Maltego Platform — GTM Enablement Guide
M

Maltego Platform — GTM Enablement Guide

Internal use only · Product positioning & capability reference
One ecosystem, one provider

Maltego is one investigation ecosystem, built and extended under a single software vendor.

Every product below is part of one Maltego ecosystem. Some ship together as Maltego One; others extend it for specific missions, data access, or evidentiary needs. GTM should always frame this as one platform story, even when a deal starts with a single product.

Maltego One

Beyond Maltego One

Data offering

New product line

How to read this guide: "Product Cards" gives full comprehensive detail per product straight from the product sheets. "Comparisons" gives ICP-fit and capability matrices across all 11 products. "Overlaps" resolves the recurring "which one do I pitch" confusion. "Decision Guide" gives the lead-with logic, bundling rules, and Cloak's separate qualification gate. "Guardrails" is the appendix of things GTM must never say or must qualify carefully — check it before any customer conversation, especially for Trace, Screen, and Cloak.

Maltego Graph (Browser)

Browser-based link analysis and investigative visualization tool — part of Maltego One.
Maltego OneCloud
Primary capability

Fast, accessible, browser-based link analysis with AI-assisted exploration

ICP fit

Broadly applicable across all ICPs as the accessible variant of Graph; explicitly called out as strong for non-technical users and mixed-maturity teams (ICP5). No separate formal ICP1–5 rating beyond that.

Description

Fast, accessible link analysis for visualizing and exploring relationships between Entities, with multiple analytical views and optional AI support. Runs inside the unified Maltego One browser workspace (investigation, case management, collaboration, admin, one Maltego ID login). Users move from discovery in Search to visual analysis here, or extend into Graph (Desktop) for advanced work. Graph (Browser) and Graph (Desktop) are two complementary variants of the same flagship link-analysis product — both are included in every new enterprise and webshop plan; customers don't choose one over the other, they get both, and the question is which variant fits which workflow (see Decision Guide).

Investigation scenarios
  • POI and threat-actor network investigation, incl. online footprinting/account discovery
  • Mapping relationships across social media and digital identifiers
  • Enriching and expanding leads to uncover deeper connections
Target users
  • Intelligence analysts and OSINT investigators
  • Investigators wanting a fully cloud-based solution
  • Fast-access, low-IT-overhead teams, incl. mixed-maturity teams with non-technical investigators
Lead with when
  • Customer wants fast access with minimal IT overhead
  • Team has mixed technical maturity, incl. non-technical investigators
  • AI-assisted analysis would speed up investigations
  • Real-time collaboration and autosave matter
  • 1-click pivot from Search into visual analysis is valued
  • Customer needs to enrich investigations with internal, proprietary, or partner data — now possible in Browser via the Maltego Transforms SDK (since ~July 2026), not just Desktop
Bad fit when
  • Customer needs Connectors (own API keys) today
  • Customer needs all Data Pass modules today
  • Air-gapped/offline work or on-premise deployment is required now
  • Graphs need to scale beyond ~5,000 Entities
Talk track

"If your team wants to get from a lead to a visual picture of connections without any installation, Graph (Browser) gets you there in one click from Search — and with the AI Assistant turned on, even less experienced analysts can navigate complex data. It's included in your plan alongside Graph (Desktop), so there's no extra cost to try it."

Deployment, system requirements & security

Deployment/Hosting: Cloud-based, accessed via app.maltego.com; log in via Maltego ID, supports SSO. No installation required.
Supported OS: Windows, macOS, Linux, web — works on any device with a modern browser. Browsers: Chrome, Firefox, Edge, Safari. Hardware: none required. Mobile/tablet: not supported.
Offline work: not supported — requires internet access (unlike Graph (Desktop), which can work offline).
On-premise roadmap (internal reference — do not commit dates to customers, see Guardrails): hybrid deployment targeted ~Fall 2026; full on-premise targeted ~2027. Graph (Desktop) remains the current choice for on-prem today.
Compliance: ISO/IEC 27001:2022, GDPR, EU AI Act; all searches anonymized and confidential.
Auth: Maltego ID (MFA + SSO); Maltego ID also covers Academy access.

Core features
  • One-click bundled Transforms (plus custom Transforms) to enrich Entities and expand investigations
  • Analyze relationships across domains, IPs, emails, social profiles, persons, organizations, and other identifiers in one graph
  • Graph, table, map, detailed, and histogram views, with split-screen analysis
  • Frictionless one-click pivot from Maltego Search directly into Graph (Browser) within one browser session — no export/import step, unlike Desktop
  • Real-time collaborative investigation on shared graphs, built into the browser experience
  • Autosave to Maltego Cases (cloud, optional E2E encryption), plus local file storage (.mtgx) as an option
  • Optional AI Assistant to guide exploration, surface connections, summarize (admin-enabled)
  • Full admin visibility via Maltego Admin within Maltego One
  • Extends into Graph (Desktop) for larger-scale, integration-heavy work

Practical scale ceiling today: Graph (Browser) currently supports graphs up to approximately 5,000 Entities, with higher limits planned. For very large or complex graphs, qualify the customer's scale requirements and position Graph (Desktop) as the stronger fit today — Browser reliability/performance at scale is actively being improved.

Data access, import/export & AI

Data Pass: built-in curated sources via Maltego Credits — Person of Interest, CTI, and Utilities modules today, with additional modules planned for late 2026 (use-case-level parity with Graph (Desktop) targeted by end of 2026).
Connectors: third-party sources via own API keys — planned, to be introduced gradually in batches from end of 2026.
Connector Builder / Connect Own Data: new as of ~beginning of July 2026 — customers can build and run custom Transforms locally in Graph (Browser) using the new Maltego Transforms SDK, closing what was previously a Graph (Desktop)-only capability. This is Phase 1 — a supported technical capability requiring SDK-based implementation, not yet a no-code experience (no-code is a later roadmap step, 2027+). See the dedicated "Connect Own Data" section below for setup and packaging detail.
Credit visibility: available Credits shown in the Transform dialog and user profile menu. Because Transforms are bundled (can query multiple sources in one action), Credit consumption can be harder to estimate upfront than on Desktop's atomic Transforms.
Export: PDF reports, or transition investigation into Graph (Desktop).
AI: optional AI Assistant — navigate data, summarize findings, explore relationships, surface connections. Must be enabled by org admin. (Also available in Maltego Search.)

Connect Own Data in Graph (Browser) — new since July 2026

What changed: until this release, own-data integration existed only in Graph (Desktop) via TRX/iTDS/pTDS — infrastructure that was complex to set up, test, debug, host, and maintain. This was a real adoption blocker: enterprise customers with own-data needs had a reason to stay on Desktop or hesitate before moving to Browser. The new Maltego Transforms SDK closes that gap for Browser and makes the equivalent workflow easier on Desktop too.
Packaging — two tiers: (1) All eligible users on Basic, Entry, Professional, and Enterprise plans can create and run custom Transforms locally in both Graph (Browser) and Graph (Desktop) at no extra entitlement. (2) Customers with the separate Own Data integration package entitlement can additionally use and share approved Transform servers hosted beyond a single user's machine — i.e., broader team/org access, managed by admins who approve which users and which "seed URLs" (pointers to the org's custom Transform servers) are allowed.
Setup — org admin: (1) confirm Maltego Transforms SDK is enabled for the org in Maltego Admin; (2) choose which users can use custom Transforms; (3) add the approved seed URLs pointing to the org's custom Transform servers.
Setup — investigator: (1) in Graph (Browser), open the Data tab in the left panel and select "Add Data Source"; (2) enter the approved seed URL provided by the admin — the custom Transforms then become available in the graph.
Where the data actually goes (important for security/compliance conversations): Graph (Browser) being browser-based does not mean customer data is automatically processed in Maltego One Cloud. The application itself runs locally in the user's browser; it uses Maltego One Cloud for services like configuration and Data Hub access, but for a configured custom data source, the browser app requests data directly from the customer-controlled source rather than routing it through Maltego infrastructure. (Internal analogy: Browser is the TV, a custom Transform is the DVD player — the TV can also play local content without going through the broadcast/cloud signal.)
Not the same as full on-premise: a fuller on-premise deployment model for all of Maltego One is a separate, later roadmap item for customers with stricter compliance needs — this release addresses the specific own-data-integration reason customers historically chose on-prem, while keeping the managed-application benefits (faster updates, less rollout friction).

Packaging & support

Available through Maltego One on new Professional and Enterprise plans. Graph access is per seat; one seat includes both Graph (Browser) and Graph (Desktop) — this is one flagship product in two variants, not an either/or choice. Capabilities vary by plan/entitlement.
Billing: Annual. License: Per user. Support: support@maltego.com; release notes via docs.maltego.com.

Maltego Monitor

Near-real-time social media and news monitoring for emerging threats, sentiment, and situational awareness.
Beyond Maltego OneCloud
Primary capability

Near-real-time social/news monitoring for emerging threats and situational awareness

ICP fit

Strong across Intelligence and Threat Intel Teams especially; grew significantly in importance for Executive Protection and Info Warfare use cases since the Monitor acquisition.

Description

Helps investigators detect emerging threats, track public sentiment, and maintain situational awareness around public-safety disruptions, crises, brand risk, and time-sensitive events. Continuously analyzes large volumes of text, images, and video across social media, news, and other online channels to surface signals, provide context, and support faster decisions — built for government, law enforcement, and corporate teams.

Investigation scenarios
  • Monitoring high-risk environments for emerging threats/safety risks
  • Tracking online discussion during active crises
  • Detecting disinformation and reputation threats
  • Monitoring threats targeting executives and VIPs
  • Assessing event risk through online activity/signals
  • Analyzing community sentiment and narrative shifts
Target users
  • Intelligence analysts and OSINT investigators
Lead with when
  • Customer needs continuous, forward-looking monitoring of a topic, event, or individual
  • VIP/executive threat monitoring
  • Crisis or live-event situational awareness
  • Brand or reputation monitoring
Bad fit when
  • Customer wants a one-time historical lookback (→ Trace's topic search or Search)
  • Customer needs SOC-style automated detection/alerting into security tooling — not a SIEM replacement
  • Customer needs image/video-based narrative detection (not supported)
Talk track

"Monitor keeps watching after the initial investigation ends — tracking a topic, event, or person continuously and alerting your team the moment something changes. It's become central to executive protection and crisis-response conversations since we acquired it, and it pairs naturally with Trace and Graph for the deeper dive when something is flagged."

Deployment, system requirements & security

Deployment/Hosting: Cloud-based.
Supported OS: Windows, macOS, Linux, iOS, Android, web. Browsers: all major. Hardware: none. Mobile: accessible via browser.
Compliance: ISO/IEC 27001:2022, GDPR; monitoring queries executed without exposing identifiable user information.
Auth: Maltego ID (MFA + SSO, also covers Graph and Academy access).

Core features
  • Near-real-time monitoring across social media and online sources
  • Configurable alerts on keywords, topics, patterns, anomalies
  • Built-in intelligence tools to process high-volume text/image/video
  • Geographic and event tracking for situational awareness
  • Sentiment and conversation-dynamics measurement
  • Collaborative monitoring — shared dashboards/insights/findings
  • AI-assisted analysis via Echo, the AI case assistant
Data access, import/export & AI

Data collection: Publicly Available Information (PAI) via official platform APIs (X, YouTube, TikTok, Bluesky), customizable RSS feeds, third-party integrations, and sock puppets (e.g. Telegram, WhatsApp). Majority via official APIs; a small portion via scraping; Facebook/Instagram partly via trusted data providers (e.g. Vetric). Coverage continually expanding. Does not consume Maltego Data Pass credits — usage is included in the Monitor package.
Import: locations, building blocks, or account lists between cases.
Export: REST API or case-level — Messages (CSV, XLSX), Reports (PDF, Word).
AI: Echo — contextual analysis, highlights key developments, sentiment analysis, keyword suggestions.

Packaging & support

Available in Base and Full Feature variants; capability/availability tailored to enterprise plans.
Billing: Annual. License: Per organization, unlimited users. Support: support@maltego.com, plus in-app help button.

Maltego Evidence

Social media intelligence collection, preservation, and analysis at scale.
Beyond Maltego OneDesktop / Collaboration
Primary capability

Controlled, defensible social media collection and preservation at scale

ICP fit

Strongest for Law Enforcement (called out repeatedly as "richest data... only tool with partial network-centrality analysis" for HVT/Organized Crime/Counter-Terrorism use cases); also relevant for corporate/incident investigation contexts.

Description

Collects, preserves, and analyzes social media content across multiple networks. Captures original data directly from supported platforms via customizable crawling profiles (sock puppets configured/authorized by the user), giving teams full control over collection while preserving data integrity. Supports downstream analysis/reporting to turn collected data into defensible findings shareable across teams.

Investigation scenarios
  • Social media investigations via secure, controlled large-scale collection
  • Capturing/preserving online content via crawling profiles for legal, compliance, or internal use
  • Investigating online communities, groups, and networks
Target users
  • Intelligence analysts and OSINT investigators
  • Digital forensics specialists and law enforcement teams
Lead with when
  • Customer needs legally defensible capture of social media content via configured crawling profiles/sock puppets
  • Customer needs private-account content
  • Customer needs network-centrality analysis — Evidence is the only tool with any support for this today, though it's partial
  • Customer needs parallel, bulk collection workflows
Bad fit when
  • Customer needs real-time alerting (→ Monitor)
  • Customer wants AI-assisted analysis (none currently)
  • Customer needs marketplace/e-commerce data (not covered)
  • Customer needs quick single lookups (→ Search)
Talk track

"When you need social media evidence that will hold up — with hashes, source attribution, and a defensible chain of custody — Evidence is the only product in our line built specifically for that, including access to private accounts through configured crawling profiles. It's also the only tool doing any network-centrality analysis today, even though that support is still partial."

