What EIP Investigates
Intelligence is a broad word. It covers everything from a financial analyst reading public filings to an agency tracking a hostile actor in a foreign capital. When someone hears that a company "builds intelligence software," the mental category they reach for depends almost entirely on what they've seen before — and the category they reach for first determines how they read everything else.
This post is about what the EPCYBER Intelligence Platform (EIP) actually investigates. Not in the abstract, not in marketing terms — in operational terms. What is the subject of the work the platform supports? What does it look at, and just as importantly, what does it not? We've written this down because the answer is more specific than the category name suggests, and because the specificity matters.
The unit of interest
Every intelligence platform is organized around a unit of interest — the thing the platform is designed to see, structure, and reason about. The architecture, the data model, the analytical tooling, and the user workflows all radiate outward from whatever that central unit is.
Some platforms are organized around individuals. Their unit of interest is a person — name, location, contacts, movement, behavior. Their value to a customer is the depth and recency of the picture they can build of any specific human being. The platform's whole architecture rewards getting closer to a single person.
EIP is not organized that way. The unit of interest in our platform is the ecosystem — adversary infrastructure, organizational entities, military and security structures, financial networks, materiel, and the operational patterns that emerge from those structures over time. The questions our clients ask the platform are about how systems behave, not about how a particular person spent their afternoon.
In practice, an analyst using EIP is doing things like:
- Mapping the structure and activity of an adversary military formation — its installations, its movement patterns, its readiness cycles, its associated units and materiel.
- Tracing the entity-level architecture of an adversary state-adjacent industry — who owns what, who supplies whom, what changes when sanctions tighten.
- Watching infrastructure at scale — airfields, ports, secure facilities, communications networks — for changes that signal a shift in posture.
- Building a picture of how an adversary's procurement networks reach into Western supply chains, and where that exposure sits.
Individuals appear in this work, of course. Generals exist. Procurement officers exist. Defense contractors have executives. But they appear as components of structures the analyst is investigating — not as the analyst's reason for being on the platform. The platform is not designed to support, and is not commercially viable as, a tool for building dossiers on ordinary people going about their lives.
A concrete contrast
The clearest way to see the difference is to compare what an analyst can do, and what an analyst can't easily do, with the same platform.
An analyst using EIP can ask the platform to surface what's changing inside an adversary's command structure over the last six months — and get back a picture built from infrastructure signals, organizational disclosures, native-language reporting, and entity-level analytics. That's the kind of question the platform is built around. It's the kind of question the architecture, the data model, and the analytical surface all support natively.
An analyst using EIP cannot use the platform to assemble a behavioral profile of a private individual whose only connection to EIP's subjects is that they happen to live in a country we cover. The platform isn't built to do that, isn't marketed to do that, and the institutions we work with aren't asking us to do that. The contractual restrictions in our Acceptable Use Policy make the boundary explicit, but the more meaningful point is that the platform's shape doesn't lend itself to that work.
This isn't a marketing distinction. It's a structural one. A platform that lets you investigate ecosystems is a different thing from a platform that lets you investigate individuals — different data model, different analytical tooling, different value proposition, different customer relationship, different governance and ethics.
How the boundary holds
A reader who has thought seriously about how products drift over time will rightly ask: what stops a platform of this capability from being repurposed for something its architecture wasn't built for? The answer has three parts.
The product itself
The platform is built around the unit of interest described above. The data model, the search and correlation tools, the workflows, the coverage areas — all of it reflects an orientation toward ecosystems and structures valuable for the West to be a step ahead of its adversaries. A capability that doesn't exist in the product can't be repurposed.
The client base
EIP does not operate as an open-market vendor. We work with vetted government, defense, and selected enterprise institutions whose missions we understand and stand behind. Every prospective client is evaluated against the criteria set out in our Acceptable Use Policy before access is granted. Misuse of the platform is treated as a contractual breach with consequences that include termination of access.
The institutional purpose
EIP exists to give democratic institutions visibility into adversary ecosystems they cannot otherwise reach. That sentence is a description of the business we are in. A pivot away from that purpose isn't a product decision — it's an existential decision, and it's one that would require changing the architecture, the client base, the agreements, the public commitments, and the people who built the company. None of that happens by accident.
Why specificity matters
The word "intelligence" is doing a lot of work in modern technology marketing, and not all of it is honest. There are products that use the word as cover for capabilities that genuinely belong in a different category, and the resulting confusion has cost the broader field — including the legitimate practitioners — real credibility.
