InfoFlow Navigator
InfoFlow Navigator is the Government Communications Agency's federated metadata and identity-discovery system. It identifies devices, people, networks and movement patterns associated with espionage, terrorism, hostile cyber activity, serious organised crime and comparably dangerous investigations. Its statutory basis, retention limits and intelligence-to-evidence rules are set out in Law and Civil Liberties.
Data and collection
The system is scaled for the communications activity of approximately 962 million adults. It records routing metadata: which devices communicated, the service used, the time and duration, and coarse network-derived location. It does not collect message or call content under its bulk authority. Content interception requires a separate targeted warrant. Domestic location sampling from communications networks may be no more frequent than half-hour intervals unless a targeted warrant authorises closer tracking.
InfoFlow also receives advertising real-time-bidding data. Advertising requests can expose device identifiers, network addresses, applications or sites, time and location fields even when no advertisement is ultimately displayed. The GCA purchases this material through several commercial front companies, which conceal the government as the ultimate customer and pass their feeds into InfoFlow. Each company, contract and transfer remains attributable in classified procurement and audit records. RTB observations are treated as commercial-source leads rather than verified facts and are linked to devices or people only with recorded source and confidence.
The visual and acoustic collection holds large real-time feeds from public CCTV, transport and municipal systems. Some connections are presented to the operator as police access. Security companies acting as GCA fronts provide an ordinary monitoring or systems-management service while passing an authorised copy of the feed to the Agency. State and local police also arrange access under agreements with local camera operators. InfoFlow additionally ingests public web material, open broadcasts, footage supplied by authorised investigations and other lawfully available open sources.
Where those routes do not provide adequate coverage, the GCA may obtain general infrastructure feeds through covert technical access. A system may be selected for non-targeted inclusion in the bulk archive without a judicial warrant where the statutory collection class, internal legal certification, necessity and proportionality tests are satisfied. If the choice of system, camera, place, period or access method is materially influenced by an expectation that a particular person will appear there, the operation is targeted and requires judicial authority. Incidental capture of a known person does not retrospectively change the basis on which a genuinely general feed was acquired.
BioMatch
BioMatch is InfoFlow's multimodal identity-resolution model. It compares faces, voices, gait, appearance and other distinguishing features extracted from live or archived imagery, video and audio. It can associate observations across different camera systems and media without first knowing a person's civil identity.
Each resolved person is assigned a unique pseudonymous BioMatch ID. The ID is an analytical control rather than a civil identity or proof that a named person has been identified. Every association carries its source, time, model version and confidence. Registration records, the limited identity-resolution feed from the Government Research Service, shared locations, communications patterns and RTB observations may connect a BioMatch ID to a name, organisation or device, but weak or contradictory links remain visible and cannot be silently merged into a confirmed identity.
An authorised investigator may submit a still image, video clip, voice recording or other media sample under a recorded serious-crime or intelligence case. BioMatch returns whether an existing ID is available, together with candidate confidence and limited provenance; it does not expose the underlying footage archive. High-impact matches require analyst validation. If no existing match is found, a lawfully submitted sample creates a new BioMatch ID that can receive later observations.
Historical footage associated with an ID remains sequestered until case-specific judicial authority permits release. Once released into the investigator's InfoFlow case compartment, it may be combined with communications, RTB and device metadata to identify locations of interest, reconstruct movement, test associations and assess which devices are likely to belong to an individual. The material remains an investigative lead until it is independently verified and made admissible through the intelligence-to-evidence process.
Where a dangerous subject must be found in real time, a short and renewable live-tracking warrant can require new BioMatch observations to be flagged and pushed automatically into the authorised case compartment. An emergency activation is permitted where delay would create an imminent danger, but it must receive prompt judicial review and expires if it is not confirmed. A live alert does not itself authorise arrest, search or use of force.