Deployment, system requirements & security

Deployment: flexible — single-user desktop, or multi-user server-based collaboration.
Hosting — Desktop: locally installed, data collected/stored/processed on that machine. Hosting — Collaboration: customer-managed infrastructure, browser-accessible shared environment.
OS (Desktop): Windows 10/11 64-bit. OS (Collaboration): any major browser.
Hardware (Desktop): min Intel i5/16GB RAM/1TB storage; recommended i7/32GB/2TB SSD; high-speed internet required. Collaboration: sized to deployment/data volume/users, defined jointly with Maltego.
Mobile: Desktop — not supported; Collaboration — accessible via browser.
Compliance: GDPR; investigations run within customer-controlled environments; user authentication and permission controls.

Core features
  • Collect social data across Facebook, X, Instagram, Telegram, Odnoklassniki, TikTok, LinkedIn, YouTube, VK — profiles, posts, comments, images, videos, interactions
  • Secure collection via configurable crawling profiles, protecting investigator identity and data integrity
  • Aggregate/normalize unstructured content into structured, analysis-ready format
  • Analyze activity to uncover patterns, relationships, key entities
  • Parallel collection workflows for efficiency at scale
  • Generate investigation-ready reports; export into Maltego Graph or other tools
Data access, import/export & AI

Direct collection: Facebook, Instagram, LinkedIn, TikTok, X, Odnoklassniki, VK, Telegram, YouTube — via crawling profiles (sock puppets) that access whatever content the profile itself can see, including group/forum/community content; coverage expanding, plus custom-network definitions.
Exports: GraphML; SNH Portable Case (read-only, browser-viewable, used for legal proceedings where accepted); SNH Media Items (all media assets); SNH2 Exchange Format (share with another Evidence user/instance); Target Export (target-profile data only); Graph Exchange Format (into Maltego Graph, incl. selected social data).
Imports: SNH Exchange Format.
AI: none currently.
Note: Evidence has its own Connector into Maltego Graph (Evidence users only) — this does not consume Data Pass credits, as it isn't part of Data Pass.

Packaging & support

Three variants: Desktop Base, Desktop Full, Collaboration — tailored to enterprise plans/deployment needs.
Billing: Annual. License: Per user. Support: support@maltego.com.

Maltego Graph (Desktop)

Desktop-based link analysis for complex, large-scale, integration-heavy investigations.
Beyond Maltego OneDesktop / flexible data hosting
Primary capability

Deepest, most flexible link analysis for large-scale, integration-heavy investigations

ICP fit

Broadly applicable; explicitly called out as the "strongest current commercial cyber fit" for complex CTI investigations, and the current choice wherever Connectors, full Data Pass, offline, or on-prem are required.

Description

Conducts complex, large-scale investigations across diverse data sources. Collects, visualizes, and analyzes relationships using Transforms, custom integrations, and advanced analytical workflows across cyber, fraud, law-enforcement, and intelligence use cases. Core Maltego ecosystem component with the deepest control over data ingestion, enrichment, and analysis. Users continue investigations initiated in Search, Monitor, or Evidence here for deeper analysis. Graph (Desktop) and Graph (Browser) are two complementary variants of the same flagship link-analysis product — both are included in every new enterprise and webshop plan; Desktop is not "legacy" and is not being replaced by Browser (see Decision Guide and Guardrails).

Investigation scenarios
  • Advanced, multi-source digital investigations
  • Complex link analysis on large datasets
  • Integrating and analyzing internal or external data
  • Investigating cyber threats and underlying infrastructure
  • Mapping complex relationships within OSINT data
  • Analyzing fraud and financial-crime networks
Target users
  • Intelligence analysts and OSINT investigators
  • Technical teams requiring data integration/custom workflows
  • Highly technical analysts who prefer granular control over Transforms and Credit usage
  • Teams needing offline/air-gapped work, on-premise deployment, or own-API-key Connectors today
Lead with when
  • Customer relies on Connectors with their own API keys
  • Customer needs full Data Pass module access today
  • Offline/air-gapped work or on-premise deployment is required now
  • Graphs need to scale to thousands of Entities
  • Highly technical analysts want granular Credit control
Bad fit when
  • Customer wants zero-install, browser-only access
  • Customer wants AI-assisted guidance (Desktop has no AI Assistant)
  • Customer has limited IT resources for desktop deployment
  • Customer wants the 1-click Search-to-Graph pivot
Talk track

"When an investigation needs to pull in your own data sources, scale to thousands of Entities, or run without an internet connection, Graph (Desktop) is built for that. It's not going anywhere — it's the deeper, more technical half of the same flagship product as Graph (Browser), and every plan includes both."

Deployment, system requirements & security

Deployment: desktop application, installed locally on Windows, macOS, or Linux. Hosting: local install, with flexible access to cloud-hosted or on-premise data/integration services depending on configuration.
OS: Windows, Linux, OS X (incl. Mac ARM/Apple Silicon chipsets). Browser: N/A (separate Graph Browser app for browser-based analysis; feature availability differs).
Software: 64-bit Java runtime. Hardware: min 8GB RAM, Intel i3 processor; performance depends on graph/dataset size and complexity.
Offline work: supported — Graph (Desktop) can work offline/locally (Data Pass and external data queries still require internet access). This is the current choice for air-gapped environments or field work without connectivity.
On-premise: supported today — the current choice for on-prem deployment while Graph (Browser)'s hybrid/full on-prem options are still on the roadmap.
Mobile: not supported.
Compliance: ISO/IEC 27001:2022, GDPR, EU AI Act; anonymized/confidential searches.
Auth: Maltego ID (MFA + SSO).

Core features
  • Advanced link analysis across complex datasets, mapping networks/patterns/connections
  • Step-by-step enrichment via atomic Transforms (specific, checkable Credit cost per Transform) with pivoting from results
  • Maltego Machines — automate repeatable multi-step workflows (sequential or parallel Transforms)
  • Large-scale, multifaceted investigations with extensive data enrichment/visualization — handles big datasets/graphs with thousands of Entities, well beyond Graph (Browser)'s current ~5,000-Entity practical ceiling
  • Pivot from Maltego Search via an export/import workflow (not the 1-click pivot available in Graph (Browser))
  • Real-time collaboration via Communication Server (up to 4 users), or work shared via Maltego Cases
  • Flexible storage — local .mtgx files or secure cloud Cases, optional E2E encryption
  • Full admin visibility via Maltego Admin within Maltego One
Data access, import/export & AI

Data Pass: access to all currently available modules (POI, CTI, Dark Web, Cryptocurrency, Corporate Intelligence, Utilities) — full coverage today, ahead of Graph (Browser)'s current POI/CTI/Utilities-only access.
Connectors: 100+ pre-built, using own API keys — the current choice for customers who rely on their own API keys (Browser support is planned in phases from end of 2026).
Connector Builder: custom integrations for internal/proprietary/external data. Desktop has always supported own-data integration, historically via the older TRX Library plus iTDS/pTDS server infrastructure — setup, testing, debugging, hosting, and maintenance were all more complex under that model. As of ~beginning of July 2026, the new Maltego Transforms SDK gives Desktop the same simpler build/test/maintain workflow now available in Browser, without requiring the older infrastructure. TRX Library still exists as the legacy method; the SDK is the new recommended path going forward. Org-wide sharing of custom Transform servers still requires the separate Own Data integration package entitlement (see Graph (Browser) card for the full packaging model, which applies identically here).
Credit visibility: Credits used/remaining shown directly in the Transform Output Window — combined with atomic (per-Transform) Credit costs, this gives more predictable, granular Credit estimation than Graph (Browser)'s bundled Transforms.
Import: external datasets. Export: CSV, Microsoft Excel, PDF, Maltego Graph files (.mtgx).
AI: no AI Assistant available on Graph (Desktop). AI capability is limited to Gemini Transforms within Data Pass (querying an AI model as a Transform) — this is a genuine capability gap vs. Graph (Browser) and Maltego Search, both of which include an optional AI Assistant for navigation/summarization.

Packaging & support

Available across Maltego plans; capabilities/data access/integrations vary by plan/entitlement. Graph access per seat — one seat includes both Desktop and Browser where included in the plan; customers don't choose one over the other.
Billing: Annual. License: Per user. Support: support@maltego.com.

Hunchly

Web capture and evidence-preservation tool that documents online activity as you browse.
Beyond Maltego OneDesktop, local-first
Primary capability

Automatic, defensible web-page capture with hashing and chain-of-custody

ICP fit

Cross-ICP utility — used inside and outside the five core ICPs (journalists, NGOs, legal/compliance teams); complements any other Maltego product rather than competing with one.

Description

Automatically documents online activity while browsing: webpages, searches, social media content, images, attachments, and metadata (URLs, timestamps, hashes, page archives) to preserve a reliable record before content changes or disappears. Organizes captures with tags, selectors, notes, and searchable case data for repeatable, defensible workflows — reducing reliance on manual screenshots. Investigators review evidence offline, build reports, and export for internal review, client delivery, legal handover, or further analysis.

Investigation scenarios
  • Capturing/preserving content before it changes or disappears
  • Building defensible records with preserved metadata and audit trails
  • Organizing web evidence with tags, selectors, notes, searchable case data
  • Preparing findings for internal review, client delivery, legal handover, compliance
  • Reviewing captured evidence offline
Target users
  • Intelligence analysts and OSINT investigators
  • Investigative journalists, NGOs, and researchers
  • Legal, compliance, and internal investigation teams
Lead with when
  • Customer needs to preserve web evidence before it disappears
  • Customer needs court-ready metadata and hash trails
  • Customer works largely offline/locally
  • Customer wants a low-cost complement to any other Maltego product
Bad fit when
  • Customer needs collection across social platforms at scale (→ Evidence)
  • Customer needs Firefox or Safari support (Chrome/Chromium/Edge/Brave only)
  • Customer needs cloud-hosted, multi-user collaboration by default
Talk track

"Hunchly is the simplest, most defensible way to capture exactly what an investigator saw on the web — timestamped, hashed, signed, ready for a legal record. It runs locally by default, so it's an easy, low-friction add for almost any team already using Maltego, regardless of which other products they have."

Deployment, system requirements & security

Deployment: desktop application + Chrome/Chromium browser extension. Hosting: local by default; optional Data Forwarding for team workflows.
OS: Windows 10 64-bit+, macOS 10.15+, Ubuntu 20.04 LTS+ (note: Apple ends Intel Mac support with macOS 27 — Hunchly ends Intel Mac support Sept 2027). Browsers: Chrome/Chromium/Edge/Brave only — Firefox and Safari not supported.
Hardware: min 4GB RAM/20GB disk; recommended 8GB RAM/SSD/modern multicore CPU. Mobile: none.
Data privacy: case data stored locally by default; no outbound connection except user-configured Data Forwarding (off by default); Hunchly does not receive usage info (pages visited, cases worked).
Evidence integrity: SHA-256 content hashing; individual hashing for images/attachments; GPG signing for non-repudiation; investigation history for audit trail.
Compliance: GDPR, EU AI Act.
Auth: offline activation via license key file — no Maltego ID sign-in required for end users; Maltego ID used only for customer account management (license keys, downloads).

Core features
  • Automatically capture webpages, searches, social pages, and other content while browsing
  • Preserve full-page content, MHTML archives, source code, URLs, timestamps, images, EXIF metadata
  • Verify integrity via hashing, digital signatures, investigation history
  • Organize with tags, notes, annotations, image captions, importance flags, to-dos, case reference numbers, full-text search
  • Detect/prioritize via keyword selectors, regex selectors, selector alerts, retroactive scanning, history filtering, data extractors
  • Generate formatted reports and export full/selected case materials
  • Work and review evidence fully offline
Data access, import/export & AI

Data access: captures directly through the investigator's browser via the Chrome/Chromium extension; stored locally, organized/searched/tagged/annotated as part of the case.
Import: previously exported Hunchly cases.
Export: full or selected case materials (pages, tags, date ranges); formatted reports via Report Builder; page captures as PDF/MHTML; selector matches as CSV.
AI: none.

Packaging & support

Hunchly Free: basic capture for individuals/community — no case management, notes, full-text search, regex selectors, data extractors, Report Builder, or Data Forwarding.
Hunchly Classic: full professional capture, preservation, organization, and reporting. Included with Maltego Entry, Professional, and Enterprise plans, or available standalone.
Billing: Annual. License: Per user. Support: support@hunch.ly; Hunchly Knowledgebase for guidance on using Hunchly alongside other Maltego products.

Cloak

Managed attribution and operational-security infrastructure for online investigations.
Beyond Maltego OneOn-prem / customer cloudQualification required
Primary capability

Managed attribution / OPSEC network infrastructure customers control themselves

ICP fit

Narrow by design — defense, intelligence, high-risk law enforcement, and compliance-driven private-sector teams with a real attribution problem. Does not map to the ICP1–5 model; qualified via its own fit framework instead.

Description

Cloak lets investigative teams create and control less-attributable network infrastructure for online investigations — reducing attribution risk, controlling how investigative traffic appears online, and supporting sensitive investigations where infrastructure control, security, or compliance matter. It solves the network layer of managed attribution (not the OS/application layer or analyst-behavior layer) — it is explicitly not an all-in-one managed-attribution solution.

