Independent Baltic security monitor · Free · Not affiliated with any government
Automated open-source intelligence (OSINT) tracking of Russia/Baltic security signals across 152 sources — national security services, wire outlets, and disinformation trackers — scored for independent corroboration before anything is ever flagged.
Don't want a Telegram account in the loop? Browser alerts use nothing but your own browser — no app, no account, no third party involved.
Signal Deviation Index
Averages four independently-tracked raw signals — GPS-jamming, AIS vessel activity, military aircraft, and thermal hotspots — against each one's own recent baseline. A measurement of current deviation, not a forecast: it never overrides the WARN/WATCH/QUIET result above, and can read elevated on a day that stays QUIET there. Full breakdown ↓
Read this first
An OSINT (open-source intelligence) tool: scans public news, official government sources, and structured event data for Baltic/Russia security signals, then scores results by how many independent sources corroborate the same story before flagging anything as a real alert. Everything here comes from publicly available sources — nothing classified, nothing covert.
Not an official government, NATO, or intelligence source, and not affiliated with any of them. Not verified intelligence or a predictor of the future — a keyword-and-corroboration score, built and run by one person. It can miss things, and it can occasionally be wrong.
Method
Every source sits in a trust tier. No single source can trigger a real alert alone — only independent corroboration across tiers does.
| Tier | What qualifies | Count |
|---|---|---|
| Tier 1 | National security/intelligence services (Estonia, Latvia, Lithuania, Finland, Sweden, Poland), NATO, ISW, wire services. | 33 sources |
| Tier 2 | National broadcasters, security think tanks, investigative outlets. | 109 sources |
| Tier 3 | Disinformation fact-checkers, plus Russian state media/officials themselves — tracked to see the narrative, never counted as evidence, never able to trigger an alert. | 10 sources |
Most sources are reached through one news aggregator, which has occasionally rate-limited an entire scan at once. To make sure a single outage cannot leave the monitor blind, 48 feeds are additionally read straight from the publishers themselves — the Baltic broadcasters in both English and local language, and, just as importantly, primary sources that would be announcing an incident themselves: defence ministries, national guards, national cyber-security teams and electricity and gas grid operators. An outlet reached by both routes still counts as one source, never as its own corroboration.
Nothing relevant matched this scan.
Relevant, but not yet corroborated by an independent source.
The same story, independently confirmed — either by sources of two different trust levels, or by three separate newsrooms. Verbatim reprints of one wire report count once.
Not everything relevant becomes a warning. Material that is routine, pre-announced, speculative, or already reported is recorded as context instead. Activity by Russia or Belarus is never treated as routine.
The rule applied: an alert counts as a real signal only if something happened, or was credibly reported as about to happen, in or against the Baltic states. Commentary, analysis and history that merely mention the region count as noise, however interesting.
Judged one by one by the project's operator — not an independent audit. The number is worth something only because every judgement is attached to an alert that was published at the time: the channel history is open, and you are free to disagree with any of them.
These items still appear in the scan record, marked as context. The reason is simple: a channel that raises an alarm over everything trains people to ignore it — and then the one alert that actually matters gets ignored too. A concrete reported incident — a cable cut, a drone crossing a border — is never filtered out this way, even if officials are quoted downplaying it.
Track record
Pulled automatically from the same data the Telegram channel uses — nothing shown here is prepared separately for this page. Scans are scheduled every ~4 hours (6x/day), not continuously — though GitHub's free scheduler is best-effort and can run a scan later than scheduled during high platform load, sometimes by several hours.
Average deviation from baseline across GPS-jamming, AIS, military aircraft, and thermal hotspots (whichever have enough history yet). A measurement of how far each scan sits from normal — never a forecast, and separate from the WARN/WATCH/QUIET result.
Each bar is one scan that reached WATCH (amber) or WARN (red); QUIET scans show no bar. Bar height is how many relevant items triggered that scan, not a severity score.
Each dot is one scan, colored by its result (green = quiet, amber = watch, red = warn). The line is GDELT's average coverage tone where available — the higher the line, the more alarmed/hostile the press coverage; not a forecast. The dashed line is 0 (neutral tone), not the bottom of the chart — scans with no GDELT data that scan sit on it by default, not because coverage was actually neutral.
