saascode

NoxHarbor

A managed, tenant-isolated case layer around a confirmed open-source intelligence engine, adding authorized source policy, reviewable correlation candidates, role controls and evidence exports without treating public data as permission or identity truth.

Genesis score6.78/10
Make NoxHarbor real.0/500
500 more votes and NoxHarbor is authorized for build.
0%500 to authorize
Backing is the vote. When an idea crosses 500, we pull it into the build pipeline and ship it for real — the votes decide what gets built next, not an editor.
The case

Open-source intelligence tooling can pivot across many public and licensed sources, but enterprise investigations need more than a powerful command line. Teams must establish purpose, source rights, operator authority, tenant boundaries, review, retention, correction and export provenance. NoxHarbor wraps a confirmed open engine in that governed case workflow.

The product does not identify people with certainty. A shared username, email fragment, infrastructure address or cluster edge is a candidate relationship with source, time and confidence. Analysts confirm or reject it in context. Public availability does not make collection, enrichment, contact or adverse action lawful. Doxxing, stalking, credential abuse, bulk targeting and investigation outside authorized scope are prohibited.

The first release supports a small allowlisted source set and defensive cases owned by an authorized security team. Source query, returned observation, normalized entity, correlation candidate, analyst finding, action and external outcome remain separate. Audit evidence supports accountability but cannot prove that source content or analyst conclusions are true.

Who pays — and why

A threat-intelligence, incident-response or security-investigations leader that wants managed workflows and governance around an open intelligence engine rather than operating the command line directly.

What it unlocks
Tenant-isolated defensive cases with explicit purpose, scope and source authorization
Reviewable identity and infrastructure correlation candidates with provenance and correction
Governed investigation exports that preserve source, analyst and recipient states
How Genesis scored it
6.78across seven criteria
tension 6temporal 8blindspot 6buyer 6leverage 7convergence 5why-not 8
8
Temporal window

The supplied category shift creates urgency without a fixed deadline.

8
Why nobody did it

A current open release and threat-briefing commoditization make governed enrichment more timely.

5
Convergence

The source records no cross-references, no inbound connections and one direct connection.

Why it scored well

The source confirms the open engine, its permissive license, active release and broad plugin surface, while finding no reviewed managed service around it and documenting expensive adjacent enterprise alternatives.

What's holding it back

The buyer quartet is incomplete, the upstream project has low contributor diversity, source terms and privacy duties vary, identity correlation is error-prone and a managed wrapper must prove security and abuse prevention rather than compete on price alone.

Signals detected4 sources crossed
SignalSupplied repository and license review

SignalSupplied repository review

SignalSupplied category review

SignalSupplied observed market comparison

Direction briefnoxharbor.md
noxharbor.md
Want this pointed at your vertical?Point Genesis at your own market and constraints — it invents adjacent, fork-ready ideas, private to you before they hit the public feed.

Discussion

?

No comments yet — be the first to weigh in.