Use cases
  • Sensitive government or intelligence investigations
  • Threat research across forums, messaging platforms, dark web environments
  • Collaborative cybercrime investigations involving multiple users, personas, or operations
Target users
  • Technically capable teams with real OPSEC/attribution needs: defense & military, intelligence agencies, high-risk law enforcement, government intelligence contractors, threat intel teams, intelligence providers, compliance-driven private-sector orgs
  • Illustrative examples referenced internally: Cybercrime Atlas, Sapper Labs (defense consulting/OSINT), SpyCloud Labs (threat research)
Lead with when
  • Customer passes all 4 qualification questions — see Decision Guide
  • Real, confirmed OPSEC/attribution problem, not a general desire for "better browsing"
  • Institutional, technically confident team comfortable with self-hosted infrastructure
  • Customer is open to early adoption and co-development
Bad fit when
  • Customer wants a fully turnkey, non-technical experience
  • Customer has no real attribution/OPSEC problem to solve
  • Customer isn't a defense/intel/high-risk investigative type
Talk track

"Cloak isn't a product to lead with by default — it's for teams that already know they have a real attribution problem and want infrastructure they control themselves, not shared with other customers. If a customer clears the qualification gate, it's a strong complement to Evidence and to their existing tradecraft."

Deployment, technical requirements & security

Deployment: on-prem server product, built around customer-controlled infrastructure — customers bring their own cloud credentials. Cloud providers supported: DigitalOcean, Akamai, AWS, Catalyst Cloud (OpenStack-compatible).
Technical: lightweight server, minimal on-prem requirements or a minimal cloud instance (e.g. AWS T3 Micro); packaged as 2 Docker containers (CLI + server); recommended Linux/Debian deployment; CLI or API access to upload cloud credentials, manage providers, deploy/destroy network paths.
Server requirements: 1 CPU, 1GB RAM, 25GB storage minimum. Auth: Auth0 (alignment toward Maltego ID underway).
Security: IP whitelisting for access control; traffic designed to blend with normal web traffic (TLS over standard ports).

Core features
  • Ephemeral and persistent network paths — built for one operation and destroyed, or kept persistent over time
  • Single- and multi-hop routing for different operational requirements
  • Customer-controlled infrastructure — own cloud credentials, aligning with sovereignty/security/compliance needs
  • Traffic designed to blend with normal web activity (TLS/HTTPS over port 443)
  • Minimal persistent footprint — nodes wipe on failure or if hosting systems reboot/power off
  • Hidden-service access via Tor and I2P proxy support in network egress
  • Administrative visibility into created networks/infrastructure
  • Works alongside broader investigation environments (e.g. Kasm) and Maltego products/personas/workspaces
Positioning notes (from internal enablement)

Managed attribution spans three layers: Network (can traffic reveal org/intent?), OS/Application (is the laptop compromised?), Analyst Behavior (does behavior reveal intent?). Cloak addresses the Network layer only — it is explicitly not a full managed-attribution solution.
Does not compete directly with IIS Long Arm or Authentic8 Silo today (those pool/share infrastructure across customers and offer transparency at best, not agency over hosting/data sovereignty) — though Maltego Browser (POC, not launched) will compete more directly in that space.
Works alongside tools like Kasm for a full investigation-workspace system, and is moving toward Maltego ID alignment. Complements Maltego Evidence for organizations needing defensible, chain-of-custody-aware outputs.

Packaging & support

License: Annual base license, per organization — includes regular updates and implementation support for Google Cloud, AWS, and DigitalOcean. Add-on: one-time implementation fee for an additional cloud provider beyond the included set.
Pricing: not included in this guide — pricing changes too frequently to keep current here. Contact your Maltego lead for current figures.
Support: support@maltego.com; release notes available in-product.

Cloak is not a "sell everywhere" product. It must pass the 4-question qualification gate (see Decision Guide) before any customer conversation — it is not suited to customers expecting a low-touch, fully turnkey, non-technical experience.

Maltego Data

The umbrella term for every way to get data into Maltego — not a product itself, but the concept that ties the other three together.
Data OfferingUnderlies Graph & Search
Primary capability

The umbrella framing for Data Pass, Connectors, and Connector Builder — "your single pane of glass for all relevant data"

ICP fit

Cross-cutting — not audience-differentiated. Relevant to all five ICPs, since every investigation needs data of some kind.

Description

Maltego Data is Maltego's overall data-access offering — an umbrella term for the three ways users get data into an investigation: Maltego Data Pass (built-in, credit-based access), Maltego Connectors (ready-made integrations using a customer's own API keys), and Connector Builder (the capability to build custom Transforms for internal/proprietary data). Positioned as "your single pane of glass for all relevant data" — Maltego is a data access/integration platform, not a data vendor. It does not sell data itself; it provides a flexible, reliable, supplier-agnostic route to trusted third-party sources, and a path to a customer's own data.

The three components, at a glance
  • Maltego Data Pass — zero-setup, credit-based, included in every plan. Always the default lead.
  • Maltego Connectors — a customer's own API key/credentials to a specific third-party source. 100+ pre-built, Graph (Desktop) only today.
  • Connector Builder — build custom Transforms for internal/proprietary data. Available on both Graph variants since ~July 2026.
Access & packaging
  • Access to Maltego Data depends on the user's plan — CE, Basic, Professional, or Organization/Enterprise — and may further depend on the customer's industry, country, organization, or use case.
  • The three components are not three co-equal choices to present to a customer — see the "Data Pass-first" messaging discipline below.
"Data Pass-first" messaging discipline: always lead with Data Pass — it's the zero-effort default included in every plan. Introduce Connectors only when the customer already has a specific vendor contract/API key they want to use directly. Introduce Connector Builder only when the customer needs to integrate their own internal or proprietary data. Never present all three as interchangeable options — see the Overlaps tab's "Data Pass vs. Connectors vs. Connector Builder" resolver and the Decision Guide for the full lead-with logic.
Terminology hierarchy (use precisely)

Maltego Data (umbrella term) contains:
Maltego Data Pass (built-in, credit-based data)
Maltego Connectors (own-API-key integrations)
Connector Builder (the capability to build custom Transforms), built using either the newer Maltego Transforms SDK (recommended, easier to build/test/maintain) or the older Maltego TRX Library (legacy, still valid) — which previously required iTDS/pTDS server infrastructure (legacy model, more complex to host/maintain, no longer the default path).
Never name individual underlying data vendors in customer conversations (e.g. say "Maltego Data Pass," not "Vetric" or "District4") — Maltego is positioned as supplier-agnostic, not a reseller of any one vendor.

Maltego Data Pass

Built-in, credit-based access to curated investigation data — the flagship of the Maltego Data offering.
Data OfferingIncluded in every plan
Primary capability

Built-in, credit-based access to curated investigation data across six modules

ICP fit

Cross-cutting data layer underneath Graph and Search — not audience-differentiated; relevant to all five ICPs.

Description

Gives users built-in access to curated investigation data directly within the Maltego platform — no separate vendor contracts, API keys, or manual setup. Helps investigators enrich Entities and expand investigations across person of interest, cyber threat intelligence, cryptocurrency, dark web, and corporate intelligence. Data Pass sits alongside Connectors (own API keys to existing third-party access) and Connector Builder (integrating internal/proprietary sources) as the three components of Maltego Data — Maltego's overall data-access offering, positioned as "your single pane of glass for all relevant data." Maltego is a data access/integration platform, not a data vendor — it does not sell data, but provides a flexible, reliable, supplier-agnostic route to trusted third-party sources.

Supported Maltego products
  • Graph (Desktop): all currently available Data Pass modules
  • Graph (Browser): POI, CTI, and Utilities modules today; full parity with Desktop planned by end of 2026
  • Search: uses Data Pass for email, phone, username, domain, and password starting points, presented as one unified search experience
  • Monitor and Evidence do not consume Data Pass credits — their data access works differently (see their cards)
Target users
  • Intelligence and national security teams; law enforcement and criminal investigation teams; military intelligence units
  • Risk advisory practices; corporate security and threat intelligence teams; fraud, due diligence, and corporate intelligence teams
Lead with when
  • Any conversation about "what data is available inside Maltego" — always lead with Data Pass ahead of Connectors/Connector Builder
  • Customer wants to avoid separate vendor contracts, API keys, or manual data-source setup
  • Customer values provider continuity (multiple providers per category) over single-vendor dependency
Bad fit when
  • Customer needs data categories currently absent from Data Pass — e.g. e-commerce marketplace data, comprehensive PEP/adverse media, air/vessel tracking — be upfront about these documented gaps
  • Customer already has a specific vendor contract they want to keep using directly (→ Connectors instead)
Talk track

"Data Pass is why customers don't need to go source data vendors themselves — it's built into the platform, credit-based, and continuously growing. Always lead with Data Pass first, then bring in Connectors or Connector Builder only if the customer needs something beyond it."

Data coverage & scale

Six modules: Person of Interest (online identities, breach data, social/online profiles); Cyber Threat Intelligence (domain/IP/infrastructure, malware/threat indicators); Cryptocurrency Investigations (wallets, transactions, blockchain activity); Dark Web Analysis (forums, marketplaces, leaked/exposed data); Corporate Intelligence (registries, ownership structures, sanctions/watchlists); Utilities (DNS resolution, geolocation, image analysis, translation).
Scale: 70+ data partners; 12,000+ search methods; 1TB+ of publicly available breach data; 1 billion+ online identities; 220 million+ companies from major corporate registries; 200+ social networks supported (major and niche platforms).
Communicating provider counts: 120+ total data partners/providers (Connectors and/or Data Pass combined); 70+ support Data Pass exclusively. Social coverage spans major platforms (Facebook, Instagram, X, YouTube) plus niche ones (Foursquare, Discord, GitHub, Steam, Duolingo, OnlyFans, TripAdvisor).
Data Pass replaces (terms no longer supported): Standalone Maltego Data Pass, Click-and-Run Allowances, Maltego Selection, Maltego Standard Transforms, OSINT Profiler Searches.

Credit model & data transfer

Maltego Credits are spent running Data Pass queries in Search or Data Pass Transforms in Graph (Browser/Desktop). Monthly organization allowance; admins distribute Credits and set per-user limits in Maltego Admin. Credit cost varies by product/query type — Graph (Desktop) Transforms run individually with defined costs (Knowledge Base); Graph (Browser) bundled Transforms vary by sources queried; Search typically ~200 Credits per query.
Illustrative only: a Professional user with 20,000 monthly Credits could run roughly ~320 Data Pass Transforms in Graph (Desktop, at ~60 Credits average) or ~100 searches in Search (at ~200 Credits average) — rough averages, not guaranteed volumes.
Credit visibility: shown in the Transform Output Window (Graph Desktop), Transform dialog/profile menu (Graph Browser), and profile menu (Search).
Data transfer model: Maltego acts as a proxy between investigator and Data Pass sources — providers do not see the investigator's identity, organization, or broader context. Maltego retains source/lineage information so users can review provenance. Provider continuity: most categories draw on more than one provider, so losing one provider doesn't remove coverage.

Security, compliance & packaging

Compliance: ISO/IEC 27001:2022, GDPR, EU AI Act; all searches anonymized/confidential.
Auth: modules are built-in and ready to use — no separate setup/authentication; Credit allowances and limits managed per user by org admins in Maltego Admin.
Packaging: included in every new Maltego plan, Basic through Enterprise; specific data categories/depth may vary by plan, product, and entitlement.
Billing: Annual. License: Per organization, Credits shared/managed across users. Support: support@maltego.com; Maltego Knowledge Base for current data sources and Credit costs.

Connectors and Connector Builder now have their own cards below — see Maltego Connectors and Connector Builder for full detail. Data Pass remains the default lead per the "Data Pass-first" messaging discipline (see the Maltego Data card).

Maltego Connectors

Ready-made integrations to other data sources or tools, using a customer's own API key or access credentials.
Data OfferingGraph (Desktop) only today
Primary capability

100+ pre-built integrations to third-party data sources, using the customer's own API keys/credentials

ICP fit

Cross-cutting — relevant wherever a customer already has an existing vendor relationship they want to keep using inside Maltego, across any of the five ICPs.

Description

Maltego Connectors are ready-made integrations to other data sources or tools. Unlike Data Pass, the user is required to enter their own API key or access credentials to access content via a Connector. This lets customers who already have existing vendor contracts (e.g. Orbis) maximize that investment inside Maltego, rather than duplicating coverage Data Pass already provides. There are currently 100+ pre-built Connectors available for Maltego Graph.

How it works — example
  • Install the desired Connector (e.g. VirusTotal) in Maltego Graph (Desktop)
  • Enter the API key or access credentials for that source
  • Use the data directly inside Maltego Graph, pivoting and enriching as with any other Transform
Target users
  • Customers with existing data-vendor contracts who want to use that investment inside Maltego rather than a separate tool
  • Technical teams comfortable managing their own API keys/credentials
Lead with when
  • Customer already has a specific vendor contract/API key they want to use directly inside Maltego
  • Customer needs a data source Data Pass doesn't cover, and a pre-built Connector exists for it
Bad fit when
  • Customer is on Graph (Browser) and needs Connectors today — not yet available there (planned in phases from end of 2026, full availability from 2027)
  • Customer wants zero-setup access — that's Data Pass, not Connectors
  • Customer needs to integrate genuinely internal/proprietary data with no existing vendor — that's Connector Builder, not a pre-built Connector
Talk track

"If you're already paying for a data source and just want it inside Maltego instead of a separate window, Connectors are built for exactly that — install it, drop in your API key, and it's part of your graph like everything else. Right now that's a Graph (Desktop) capability; Browser support is coming in phases."

Deployment & data access

Availability: Graph (Desktop) only today. Graph (Browser) support is planned in phases, with batches introduced from end of 2026 and full availability from 2027 (internal reference only — don't commit these dates to customers, see Guardrails).
Credits: Connectors do not consume Maltego Data Pass credits — they're a separate access path, billed/authenticated through the customer's own vendor relationship.
Setup: install the Connector, enter the API key/credentials, then use the data directly inside Graph.