We think specificity is the cure for that confusion. A company that can say plainly what it investigates, what it doesn't, who it works with, who it won't, and what it commits to in writing — and then matches its conduct to those words over time — is a company that earns the trust the work requires. A company that can't do that, or won't, has chosen a different bargain.
Why nowThe coverage gap is widening — and it is measurable.
The ecosystems that matter most to Western intelligence and defense are the ones conventional tooling covers least. Native platforms, native-language reporting, infrastructure signals, and entity-level disclosures inside hard-target ecosystems sit largely outside the reach of Western tools. The result is a structural blind spot: not a lack of data, but a lack of structured, searchable access to data that already exists.
Why it matters now
Posture, procurement, and infrastructure change continuously. Decisions made against a partial picture carry real cost. As adversary ecosystems grow more complex — and as supply chains reach further into Western economies — the gap between what is knowable and what is accessible becomes a mission risk in its own right.
What structured access changes
EIP consolidates native-platform reporting, infrastructure signals, and entity-level analytics into a single operational picture, refreshed continuously. Analysts work with method and native-language depth at scale, rather than assembling fragments by hand.
Who this is for
Western governments, defense and intelligence organizations, and the compliance and critical-infrastructure teams whose missions depend on seeing the ecosystems that go dark.
Who we areFounded by intelligence practitioners. Built for the West.
Our mission
The institutions responsible for protecting Western societies have a visibility problem that has been described for at least a decade and largely left unsolved. The adversary ecosystems that shape this century — their infrastructure, their organizational structures, their procurement networks, their military formations — are not adequately legible to the people whose job it is to understand them.
The cost of that illegibility is paid in stolen intellectual property, in compromised supply chains, in capital flows that financed adversary capability, and in decisions made by Western governments and enterprises with materially incomplete information.
The EPCYBER Intelligence Platform (EIP) exists because closing this gap is not a marketing exercise. It is the work of building infrastructure — methodology, frameworks, deep coverage, collection architecture — specifically for the ecosystems that matter most. The West does not have an information problem. It has an access problem. That is what we solve.
Who we work with
EIP operates exclusively with government, defense, and a small number of selected institutions whose missions require visibility that standard tools cannot provide. Our clients work in contexts where incomplete intelligence is not an option.
EIP is currently engaged with a select group of these institutions under standing confidentiality. References can be discussed privately with serious procurement and investor counterparties under appropriate agreements. As the platform matures, we plan to extend access to a broader set of enterprise clients in 2027.
Our principles
The integrity of intelligence work begins with the integrity of how it is collected, who it is collected for, and what it commits to in writing. We hold ourselves to a small number of principles that do not change with the commercial conditions.
We collect inside the environment — not from aggregators, not from recycled feeds, not from secondhand layers. The depth of what EIP surfaces is a function of the methodology it took years to build, and the discipline of focusing on a single ecosystem rather than expanding broadly.
We work with institutions whose mission we understand and whose use of the platform we stand behind. The selection happens before access is granted, not after. This is described in detail in our Acceptable Use Policy.
What our clients see stays with our clients. We do not publish intelligence findings, client names, or operational specifics. We do publish our principles, our policies, and the standards by which we operate. The asymmetry is intentional. At this stage, EIP is entirely self-funded — built on the conviction that the gap was real and the solution was overdue.
The team
EIP is built by intelligence practitioners. The team is small by design.
The founder
Eva Prokofiev founded EIP from a vantage point most analysts never reach — working inside China's digital infrastructure rather than observing it from the outside. A former Military Intelligence Officer in the Special Operations Division, she has spent 15+ years training defense contractors, NATO-aligned agencies, and government teams across Europe and the United States.
Her work on China's digital ecosystem began in 2017, growing from an unfilled gap into a professional discipline and, eventually, a platform. Her work has been cited by the U.S. Army War College, Defense Magazine, CIMSEC and other US and EU think tanks. She completed executive leadership studies at Oxford University and became a certified Chief Information Security Officer at 22.
EPCYBER trains global government and defense institutions to operate in hard-to-access environments. EIP gives them the engine to see inside those environments — built to close the West's access gap on the ecosystems that shape our national security.
— Eva Prokofiev, Founder & CEO, EPCYBER
Discuss coverage, method, and mission fit: demo@epcyber.com · Office of the founder: eva@epcyber.com