Turn one identifier into the whole picture.
Search an email, phone, username or wallet across 900+ sources. Get linked accounts, breach exposure and a verified timeline — in one report, in seconds.
No card required · SOC 2 Type II · GDPR-aligned
Jordan Calder
San Francisco, CA
- Accounts
- 24
- Breaches
- 4
- Confidence
- 94%
- Sources
- 912
Linked accounts
Breach exposure
- 2019Collection #1email, password hash
- 2021LinkedIn Scrapeemail, name, employer
- 2023Twitter API Leakemail, phone, handle
- 2024Stealer Log — RedLinecookies, autofill
Digital footprint timeline
- 2013First indexed account
- 2018Domain registration
- 2021Number ported
- 2024Latest activity
- 900+
- Connected sources
- 4.2s
- Median full scan
- 99.9%
- API uptime
- 27M
- Lookups served
The platform
Everything an investigator needs before the first phone call.
Manual OSINT means forty tabs and a spreadsheet. We compress that into one query and hand you back evidence you can actually cite.
One query, every source
A single identifier fans out to 900+ connectors in parallel — social, financial, infrastructure, breach corpora and public records.
Live, not cached
Modules hit sources at query time. Nothing is served from a stale index, so what you see is the state of the account right now.
Scored, not guessed
Every result carries a confidence score and a provenance trail, so you can defend a finding in a report, a filing or a courtroom.
Chronology built in
Account creation dates, breach timestamps and registration deltas assemble into a timeline of the subject's digital footprint.
Search leaves no trace
Queries are never disclosed to the platforms being searched, and your search history is encrypted at rest and purgeable on demand.
Built to be exported
PDF for the case file, CSV for the spreadsheet, JSON for your pipeline. Every report ships with a hash and an audit trail.
Modules
Every connector, and exactly what it returns.
No black boxes. Each module declares its source class, its output fields and the plan it belongs to — before you spend a credit.
26 of 26 shown
- Instagramcore
Profile, avatar, obfuscated recovery
Social
- X / Twittercore
Handle, creation date, bio
Social
- LinkedIncore
Employer, role, location
Social
- Telegramcore
Handle, last-seen bucket
Social
- Discordcore
User ID, creation date
Social
- Snapchatcore
Display name, avatar
Social
- TikTokcore
Handle, follower band
Social
- Stravapro
Activity region, club links
Social
- PayPalpro
Account existence, display name
Financial
- Venmopro
Handle, avatar, public feed
Financial
- Cash Apppro
$cashtag, display name
Financial
- Revolutpro
Account existence
Financial
- Chain Traceenterprise
Wallet cluster, exchange tags
Financial
- Breach Indexcore
Source, date, exposed fields
Breach
- Combo Listspro
Credential pair presence
Breach
- Stealer Logsenterprise
Infected host, capture date
Breach
- Paste Monitorpro
Paste ID, first-seen
Breach
- WHOIS Historycore
Registrant deltas over time
Infrastructure
- Passive DNSpro
Historic A/MX records
Infrastructure
- Certificate Logcore
SAN entries, issuance
Infrastructure
- ASN / GeoIPcore
Carrier, ASN, coarse geo
Infrastructure
- Port Surfaceenterprise
Open services, banners
Infrastructure
- Carrier Lookupcore
Carrier, line type, portability
Records
- Corporate Registryenterprise
Officerships, filings
Records
- Sanctions & PEPenterprise
Watchlist match, confidence
Records
- Court Recordsenterprise
Docket references
Records
Plus 870+ long-tail connectors. Browse the full registry
API
One endpoint. Everything the dashboard knows.
The web app is a client of the same public API you get. Fire a scan, poll or take a webhook, and receive structured JSON with per-field provenance.
Streaming or batch
Server-sent events per module, or a single settled payload.
Webhooks
Signed callbacks on scan completion and on new breach hits for monitored subjects.
Idempotent & metered
Idempotency keys, per-key rate limits, and credit usage on every response.
SDKs
TypeScript, Python and Go — generated from the OpenAPI spec.
curl -X POST https://api.tracegrid.io/v1/scan \
-H "Authorization: Bearer $TRACEGRID_KEY" \
-H "Content-Type: application/json" \
-d '{
"type": "email",
"value": "j.calder@protonmail.com",
"modules": ["social", "breach", "finance"]
}'{
"scan_id": "scn_8Kd2mQ",
"status": "complete",
"elapsed_ms": 4180,
"credits_used": 1,
"subject": {
"name": "Jordan Calder",
"location": "San Francisco, CA",
"confidence": 0.94
},
"accounts": [
{ "module": "instagram", "handle": "j.calder", "confidence": 0.97 },
{ "module": "linkedin", "handle": "jordancalder", "confidence": 0.91 }
],
"breaches": [
{ "source": "Collection #1", "year": 2019, "fields": ["email", "hash"] }
]
}Use cases
The same query, four very different jobs.
Fraud & AML
Tie a chargeback ring to one operator across nine merchant accounts.
-63%
manual review time
Due diligence
Surface undisclosed directorships before the term sheet is signed.
4.2s
per counterparty
Trust & safety
Link ban-evading accounts by recovery phone rather than device ID.
12x
evasion detection
Journalism
Establish that a shell company and a public official share an address.
900+
citable sources
Pricing
Pay for lookups, not for seats you don't use.
Every plan includes the full result view — no paywalled fields, no “upgrade to reveal”. Unused credits roll over for 30 days.
Recon
Kick the tyres. No card required.
$0forever
10 lookups / month
Start free- Core social modules
- Breach index summary
- Web dashboard
- Community support
Analyst
For solo investigators and journalists.
$49/mo
1,000 lookups / month
Start 7-day trial- All core + pro modules
- Full breach detail & timelines
- PDF / CSV / JSON export
- Saved cases & tagging
- Email support
Agency
Teams that run investigations daily.
$199/mo
6,000 lookups / month
Start 7-day trial- Everything in Analyst
- REST API + webhooks
- 5 team seats, shared cases
- Bulk upload (CSV)
- Audit log & SSO
Enterprise
Gov, LE and regulated buyers.
Custom
Unlimited / negotiated
Talk to sales- Enterprise-only modules
- Dedicated infrastructure
- Data residency options
- Onboarding & training
- Named account manager
Verified journalists, non-profits and public-interest researchers can apply for free access.
Questions people ask before signing up.
Where does the data come from?
Publicly accessible endpoints, open registries, certificate transparency logs and licensed breach corpora. Every field in a report carries a source tag so you can trace it back.
Is the subject notified that I searched them?
No. Modules query sources without triggering account-recovery emails, login alerts or notifications. Read-only by design.
Who is allowed to use this?
Use is governed by our acceptable use policy. Investigations tied to fraud, due diligence, journalism, trust & safety and law enforcement are in scope; stalking, harassment and unlawful surveillance are not, and accounts doing so are terminated.
How do credits work?
One lookup equals one credit regardless of how many modules return a hit. Failed scans are never charged, and unused credits roll over for 30 days.
Can I get my own data removed?
Yes. Submit a removal request and we suppress your identifiers across the index within 72 hours, and permanently thereafter.
Do you retain my search history?
Search history is encrypted at rest and visible only to your account. You can purge it at any time, and Enterprise plans can enforce zero-retention.
Run your first scan in under a minute.
Ten free lookups, no card, full result view. If it doesn't find something you didn't already know, you've lost nothing but a minute.