BurnBox
Platform Capabilities

Built for Rigorous Web Research

Every capability in BurnBox is designed to streamline intelligence gathering, protect internal networks, and preserve audit-ready evidence.

Discovery

Target Discovery & Pre-flight Inspection

Screen web URLs, validate target hostnames, configure crawl depth (1–3), and set page limits before launching deep web investigations.

Perimeter Defense

SSRF-Shielded Network Perimeter

Pre-flight DNS checks filter private RFC1918 subnets, loopbacks, link-local addresses, and cloud provider metadata services (169.254.169.254).

Web Intelligence

Decoupled Scrapy Cloud Crawling

Asynchronous crawling offloaded to Scrapy Cloud workers. Control plane nodes never execute untrusted web payloads directly.

Evidence Capture

Evidence Harvesting & Link Graph

Automatically capture raw page text, clean body content, HTTP status codes, and outbound domain link graphs with full JSON export capability.

Workspace

Collaborative Research Projects

Organize research targets, findings, and harvested evidence into scoped projects with tagging and investigator notes.

Identity & Access

Clerk Identity & Server-Side RBAC

Multi-tenant organization isolation backed by Clerk auth. Permissions are enforced strictly on the server across all API endpoints.

Compliance

Immutable Compliance Audit Trail

Tamper-resistant audit events recording every investigation run, project mutation, and security block with nanosecond correlation IDs.

Analytics

Data Science & Deepnote Analytics

Export investigation datasets for external analysis, or trigger automated Deepnote Python notebooks for link analysis and reporting.

BurnBoxSecure Web Research Workspace
SSRF Protection Verified
Multi-Tenant RBAC Isolation

© 2026 BurnBox. All rights reserved.

Evidence-focused investigation platform for security and intelligence researchers.

BurnBox | Secure Web Research Workspace