KLOOM
Book a demo
PLATFORM
Morphic Identity EngineImmutable Evidence APIPoint-in-Time InvestigationsAgent Identity Layer
SOLUTIONS — BY INDUSTRY
National Security & IntelFinancial Intelligence & BankingCrypto & Web3 Compliance
BY MISSION
Sanctions & SDN ScreeningAdverse Media MonitoringOSINT Subject ResolutionContinuous Due Diligence & KYC
COMPANY
CareersContact
Book a demo
Solutions / National Security & Intel
By industry

Resolve identity across the collection environment.

Cross-script entity resolution from open and acquired source material — with every decision traceable to citable evidence, and investigations replayable against the exact evidence basis that produced them.

Book a technical walkthrough
entity relationship graph · graph v_20260301_0900
PERSON · 9 MENTIONS ORG · SDN MATCH EVIDENCE-WEIGHTED RELATIONSHIPS co-director · 0.71 director_of · 0.83 CEO_of · 0.92 same-person · 0.91 cross-script Tariq al-Rashid PERSON · 24 MENTIONS Andrey Volkov PERSON Lumen Reserve LP ORG · SDN MATCH Farouk Trading LLC ORG · 11 MENTIONS محمد الراشد PERSON · Arabic
subject entity
Tariq al-Rashid
related entities
4 resolved
evidence mentions
48 total
01 · Where incumbent stacks break

Rules collapse.
Evidence holds.

Most identity stacks were built for clean data in a single script. The collection environment is none of those things. Three failure modes compound in practice.

01

Cross-script dropout

A name in Arabic returns zero candidates against a Latin-script index. Translation at ingest time introduces ambiguity — عمر maps to "Umar" or "Amar" depending on the chosen convention — and that error propagates silently through every downstream stage.

"طارق الراشد" → 0 results
02

Binary collapse at ingest

Three sources mention the same subject across Latin, Arabic, and Cyrillic. The system is forced to emit a match or no-match before the evidence is complete. The genuine underdetermination collapses to a single bit. Analysts inherit false positives they cannot explain.

match: true // evidence: null
03

Opaque scores survive no audit

A screening tool returns 0.73. What produced it? Without per-component evidence, an analyst cannot override it, a regulator cannot audit it, and a false positive cannot be corrected without re-running the entire pipeline from scratch.

score: 0.73 // reason: null
02 · What Kloom provides

Four capabilities.
One platform.

Cross-script entity resolution

Names are stored in the script and language in which they arrive — no lossy index-time translation. Query in Arabic against a mixed-script index and receive candidates in Arabic, Cyrillic, and Latin, scored on coherence and confidence as two independent axes.

original-script storage cross-script retrieval multi-script

Long-lived, version-pinned sessions

An investigation pins to a graph version. Every query inside the session resolves against that version — regardless of how many ingest events have arrived since. A migration report surfaces which clusters split, merged, or shifted when you choose to advance.

session pinning migration reports reproducible investigations

Tradecraft-grade auditability

Every resolved claim traces to a citable mention: source document, passage, confidence, and the per-component scores that produced it. Nothing the engine decides is unprovenanced. Blocking evidence and resolving attributes are returned in the response envelope — not behind a second call.

per-mention provenance tamper-evident stream citable evidence

Mission isolation & corpus partitioning

RBAC, per-mission corpus partitioning, and an air-gap-deployable build for sovereign environments. Your collection environment, your perimeter. No phone-home, no vendor cloud dependency — integrator-controlled data flows throughout.

RBAC corpus partitioning air-gap deployable
03 · Long-lived investigations

A session pinned for months. A verdict defensible for years.

An investigation pins to a graph version. Every query inside the session resolves against that pinned version, no matter how many ingest events have arrived since it opened.

When the graph evolves, the session surfaces a migration report — which clusters split, merged, or shifted — and the analyst decides whether to adopt the new view. The evidence basis cited in the original decision is never silently overwritten.

differentiation

"Reproducibility" usually means re-run the query and hope. Here it is a guarantee, expressed in the architecture.

Day 0 session opened

Investigation opened

Subject: "Tariq al-Rashid". Session pinned to graph v_20260301_0900. All subsequent queries inside this session resolve against this exact version — regardless of ingest.

graph v_20260301_0900 · session sess_a4f2c918
Day 12 ingest event

3 new mentions arrive

New mentions in Arabic and Hebrew sources processed. Graph advances to v_20260313_1142. Alert delivered to session. The session continues to resolve against v_20260301_0900 — no disruption to the active investigation.

+3 mentions · Arabic, Hebrew · graph v_20260313_1142
Day 45 migration report

Cluster split detected

The "Tariq al-Rashid" cluster has split into two candidates in the live graph. Migration report surfaced: 1 split, 2 new resolving attributes. The session is unchanged. The analyst sees what diverged and why.

1 cluster split · 2 new attributes · action required
Day 45+ analyst action

Session advanced to v_20260415_1607

Analyst reviews the migration report and adopts the new graph version. Confidence on the primary candidate advances from 0.83 to 0.91 — the new evidence is qualifying. The original decision's evidence basis remains intact and replayable.

confidence 0.83 → 0.91 · graph v_20260415_1607 adopted
04 · Deployment posture

Sovereign by design.
Air-gap-ready where the mission requires it.

Identity work in national-security environments cannot be outsourced to a vendor's cloud. Kloom is a library you operate inside your own perimeter, with the data flows you define.

Air-gap deployable

Kloom runs inside your perimeter with no network egress required. No phone-home, no vendor cloud dependency — data flows you define, from ingest through query.

Mission isolation

Per-mission corpus partitioning and RBAC ensure that collection, evidence, and query results from one mission cannot bleed into another.

Tamper-evident audit stream

Every mutation is logged with the acting principal. A forensic stream with tamper-evidence sits alongside a lean operational stream — both configurable by the integrator.

Integrator-owned operations

Kloom ships as a library. The host process owns identity, access control, persistence, and operational concerns. The library owns entity resolution — nothing more.

Security posture Compliance & regulatory
Platform

Relevant platform capabilities

Name Intelligence

Two-phase resolution: shortlist, then coherence-scored rerank. Multi-script, original-script storage, coherence and confidence on separate axes.

standalone library
Read the page

Immutable Evidence API

Append-only record of every mention and attribute. Blocking evidence and resolving attributes returned in the response envelope.

Read the page

Point-in-Time Investigations

Deterministic session pinning over the append-only evidence layer — reproducible without a snapshot copy.

Read the page

Morphic Identity Engine

The core entity layer. Continuous reshaping as evidence arrives — no destructive merges, splits are recomposition events.

Read the page
Ready when you are

Book a technical walkthrough.

A demo runs against representative data from your domain and returns resolved entities you can audit end to end. Thirty minutes, with engineering in the room.

Book a demo