Connector Builder

Not a standalone product — the capability to build custom Transforms to integrate any internal or external data source.
Data OfferingBoth Graph variants, since ~July 2026
Primary capability

Build custom Transforms for internal, proprietary, or partner data — via the new Maltego Transforms SDK or the older TRX Library

ICP fit

Cross-cutting, technical-team-dependent — relevant to any ICP with internal data they want alongside Maltego's built-in sources, provided they have (or can get) technical implementation support.

Description

Connector Builder makes it easy to integrate any data source or tool into Maltego, giving users the flexibility to customize their investigations. With Maltego's developer-friendly tooling — the open-source TRX Library (older method, still valid) or the newer Maltego Transforms SDK (recommended, simpler to build/test/maintain) — technical users can quickly build their own Transforms, whether connecting to internal databases, APIs, or other external sources. There is no standalone "Connector Builder" product — the term refers to the capability itself. As of ~beginning of July 2026 (the "Connect Own Data in Maltego One" release), this capability is available on both Graph (Desktop) and Graph (Browser) — previously, own-data integration existed only in Graph (Desktop) via the older TRX/iTDS/pTDS infrastructure model, which was a real adoption blocker for Browser.

Packaging — two tiers
  • All eligible users (Basic, Entry, Professional, Enterprise) can build and run custom Transforms locally in both Graph (Browser) and Graph (Desktop) at no extra entitlement.
  • Customers with the separate Own Data integration package entitlement can additionally use and share approved Transform servers hosted beyond a single user's machine — broader team/org access, managed by admins who approve which users and which "seed URLs" are allowed.
Setup
  • Org admin: (1) confirm the Maltego Transforms SDK is enabled for the org in Maltego Admin; (2) choose which users can use custom Transforms; (3) add approved seed URLs pointing to the org's custom Transform servers.
  • Investigator (Graph Browser): (1) open the Data tab in the left panel, select "Add Data Source"; (2) enter the approved seed URL — the custom Transforms become available in the graph.
Lead with when
  • Customer needs to integrate genuinely internal, proprietary, or partner data with no existing off-the-shelf Connector
  • Customer has (or is willing to get) technical implementation support — this is SDK-based, not no-code
  • Customer wants the same capability on both Graph (Browser) and Graph (Desktop), not just Desktop
Bad fit when
  • Customer expects a no-code, drag-and-drop experience — that's a later roadmap step (2027+), not current
  • Customer wants the whole team to access shared custom Transforms without the Own Data integration package entitlement — local-only access is all that's included otherwise
  • A pre-built Connector already covers the source — no need to build one from scratch
Talk track

"If your team has internal or proprietary data you want alongside Maltego's built-in sources, Connector Builder is how you bring it in — and as of this year, that works in Graph (Browser) too, not just Desktop. It still takes some technical setup; this isn't a no-code experience yet, but it's a lot simpler than the old TRX/iTDS setup was."

Customer assurance: "browser doesn't mean cloud"

Graph (Browser) being browser-based does not mean customer data is automatically processed in Maltego One Cloud. The application runs locally in the user's browser; it uses Maltego One Cloud for services like configuration and Data Hub access, but for a configured custom data source, the browser app requests data directly from the customer-controlled source rather than routing it through Maltego infrastructure. (Analogy: Browser is the TV, a custom Transform is the DVD player.) See the Messaging Guidelines tab (section 8) for the full talk track and Say/Don't Say guidance.

Never call this "no-code" or imply any customer can do this without technical help. Never reference the internal codename "V3 SDK" externally. Never say "all customers can share custom Transforms across their organization" — that specifically requires the Own Data integration package entitlement.

Maltego Profile

Public-source profiling software for persons, companies, topics, and areas of interest — the core of the new product line.
New Product LineCloud (default), on-prem, or private cloudCore / broad-audience default
Primary capability

One curated, AI-assisted profile on a person, company, topic, or area — no ADINT

ICP fit

Strong across all five ICPs — the only new-line product with that breadth; anchors Law Enforcement, Risk Consultancies, and Threat Intel Teams.

Description

Maltego Profile builds structured profiles from public-source information on a person, company, topic, or area, with AI-assisted highlighting of adverse information and key themes. It consolidates public-source findings into one curated, reviewable result, helping investigators move from a scarce starting point — a name, location, online account, or other preliminary lead — to a clearer picture of who or what they are investigating within minutes. Findings can help investigators identify leads and areas for follow-up analysis to explore further in other Maltego solutions. Profile, Trace, and Screen share one platform/codebase — Profile is the core, Trace and Screen are extensions. Profile carries no ADINT, so it sits under far fewer constraints and is the broad-audience, GDPR-friendly default for Europe and commercial accounts where Trace cannot go.

Investigation scenarios
  • Investigating persons of interest and uncovering hidden relationships between individuals
  • Profiling topics, companies, and areas to support case-driven background research
  • Conducting due diligence and risk assessments on individuals and companies ahead of a client engagement, hire, or transaction
Target users
  • Intelligence analysts and OSINT investigators
  • Risk and compliance teams conducting due diligence
  • Law enforcement and threat intelligence teams
Explicitly excluded (present in Trace, not Profile)
  • Tracks feature; Visits feature (area search); emails tab; "next traffic" tab; consumer devices in area search
  • Device tab limited to cell towers/traffic cameras only
  • ADINT and the full geospatial pattern-of-life layer
  • Restricted Identity Insights add-on (device-ID-to-real-identity de-anonymization)
Lead with when
  • Customer needs GDPR-friendly due diligence/background research without ADINT
  • Customer needs company, topic, or area profiling beyond what Search offers
  • Customer is in Europe or a compliance-sensitive commercial context
Bad fit when
  • Customer specifically needs geospatial/pattern-of-life or ADINT (→ Trace instead — don't bundle both)
  • Customer needs bulk/batch screening of many people (→ Screen)
Talk track

"Profile is the product almost anyone can use — no ADINT, GDPR-by-design, and it builds a full curated picture of a person, company, topic, or area in minutes. It's the default starting point for the new product line; only add Trace on top if the customer specifically needs the geospatial layer."

Deployment, system requirements & security

Deployment model: Cloud (default), on-premises, or private cloud. Hosting: Cloud (Maltego-hosted) by default; on-premises or private cloud is customer- or partner-hosted.
Browser compatibility: all major browsers (Chrome, Firefox, Edge, Safari), optimized on Chrome and Edge. Mobile & tablet: accessible via browser.

Core features
  • Build a curated profile on a person, company, theme, or area: consolidate a broad collection of public sources into one structured, reviewable result, with AI-assisted highlighting of adverse information and key themes.
  • Resolve and enrich an individual's identity: start from an identifier (name, date of birth, address, phone number, email address, or username), review candidate profiles across platforms, confirm the correct match, and enrich with accounts, aliases, connections, media, and posts.
  • Discover relationships in a single step: the "Find relations" action surfaces how two people are connected, without manually reproducing the analysis through link analysis.
  • Search beyond individuals: build profiles of companies, topics, and areas, including geolocation-based area search, to support broader investigative research.
  • Analyze collected media: review media gathered during an investigation using built-in media analytics.
Data access, import/export & AI capabilities

Data access: open web and public content (news, blogs, forums, classifieds, hosting/services, general web data); social media and global messaging platforms (mainstream — X, Instagram — plus region-specific platforms like VK, Douyin, and messaging apps where accessible/allowed); deep & dark web data (forums/marketplaces, leaked credentials, stealer logs, and other high-risk datasets, where access is permitted).
Import/Export: supports importing external datasets and exporting results into other tools and environments — avoids locking users out of pivoting data in or out of Profile for further analytical development. Export formats: CSV, Microsoft Excel, PDF.

AI capabilities (shared across Profile, Trace, and Screen — see the note below the Capability Matrix):

AI-driven text analysis:

  • Text classification: automatically reviews text content within a search and assigns labels — e.g. violence-related, benign, influence indicators — to support rapid filtering and prioritization. Does not use transcript content.
  • Named entity recognition: extracts references to real-world entities (people, locations, organizations) and key values (e.g. credit card numbers), enabling structured filtering and analysis. Can also extract named entities from transcribed media content.
  • Sentiment analysis: tags captions and titles by apparent mood to help spot escalation, agitation, or shifts in narrative tone. Does not use transcript content.

AI-driven media analysis:

  • Object detection in images and video: detects predefined object categories of concern and highlights them with bounding boxes; filterable by category (e.g. weapons, militant insignia).
  • Text detection / OCR in images and video: extracts printed, typed, or handwritten text from media so results can be searched and filtered by keywords.
  • Face detection and matching in images: isolates image results containing faces for review. Face matching is not supported for video.
Target users & ICP fit

The only product in the new line with strong fit across all five ICPs — anchors ICP3 Law Enforcement, ICP4 Risk Consultancies, and ICP5 Threat Intel Teams; also strong for ICP1/ICP2. Documented scenario: a European risk-advisory firm (ICP4) assessing an individual before a client engagement, with no ADINT permissibility — Profile builds the full picture in minutes, GDPR-by-design.

Packaging & support

Sold as a standalone license; additional Maltego products and services can be purchased as part of a broader bundle depending on customer needs. Access, configuration, and deployment depend on customer needs, use case, and plan entitlements.
Billing: Annual. License: Per user — reach out to your Maltego contact for exact terms. Support: support@maltego.com. Release notes: in-app announcement upon login to Maltego Profile.
Open items (unconfirmed in source): whether media analytics becomes a paid upsell; whether the candidate-confirmation step is a current Profile-native UI flow or underlying engine behavior.

Maltego Trace

The geospatial-intelligence extension of the line — Profile plus pattern-of-life analysis.
New Product LineCloud or on-premEligible GOV ICPs only
Primary capability

Everything Profile does, plus geospatial pattern-of-life and (for eligible customers) ADINT

ICP fit

Anchors Intelligence and Military & Defense; strong in Law Enforcement where authority exists; medium for commercial ICPs. Eligibility-gated — see Guardrails before sharing any materials.

Description

Formerly OiO/OpenIO. Enables investigative, security, intelligence, and defense teams to derive precise, near-real-time intelligence from digital location-related signals — correlating identifiers across time and geography to reveal high-confidence movement, behavior, and co-location patterns at global scale, connected back to persons of interest and enriched with AI. Trace is everything Profile does, plus the geospatial pattern-of-life layer. ADINT (advertising-derived location intelligence, externally "Commercial & Proprietary Telemetry Data"/CTD) is one data category the geo layer draws on — the most sensitive, but not the headline; Trace's differentiator is the intelligence in the geo normalization and algorithms.

Uses / investigation scenarios
  • Person-of-interest investigations and VIP protection
  • Situational awareness: force protection, counter-terrorism, drug/human trafficking
  • Signature awareness of digital footprints, including location-related signals
  • Insider threat monitoring (behavioral red flags, policy violations)
  • Supply chain analysis for operational/reputational risk
What Trace runs from
  • Area-based discovery: geofence a location, surface every device/entity/signal inside, ranked into patterns over time
  • Pattern-of-life: movement, frequented places, co-location, behavioral shifts — Trace's defining capability
  • Person search & identity resolution: name, alias, email, phone, or device identifier → full entity profile
  • Relationship discovery: one-click "find relations"
  • Topic search & alerts: investigative lookback with alerting for force protection
  • Company investigation: company profile + personnel, supports sanctions work
  • Media analytics: face, object, and text detection/classification across media
Lead with when
  • Customer eligibility is already confirmed and needs geospatial/pattern-of-life analysis
  • Force protection, counter-terrorism, or VIP location-security use cases
  • Customer needs ADINT specifically (where geographic coverage supports it)
Bad fit when
  • Customer eligibility is unconfirmed — stop, don't share Trace materials (see Guardrails)
  • Commercial customer asking about Identity Insights specifically — absolute no
  • ADINT coverage is thin in their geography and that's the sole draw
Talk track

"Trace does everything Profile does, then adds the geospatial layer — movement, co-location, and for eligible customers, ADINT. Never pitch this without confirming eligibility first, and never bundle it with Profile, since Trace already includes Profile's core."

System requirements & data access

Deployment: cloud-based (also cloud or on-prem per line-level commercial posture). OS: Windows, macOS, Linux, web. Browsers: all major. Hardware/mobile: none required/not supported.
Scale: sub-second queries across 160+ integrated public and commercial sources; 30B+ indexed/publicly available records; 130+ languages supported.
Data categories: open web/public content (news, blogs, forums, classifieds); social media & global messaging (mainstream + region-specific, e.g. VK, Douyin); deep & dark web data (forums/marketplaces, leaked credentials, stealer logs, where permitted); Commercial & Proprietary Telemetry Data (mobile ad IDs/MAIDs, SDK/RTB-derived signals, geo-temporal mobile signals, WiFi/infrastructure signals where applicable); geospatial/geo-temporal analytics inputs.
Import/Export: imports external datasets; exports CSV, Excel, PDF.
AI capabilities (shared across Profile, Trace, and Screen):
AI-driven text analysis: text classification (labels e.g. violence-related, benign, influence indicators — does not use transcript content); named entity recognition (people, locations, organizations, key values like credit card numbers — can also extract from transcribed media content); sentiment analysis (captions/titles by apparent mood — does not use transcript content).
AI-driven media analysis: object detection in images/video (predefined categories of concern, bounding boxes, filterable — e.g. weapons, militant insignia); text detection/OCR in images/video (printed/typed/handwritten text, searchable/filterable by keyword); face detection and matching in images (face matching not supported for video).

