System operational · Production 2026

TRACEZ investigates. GRIMZ operates. One core.

The shared infrastructure behind OSINT investigation and authorized pentesting operations.

  • < 50 msTo Cloudflare's edge
  • Zero-trustOn every request
  • 0Data sold
The cycle

From investigation to the signed deliverable

Investigate, authorize, operate and attest are not separate products that happen to share a website: they are phases of the same job. Here is what each one solves, and the exact point where the chain connects today.

01
TRACEZ

Investigate

Builds the graph of the case: entities, relationships, geolocation and timeline, from open sources and live Earth data.

02
Manual, today

Authorize

The operator sets the scope: which specific assets are covered. This step is explicit and human by design — never automatic.

03
GRIMZ

Operate

Scans only the authorized scope and ranks exploits by CVE, with evidence for every action recorded end to end.

04
ATTEST

Attest

Signs the whole case with Ed25519 and an RFC 3161 timestamp, delivered as a dossier anyone can verify without trusting the issuer.

The missing link, covered

DEEPWIRE — security engagements

Step 02 no longer happens by hand or half-finished: DEEPWIRE unites recon and exploitation in a single console, with explicit per-target authorization and full traceability. We operate it as a service — you define the scope, we run it and deliver verifiable evidence.

See engagements →
Platforms

Two consoles available today

Each covers one phase of the cycle and shares authentication, edge compute and storage with the other.

Phase 01 — Investigation

TRACEZ

Public beta

The graph analytics and GEOINT console for multi-source OSINT investigation: entities, geolocation, timeline and live Earth data in a single workspace.

  • Interactive investigation graphs
  • Automated transforms on entities
  • Live panel: flights, earthquakes, weather and the ISS
  • Satellite imagery (NASA GIBS) and nearby places from Wikipedia
  • Event timeline and history
Phase 03 — Operation

GRIMZ

Enterprise

The offensive operations console for red teams and pentesters: from live attack surface to CVE-prioritized exploits, without switching screens.

  • Real-time host map
  • Integrated nmap scanning
  • CVE-ranked exploits
  • Metasploit integration
Who it is for

Who works with these tools today

Profiles already investigating and operating daily, usually splitting the work across spreadsheets, screenshots and loose tabs.

With TRACEZ

Anyone rebuilding a case

  • Investigative journalists building a case
  • Independent risk and OSINT analysts
  • Legal teams that need source traceability
  • Anyone investigating with spreadsheets and loose tabs
With GRIMZ

Anyone entering with a defined scope

  • Authorized pentesters prioritizing by CVE, not blindly
  • Red teams with a defined, auditable scope
  • Operators already using Metasploit who want a unified view
  • Controlled-intrusion training labs
The core

What holds up both platforms

NO-DO.DEV does not sell a third platform: it maintains the shared infrastructure — authentication, edge compute, storage — that both consoles are built on and evolve from.

01

In-house engineering

No third-party dependencies in the critical pieces: authentication, graph engine and scan engine are maintained in-house.

02

Edge-first

Every new product inherits the same edge deployment base, with no infrastructure to set up from scratch.

03

Security by design

Explicit scope, human confirmation before any active action, and end-to-end traceability.

Specifications

The same technical base

PERF

Compute on Cloudflare's edge

Workers and D1 on Cloudflare's network, which puts the edge within 50 ms of most users. No servers of our own to scale or maintain.

RENDER

Smooth graph rendering

The investigation graph is drawn on canvas and stays smooth as it grows in entities and relationships.

AUTH

Zero-trust on every request

No implicit trust between services: each request is explicitly authenticated and authorized before it touches any data.

ISO

Logical per-client isolation

Every record is tagged by client and encrypted in transit; access controls are enforced on every query, not by convention.

LIVE

Live public status

The status of every service is public and doesn't depend on us telling you: check the status page.