An investigative intelligence platform for law enforcement brings the data an investigation produces into one system, so analysts can search it, link it and visualise it without moving between tools. Octostar is that platform: it ingests structured records and unstructured evidence at petabyte scale, connects them into a knowledge graph, and puts search, link analysis, timelines, maps and AI assistance on the same screen.
Octostar was founded in 2023 by a team with decades of experience building investigative software for police and intelligence agencies. It works with the Servizio Centrale Operativo of the Italian State Police, and Intelligence Online has described it as one of only two European alternatives to Palantir. It runs on-premise, in a sovereign private cloud, or on the Octobox appliance for air-gapped sites, so case data never leaves your jurisdiction.
Octostar sits alongside records and case management systems rather than replacing them. The full feature list is on the platform overview.
What slows investigations down
Evidence is scattered across systems
Records management, call data, financial disclosures, seized phones, CCTV and open-source material each sit in a different tool with a different search. Investigators spend more time exporting and re-importing than analysing.
Volumes have outgrown desktop tools
A single device extraction can contain millions of messages and images. Spreadsheets and desktop link-chart tools cannot hold a modern case, let alone correlate it with everything the agency already knows.
Cloud is often not an option
Operational data, intercept product and informant material are subject to national rules that rule out foreign-hosted SaaS. Many agencies need a platform that works fully disconnected.
AI must be explainable in court
Any AI output that reaches a case file must be traceable to its source, reproducible and auditable. Black-box models that cannot show their working create disclosure risk rather than removing it.
What investigators get on day one
Every capability below is part of the core platform, not a separate product, and works on the same data model.
360-degree search across every source
One query across records, documents, media, intercepts and open sources, with sub-second response on petabytes thanks to a ClickHouse-based engine. Results are grouped by entity, not by system.
Link analysis on a virtual knowledge graph
Datasets are mapped onto a shared ontology without copying them, so people, phones, vehicles, accounts and addresses resolve into one graph. Analysts expand, filter and annotate links directly on the chart.
AI-assisted evidence processing
Transcription of audio and video, image tagging, face search, document entity extraction and automatic graph building turn seized material into searchable, linked evidence in hours instead of weeks.
Geospatial and timeline analysis
Plot cell-site data, ANPR hits, financial transactions and events on maps and timelines, filter by time window, and replay movements to reconstruct what happened and who was where.
Alerting, risk scoring and anomaly detection
Watchlists, rules and models raise alerts when new data matches a subject of interest, a pattern of behaviour or an anomaly, so analysts see what changed without re-running searches.
AI copilot with source traceability
A generative AI assistant summarises cases, drafts reports and answers questions over the case data. Every answer cites the records it came from, and every interaction is logged for disclosure.
Collaboration and workflow
Shared case folders, role-based access, real-time co-working on charts and one-click executive reports support multi-agency task forces and distributed teams.
Audit logging and AI governance
Every query, view and export is logged. AI outputs carry provenance. The platform is being aligned with the EU AI Act, OECD, NIST and Council of Europe frameworks ahead of the 2027 deadline.
APPs for specialised work
Extend the platform with SIGINT processors, media analysis suites, auto-graphing tools and vetting workflows from the APPs ecosystem, or build your own on the open API.
From proof of concept to production
- Step 1
Start with an Octobox
The Octobox appliance ships pre-installed with the full platform and 20 TB of AI-analysed storage. It runs all AI locally and works air-gapped, so a proof of concept can run on real case data within a day.
- Step 2
Connect your sources
Records management, CAD, custody, telephony, financial and open-source feeds are mapped onto the ontology through semantic drivers. Data can stay where it is and be federated, or be ingested for speed.
- Step 3
Scale on your own infrastructure
Move to a Kubernetes deployment on-premise or in a sovereign private cloud. Your team operates it, extends it and keeps the source-level control that outsourced platforms do not offer.
Why police forces choose Octostar
- Sovereign by design: runs entirely on your infrastructure, including fully disconnected sites, with no dependency on a foreign cloud provider.
- Open and extensible: an open API and APPs ecosystem mean your own developers and integrators can add capability rather than waiting on a vendor roadmap.
- Built for scale: petabyte-scale storage and sub-second search were design goals from the first release, not later additions.
- AI you can disclose: transparent outputs, full source traceability, audit logging and human oversight are built in, and compliance work is aligned with EU and international frameworks.
- Working with national police: the Servizio Centrale Operativo of the Italian State Police is a customer, and a collaboration with BAE Systems was announced in March 2026.
- European company: headquartered in Galway, Ireland, with R&D in Bergamo, Italy and offices in London and Dubai.
Frequently asked questions
- What is an investigative intelligence platform?
- An investigative intelligence platform is software that aggregates data from many sources, resolves it into entities such as people, phones, vehicles and accounts, and lets analysts search, link, map and visualise it in one place. It differs from a records management system, which stores case files, and from a single-purpose analysis tool, which handles one data type. Octostar combines the data layer, the analysis tools and AI assistance in one platform.
- Does Octostar replace our records management or case management system?
- No. Octostar sits alongside records, case and custody systems and reads from them. It becomes the analytical layer where data from those systems is joined with device extractions, intercepts, financial data and open sources. Existing systems remain the system of record.
- Can it run without any internet connection?
- Yes. The Octobox appliance performs every function, including all AI processing, locally and is designed for air-gapped environments. Larger on-premise Kubernetes deployments can also run fully disconnected.
- How is AI output kept admissible and auditable?
- Every AI-generated summary, transcript, tag or answer is linked to the source records it was derived from, and every interaction is written to the audit log. Analysts review and confirm outputs before they enter a case file. The platform is being aligned with the EU AI Act and with OECD, NIST and Council of Europe guidance.
- What data sources can Octostar connect to?
- Structured records such as RMS, CAD, custody and telephony data; unstructured evidence such as documents, images, audio and video from device extractions; financial and third-party datasets; and open-source intelligence feeds through on-demand semantic drivers. New sources are added by mapping them onto the shared ontology.
- How long does deployment take?
- An Octobox appliance is operational within a day and supports proof-of-concept and small production workloads of up to five concurrent users. A full Kubernetes deployment on your own infrastructure takes hours to install; the time to production depends on how many sources you connect.
