How this works
No mystery, no magic.
This tool asks you to trust it with something you may not have shown anyone. That obliges it to be specific about what it does. Everything below describes the system as it is actually built, not as it is described elsewhere.
Intent, not signature
Network defence gave up on detection by signature, because changing a signature became trivial. What replaced it was detection by intent: no single artefact means anything, and the sequence of actions gives the operation away, because the sequence is the operation.
Confidence fraud died the same death at the same time and for the same reason. The two signatures everyone was taught — poor English, and a refusal to video call — were both killed by generative AI, and the FBI documented it in a public notice in December 2024: operators use it to remove grammatical errors, and to generate live video that proves they are a real person.
What did not die is the sequence. Approach, rapport, control, extraction. That order is mechanics rather than habit — nobody can ask for money from a person who is still free to check with someone else, so control has to come first. An operator can change every word in the script and not one phase of it.
This is why the analyser names techniques instead of pronouncing a verdict, why the glossary is ordered by phase, and why the practice debrief shows you the chain rather than a mark out of ten. It is also the honest limit: a single pasted message is one point in a sequence, so the techniques defined by what came before them — a grief hook, a swing from warm to cold — are the ones a single message cannot show.
The two things it does
The analyser
You paste a message. A language model reads it, names the techniques it recognises, quotes the words that triggered each one, and gives a risk level. It is looking for patterns of manipulation, not for whether a specific person is lying.
The simulator
A language model plays a character running one of two dozen scripted approaches. It follows a persona and an escalation arc written in advance, so the scenarios are consistent and reviewable rather than improvised. The debrief afterwards is generated from the transcript, while the score is computed in code from five specific behaviours, not decided by the model.
Which models
Claude Haiku 4.5, from Anthropic, for all three jobs: the analyser, the characters and the debrief. Your text is sent to Anthropic to be processed and their handling of it is governed by their terms. We do not train anything on it, and we could not: we do not keep it.
The character in a scenario is always an AI. The banner saying so does not scroll away, which is both an obligation under Article 50 of the EU AI Act and, more simply, true.
What it stores
The analyser never stores your text.
Only a salted hash of it and its length, so an identical message can reuse an earlier result. A hash cannot be turned back into the message.
Simulator conversations are stored while the run is live.
The debrief is written from the transcript, so it has to exist until then. The text is blanked after 30 days and only the shape survives: which tactic appeared at which turn, whether it was caught, the score.
Your address is never stored, only a salted hash of it.
Used to stop one person exhausting the service for everyone else. The same is true of your browser identification.
Anonymous sessions are deleted after 90 days.
Along with everything attached to them.
There is no analytics, no tracking pixel and no third-party script.
Fonts are served from this server rather than a font CDN, so loading a page does not tell anyone else that you did.
The detail, including who to contact, is on the privacy page.
What it cannot tell you
- Whether a specific person is a fraudster. It reads the text, not the person. A warm message from someone entirely genuine can carry the same markers, and a careful operator can write a message that scores low.
- Whether your money can be recovered. That depends on your bank, the route the payment took and how quickly you called. Nothing here changes it.
- A low score is not a clearance. If the analyser says the risk is low and something still feels wrong, the feeling is better evidence than the score. It has your context and the model does not.
- Whether practising here makes you safer. We believe it does, and the reasoning is in the lessons. We have not measured it yet, and until we have, saying otherwise would be a claim about you rather than a fact.
Who made it
HeartOSINT is built and published by Riskoria Advising & Professional Services d.o.o., a consultancy in Zagreb working on cybersecurity and AI governance. The public version is free and is intended to stay that way. The work is funded by licensing a version of it to institutions, not by advertising, and not by anything to do with the people who use this one.