Service architecture · Edition 2026
From TLS certificate to investigative dossier,deterministic and auditable process.
The pipeline runs 24/7 without human intervention. Every step preserves input, output and integrity hash. On institutional request, any signal can be reconstructed step by step from the preserved evidence.
§ 1 · Operational summary
The system observes public Certificate Transparency registries, classifies every new financially relevant domain, and produces an informational dossier preserved in chain of custody, ready for activation by the competent interlocutors.
§ 2 · Process
Six automated steps, each preserves the evidence.
p50 analysis latency · 0.7 s
Public log observation
Continuous subscription to the Certificate Transparency logs. Every HTTPS certificate issued worldwide enters the feed within a few seconds of publication.
Financial relevance filter
Automatic selection of domains linked to the financial sector by terminology, known brand, name structure or typosquatting pattern.
Content capture
Public retrieval of the page, multilingual analysis of return promises, promotional wording and the presence of mandatory regulatory disclaimers.
Risk qualification
A specialised language model classifies the domain: type of service offered, risk indicators, similarity to firms already on the register.
Jurisdiction check
Comparison between the declared jurisdiction and the one actually targeted: main language, currency, phone prefixes, cultural and tax references.
Dossier consolidation
Aggregation by apex domain, production of the information dossier with preserved evidence, integrity hashes and a digital signature for the chain of custody.
§ 3 · Recurring patterns
Four patterns observed every day.
Categories covering most critical-severity detections. The classification is a motivated technical hypothesis, not a legal qualification.
Sites imitating registered intermediaries
Domains replicating the name, logo and layout of banks, investment firms and asset managers already listed in the CONSOB register.
Purported wealth management
Guaranteed returns, savings plans and personalised advice offered by parties without authorisation.
Trading signal services
Paid platforms providing investment recommendations without the requirements set out in the Italian TUF.
Unnotified crypto services
Wallets, custody or exchanges operating on the Italian market without MiCAR notification (Reg. EU 2023/1114).
§ 4 · Output
What the preserved dossier contains.
Standard structure of the informational dossier produced for every signal. Each element is digitally signed and linked to the unique signal ID.
Technical site identity
- Apex domain and correlated subdomains
- Exact certificate publication date (CT timestamp)
- Snapshot and hash of the page at discovery
- Languages detected and targeted geographic markets
- Issuing Certificate Authority and source CT log
Content classification
- Type of service offered (management, CFD trading, exchange, ICO)
- Explicit targeting of the Italian/EU public (linguistic, fiscal)
- Abuse indicators: guaranteed returns, urgency, missing disclaimers
- Similarity with intermediaries already in the official register
- Attribution to operators already monitored
Chain of custody
- Structured reasoning: indicators (hypothesis) signal
- Pipeline version at the time of analysis (reproducibility)
- Unique ID linking every piece of evidence to the signal
- Digital signature and SHA-256 integrity hash of the dossier
- UTC timestamp for every process step
§ 5 · Governance & perimeter
What the service is not.
- Does not qualify
- InvestShield does not replace the competent authority. Every signal is a motivated technical hypothesis; legal qualification rests with the competent body.
- Does not publish
- We do not publish lists of suspect domains nor make any signal-related data accessible to the general public.
- Does not block
- We do not intervene on DNS, registrar, hosting, or the site operator. Takedown follows the procedures of the competent authorities (e.g. TUF art. 7-octies).
- Does not profile
- We do not collect personal data of investors. We do not profile visitors to analysed sites. Analysis is limited to the public content of web pages.
The evidence collected supports the investigative powers set out in the Italian TUF (arts. 18, 166, 7-octies) and in the European regulatory framework on investment services (MiFID II, MiCAR).
§ 6 · Infrastructure
Technical specification.
Infrastructure hosted in the European Union (Milano). Web dashboard accessible from browser, no installation required on the interlocutor's side. REST API available for integration with internal supervisory systems, on named credentials with full audit trail.
01
0.7 s
p50 analysis latency, from page request to classification · 30-day average
latency
02
21,033
Distinct apex domains analysed in the 30-day window
volume
03
EU only
Infrastructure hosted exclusively in the European Union · Milano
hosting
04
25 languages
Content languages with at least 20 detections in the 30-day window
i18n
05
1 per apex
One detection per apex domain, no duplicates on subdomains
dedup
06
Auditable
Every analysis preserves input, output and integrity hash
audit
§ 7 · Access
A non-commercial channel for supervisory authorities.
Same detections, same preserved evidence. Scope and format are agreed together; the observations remain reasoned technical hypotheses, and legal qualification rests with those who hold the competence.
Institutional path. Commercial brand protection starts on the home page.