A verdict is only useful if the next person can reproduce it.
EvidencePack is Dralvia's universal report artifact. Every scanner, URL, domain, contract, repository, identity, produces the same structure. PDF for humans, JSON for systems, hash-pinned for auditability. Built so the handoff from analyst to auditor never loses the evidence.
Evidence reports
See Dralvia in action.
Turn completed scan evidence into executive, technical, and compliance reports.
- Choose a completed scan
- Generate the required report shape
- Reopen prior report history
This preview shows the Dralvia workspace. Sign in to see your own scans, alerts, and activity.

One structure, every scanner.
1 · Verdict
The decision and risk level up front, with the score and the reasoning that produced it.
2 · Signals
Every triggered signal, the engine that found it, and its individual contribution to the verdict.
3 · Raw evidence
WHOIS snapshots, headers, DNS records, bytecode references, the underlying data, not a summary of it.
4 · Capture
Redirect chains, rendered content, and form analysis captured at scan time so the evidence survives takedown.
5 · Threat-feed reference
Which external feeds and Dralvia intel contributed, and what each said about the target.
6 · Chain of custody
Timestamps and a content hash so anyone can confirm the pack has not been altered since it was produced.
7 · Public anchor
Every pack is entered in an append-only transparency log. That log's root is countersigned by two independent timestamp authorities and published openly, so the record cannot be rewritten later, by us or by anyone who compromises us.
Honest answers.
All of them, phishing/URL, domain reputation, smart contract, repository, and identity events, plus gateway block decisions. The structure is identical across surfaces.
Run a scan and export the evidence.
See the EvidencePack on a real verdict, PDF for the report, JSON for the pipeline.
Evidence comes from every scanner.
Verdicts for suspicious links
100+ signals and a full redirect-chain capture per URL.
Pull packs into your pipeline
REST and Python / JavaScript SDKs return the same structured artifact.
How we handle your data
Retention windows, what we collect, and what we do not.