How many rumor/disinformation items (Tier 3 — never able to trigger a real alert on its own) were tracked per scan.
High-interference GPSJam cells detected per day in the Baltic region. Crowdsourced from aircraft-reported GPS accuracy — correlates with, but doesn't confirm, deliberate jamming.
Vessels observed per scan during a short live AIS listen window. Not exhaustive coverage — whichever ships happened to report during that window.
Aircraft broadcasting ADS-B per scan in the Baltic region. Many military flights fly with it off or spoofed, so this is a partial picture.
Satellite thermal-anomaly detections per scan in the Baltic region. Raw heat-signature data — wildfires and agricultural burning trigger it as readily as anything else.
Forced (unplanned) generation-unit outages per scan in Estonia, Latvia, and Lithuania, via ENTSO-E's official EU outage-reporting platform. Almost always ordinary equipment failure, not sabotage — undersea-cable/transmission outages aren't covered yet.
Self-reported when a mistake is noticed — not an automated audit. A clean record means nothing has been caught and reported yet.
A plain-language log of features and fixes shipped over time.
Live status temporarily unavailable — check the Telegram channel directly for current status.
Before you ask
It gets logged and published as a correction, not quietly fixed — the list above is the full record of what's been reported this way. Occasionally being wrong and saying so openly is more trustworthy than a suspiciously spotless record. One honest limit: this isn't an automated audit — a correction only appears if a mistake is actually noticed and manually reported. A clean record means nothing has been caught and reported yet, not a formal guarantee of zero errors. The "correction rate" figure above is corrections divided by scans, for scale — not an independently verified accuracy score.
GDELT is a public database that automatically codes political and conflict-related news worldwide into structured categories, with a standard severity rating called the Goldstein scale (-10 to +10 — more negative means more hostile/conflictual). When a flagged item comes from GDELT, its category and Goldstein score are shown alongside it as extra context. This is just added detail on an item that already qualified: any GDELT-sourced item shown here has already passed the exact same relevance and corroboration checks as every other flagged item on this page — it is not raw or unfiltered data. (When a WATCH or WARN is posted, the Telegram channel automatically attaches a map — but it only plots the specific events that triggered that alert, not a general snapshot of regional activity.)
A source's feed didn't respond during that scan — usually a normal, isolated hiccup. Occasionally a large batch fails all at once instead: this project runs on free, shared hosting (GitHub Actions), and that shared pool sometimes gets a server whose IP address Google has already rate-limited for unrelated reasons, which blocks every Google-News-routed source in one scan together. When that's detected, the scan now recognizes it within about a minute and automatically retries on a different server, rather than waiting for the next scheduled run. Either way, it means that result may be less complete than usual — not that something was hidden. We'd rather show this than let a broken scan look identical to a real all-clear.
So the scoring can't be gamed — naming exactly which outlets can trigger an alert would let someone target or exploit the specific sources that matter. Tier and count are public; the moment a source actually produces a real WATCH/WARN, its name and link are shown too (see "Recent flagged items" above).
On Telegram, yes — as the channel admin, that's normal for any Telegram channel owner, not something built specifically for this project. Browser push subscribers are different: no name or identity is attached, just an anonymous device token, so I can't see who anyone is there. Other Telegram subscribers can't see each other, and nothing is exported, stored elsewhere, sold, or shared beyond what Telegram itself already handles.
Mobile browsers can be inconsistent here — a phone's battery optimization, or the browser's own per-site notification setting, can silently mute alerts with no error shown anywhere. The most common cause: check that notifications for this site aren't muted directly inside your browser's own settings (not just your phone's system settings) — that's usually it.
Yes. There's an optional tip button (Ko-fi) for anyone who wants to support the project — it won't buy faster or better alerts; everyone gets exactly the same thing, at the same time, regardless. Who funds this project — currently nobody — is listed in full on the funding page.
No. If you're worried about an actual emergency, always check your own country's official channels first: Estonia — kriis.ee · Latvia — vugd.gov.lv · Lithuania — lrv.lt.
Other ways to follow this
Prefer your own reader over Telegram or browser push? Subscribe to the RSS feed — same flagged items, no account needed.
Doing your own analysis? Download this project's own history as CSV: scan-level history (level, source counts per scan) and Composite Escalation Index (deviation score per scan). Same data behind the charts above, free to reuse.