Compliance, eligibility & commercial posture

The most strictly governed product in the line. Permissibility decided by customer segment/jurisdiction; Maltego's own KYC applied per deal. Maltego is data processor, customer is controller. Identity Insights (resolving ad identifiers to real-world identities) is a separate restricted add-on for eligible customers only — an absolute no for commercial customers.
ADINT coverage is geography-dependent — strongest in the US, weaker in Europe, case-by-case elsewhere, actively being improved (European coverage is the top roadmap priority).
ICP fit: anchors ICP1 Intelligence and ICP2 Military & Defense; strong in ICP3 Law Enforcement where the customer has authority. Buyer is typically a mission/program owner; user is the analyst.
Containment by design: ADINT and Identity Insights are concentrated in Trace specifically so Profile and Screen carry none of that exposure — if ad-tech data is ever restricted, the rest of the line is insulated.

Trace materials require confirmed customer eligibility before use. Do not produce or hand over Trace decks, demos, or product materials unless eligibility has already been verified.

Maltego Screen

The automated, large-scale extension of the line — batch social media screening with human-in-the-loop review.
New Product LineCloud or on-premCommercial eligibility unconfirmed
Primary capability

Automated batch social media screening across many people, with human-in-the-loop review

ICP fit

Strong for Intelligence and Military & Defense; medium-strong for Law Enforcement; commercial eligibility (Risk Consultancies/Threat Intel Teams) unconfirmed.

Description

Runs Profile's person-search core as automated batch screening across many people at once — classifiers plus human-in-the-loop review. Formerly the Creative Radicals "Vision" platform. Screen does not include area, topic, or company search — it is the person-search core, run at scale. Helps teams triage large batches of people (applicant vetting, background/suitability screening) where manual review would not scale — with human judgment kept in the loop.

Investigation scenarios
  • Triage large applicant/profile batches to identify records needing human review
  • Reviewer-led suitability screening surfacing potentially relevant online activity
  • Standardized applicant vetting with configurable thresholds, review states, notes, escalation paths
  • Security-clearance/background/role-specific screening review
  • Ongoing monitoring of screened profiles for new activity
  • Review-ready findings/exports for reporting or escalation
Target users
  • Government, defense, law enforcement, and enterprise teams running structured, human-led vetting at scale
  • High-volume applicant/background/suitability/security-clearance screening organizations
  • Review teams and supervisors managing screening queues and escalations
Lead with when
  • Customer needs to vet large volumes of people at once (applicant vetting, security clearance, insider threat screening)
  • Customer wants human review kept in the loop, not full automation
Bad fit when
  • Customer expects a full background-check platform (sanctions, PEP, adverse media, criminal history — none supported)
  • Customer needs image/video-based flagging
  • Customer is commercial and eligibility hasn't been confirmed
Talk track

"Screen takes Profile's person-search core and runs it across thousands of people at once, with classifiers doing the first pass and a human reviewer making the final call. It's not a background-check platform — be upfront that it's social-media screening specifically, with 16 adverse-behavior labels behind it."

How it works & classifiers

Workflow: add one person or bulk-upload a CSV of thousands → automated collection (posts, media, account connections) → classifiers flag potentially relevant material → Kanban-style review board (To Do / In Progress / Done) → reviewer inspects trigger, adds notes, marks reviewed/adverse → optional pivot into deeper person-search investigation.
Classifier: a single multi-label classifier (merged former "High-risk Person" and "Adverse Behavior" models) — a post can carry multiple labels at once, with first-person sentiment captured per label.
16 adverse labels: Alcohol Abuse, Anti-US, Criminal Activity, Domestic Extremism, Drug Abuse, Financial Affairs, IT System Misuse, Pro-China, Pro-Iran, Pro-North Korea, Pro-Russia, Psychological Issues, Sensitive Information (mishandling/leaking), Sexual, Supremacist, Violence. Plus two non-adverse outcomes: Benign and Indeterminate. Plus a separate Pro-Country classifier detecting declared allegiance to any foreign country.
Platforms: Snapchat, Truth Social, Twitch, LinkedIn, X, TikTok, Bluesky, Reddit, VKontakte, and more — coverage continuously expanding. Instagram support is username-based lookup only today; name-based discovery is not yet available.

Deployment & data access

Deployment/Hosting: cloud-based; browser-accessible on all major browsers, optimized on Chrome/Edge; accessible via mobile browser.
Import: large applicant/profile batches via spreadsheet/CSV upload.
Export: flagged-item reports, bookmarked-item reports, profile data exports.
AI: ML-based multi-label classifiers for person-level screening (not a conversational AI assistant like Search/Graph) — see the AI capabilities details below for the shared text/media analysis engine underneath.

AI capabilities (shared across Profile, Trace, and Screen)

Screen's 16-label person classifier (above) sits alongside the same underlying AI-driven text and media analysis engine used in Profile and Trace:

AI-driven text analysis:

  • Text classification: automatically reviews text content within a search and assigns labels — e.g. violence-related, benign, influence indicators — to support rapid filtering and prioritization. Does not use transcript content.
  • Named entity recognition: extracts references to real-world entities (people, locations, organizations) and key values (e.g. credit card numbers), enabling structured filtering and analysis. Can also extract named entities from transcribed media content.
  • Sentiment analysis: tags captions and titles by apparent mood to help spot escalation, agitation, or shifts in narrative tone. Does not use transcript content.

AI-driven media analysis:

  • Object detection in images and video: detects predefined object categories of concern and highlights them with bounding boxes; filterable by category (e.g. weapons, militant insignia).
  • Text detection / OCR in images and video: extracts printed, typed, or handwritten text from media so results can be searched and filtered by keywords.
  • Face detection and matching in images: isolates image results containing faces for review. Face matching is not supported for video.
What Screen is not / boundaries

Screen should be positioned as bulk social media screening with human-in-the-loop review — not as a complete background-checking platform. It currently does not provide sanctions screening, PEP checks, corporate affiliations, adverse media coverage, litigation data, licensing data, asset records, UBO data, identity verification, or employment verification. It focuses on social media presence plus simple search-engine discovery (e.g. ResearchGate, Google Scholar mentions).
Compliance-friendly relative to Trace: Screen does not carry ADINT or Identity Insights components, easing the compliance conversation where the customer is otherwise permitted to use Maltego products.
ICP fit: strong for ICP1 Intelligence and ICP2 Military & Defense; medium-strong for ICP3 Law Enforcement; to-be-defined for ICP4/5. Commercial eligibility for non-government ICPs is not yet confirmed — least validated sales history of the three new products.

Do not call Screen a complete background-checking platform, imply it produces a comprehensive risk score, or claim comments/reactions/full Instagram name-search/media-based board promotion are supported today — none of these are current capabilities.
Comparisons

ICP fit and capability matrices across all 11 products

Strong / High Explicit strong fit / natural anchor Medium Partial fit, secondary, or a between-tier rating (e.g. Med–Strong) Low Weak fit N/A Not applicable — product's core value doesn't extend to this ICP (e.g. Trace's ADINT focus isn't commercial)
ProductICP1
Intelligence
ICP2
Military & Defense
ICP3
Law Enforcement
ICP4
Risk Consultancies
ICP5
Threat Intel Teams
ProfileStrongStrongStrongStrongStrong
TraceStrongStrongStrongN/AN/A
ScreenStrongStrongMed–StrongMediumMedium
Graph (Browser)MediumMediumMediumMediumMedium
Graph (Desktop)StrongStrongStrongStrongStrong
SearchStrongStrongStrongStrongStrong
MonitorStrongStrongStrongStrongStrong
EvidenceStrongStrongStrongLowLow
HunchlyMediumMediumHighMediumMedium

Data Pass, Connectors, Connector Builder: not audience-differentiated — they're the data layer under Graph/Search, used across all five ICPs as needed. Not rated on this scale.
Cloak: does not map to the ICP1–5 model at all. It's qualified through its own fit framework (technical sophistication, real OPSEC/attribution need, institutional maturity, openness to co-development) — see the Decision Guide tab.

Clarification on ICP4/ICP5: the ICP definitions remain ICP4 = Risk Consultancies and ICP5 = Threat Intelligence Teams, per marketing-icp-context — that hasn't changed. Separately, GTM has recently started applying a Commercial Cyber / Non-Cyber use-case lens across both ICP4 and ICP5 (as reflected in marketing-use-cases-context's readiness ratings), not as a competing ICP definition. Treat "Commercial Cyber" and "Commercial Non-Cyber" as a use-case-level split within ICP4/ICP5, not as ICP4/ICP5 themselves.
Yes Core capability Partial Present but limited, indirect, or in-progress No Not offered N/A Not applicable to this product's category
Product Person searchCompany/org searchTopic searchArea / geospatial search Batch / bulk profile processingPattern-of-life / ADINTSocial media collection & preservation Real-time monitoring & alertingMedia analytics (image/OCR/face)AI capabilities Link analysis / graph vizCase managementData Pass accessConnectors (own API key) Connector BuilderManaged attribution / network infraEvidence / chain-of-custody Cloud deploymentDesktop / on-prem deployment
Graph (Browser)YesPartialNoPartialNoNoYesNoNoYesYesYesPOI, CTI, UtilitiesPlanned, phased from end 2026Yes (via SDK)NoN/AYesRoadmap: hybrid ~Fall 2026
Graph (Desktop)YesPartialNoNoNoNoYesNon/sGemini Transforms onlyYesYesYes (all)Yes (100+)YesNoN/ANoYes
SearchYesPartialNoMap viewNoNoYesNoNoYesNo (pivots)YesPOI by defaultNoNoNoN/AYesNo
MonitorPartial (VIPs)NoYesYesNoNoYesYes (core)YesYes (Echo)NoCase-levelSeparate pkgNoNoNoN/AYesNo
EvidencePartialNoNoNoNoNoYes (core: securing/preserving known accounts)NoNoNoneBasicYesSeparateOwn connectorNoNoYesCollab. onlyDesktop
HunchlyNoNoNoNoNoNoYes (captures)NoNoneNoneNoYesN/AN/AN/ANoYes (core)NoYes
CloakN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AYes (core)Complements EvidenceOwn cloudYes (core)
Data PassN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AIs the layerSeparateSeparateNoN/AYesN/A
ProfileYesYesYesYes (lighter)NoNoYesNoYes*YesFind relationsYesRoadmapNoNoNoN/AYesYes
TraceYesYesYesYes (core)NoYes (core)YesBackward-looking lookback, not real-time (see Overlaps)YesYesFind relationsYesRoadmapNoNoNoN/AYesYes
ScreenYes (core)NoNoNoYes (core)NoYesYes (alerts)Yes*Yes (classifiers)No (pivots)Yes (Kanban)RoadmapNoNoNoN/AYesYes

"n/s" = not specified in the reviewed source material — flag for confirmation rather than treating as a hard "no." *Profile's and Screen's media analytics packaging status (included vs. paid upsell) is still open per internal notes. "AI capabilities" for Profile, Trace, and Screen refers to one shared engine (text classification, named entity recognition, sentiment analysis, object detection, OCR, face detection/matching) — Screen additionally layers its own 16-label person-level classifier on top; see each product's card for the full detail. "Batch/bulk profile processing" specifically means processing many people's profiles in one workflow (Screen's core design) — not general workflow automation (e.g. Graph Desktop's Machines) or at-scale data collection (e.g. Evidence's parallel crawling), which are different capabilities. "Real-time monitoring & alerting" is Monitor's core, forward-looking, continuous capability; Trace's topic search is a backward-looking, case-driven lookback and a complement to Monitor, not a substitute — see the Overlaps tab. "Evidence / chain-of-custody" here means a defensible, court-ready evidentiary record (hashing, signatures, audit trail) — reserved for Hunchly and Evidence specifically, not general export/download features every product has. Graph (Browser)'s practical scale ceiling today is approximately 5,000 Entities per graph, with higher limits planned — qualify large/complex graph needs toward Graph (Desktop) until this is raised. Roadmap dates shown (Connectors, on-prem, Data Pass parity) are internal reference only — see Guardrails before repeating any of them to a customer.

Overlap deep-dives

Where products genuinely compete for the same pitch — and how to resolve it

Click a pair to expand it. Each one resolves a specific point of GTM confusion — some are genuine "which product wins the pitch" decisions, others are packaging/positioning clarifications rather than product overlaps.

Profile vs. Search

Both start from limited information, use built-in public-source data, support person-of-interest research, and help users identify relevant findings and leads — the overlap most likely to confuse reps working existing Maltego One accounts. The two products should not be distinguished only by their starting points, or by saying that one searches while the other structures information. The clearer distinction is based on: what the user is trying to accomplish, how they want to work with the findings, and what output or next step they need.

Maltego Search

The fast and accessible starting point for investigating a lead. Used two ways: (1) as a standalone quick check — retrieve relevant information, enrich an initial lead, and decide whether further investigation is necessary; or (2) as an entry point into Maltego Graph (Browser) — establish a starting point in Search, then continue in Graph to explore relationships, make further pivots, and develop the investigation.

Maltego Profile

The dedicated workflow for building a curated, structured profile. Reconciles related findings from multiple sources, supports reviewer confirmation of person matches, and uses text and media analysis to surface adverse information, key themes, relationships, and other relevant context. The stronger fit when the user needs an organized result for review, triage, due diligence, background research, or follow-up investigation — rather than primarily wanting to explore findings through link analysis.

The simplest distinction: use Search when the priority is to check a lead quickly or establish a starting point for deeper investigation in Graph. Use Profile when the priority is to reconcile and review related findings as one curated, structured profile.
What overlaps

Both products start from limited information; provide built-in access to public-source data; support person-of-interest investigations; identify relevant accounts, identifiers, connections, and other leads; reduce manual research across separate sources; and support follow-up investigation. Because of this, don't present them as entirely separate product categories, or imply that only Profile organizes findings.

