Skip to content
InvestShield

Service architecture · Edition 2026

From TLS certificate to investigative dossier,deterministic and auditable process.

The pipeline runs 24/7 without human intervention. Every step preserves input, output and integrity hash. On institutional request, any signal can be reconstructed step by step from the preserved evidence.

§ 1 · Operational summary

The system observes public Certificate Transparency registries, classifies every new financially relevant domain, and produces an informational dossier preserved in chain of custody, ready for activation by the competent interlocutors.

§ 2 · Process

Six automated steps, each preserves the evidence.

01CT logs · RFC 6962

Public log observation

Continuous subscription to the Certificate Transparency logs. Every HTTPS certificate issued worldwide enters the feed within a few seconds of publication.

02lexical · NER

Financial relevance filter

Automatic selection of domains linked to the financial sector by terminology, known brand, name structure or typosquatting pattern.

03fetch · sanitize

Content capture

Public retrieval of the page, multilingual analysis of return promises, promotional wording and the presence of mandatory regulatory disclaimers.

04llm · classifier

Risk qualification

A specialised language model classifies the domain: type of service offered, risk indicators, similarity to firms already on the register.

05i18n · phone · ccy

Jurisdiction check

Comparison between the declared jurisdiction and the one actually targeted: main language, currency, phone prefixes, cultural and tax references.

06apex · hash · sig

Dossier consolidation

Aggregation by apex domain, production of the information dossier with preserved evidence, integrity hashes and a digital signature for the chain of custody.

§ 3 · Recurring patterns

Four patterns observed every day.

Categories covering most critical-severity detections. The classification is a motivated technical hypothesis, not a legal qualification.

01clone

Sites imitating registered intermediaries

Domains replicating the name, logo and layout of banks, investment firms and asset managers already listed in the CONSOB register.

02wealth

Purported wealth management

Guaranteed returns, savings plans and personalised advice offered by parties without authorisation.

03signals

Trading signal services

Paid platforms providing investment recommendations without the requirements set out in the Italian TUF.

04crypto

Unnotified crypto services

Wallets, custody or exchanges operating on the Italian market without MiCAR notification (Reg. EU 2023/1114).

§ 4 · Output

What the preserved dossier contains.

Standard structure of the informational dossier produced for every signal. Each element is digitally signed and linked to the unique signal ID.

01identity

Technical site identity

  • Apex domain and correlated subdomains
  • Exact certificate publication date (CT timestamp)
  • Snapshot and hash of the page at discovery
  • Languages detected and targeted geographic markets
  • Issuing Certificate Authority and source CT log
02classify

Content classification

  • Type of service offered (management, CFD trading, exchange, ICO)
  • Explicit targeting of the Italian/EU public (linguistic, fiscal)
  • Abuse indicators: guaranteed returns, urgency, missing disclaimers
  • Similarity with intermediaries already in the official register
  • Attribution to operators already monitored
03audit

Chain of custody

  • Structured reasoning: indicators (hypothesis) signal
  • Pipeline version at the time of analysis (reproducibility)
  • Unique ID linking every piece of evidence to the signal
  • Digital signature and SHA-256 integrity hash of the dossier
  • UTC timestamp for every process step

§ 5 · Governance & perimeter

What the service is not.

InvestShield does not replace the competent authority. Every signal is a motivated technical hypothesis; legal qualification rests with the competent body.
We do not publish lists of suspect domains nor make any signal-related data accessible to the general public.
We do not intervene on DNS, registrar, hosting, or the site operator. Takedown follows the procedures of the competent authorities (e.g. TUF art. 7-octies).
We do not collect personal data of investors. We do not profile visitors to analysed sites. Analysis is limited to the public content of web pages.

The evidence collected supports the investigative powers set out in the Italian TUF (arts. 18, 166, 7-octies) and in the European regulatory framework on investment services (MiFID II, MiCAR).

§ 6 · Infrastructure

Technical specification.

Infrastructure hosted in the European Union (Milano). Web dashboard accessible from browser, no installation required on the interlocutor's side. REST API available for integration with internal supervisory systems, on named credentials with full audit trail.

01

0.7 s

p50 analysis latency, from page request to classification · 30-day average

02

21,033

Distinct apex domains analysed in the 30-day window

03

EU only

Infrastructure hosted exclusively in the European Union · Milano

04

25 languages

Content languages with at least 20 detections in the 30-day window

05

1 per apex

One detection per apex domain, no duplicates on subdomains

06

Auditable

Every analysis preserves input, output and integrity hash

§ 7 · Access

A non-commercial channel for supervisory authorities.

Same detections, same preserved evidence. Scope and format are agreed together; the observations remain reasoned technical hypotheses, and legal qualification rests with those who hold the competence.

Write to the non-commercial channel

Institutional path. Commercial brand protection starts on the home page.