

Keep the public dashboard, daily research, `/check`, embed widgets, and quarterly reports public-safe. Specific live URLs, victim identities, brand-sensitive details, and operational case state stay behind role-gated workspaces.

Public check and evidence reporting stays available for citizens and partners: check a suspicious link, submit screenshots or email evidence, then read public research such as Attack-kit vault research and raw cyber evidence observation metadata. For underwriters, the cyber-insurance risk intelligence path connects public research to product-grade evidence.

EU-sovereign by architecture

Built where the regulation is written.

Belgian engineering, EU jurisdiction, GDPR-native processing, multilingual output, data minimization, row-level controls, and no casual US data egress. The trust story is structural, not decorative.

Data residency

EU-hosted infrastructure and processing patterns designed for institutional security reviews.

Audit-ready evidence

Run lifecycle, raw artifacts, citations, and export profiles keep the answer to “how did you know?” close to the claim.

Belgian operating context

KBO-based entity resolution and Belgian/EU regulatory vocabulary across workspaces and public pages.

Contact

Book a 30-minute platform tour.

Bring the audience you care about: CCERT coordination, bank compliance, OT advisory tracking, cyber underwriting, brand protection, or public research.