What distinguishes Search

Prioritizes: fast retrieval of relevant information; quick checks and preliminary research; early-stage enrichment and lead generation; a simple, guided entry point; deciding whether deeper investigation is needed; moving findings into Graph (Browser) for link analysis and further pivots.

Main user questions: "What can I quickly find from the lead I have?" — and, when deeper investigation is needed, "What should I explore and connect next?"

What distinguishes Profile

Prioritizes: a curated profiling workflow; reconciliation and normalization of related findings; one structured result for review; reviewer confirmation of candidate person matches; AI-assisted highlighting of adverse information and key themes; analysis of collected text, images, and video; relationship discovery between individuals; profiling of people, companies, topics, and areas; repeatable due diligence, risk assessment, and background research workflows.

Main user question: "How can I turn the available information into a structured profile that is easier to review and act on?"

Practical decision rule
Position Search when the customer needs to
  • Check a lead quickly
  • Run preliminary research
  • Identify potentially relevant accounts or identifiers
  • Generate initial investigative leads
  • Decide whether further work is warranted
  • Begin an investigation that will continue in Graph (Browser)
  • Explore relationships and make investigative pivots
Position Profile when the customer needs to
  • Produce a curated profile for review
  • Reconcile findings from multiple sources
  • Confirm the correct person before enrichment
  • Identify adverse information or recurring themes
  • Conduct due diligence or background research
  • Investigate companies, topics, or geographic areas
  • Apply a consistent profiling workflow across cases
Don't use the current range of starting points as the long-term distinction. Today, Search is primarily associated with person-of-interest starting points — names, phone numbers, email addresses, usernames, and domains. Search will expand beyond this coverage, with additional points of interest and starting points planned, including companies (confirmed via internal sources). So the durable distinction is not "Search is for people, Profile is for companies/topics/areas" or "Search supports identifiers, Profile supports broader subjects" — those will become inaccurate as coverage expands. Distinguish by workflow and outcome instead: Search supports fast discovery and investigation; Profile supports curated, structured review.
How Search, Profile, and Graph work together
Search — find and establish direction

Helps users retrieve relevant information quickly and determine what's worth pursuing. For some, the Search result is sufficient — check the lead, review findings, done. For others, Search is the beginning of a deeper investigation.

Graph — explore and develop

Graph (Browser) helps users explore relationships, make further pivots, and investigate leads in different directions. Recommended journey: start with a guided Search, identify relevant findings, and continue in Graph when deeper link analysis is required.

Profile — reconcile and review

Helps users turn related information into one curated, review-ready result. Its primary value is not acting as the entry point to Graph — its value is the profiling workflow itself: confirming, reconciling, analyzing, and organizing findings for review and action.

Example customer scenarios
Scenario 1 — Quick lead check: a user has an email address and wants to know whether it's linked to relevant online accounts or other identifiers. → Maltego Search. Retrieve findings quickly and decide whether further investigation is needed.
Scenario 2 — Search followed by deeper investigation: a user begins with a username, identifies several accounts and connections, and needs to understand how the people, aliases, and infrastructure relate to one another. → Maltego Search → Maltego Graph (Browser). Search provides the starting point; Graph supports deeper link analysis and pivots.
Scenario 3 — Due diligence review: a reviewer needs to assess an individual or company before a hire, transaction, or client engagement, and wants one organized result with adverse information and key themes highlighted. → Maltego Profile. The desired output is a curated profile, not an open-ended link analysis investigation.
Scenario 4 — Case-driven background research: an investigator needs a structured view of a company, topic, or geographic area to support an existing case. → Maltego Profile. Profile provides a consistent workflow and review-ready output across different points of interest.
Customer-facing explanation (approved)
"Both Maltego Search and Maltego Profile help investigators start from limited information and work with built-in public-source data. Search is optimized for quickly checking a lead or establishing a starting point for deeper investigation in Graph. Profile provides a curated profiling workflow that reconciles and organizes related findings into one structured, review-ready result."
Portfolio story

Search helps users find relevant information and determine where to go next. Graph helps them explore connections and develop the investigation further. Profile helps them reconcile related information into a curated profile for review and action.

Language to avoid
Do not say: "Search only aggregates disconnected findings" · "Profile replaces Search" · "Search is basic, while Profile is advanced" · "Search is only a lookup tool" · "Search is for people, while Profile is for other points of interest" · "Profile is the only product that structures results" · "Profile automatically confirms a person's identity" · "Profile guarantees a complete or accurate picture."
These either undersell Search, overstate Profile, or will become inaccurate as product coverage expands.
Internal one-line resolver: Search is for fast lead checking and starting deeper investigations in Graph; Profile is for curated, structured review.
Trace vs. Graph

Both let an analyst pivot from an entity to its connections — but they solve different problems.

Maltego Graph

The generic, point-and-click link-analysis tool Maltego is known for — flexible, custom Transforms, atomic investigation logic, raw data-source breadth, applicable across person-of-interest, cyber, crypto, dark web, corporate intelligence, or any custom use case.

Maltego Trace

Purpose-built geospatial investigation platform: area-based discovery, pattern-of-life, and (for eligible customers) ADINT — plus person/topic/company search and one-click "find relations" that's far simpler than reproducing the same link analysis by hand in Graph.

Decision rule: Graph is the choice for flexible, custom-Transform-driven link analysis and where the customer needs their own data sources deeply integrated. Trace is the choice specifically when the mission needs geospatial pattern-of-life or ADINT — and note Trace already contains everything Profile does, so it's never bundled with Profile (see Decision Guide).
Existing Graph customers may already associate person investigation and link analysis with Graph — for these accounts, Trace's incremental value is usually ADINT specifically, which needs to be explained against their current stack rather than assumed.
Trace vs. Monitor

Both can track a topic or event over time — the difference is direction: forward-looking vs. backward-looking.

Maltego Monitor

Forward-looking, continuous, real-time situational awareness — tracking an incident, event, area, or theme as it emerges, with alerting and sentiment analysis.

Maltego Trace

Trace's topic search is a case-driven lookback — investigative, historical, connected to a specific lead or case, not a continuous monitoring feed.

Decision rule: pitch Monitor for "what's happening right now and what should I watch for." Pitch Trace's topic search only as a complement inside a geospatial investigation, never as a Monitor replacement.
Profile vs. Trace (bundling logic)

Not really an "overlap" to resolve with positioning — it's a bundling rule.

Never bundle these two. Trace already includes the entire Profile core (curated profiling on persons, topics, companies, areas, investigation management, media analytics, relationship discovery) plus the geospatial layer. Selling both is redundant — pitch Trace alone when geospatial/ADINT is needed, otherwise pitch Profile alone.
Cloak positioning note

Not an overlap with an existing Maltego product — but a common point of GTM confusion worth clarifying up front.

What Cloak is not

Not a general-purpose browser or full investigation workspace. Not an all-in-one managed-attribution solution — it addresses only the network-infrastructure layer (not the OS/application layer or analyst-behavior layer).

What Cloak works alongside

Complements Maltego Evidence for organizations needing defensible, chain-of-custody-aware outputs; can integrate with tools like Kasm for a full workspace; is moving toward Maltego ID alignment; used alongside customer-managed accounts, personas, and tradecraft — never sold as a replacement for those.

Decision rule: Cloak is additive infrastructure, not a competing or overlapping product line — pitch it only after a customer has a real, qualified OPSEC/attribution need (see Decision Guide), regardless of which other Maltego products they use.
Data Pass vs. Connectors vs. Connector Builder

All three are ways to get data into Maltego, and reps often either blur them into one thing or aren't sure which to lead with in a data conversation.

Maltego Data Pass

Built-in, credit-based, zero setup — included in every plan, no separate vendor contracts or API keys. Supports Search and both Graph variants today (POI/CTI/Utilities in Browser now, full parity with Desktop by end of 2026).

Maltego Connectors

User supplies their own API key/credentials for a specific third-party source. 100+ pre-built. Graph (Desktop) only today — Browser support is planned in phases, with batches introduced from end of 2026 and full availability from 2027.

Connector Builder

Not a standalone product — the umbrella term for building custom Transforms, via the newer Maltego Transforms SDK (recommended) or the older TRX Library (legacy, still valid). As of ~beginning of July 2026, available on both Graph (Desktop) and Graph (Browser) — closing what was previously a Desktop-only own-data gap. Local use is broadly included; sharing hosted Transform servers org-wide requires the separate Own Data integration package entitlement.

Decision rule: Always lead with Data Pass — it's the default, zero-effort option. Bring in Connectors only when the customer already has a specific vendor contract/API key they want to use directly (Graph Desktop only, for now). Bring in Connector Builder when the customer needs to integrate their own internal or proprietary data — and note this is available today on both Graph variants via the new Transforms SDK, not just Desktop, which is a stronger current story for Browser than Connectors are. If the customer wants multiple users/the whole team to access the same custom Transforms (not just the one who built them), that needs the separate Own Data integration package — check entitlement before promising org-wide sharing.
Don't call Connector Builder "a product" — there is no standalone Connector Builder product. It's a capability (building custom Transforms), and describing it as a separate SKU overstates and confuses the packaging.

Additional guardrails for the Connect Own Data / Transforms SDK release specifically — do not say: "this is no-code" · "anyone can connect own data without technical help" · "this replaces all previous integration methods immediately" · "all customers can share custom Transforms across their organization" (only true with the Own Data integration package) · "nothing touches Maltego One Cloud" (Cloud still handles configuration and Data Hub access — only the custom-data request itself goes direct to the customer-controlled source) · never reference the internal codename "V3 SDK" externally.
Maltego One vs. products beyond Maltego One

Not a product-vs-product decision at all — this is a packaging boundary that's easy to accidentally describe as "starter tier vs. premium upsell," which isn't accurate and undercuts the one-ecosystem story from the Overview tab.

Maltego One

Graph (Browser) + Search — the cloud-native entry surface into the platform: one browser workspace, one Maltego ID login, shared case management and admin.

Beyond Maltego One

Monitor, Evidence, Graph (Desktop), Hunchly, and Cloak — additional products in the same ecosystem, added based on investigative need (continuous monitoring, evidence preservation, large-scale link analysis, web capture, OPSEC infrastructure) — not because they're a "higher tier" of Maltego One.

Clarification, not a decision rule: a customer can need Graph (Desktop) or Monitor from day one — these aren't graduation products someone earns access to after starting with Maltego One. Frame it as "one ecosystem, add what the mission needs," never as "basic vs. advanced" or "free vs. paid tier."
Workspace apps vs. investigation apps

Another packaging-layer confusion, not a product overlap: Maltego Admin and Maltego Cases aren't investigative products a customer picks instead of Graph or Search — they're the shared platform layer every investigation app runs on top of.

Workspace apps

Maltego Admin — organization and user management, Credit allocation and usage limits, plan/entitlement administration.
Maltego Cases — case storage (local or cloud), optional encryption, and collaboration, shared across the products that use it.
These operate across the whole platform, not within any single investigation.

Investigation apps

Graph (Browser), Graph (Desktop), Search, Monitor, Evidence, Hunchly, Trace, Screen, Profile — where the actual investigative work happens. Each one relies on the workspace layer underneath it (login/entitlements via Admin, storage via Cases) rather than replacing it.

Clarification, not a decision rule: never position Admin or Cases as something a customer chooses instead of an investigation app. Admin questions usually come from IT/procurement stakeholders (user management, Credit budgets); Cases questions usually come from investigators asking about data storage, retention, or encryption — route each to the right stakeholder rather than treating them as product choices.
Use cases by ICP

26 documented use cases, mapped to readiness and supporting products

Filter by ICP:
Decision framework

Which product to pitch when

Click a section to expand it.

Lead-with logic (new product line)
Default
Lead with Profile — the core, fits the broadest set of customers and use cases.
If geospatial need
Add Trace when the customer needs pattern-of-life / geospatial intelligence.
If volume need
Add Screen when the customer needs to vet many people at once.

"ADINT is restricted or thin for this geography" is not a dead end — Profile remains the core product regardless, and Trace's geo algorithms still apply to non-ADINT data where Trace is otherwise in scope.

Bundle logic
BundleMakes sense?Why
Profile + ScreenYesCurated profiling one-at-a-time plus batch screening at scale — complementary jobs on the same core.
Screen + TraceYesScreen triages many people; Trace runs deep geo/pattern-of-life on the records that warrant it.
Profile + TraceNoTrace already includes everything Profile does. Pitch Trace alone — selling both is redundant.
Two messaging paths
Net-new customers

Position Trace as a broad geospatial investigation environment, and Profile as the curated-profiling core that fits almost everyone.

Existing Monitor / Graph customers

Explain incremental value carefully against their current stack — they may already associate topic monitoring or person investigation with Monitor/Graph. For these accounts the buying reason is often ADINT specifically, which raises value-perception questions to handle directly.