Retention and access
The bulk footage and acoustic archive is a rolling 60-day holding. Unselected media is deleted at the end of that period. BioMatch IDs, templates, provenance and confidence histories survive deletion of the source footage so that later observations can be linked across time. They undergo periodic accuracy and necessity review and may be corrected, separated or deleted following compliance review or an order of the closed complaints tribunal. Footage selected under judicial authority may remain with the case file for the authorised investigation and legal-review period.
Raw domestic communications-location metadata is deleted after 30 days. Other unselected domestic communications metadata is deleted after 180 days. Foreign metadata is retained for no more than two years while it continues to meet a recorded requirement. Material selected under a warrant may remain with the case file for the authorised investigation and legal-review period.
An analyst must state an approved intelligence purpose before making a query. Revealing the identity of a Republic resident requires second-officer approval, and protected legal, medical, journalistic, parliamentary and treaty-government material receives additional handling controls. The FIA may query foreign-intelligence holdings; the DIA and Counter Terrorism Group may submit domestic queries under their own case authorities. The National Crime Agency and territorial police submit samples and requests through controlled GCA gateways. They receive authorised results but cannot browse the raw archive, the national BioMatch index or unrelated InfoFlow holdings.
Every collection route, covert access, query, ID creation, identity link, merge, separation, footage release, live alert, export and deletion is recorded in an immutable audit trail. The Intelligence Inspector-General conducts continuous compliance sampling, inspects the real purpose for infrastructure access and investigates anomalous use. The closed complaints tribunal can inspect the system and order correction, separation, deletion or compensation.
Typical InfoFlow data centre
Every InfoFlow data centre is occupied and presented through a front company. There is no openly marked GCA data centre and no site at which the commercial cover is optional. The fronts differ by region and may claim to provide records storage, business-continuity services, facilities monitoring or industrial-data processing. They have ordinary registrations, tax records, staff contracts, suppliers and enough genuine activity to survive routine commercial contact. Classified procurement and property records nevertheless identify the government interest, the officers responsible for the cover and the route by which the site enters the GCA estate.
The first line of defence is security through obscurity. The building is intended to look dull, inconvenient and unimportant rather than visibly impregnable. Signage is small, public opening hours are limited, recruitment is handled away from the site and the reception staff politely discourage tours, speculative sales visits and casual deliveries. Loading activity, electrical demand, cooling plant and standby generation are explained by the front company's declared work. Local fronts are deliberately varied so that a records contractor in one state does not share a public identity with a facilities-monitoring company elsewhere.
The second layer begins outside the property. Cameras, vehicle readers, vibration and intrusion sensors, and environmental monitors cover the roads, foot approaches, service routes and adjoining ground from unobtrusive positions. Some belong to the site, some sit on property leased by the front company and some are carried through lawful arrangements with nearby infrastructure operators. They establish patterns and warn of surveillance, tampering or repeated approaches; they do not by themselves authorise investigation of everyone who passes through the area.
The third layer is hidden inside the benign front. The public offices and working warehouse stand in front of a controlled transition spine with separate routes for personnel, freight and building services. Beyond it, reinforced construction, guarded screening, intrusion detection, compartmented credentials and internally hardened doors protect the operational core. A person admitted to the commercial frontage has no line of sight or unescorted route into GCA space. Rank or general clearance is insufficient: access depends on a current duty, the correct compartment and an authenticated credential.
The following schematic is directional rather than scaled. The public road is at the south; secure plant and communications routes leave on the less visible northern and side boundaries.
