The complete architecture of Submarine v1.5
Submarine is a graph-native investigation platform that unifies cases, entities, evidence, timelines, and narratives into a single, auditable intelligence fabric.
It is designed for complex, multi-source investigations where:
Financial crime, fraud, insider threat, due diligence, counterintelligence
Law enforcement, regulatory enforcement, internal investigations
Investigative journalism, OSINT, document leaks, public interest research
Compliance, legal holds, litigation support, risk management
National security, critical infrastructure protection, cross-agency collaboration
| Component | Description |
|---|---|
| Cases | Investigation containers with metadata, provenance, versioning |
| Entities | People, organizations, assets, accounts, devices, locations |
| Evidence | Documents, images, audio, video with chain of custody |
| Graph | Entity-relationship graph with path reasoning and explanations |
| Timelines | Event sequences with temporal analytics |
| Notes | Analyst annotations with mentions and threading |
| Tasks | Investigation task management |
| Capability | Description |
|---|---|
| Workflow Engine | Triggers, actions, conditions, state machine, audit hooks |
| Graph Explanations | Path reasoning, cluster explanations, relationship summaries |
| Narrative Intelligence | Narrative generator, diffs, timelines, contradiction detection |
| AI Suggestions | Suggestion engine, ranking, feedback loop, safety constraints |
| Cross-Case Intelligence | Entity resolution, pattern detection, case similarity, CCI alerts |
| Graph Analytics | Centrality, community detection, temporal analytics, pathfinding, heatmaps |
| Evidence Intelligence | Document, image, audio, video analysis with graph/narrative linking |
| Knowledge Base | Knowledge objects, extraction, search, governance |
| Capability | Description |
|---|---|
| Presence | Real-time user presence |
| Comments | Threaded comments on any object |
| Mentions | @-mentions with notifications |
| Shared Cursors | Collaborative graph navigation |
| Activity Feed | Team activity stream |
| Personalization | Analyst profiles, personalized views, dashboards, privacy controls |
| Capability | Description |
|---|---|
| Audit System | Immutable audit trails, compliance exports |
| Plugin System | Sandboxed plugins with permissions and event hooks |
| Identity Federation | SAML, OIDC, SCIM, JIT provisioning, MFA, WebAuthn |
| Mobile Clients | iOS, Android with offline mode, sync queue, evidence capture |
| Sync Fabric | Real-time distribution, device sessions, conflict resolution, continuity |
| Red Team Mode | Scenario engine, synthetic data generators, playbooks, scoring |
Submarine v1.4 hardened the platform for enterprise deployment:
Unified permission model across all subsystems
Standardized event types for audit and integration
Unified observability across all components
Identity federation, session security, MFA, WebAuthn
Real-time distribution, offline/online transitions, conflict resolution
iOS and Android with offline mode and evidence capture
Submarine v1.5 transforms the platform into an enterprise intelligence ecosystem:
| Phase | Capability |
|---|---|
| Cross-Case Intelligence | Pattern detection across all organizational cases |
| Workflows 2.0 | Declarative workflow language with AI integration |
| Knowledge Base | Institutional memory with governance |
| Graph Analytics Suite | Advanced algorithms with pattern explanation AI |
| Evidence Intelligence | Multi-modal evidence analysis with graph linking |
| Deployment Toolkit | Production-grade deployment automation |
| Red Team Mode | Adversarial testing and training |
| Personalization Engine | Per-analyst customization with privacy controls |
| Multi-Org Federation | Secure cross-org collaboration with zero-trust |
| Submarine Cloud | Managed multi-tenant offering |
Every action logged with tamper-evident storage
Hash-chained evidence custody records
SAML, OIDC, SCIM, JIT provisioning
MFA, WebAuthn, session security
Federated case/evidence sharing with explicit trust policies
Conflict resolution, offline/online transitions, continuity state
Audit trail exports for regulatory compliance
Isolated plugin execution with explicit permissions
Connect Submarine to your existing infrastructure and workflows
Full programmatic access to cases, entities, evidence, graph, and exports. OAuth 2.0 and API key authentication.
POST /api/v1/casesGET /api/v1/entitiesPOST /api/v1/evidence/uploadGET /api/v1/graph/queryReal-time event notifications for case updates, entity matches, workflow triggers, and audit events.
Pre-built integrations for common enterprise systems:
Full API documentation available upon early access approval.
On-premises deployment with Helm charts, scaling profiles, backup/restore.
Multi-org deployment with federated identity, case sharing, zero-trust.
Managed multi-tenant SaaS with tiered plans and cloud admin console.
Ready to transform your investigations? Complete the form below to get started with Submarine v1.5.
Interested in Submarine? Fill out the form below and our team will get back to you with pricing details.