Maltego Graph (Browser) vs. Graph (Desktop) — and pitching both together
Key context: Graph (Browser) and Graph (Desktop) are two complementary variants of the same flagship link-analysis product, both included in every new enterprise and webshop plan. The customer doesn't choose one over the other — they get both. The only question is which variant fits which workflow, and reps should never frame this as picking a "winner."
Lead with Graph (Browser) when the customer…
  • Prioritizes fast access and ease of adoption with minimal IT overhead
  • Needs browser-based workflows without a desktop install
  • Values the 1-click Search-to-Graph pivot within one browser session
  • Wants AI-assisted analysis to speed up investigations
  • Has mixed user maturity, incl. non-technical investigators
  • Prioritizes autosave and reduced risk of losing work
  • Needs smooth handoffs when team members are unavailable, or shared cases teams can revisit later
Don't lead with Browser when: the customer needs Connectors (own API keys) today; needs all Data Pass modules today; works air-gapped/offline; needs on-premise today; or needs to load graphs with thousands of Entities — qualify scale needs and steer to Desktop.
Lead with Graph (Desktop) when the customer…
  • Relies on Connectors — their own API keys to access data
  • Handles large-scale, complex investigations needing extensive data enrichment
  • Works with big datasets/graphs with thousands of Entities
  • Has highly technical analysts who want granular control over Transforms
  • Needs access to all Data Pass modules today
  • Works in offline environments, or requires on-premise deployment today
  • Needs closer visibility/control over Credit consumption (atomic Transforms, granular Credit Output Window)
Don't lead with Desktop when: the customer explicitly wants zero-install browser access; wants AI-assisted analysis; has limited IT resources for desktop deployment; needs a quick Search-to-Graph pivot without export/import steps; or needs to enable less-experienced analysts.

Recommended flow when a team wants both

Discovery
Start in Maltego Search for fast lead enrichment.
Accessible analysis
1-click pivot into Graph (Browser) for guided, collaborative investigation.
Deep-dive (as needed)
Export into Graph (Desktop) for advanced, integration-heavy, large-scale analysis.

When to recommend both together

1. Land-and-expand opportunity

Start users in Graph (Browser) to drive adoption, then expand Graph (Desktop) usage as investigation needs mature — e.g. a Graph (Desktop) account bringing on newer, less-mature OSINT teams.

2. Mixed user maturity

Non-specialists and broader teams start in Search and Graph (Browser); senior or technical investigators use Graph (Desktop) for deeper work. If Credit usage is a concern, admins can cap Credits per user to protect budget for senior investigators' complex work.

3. Diverse investigation needs

Some workflows benefit from browser accessibility; others require advanced integrations and full data coverage — both variants cover the full spread.

4. Teams across locations

Some users prefer cloud-native collaboration; others need offline capability for field work — Browser and Desktop cover both needs respectively.

Objection handling

"Why do I need two versions of the same tool?" Graph (Desktop) and Graph (Browser) are not duplicates — they support different ways of working, similar to using both a desktop and browser version of a tool like PowerPoint. Browser gives faster access and easier browser-based workflows; Desktop supports deeper technical workflows, broader data coverage, and Connectors. For many teams the best setup is both — and both are included in the plan.
"Is Graph (Desktop) going away?" No. It remains important for advanced/technical workflows, including broader data access via Connectors, offline work, and more. Graph (Browser) is a complementary, faster, browser-based experience that will keep growing over time — today, the right choice depends on the customer's workflow and technical needs.
"Graph (Browser) doesn't have all the data I need." Graph (Browser) currently focuses on Person of Interest and CTI data, working toward use-case-level Data Pass parity by end of 2026. For investigations needing broader coverage today, Graph (Desktop) is the right choice — many customers use Browser for POI workflows and Desktop for other investigation types.
"I need Connectors with my own API keys." Connector support is planned for Graph (Browser), introduced gradually from end of 2026. Until then, Graph (Desktop) supports all 100+ Connectors with your own API keys. From July 2026, you can also integrate your own data into Graph (Browser) via the Maltego Transforms SDK.
"We need on-premise deployment." Graph (Desktop) supports on-premise deployment today. Hybrid on-prem for Graph (Browser) is planned; if the customer needs on-prem now, Desktop is the right fit, and Browser on-prem can be revisited once available.
Reminder: don't state the specific roadmap dates above to a customer unless approved by Product — say "planned" / "in progress" instead. Full "never say / instead say" list is in the Guardrails tab.
Cloak qualification gate

Cloak is not a "sell everywhere" product. Run this cheat sheet before any customer conversation:

Q1. Is this a defense, intelligence, or other high-risk investigative customer where attribution risk is material?✅ Yes → continue (strongest-fit customer type). ❌ No → stop; Cloak is not a broad, general-purpose offering.
Q2. Does the team have a real OPSEC / attribution problem to solve? (e.g. investigator-exposure concern, reliance today on fragile VPN/VM/proxy setups) ✅ Yes → continue. ❌ No → stop; if they just want easier/lighter browsing, Cloak is not the right fit.
Q3. Is this an institutional, technically confident enterprise team? (comfortable with infrastructure, self-hosting, cloud providers, deployment) ✅ Yes → continue. ❌ No → stop; not suited to customers expecting a low-touch, fully turnkey, non-technical experience.
Q4. Is the customer open to early adoption and working with us on requirements? ✅ Yes → continue — this is the right kind of customer, since pieces of the product are still being built out. ❌ No → lower fit for now.
If all four qualify: share currently available Cloak material; if the customer shows interest, connect with the Cloak product lead for a next-step meeting, demo, and current pricing. Go-to-market motion for Cloak is design-partner-led (co-development with 1–2 representative customers), not open trials.
Maltego Data offering — lead-with logic
Always lead with
Data Pass — the clear differentiator and the strongest driver of the Data value proposition.
Position as enhancement
Connectors — for customers with existing vendor contracts, or data outside Data Pass.
Position as enhancement
Connector Builder — for technical customers needing internal/proprietary data integrated.

Never lead with, or name, individual data vendors in customer conversations (e.g. say "Maltego Data Pass," not "Vetric" or "District4") — see Guardrails for the full messaging discipline.

Guardrails & compliance appendix

Check this before any customer-facing conversation

Maltego Trace
Eligibility gating
Sellable only to eligible GOV ICPs. Do not produce or hand over Trace decks, screenshots, demos, or product materials unless the requester confirms customer eligibility has already been verified.
Don't reduce Trace to "the ADINT product"
Trace delivers value even without ADINT (person search, identity resolution, company investigation, area discovery, investigation management, automations). Frame it as a geospatial investigation platform with ADINT as a high-value layer for eligible customers.
Identity Insights is an absolute no for commercial
Never raise device-ID-to-real-identity de-anonymization workflows with commercial clients, regardless of context.
ADINT coverage varies by geography
Strongest in the US, weaker in Europe, case-by-case elsewhere. Avoid broad coverage claims — validate with SEs before setting trial expectations.
Maltego Screen
Not a background-checking platform
Do not imply sanctions, PEP, corporate affiliations, litigation, licensing, asset records, UBOs, identity verification, or employment verification — Screen does none of these today.
Commercial eligibility unconfirmed
Non-government ICP eligibility is not yet confirmed — flag this before promising Screen to a commercial prospect.
Don't overstate current capability
No comments/reactions contributing to classification, no full Instagram name-search, no media-based board promotion, and no comprehensive risk score today — these are roadmap items, not shipped features.
Cloak
Not a "sell everywhere" product
Must pass the 4-question qualification gate (Decision Guide) before any customer conversation.
Pricing is not included in this guide
Pricing changes too frequently to keep reliably current here. For Cloak — or any product — contact your Maltego lead for current figures rather than quoting anything from a past version of this guide.
Not an all-in-one managed-attribution solution
Cloak addresses the network layer only — don't imply it also solves OS/application compromise or analyst-behavior exposure.
Maltego Graph (Browser) vs. Graph (Desktop)
Never say these
"Graph (Desktop) is legacy" or "the old version"; "Graph (Browser) replaces Graph (Desktop)"; "Graph (Browser) can do everything Graph (Desktop) can"; "Connectors are available in Graph (Browser) today"; "All Data Pass modules work in Graph (Browser)" today.
Instead say
"Graph (Desktop) is designed for advanced, complex investigations"; "Graph (Browser) is designed for accessible, fast investigations"; "Both are included in your plan and serve different needs"; "Connector support is planned for Graph (Browser) and will be introduced in batches"; "The team is working toward use-case-level Data Pass parity in Graph (Browser)."
Never commit specific roadmap dates to customers
The Fall 2026 / end-of-2026 / 2027 dates referenced in the Graph (Browser) and Graph (Desktop) product cards and the capability matrix are internal reference only, sourced from an internal GTM deck (July 2026) explicitly marked "for internal enablement only, do not show to or share with customers." Don't repeat specific dates to a customer unless approved by Product — use "planned" / "in progress" / "coming" instead.
Connect Own Data in Maltego One (Maltego Transforms SDK)
Never say the internal codename
This capability is internally sometimes called "V3 SDK." Never use that name externally — it's an internal version label and communicates nothing about customer value. Customer-facing name: "Connect Own Data in Maltego One." Developer-facing name: "Maltego Transforms SDK."
Never claim it's no-code
Do not say: "this is no-code," "anyone can connect own data without technical help," "this replaces all previous integration methods immediately," or "all customers can share custom Transforms across their organization" (org-wide sharing specifically requires the separate Own Data integration package entitlement). This is Phase 1 — a supported technical, SDK-based capability. A lower-code/no-code approach is a later roadmap step (2027+), not current.
Never say "nothing touches Maltego One Cloud"
The correct framing: Graph (Browser) runs locally in the user's browser and interacts with Maltego One Cloud for services like configuration and Data Hub access; for a configured custom data source, the browser app requests data directly from the customer-controlled source rather than routing it through Maltego infrastructure. Don't make the absolute claim that Cloud isn't involved at all — it still handles configuration and Data Hub access.
Don't conflate this with full on-premise Maltego One
Full on-premise deployment (the entire service stack running on-prem) is a separate, later roadmap item for customers with strict compliance requirements. This release addresses the specific own-data-integration reason customers historically chose on-prem — it is not full on-premise Maltego One, and shouldn't be positioned as such.
Correct packaging framing
All eligible users (Basic, Entry, Professional, Enterprise) can build/run custom Transforms locally in both Graph variants included in their plan. Sharing approved, org-hosted Transform servers with a broader team requires the separate Own Data integration package entitlement — always check which tier the customer is asking about before promising organization-wide sharing.
Maltego Data (Data Pass, Connectors, Connector Builder)
"Data Pass-first" messaging discipline
Always lead with Data Pass; introduce Connectors and Connector Builder as enhancements beyond it — not as three co-equal options.
Never name individual data vendors in customer conversations
Say "we use Maltego Data Pass to search for a profile" — not "we use Vetric" or "we use District4." Maltego is positioned as a data access/integration platform, supplier-agnostic, not a reseller of any one vendor.
Vendor-change conversations
If a customer asks about a discontinued provider, reinforce Data Pass's continuity and breadth rather than dwelling on the specific loss — Data Pass draws on multiple providers per category, and coverage keeps expanding.
Credit-usage figures are illustrative only
The ~320 Transforms / ~100 searches per 20,000 Credits figures are rough averages for planning conversations, not guaranteed volumes or fixed usage limits.
Cross-cutting (all products)
Never state a specific price, discount, or number externally
Pricing is flexible, tailored, licensed via user seats + data credits, shared via custom quote. This guide deliberately does not include pricing figures for any product, since pricing changes too frequently to keep current — always check with your Maltego lead for the latest figures.
No surveillance-adjacent language
Avoid "surveillance," "track people," "monitor anyone," "real-time tracking" in public-facing material — stay outcome-focused (e.g. "detect emerging threats faster").
Restricted-to-direct-conversation terms
"Pattern-of-life," "device identifier tracking," "commercial telemetry data (CTD)" are fine only in direct conversations with eligible government accounts or controlled procurement materials — not in public-facing collateral.
Approved proof points only
200K+ users worldwide; 2K+ government organizations; 500+ law enforcement agencies; 170+ national security/intelligence/military agencies; used across NATO member states; Fortune 500 commercial customers across finance, tech, energy. Don't round up, combine into new stats, or add uncleared customer names/logos. The Department of State (Babel Street/Skopenow displacement) proof point is product-line-level, not confirmed as specific to any one product.
Company/origin narrative sequencing
Lead with "Maltego," not a legal entity name (except the dedicated US GOV introduction — flag rather than improvise). German-engineering narrative (Munich HQ, est. 2017) is usable proactively. Paterva origin story is reactive-only.
Messaging guidelines

Approved platform & product messaging, straight from the source

1. What is Maltego? (platform positioning)

Maltego is an OSINT and investigation platform that helps law enforcement, intelligence, military and defense, corporate security, and threat teams turn scattered data into connected intelligence. It lets you bring together open-source intelligence and your own data, monitor online signals, and visualize relationships across entities so you can move much faster from single leads to defensible findings, all within one environment.

Thanks to Maltego, your team will be able to (tailor by ICP)
  • ICP1 Intelligence Agencies: Detect emerging threats, trends, and narratives sooner, understand who is acting and what's happening, and respond faster.
  • ICP2 Military & Defense: Get faster insight and clearer context on adversary activity across areas of operation to reduce operational risk.
  • ICP3 Law Enforcement: Connect suspects, networks, and evidence faster to move cases forward with defensible outputs.
  • ICP4 Risk Consultancies: Detect threats and deliver client-ready insights faster.
  • ICP5 Threat Intelligence / Corporate Security: Reduce tool sprawl, improve early warning of emerging risks, and run investigations on hybrid threats.

Approved keywords: ecosystem, platform, solutions. Always position Maltego as a platform, not a single tool.