NORTH
[Remote fibre entry] [Secure plant yard] [Remote fibre entry]
\ | /
+--------------------------------------------------+
| HARDENED CORE: data halls | operations |
| continuity rooms | secure stores | staff | egress |
+-----------------------+--------------------------+
|
+--------------------------------------------------+
| CONTROLLED TRANSITION SPINE |
| personnel screening | freight search | guard post|
+---------------+------------------+---------------+
| |
+-----------------------+ +------------------------+
| FRONT OFFICES | | DECOY WORKING SPACE |
| reception | meeting | | records/warehouse/ |
| rooms | administration| | facilities operations |
+-----------------------+ +------------------------+
\ /
[Visitor parking and ordinary service yard]
- - - - Site boundary and concealed detection - - -
cameras and sensors on roads, approaches and nearby ground
SOUTH / PUBLIC ROAD
Area conditions
| Area | Position, function and access | Character and sensory conditions |
|---|---|---|
| Surrounding observation area | Extends along the public road, foot approaches, service routes and adjoining ground beyond the immediate boundary. Discreet cameras and sensors give warning before a person or vehicle reaches the site. | Nothing announces a protected facility. Traffic noise, weather, vegetation and neighbouring activity dominate; equipment is quiet, visually ordinary and noticed mainly by technicians during inspection. |
| Visitor parking and ordinary service yard | Sits between the public road and the front buildings. Visitors, office suppliers and declared commercial deliveries stop here and cannot continue to the secure loading route. | Painted bays, delivery cages, waste containers and work vans make the area deliberately mundane. It smells of wet paving, vehicle exhaust and cardboard; security presence is felt through orderly movement rather than visible fortification. |
| Front offices | Faces the public approach and contains reception, meeting rooms, administration and a small number of genuine front-company staff. Doors behind the office circulation lead only to ordinary support rooms or alarmed controlled points. | Lighting is flat and economical, furniture durable and branding forgettable. Telephones, printers and subdued conversation cover the hum of ventilation; the reception is comfortable enough for business but too joyless to encourage lingering. |
| Decoy working space | Occupies the visible warehouse or operational side of the frontage. It holds real records, test benches, monitoring desks or facilities stores consistent with the local cover and masks secure freight and utility demand. | Racking, sealed cartons, ordinary monitors and pallet equipment create dust, paper smells and intermittent mechanical noise. Temperatures vary more than in the secure core, and loading doors admit damp air, road grit or industrial odours. |
| Controlled transition spine | Lies behind the public frontage and separates the personnel entrance, searched freight route and guarded building-services access. Authentication, screening and escort rules are applied here before the hardened core. | Exterior noise drops away. White light, hard finishes and low conversation make footsteps, locks and ventilation obvious; air is cooler and cleaner, and the absence of commercial decoration marks the point at which the cover ends. |
| Guard and incident post | Overlooks the transition routes without being visible from reception. It coordinates alarms, local response, camera review and emergency access while remaining separate from national InfoFlow operations. | Displays cast a muted glow over acoustic panels and plain consoles. Radio speech, alert tones and the dry smell of electronics replace warehouse noise; the room remains cool even during a busy incident. |
| Operations rooms | Occupies the inner core beside, but not inside, the data halls. Staff monitor ingestion, query routing, storage health, access control and site continuity from compartmented rooms. | Light is subdued around bright status displays. Fans and filtered air produce a constant soft hiss; voices are restrained, surfaces are cool and there is little sense of daylight or weather. |
| Continuity rooms | Sits within the hardened core but outside the routine operations compartment. It holds restoration consoles, isolated recovery media and alternate work positions used during maintenance, cyber isolation or loss of a peer centre. | The rooms are normally sparsely occupied and unusually still. Locked media cabinets, low equipment hum and cool dry air give them an archival quality; activity becomes bright, crowded and procedural during an exercise or real restoration. |
| Data halls | Form separated compartments within the reinforced core. Regional and functional shards are divided between halls so that maintenance, fire or intrusion in one space does not open the rest. | Air is cold, dry and fast-moving. Server fans create a dense, directionless roar, cable trays and indicator lights repeat into the distance, and vibration is felt through raised floors and cabinet handles. |
| Secure stores and build rooms | Stand between the freight screening route and data halls. Cleared teams receive, inspect, configure, quarantine and account for equipment before installation or removal. | Benches are brightly lit and tools are laid out with clinical order. Packaging, warm electronics and anti-static materials give the rooms a faint plastic smell; scanners, label printers and test fans interrupt an otherwise controlled quiet. |
