Back to Blog

How AI Deep Search Works: From One Identifier to a Sourced Report

How AI Deep Search works: one email, username, or phone number expands into a sourced report of linked accounts, breach matches, and confidence scores.

Bob Adams

Threat Analyst at Revealer

Most people search tools are simple lookups. You type an email, they query a few static databases, and they return whatever rows happen to match. The moment the trail forks, for example a username that does not match the email, or a breach record pointing at a second address, a flat lookup stops. AI Deep Search keeps going. It starts from one identifier and follows the connections between accounts until it runs out of new leads.

What AI Deep Search does with one email, username, or phone number is less mysterious than the name. It keeps following every new identifier until the trail stops, then writes the whole chain into one report with every source attached.

What AI Deep Search does

AI Deep Search takes one starting signal (an email, a username, a phone number, or a name) and expands it into a set of connected identities. Each new fact it finds becomes a starting point for the next step. Breach records surface old usernames, usernames surface profiles, and profiles surface bios and more handles. The search continues until further steps stop finding new, high-confidence matches.

You do not get a dump of raw rows. You get one report: weak signals stitched together, each one cited back to a breach, a platform, or a live page, and each match scored.

Following the trail step by step

The search runs in passes. On each pass it takes the identifiers it already knows, looks for new ones connected to them, removes duplicates, and scores how strongly each new match belongs to the same person.

The important decision is when to stop. Stop too early and you miss the second and third accounts that make a search useful. Keep going with weak matches and you collect noise and false positives. AI Deep Search applies a confidence threshold to every new match, so the results stay tied to the subject and drop coincidental collisions.

Breach and stealer-log matches

The most useful matches come from breach and stealer-log data. When the search has an email, it checks that email against the breach records Revealer.US searches, the same corpus behind our data breach lookup. Those records often expose the other identifiers a person used: an old username, a recovery phone number, or a secondary email.

Each of those becomes a new starting point. A username pulled from a breach that a flat search would never connect to the original email gets checked across platforms, where it can turn into live profiles. That hop is how forgotten accounts show up, the ones a flat search never had a reason to look for.

Reading usernames

People reuse the stem of a handle, append birth years, or carry the same alias across many platforms. AI Deep Search reads these patterns: it separates the meaningful part of a handle from the noise, recognizes common variations, and tests likely variants across platforms, the same variants a manual username search would try one at a time.

That is what lets the search connect coolmike_88 on one service to cool.mike on another and mike1988 on a third, then attach a confidence score to each link instead of treating them as unrelated.

Live search across 200+ platforms

Static databases go stale. To stay current, AI Deep Search runs live searches across 200+ platforms: social networks, forums, marketplaces, developer sites, gaming services, and smaller communities. It decides which platforms are worth checking for a given subject based on the signals already gathered, and it reads the live page rather than relying on model memory.

Live pages matter because you can open the same URL. The search is not guessing that a profile exists. It opened the page, read it, and kept the evidence.

Confidence scores and cited sources

The final step turns the collected matches into a report. The search compares every signal it found (emails, handles, phone numbers, profiles, and breach records) and scores how strongly they belong to the same person. Reinforcing evidence raises the score; contradictions lower it.

Nothing is presented as certain without a score attached, so you can tell a near-certain link from a speculative one at a glance. Every match also carries its source: which breach, which platform, or which live page it came from. You can trace any claim back to its origin, check it yourself, and stand behind it.

Why this beats a flat lookup

A flat people search answers one question and stops. AI Deep Search asks the next one without waiting for you. Breach matches, username reading, live platform search, and confidence scoring are stages of the same run, each one sharpening the next. The report is a digital footprint assembled from those stages. No single lookup builds that picture on its own.

Frequently asked questions

What is AI Deep Search?

A search mode that takes one identifier and expands it recursively. Every fact it finds (a breach entry, a handle, a linked profile) becomes the input for the next pass, and the run finishes when new passes stop producing high-confidence matches.

What can I start a search from?

An email address, a username, a phone number, or a name. Email and username tend to be the strongest starts, because they link to more accounts and appear in more breach records than a name alone.

How is it different from a regular people search?

A regular search runs one lookup against a set of records and returns the rows that match. AI Deep Search chains lookups together, pivots on each new identifier it finds, and returns one scored report instead of separate result sets.

What does the confidence score on each match mean?

It expresses how strongly the evidence ties a result to the person you searched for. Reinforcing signals raise it, contradictions lower it, and matches below the threshold are dropped so coincidental collisions do not reach the report.

Can I see where each result came from?

Yes. Every match carries its source: the breach or stealer-log dataset, the platform, or the live page it was read from. Any claim in the report can be traced back and checked by hand.

Can I use it on my own accounts?

Yes, and it is a common use. Starting from your own email or handle shows which old accounts, reused handles, and breach entries are still attached to you, which is the fastest way to scope what to close or rotate.


Want to see it run on a real identifier? Explore AI Deep Search and watch a single input expand into a fully sourced report.

Get started

Ready to check your exposure?

Create a free account. Every result is pulled live, in real time, from public sources and endpoints we do not own. We do not retain your search data. Items you choose to save, publish, or monitor are kept until you delete them.

Create account