2. What does Maltego offer? (product suite + data access)
ProductApproved one-linerNotes
Maltego MonitorTracks events and narratives across multiple social media platforms in near real time
Maltego SearchBuilds profiles of persons of interest from minimal input like a phone number, alias, email, name, or domain
Maltego GraphConducts link analysis to uncover networks and key relationshipsFlagship product
Maltego OneBrowser-based platform bundling Maltego Search + Maltego Graph (Browser), with built-in data for person-of-interest investigationsNew technology; will soon allow greater product and data integration
Maltego EvidenceCaptures and preserves online content before it disappearsRelevant mostly to GOV ICPs
Maltego TraceGeospatial analysis tool deriving precise, near-real-time intelligence from digital location-related signalsCan only be sold to eligible GOV ICPs. Formerly OpenIO/OiO — see section 13
Maltego ScreenScreens and classifies large volumes of social media profiles to surface potentially relevant risk signals for human reviewFormerly VisiOn (Creative Radicals)
Maltego ProfileBuilds a structured profile from public-source information on a person, company, theme, or area, with AI-assisted highlights of adverse information and key themesFormerly Syft (Creative Radicals)
HunchlyAutomatically captures and archives web pages with full metadata and chain of custody for legal or internal useSee section 11
Flexible access to data via
  • Maltego Data Pass — out-of-the-box access to curated OSINT and commercial intelligence for POI, CTI, dark web, crypto, corporate, and more investigations. Available in Graph (Desktop) (all modules), Graph (Browser) (POI/CTI/Utilities today, more modules coming), and Search (POI-oriented starting points).
  • Maltego Connectors — 100+ integrations to external data sources in Graph (Desktop), using your own API keys.
  • Connector Builder — a data integration capability that lets customers integrate their own data, now via the Maltego Transforms SDK on both Graph variants (see the Data Pass card and the Overlaps tab for the full, current detail — this table reflects the original approved one-liners, which predate that release).
  • Maltego Monitor — access to social media data via direct access or BYOK (bring your own key).
  • Maltego Evidence — captures social media data using sock puppets.
  • Maltego Trace — offers built-in data modules.

Approved keywords for this section: ecosystem, platform, solutions.

3. Why choose Maltego? (value propositions)

Our customers choose Maltego because it helps them:

  • Reduce tool sprawl with one investigation environment — bring monitoring and investigation workflows together, so teams don't have to jump between disconnected single-purpose tools to go from signal to insight.
  • Start investigating fast with trusted data options, then expand — access a growing set of reliable data sources to begin investigating quickly and add coverage as needs evolve.
  • Cut through noise and add missing context — surface what matters, connect relationships, and provide enough context to brief, decide, or document outcomes with confidence.
"Maltego helps teams cut through noisy, fragmented signals, connect and correlate entities across sources, and move faster from single leads to defensible findings, with less tool sprawl and less rework."
4. Who uses Maltego? (proof points)

Maltego is trusted by 200K+ users worldwide.

Commercial

Fortune 500 companies across finance, tech, and energy buy Maltego for analysts across: corporate security units, cyber threat intelligence teams, threat intelligence teams, fraud and financial crime teams, trust & safety teams, executive protection and physical security units.

Government

2K+ government organizations, including 500+ law enforcement agencies and 170+ national security/intelligence/military agencies. Used across NATO member states.

General framing: any team that needs to investigate threats, build cases, or connect complex data across digital and real-world domains. Do not invent additional customer counts, named customers, or verticals beyond what's listed here without checking with marketing.

5. How does Maltego work? (workflow narrative)

Recommend starting in one of two ways: monitoring a topic/area/event, or investigating from a single lead (email, phone number, alias, or domain), then pivoting further.

  • If monitoring: set up dashboards and alerts to track developing situations across online sources in near real time, then pivot promising signals into an investigation.
  • If investigating: start with what you already have (alias, email, phone, domain, etc.) and run searches to pull relevant context.

From there, enrich what you find using Maltego Data Pass and/or your own data sources, and visualize the results to reveal relationships, infrastructure, and networks.

Closing line for live conversations: "That's an example workflow. It's much easier to see in practice, so I can show you a quick demo."
6. What makes Maltego different? (four differentiators)

Use the "X, not Y" pattern — don't invent a fifth differentiator:

  • Investigation platform, not a single-purpose OSINT tool — combine real-time monitoring with deeper link analysis and pivoting in one workflow.
  • Data-source flexible (supplier-agnostic), not vendor-locked — Data Pass for multiple trusted providers, Connectors for existing vendors/internal systems.
  • Built for the full picture, not just quick lookups — maps relationships, infrastructure, and networks at scale; standardizes repeatable workflows.
  • Investigation-grade security and transparency — clear data lineage, OPSEC support, secure proxy option via Data Pass to protect investigator anonymity.
7. Where does the data come from?
  • Maltego connects data from 120+ data partners/providers — partners with a Connector and/or part of Maltego Data Pass.
  • 70+ data partners/providers support Maltego Data Pass exclusively.
  • Supports all major platforms (Facebook, Instagram, X, YouTube) plus niche ones (Foursquare, Discord, GitHub, Steam, Duolingo, OnlyFans, TripAdvisor).
  • Maltego Data Pass is the flagship data solution — a trusted, convenient single access point to an ever-increasing collection of relevant data from reputable data providers, credit-based, already included in the plan. Approved analogy: "think of it as Spotify for OSINT."
Check before making a claim
  • Data Pass: all modules in Graph (Desktop); POI/CTI/Utilities today in Graph (Browser) and Search, more modules planned.
  • Connectors: Graph (Desktop) only today, Browser planned in phases.
  • Monitor gives access to social media data via direct access or BYOK.
  • Evidence lets you capture social media data using sock puppets.
  • Trace, Profile, and Screen offer built-in data modules.
8. Can I use my own data? — incl. Customer Assurance Guide detail

Base approved answer: Yes — Maltego allows secure integration of internal data sources. You can investigate internal + external data side-by-side in a single view. Caveat — do not drop this when making the claim: this was true only for Graph (Desktop) historically; as of ~July 2026, Connect Own Data extended this to Graph (Browser) too via the Maltego Transforms SDK — see the Graph (Browser) card and the Data Pass overlap resolver for full detail. Still not a no-code experience.

Customer Assurance Guide: "Browser does not automatically mean Cloud"

Core message: Graph (Browser) is browser-based, but that does not mean your own data is automatically processed in Maltego One Cloud. The application runs locally in the user's browser and can connect directly to customer-controlled data sources, while Maltego One Cloud supports services such as configuration and Data Hub access.

Why this matters: many customers instinctively equate browser-based applications with cloud-hosted data processing. GTM should clearly separate the application delivery model from the customer data path — this distinction is critical for security, privacy, compliance, and enterprise adoption conversations.

Analogy: Browser = TV, a custom Transform = a DVD player. A TV can run programs directly from a broadcast/cloud signal — but with a DVD player, it can also run content that's available locally.

Master talk track: "A common misconception is that because Maltego Graph (Browser) runs in a browser, all customer data must be processed in the cloud. That is not the right mental model. Graph (Browser) is accessed through the browser, but the application runs locally on the user's machine. It does interact with Maltego One Cloud services for things like configuration and access to the Maltego Data Hub, but when a customer configures their own data source, the browser app can request data directly from that customer-controlled source rather than piping all of that data through Maltego infrastructure. The Connect Own Data release addresses one of the main reasons customers historically needed on-premise deployments: integrating custom data. For customers with stricter compliance requirements, a fuller on-premise deployment model for Maltego One is also on the roadmap. Longer term, Maltego also plans to make own-data integration easier through a lower-code or no-code approach."
Addressing specific concerns
  • Why Maltego is taking this route first: many customers historically chose on-premise deployments because they needed to integrate internal or sensitive data. This release addresses that specific need first, while preserving managed-application benefits (faster updates, less rollout friction).
  • Full on-premise is a separate roadmap item: don't position the current release as full on-premise Maltego One — that's where the broader service stack would run on-prem, a later step.
  • Low/no-code is a later direction: this release is aimed at customers who can work with an SDK-based approach; a lower-code/no-code experience is a later roadmap step, not current.
  • Access control: connecting own data isn't the same as saying every analyst can use every piece of internal data in every workflow — access control can be built around the customer's own authorization mechanisms, but specialized remapping of access controls for Maltego-specific investigation workflows isn't part of the first version. Ask discovery questions before making claims here.
  • Longer-term data modeling: the longer-term direction is a more structured, ontology-management concept for custom data models — position as future direction, not current capability.
Say / Don't say (Connect Own Data specifically)
Say
  • Graph (Browser) runs in the browser on the user's local machine.
  • The app interacts with Maltego One Cloud for configuration and Data Hub access.
  • Configured custom data sources can be called directly from the browser app to the customer-controlled source.
  • This release helps address privacy/security concerns around feeding own data into a browser-based workflow.
  • A fuller on-premise deployment model is on the roadmap for customers with strong compliance needs.
  • A low/no-code own-data integration experience is a later roadmap direction.
Don't say
  • Browser means all customer data is processed in Maltego One Cloud.
  • Nothing touches Maltego One Cloud.
  • All own-data requests are routed through Maltego infrastructure.
  • This release solves every data-flow, data-classification, and access-control scenario.
  • The current release is full on-premise Maltego One.
  • This release is a fully no-code own-data integration experience.
9. How much does Maltego cost?

Maltego pricing is flexible and tailored to the organization, based on factors like team size, required products, and data usage. Licensed using a combination of user seats and data credits, with different plans for commercial and government use cases. Because setups vary widely, pricing is typically shared through a custom quote after understanding the customer's investigation needs.

Never state a specific price, discount, or number in customer-facing material. This guide deliberately carries no pricing figures for the same reason — see the Key GTM Materials tab for the current Pricing and Packaging reference.

10. Where does Maltego come from? (company narrative)

Introduction: say you're representing Maltego (not any legal entity name), except the US GOV-specific introduction.

German engineering narrative (usable proactively)
  • Maltego is developed by Maltego Technologies, established in 2017, headquartered in Munich, Germany.
  • German privacy and compliance laws are not a challenge, they are a match: security, precision, quality.
  • Being headquartered in Germany means Maltego builds with high privacy and compliance expectations from day one.
Paterva origin story — reactive only, never proactive

Only share if a customer asks: Maltego started as a tool created by security practitioners. The first public version of what became Maltego Graph included a Community Edition developed by Paterva in South Africa, before Maltego Technologies took over responsibility and scaled it into the platform it is today.

"Built by practitioners, scaled by professionals."

US GOV reps: use the dedicated US GOV introduction — do not introduce yourself as part of Maltego Technologies GmbH. Additional guidance lives in the US Trust Pack (ask your function lead); this guide doesn't contain that content — flag rather than improvise.

11. What is Hunchly?

What it is: a web capture and evidence preservation tool for online investigations. As an investigator browses websites and social media, Hunchly can automatically capture full pages and store key details like URLs, timestamps, and integrity data (e.g. hashes), creating a transparent audit trail that supports defensible documentation and reporting.

What's next: Maltego acquired Hunchly in May 2025 to offer a more complete investigation workflow, pairing in-browser evidence collection with deeper data analysis and insights. Maltego and Hunchly are working to integrate products, teams, brands, and services. From 2026, Hunchly is included by default in every Maltego subscription plan for new customers.

Optional origin story — only if asked: Hunchly was launched in 2015 by Dark River Systems, later supported within the Sapper Labs ecosystem; in 2022 Dark River Systems joined Sapper Labs Group. Hunchly was acquired by Maltego in May 2025.

12. Maltego Trace (formerly OpenIO/OiO)

Approved explanation: Maltego Trace is a solution for geospatial analysis that enables investigative, security, intelligence, and defense teams to derive precise, near-real-time intelligence from digital location-related signals. By correlating identifiers across time and geography, it reveals high-confidence movement, behavior, and co-location patterns at global scale. Instead of showing raw location points on a map, Trace automatically analyzes data to surface travel patterns, frequented locations, and shifts in behavior within defined areas of interest — enhanced situational awareness and operational insight into force protection, counter-terrorism, high-value targeting, and drug trafficking.

Verbal-only bridge: in conversations where a customer already knows "OiO," it's fine to say "Maltego Trace (formerly OiO)" verbally — don't use that phrasing as the primary name in written/marketing material.

Eligibility guardrail — critical: eligibility requirements for Maltego Trace are significantly stricter than for other Maltego products. Do not share Trace decks, screenshots, demos, or other product materials until customer eligibility has been confirmed.
13. Messaging guardrails for marketing materials

Goal: maintain a clear separation between what reps say in qualified, direct government conversations and what appears in public marketing materials.

  • Marketing will not use language that implies monitoring individuals or broad surveillance — e.g. "surveillance," "track people," "monitor anyone," "real-time tracking." Public-facing assets stay outcome-focused and mission-aligned without describing sensitive mechanics.
  • Restricted-to-direct-conversation terms: "pattern-of-life," "device identifier tracking," "commercial telemetry data (CTD)" — fine in direct conversations with eligible government accounts and controlled procurement materials, but must not appear in public-facing marketing collateral.

Why this matters: if this language circulates beyond the target audience, it can be misinterpreted and trigger hesitance or criticism — especially outside the scope of a given pilot or program.

Practical rule of thumb: the same underlying capability can be described two ways depending on the channel — mission/outcome language for anything public-facing, mechanism-specific language only in qualified, direct/controlled contexts. When in doubt, treat it as public-facing and use the safer language.

See the full Guardrails tab for the product-specific version of these rules.

Key GTM materials

Where to go for the resources this guide doesn't replace

This guide covers positioning, capabilities, and pitch logic — for pricing, deal support, data-source detail, and marketing assets, go directly to the source. These links open in a new tab.

Pricing and Packaging

Current pricing, plan tiers, and packaging detail for every product — the source of truth this guide deliberately doesn't duplicate, since pricing changes too often to keep current here.

Open Pricing and Packaging →

Sales Master

The broader sales enablement reference — deal support, playbooks, and materials beyond product positioning.

Open Sales Master →

Maltego Data Airtable

Live detail on Data Pass modules, data partners, and Connector coverage — useful when a data-source question goes deeper than this guide's summary level.

Open Maltego Data Airtable →

Marketing Materials Hub

Decks, one-pagers, case studies, and other customer-facing assets referenced throughout this guide's product cards.

Open Marketing Materials Hub →