| Power and cooling plant | Occupies hardened rooms and a screened northern yard with independent fire separation. It contains switchgear, batteries, generators, pumps, heat rejection and water-treatment equipment without sharing public service access. | Machinery produces low vibration, pump thrum, warm oil and metallic heat indoors; cooling areas are windy, wet and loud. Warning paint, ear protection and sudden temperature changes distinguish the plant from office and data spaces. |
| Communications entries | Approach through physically separated routes on different sides of the site and terminate in protected rooms before entering the core network. No public-facing telecommunications cabinet gives direct access to operational fibre. | These rooms are narrow, cool and intensely ordered. Cable labels, splice enclosures and quiet equipment fans dominate; there is little smell beyond clean insulation and the faint warmth of optical hardware. |
| Staff rooms and internal support | Includes lockers, rest rooms, a small mess, first aid, welfare space and internal sanitation within the secure side, limiting repeated movement through screening. | Softer light, hot drinks and food smells briefly interrupt the sealed technical atmosphere. Even here the ventilation hum and lack of outside windows remain noticeable, and privacy is practical rather than generous. |
| Protected emergency routes | Lead from each compartment to alarmed, monitored exits and assembly points that do not pass through another secure compartment. They permit evacuation and fire access without creating an ordinary entry route. | Routes are stark, brightly marked and normally empty. Fire doors close heavily, emergency lighting is conspicuous and outside air, rain or cold arrives abruptly when an exit is opened. |
Federation and continuity
InfoFlow storage and processing are federated across geographically separated secured GCA data centres throughout the Republic. Collection is divided into regional and functional shards, each replicated into separate failure domains. The BioMatch index and query-routing services are likewise partitioned and replicated; no data centre holds the only copy of an operational shard, the only usable identity index or an indispensable central control plane.
Queries are routed across the federation and return only the fields authorised for the requesting compartment. A disconnected centre can continue limited regional ingestion and matching until authenticated reconciliation resumes. The loss or isolation of a site reduces capacity, freshness or regional coverage but does not disable the national service. Offline recovery copies, independent communications routes and tested restoration exercises protect against simultaneous cyber attack, power failure or physical destruction.
Access uses hardware credentials, role separation and continuous monitoring. Encryption and authentication standards are replaced through the ordinary national cryptographic migration programme rather than through unapproved experimental deployment. The Communications Surveillance Division operates collection and initial analysis. The GCA legal office certifies collection classes and query rules, while agency liaison cells validate whether a proposed dissemination falls within the recipient's authority. Operational secrecy does not displace parliamentary, judicial or inspector access.
Working life and institutional memory
InfoFlow is experienced differently by each user. GCA analysts see collection classes, provenance and confidence histories. DIA officers see a controlled route to a domestic-security lead. NCA and territorial police receive constrained results through gateways rather than a searchable national archive. Legal and compliance staff see purpose statements, approvals, live-alert renewals and deletion records. The system's design is therefore as much about what it refuses to show as what it can find.
After the Silent Files scandal and the later GCA/DIA compliance inquiry, staff adopted a practice of writing the purpose of a query before opening the result. Analysts call this “the sentence before the screen”. It is a small bureaucratic habit, but it makes a later audit possible and discourages exploratory browsing. The persistent problems are false merges, stale source material, contractor access, pressure for faster identity resolution and the public suspicion that a pseudonym is only privacy until an agency wants a name.
Political costs and opposition
InfoFlow allows agencies to share a useful lead without creating a national searchable archive, but the boundary makes investigations slower and can leave a receiving officer with too little context. Victims and investigators may lose time while legal staff confirm purpose, identity and dissemination authority; contractors and departments lose convenience when access controls reject a legitimate but unusual workflow.
False merges and stale records also burden innocent residents, especially people with common names, migration histories or changed identities. Human review, confidence histories, deletion records and controlled gateways are the compromise. They reduce the speed promised by a single database, but preserve a defensible distinction between finding a lead and authorising state action.