What this page covers
How the tracker collects, classifies, and publishes alerts, and where the limits are. The short version: official sources first, automation with narrow AI use, and honesty when our coverage is not good enough to support a claim.
Sources, not stories
The tracker monitors official government channels: defence ministries, interior ministries, civil defence and civil aviation authorities, armed forces, and state wire services. Media is included deliberately at a lower tier, because decision-makers need to see how stories surface and spread, but media alone can never drive the highest urgency level.
Host-government sources are fetched and checked before they go into the registry, and the date of that check is recorded against the source. Several other layers carry no such date. Some older source lists were assembled before this check existed. The national meteorological and disaster-management agencies arrive as one registry published by the World Meteorological Organization, so they are checked as a registry rather than one feed at a time. The US embassy alert feeds are generated from a standard address pattern for every country, so a mission that publishes nothing simply returns nothing. A fabricated or dead handle returns nothing forever and silently inflates coverage, which is worse than an honest gap.
The host-government model
The primary source for any country is that country's own government speaking to its own people. Foreign-government assessments, such as embassy alerts, and international feeds are kept and clearly labelled, but they are the fallback, not the foundation. A country with an interior ministry, a defence ministry, and civil protection publishing daily should never be scored off another government's view of it.
Source tiers
Tier 1 — a government body speaking officially. That covers a host government talking to its own people, and it covers international agencies such as the UN, the WHO and civil aviation authorities. Tier 2 — state news agencies and state-affiliated outlets. Tier 3 — a closed wire list, capped at MONITOR urgency so a wire report cannot drive an IMMEDIATE alert. Every source read for a country is named on the coverage page, with its tier.
A tier label describes the authority of a source, never the accuracy of its content. Some official channels are state media, meaning the state owns or runs the outlet; those carry a state media label so a reader knows whose outlet is speaking. We do not grade what a source says.
Why we label the outlet and not the claim
A claim rarely reaches you in the form it was issued. It starts somewhere, gets repeated, and arrives as a news story with nothing on it to say where it began. Each hop drops a little context. By the end, an open-source list compiled by one account off public business directories can read as state intelligence, because a state outlet republished it and a regional outlet then cited that state outlet.
The tracker puts the origin back. Every alert names the source that published it, says whose outlet that is, gives the time it went out, and links to the original. A reader who can see that a report began on a personal account and was picked up by a state wire is in a different position from one who meets it as a headline.
This is why we carry state media rather than exclude it, and why we do not grade what any source says. An inaccurate government statement is still a government statement, and knowing it was made is often the operative fact. Excluding those outlets would hide exactly the material a reader needs to see, and marking them true or false would put our judgement where theirs should be. We tell you who is speaking. You decide what it is worth.
A worked example
In March 2026 we traced one claim through six hands in five days. It is the clearest case we hold of why the source line matters.
An IRGC-affiliated outlet published a general statement that categories of Western companies in the region were legitimate targets. It named no addresses. Separate accounts then built their own lists from public business directories, corporate filings and mapping services, and posted them in English as shareable images with company names and office addresses. Follower networks moved those images onto Telegram, where they circulated as screenshots with nothing linking back to where they started. Fars News republished one with no mention of its open-source origin. Anadolu Agency then reported the warning, and the companies and locations it carried matched the compiled list exactly. English-language outlets published last, and by then the material read as regime-sourced targeting intelligence.
No stage of that required privileged access, and nothing in it was fabricated. What fell away at each hop was the context: the list was written in English rather than Persian, it was assembled from public data rather than gathered, and it was an influence tool rather than a strike order. By the end it carried a state byline and no origin.
A reader who saw the Fars item labelled as Iranian state media, with the time it was published and a link to the original, could ask where the list came from. A reader who met the same claim a week later, as a news story, could not. Putting that reader in the first position is the whole of what this service does.
Automation and AI
Automation runs the pipeline and AI does part of the work. It searches the monitored sources for newly published material, pulls what it finds into a fixed structure, translates content that is not in English, and assigns each item to a country. Translation is not limited to a fixed list of languages. On the global network, text in a non-Latin script is detected from the text itself, and text in a Latin script is translated where the source declares its language. Spanish, Portuguese, French and Arabic are the largest groups today. On the older Middle East feeds, translation covers Arabic, Turkish, Farsi, Hebrew and Urdu; some curated English-language feeds are not translated. Translated items carry a [Translated] tag.
AI is not allowed to form a view. It does not assess what an event means, predict what comes next, score a country, or write an opinion. Many items are never rewritten at all: they carry the source's own text as published. Two pathways do have a model write the summary, the main scan and the revalidation of government travel advisories. On those, extraction runs as a parser. The item may carry only facts stated in the source text, it must name the source that stated them, a block with no named source is discarded rather than guessed at, and the model is instructed to replace editorial words like crisis and alarming with neutral operational language.
Urgency is graded against written criteria, set out below. The model applies those criteria to the item, and that is the whole of its role here. It forms no view about how dangerous something is. Deterministic rules then sit downstream where the model cannot reach them: a wire report can never produce an IMMEDIATE alert, a restriction that has become a standing state rather than news is capped at MONITOR, and an item that stops matching the patterns is dropped back. Direct feeds skip the model and are graded by pattern alone.
Every item traces to an official source you can open yourself. No person reviews an item before it reaches you, so every classification is machine-assigned and we do not warrant it. Where an item links to an original, that original governs.
Urgency levels
IMMEDIATE — active, high-impact events requiring immediate awareness or action. MONITOR — developing situations warranting continued attention. BACKGROUND — standing information with no immediate action required.
What we leave out, and what we cut short
A set of named commercial outlets is not carried as a source at any tier. Where an official source quotes one of them, the public pages publish that the source spoke, with its urgency, country, time and a link to the original, and do not reproduce the quoted words. That is why some items on those pages carry no body text. Where a wire report quotes one, the item is dropped. The rights in those words belong to whoever wrote them, and a link is the honest way to point at them.
Government press-office material is filtered out: ceremonies, ribbon-cuttings, sports results, awards, recruitment notices. An item is dropped only when it carries press-office language and carries no security or hazard language at all. One signal is never enough, because a wrong drop deletes a real alert.
Nothing is dropped silently. Every filter that deletes an item increments a counter, and those counters are published on the service's own health endpoints, so a rule that starts eating real alerts shows up as a rising number rather than as pages that quietly went empty.
On the global network, items are imported if they were published in the last five days, and an item whose date cannot be read is let through rather than dropped. The Middle East feeds run tighter windows, measured in hours by tier. Live alerts are pruned after 48 hours. Standing items last as long as they are in force: travel advisories from the US State Department and the UK FCDO, and standing registers such as the EASA conflict-zone bulletins. A register is not a news feed, so it is not aged out like one, and withdrawn bulletins are kept alongside live ones because the withdrawal is itself the news.
What we do not publish
We do not publish a count of days since the last incident in a country. We used to. It had a failure mode that ran in the dangerous direction: a dead feed and a peaceful country look identical, because nothing arrives either way, so an ingestion outage pushed the number up, toward "safe". Keeping it honest across every country needed a person watching it, and a number that needs a person watching it does not belong in an automated service.
We publish no risk score, no forecast, and no assessment of how dangerous a country is. What the service reports is what the monitored sources published, and when. The coverage page at /coverage shows which sources those are for each country, and which of them have gone quiet.
What the tracker is not
It is not a warning system, and it is not security, legal, medical, or travel advice. The absence of an alert is not evidence of safety: events can occur before any official statement, and feeds can fail. Verify with official sources and take advice from your own security professionals before acting. The Terms of Service at /terms set out the full position.