Your phone and accounts, examined. Every claim cited.

A consent-gated audit of your Android phone, your Instagram account history, your Microsoft 365 sign-ins, and known breaches — correlated into one timeline, with the raw artifact behind every finding. No verdicts. No scare tactics.

Passwords never leave your providers · raw data deleted at completion, 24 h at most · delete everything at any time, logged.

finding F-001 · with its evidencesample
Needs attention

New Apple device signed in to Instagram over a VPN

First Apple device and first VPN in this account's 8-year history. No alert was sent; the session is still active. [ev:42]

[ev:42] account_activity.json › sessions[12]
"time":   "2026-08-27T21:14:09Z"
"device": "Mac/iPad · Safari 17"
"ip":     "104.28.•.• — Cloudflare WARP"
"status": "active"
This is the unit of the whole product: a claim, its raw evidence, and what to do.

HOW IT WORKS

Four sources in. One cited report out.

  1. 01 · CONSENT

    You attest, we begin

    Plain-language attestation that the phone and accounts are yours to examine. Blocking — nothing is read before it.

    the exact wording you agreed to, stored with the audit

  2. 02 · COLLECT

    Sources, any order

    Phone over USB on your computer (Chrome, nothing installed). Instagram export upload. Microsoft 365 sign-in log upload. Breach check.

    encrypted per-job key

  3. 03 · CORRELATE

    39 rules, one timeline

    Device records, logins and breaches merge onto one clock. Every rule that runs is listed — and every rule that couldn't run, with why.

    nothing silently dropped

  4. 04 · REPORT

    Findings you can check

    What we saw, why it matters, the raw excerpt behind it, and what to do — plus what was checked and clear, and what we could not check.

    raw data deleted at completion

Device, email, Meta and breach records feed one timeline, and every finding cites its evidence.

WHAT WE CHECK

Every installed app and who installed it · when apps last used the camera, microphone and location · per-app network history · spyware and stalkerware indicators from published feeds
Microsoft 365 sign-in history, from a work or school account's own export
Logins, logouts, devices and password changes from Instagram's own account-history export
Known breach corpora and infostealer logs, opt-in

WHAT WE CAN'T

iPhones · what apps hold on their servers · SIM-level interception · anything deleted before the audit · someone watching you in person.

"No indicators found" is not a clean bill of health. We report what was checked, what was found, and what we couldn't see — each in its own section, none left out.

PRICE

Completely free. There is nothing to buy.

The audit, the summary, the findings, the full evidence appendix and the merged timeline — all of it, at no charge. No card, no trial, no locked sections.

Everything included

  • Full audit run · consent + deletion controls
  • Summary + all findings · every [ev:n] artifact
  • Merged timeline · the full report, in the app