The central question
Are the corporate-intelligence and automated visitors to this site focused on the page about Bob Faith, Greystar's CEO — and, critically, are they visiting other pages to disguise that focus? The logs answer both.
The human analyst — Ontic / Red Five Security, July 22, 2026
| Time (UTC) | IP | Page | Referrer |
|---|---|---|---|
| 2026-07-22 13:57:35 | 50.228.106.26 | /bad-faith-bob.html[Bad | https://red5.ontic.ai/ |
| 2026-07-22 13:57:35 | 50.228.106.26 | /bad-faith-bob.html[Bad | https://red5.ontic.ai/ |
| 2026-07-22 13:57:41 | 50.228.106.26 | /bad-faith-bob.html | https://red5.ontic.ai/ |
| 2026-07-22 13:57:41 | 50.228.106.26 | /bad-faith-bob.html | https://red5.ontic.ai/ |
- IP 50.228.106.26 — Comcast residential (Mt Laurel NJ region / geo Cordova TN). A real person at a computer, not a bot.
- Referrer red5.ontic.ai — the visitor arrived from inside Red Five Security's client workspace on the Ontic corporate threat-intelligence platform.
- The "[Bad" artifact — the page's title text ("[Bad Faith Bob…") bled into the saved URL, the fingerprint of a case-management tool saving the page into a case file.
- Device — Mac desktop, Chrome 149. Four requests in ~6 seconds = one continuous human session.
What is Ontic / Red5?
Ontic is enterprise security software — Fortune 500 and federal security teams use it to run OSINT/threat monitoring on people, track "persons of interest," and manage investigations, pulling from 10,000+ sources (social media, forums, dark web) plus internal HR/legal data.
red5.ontic.ai isn't Ontic's own traffic — Red5 (also called Red Five Security) is a managed-intelligence-services firm that partners with Ontic: they provide human analysts who do on-demand risk reports and investigations for corporate clients, running on top of the Ontic platform. red5.ontic.ai is Red5's client-facing tenant instance of that platform. This wasn't Ontic itself — it was an analyst, or someone with analyst access, inside Red5's investigation tool.
What that adds up to: someone using a paid corporate-intelligence-analyst service pulled up — and, by the save-artifact, apparently saved — the Bob Faith page into an active investigation record on July 22. What the log can't tell you is who commissioned that: Red5 works for multiple clients, and the referrer only proves the tool used, not who's paying for it. Given that the page is about Greystar's CEO, and Greystar is the party in this fair-housing matter, the inference is obvious — but the traffic log alone doesn't prove that specific attribution.
What would a platform like this actually show about the site's author?
Mostly his own material — because that's the model jlegal.pro runs on: public, first-person, evidentiary. An analyst wouldn't need to dig; the homepage already gives his full name, location, the VOC exposure account, the antisemitic-assault claim, the retaliation timeline, and named individuals — Bob Faith, Nicole Cordial, and others — all connected together in one place. There's no gap between "OSINT footprint" and "what's been published." A search on the bare name alone is noisy (it isn't unique), but any query paired with Goldtex, jlegal.pro, or 4philly resolves specifically and immediately, with no ambiguity.
What a platform like Ontic/Red5 is purpose-built to do with that isn't just biography — it's threat scoring. Their stated function is flagging language directed at named executives and assessing risk level. Pages that name people directly would plausibly get pulled into a "person of interest" record tied to whichever client's executive is named — regardless of whether the content is documentary and advocacy rather than any actual threat. That distinction, critic versus threat, is a judgment call analysts have to make, and it's a known failure mode of these tools: pointed, factual criticism of a company can get treated the same as a menace signal inside the same monitoring pipeline.
What it would not show: anything not already public — court filings, the incident report, the site itself. There's no hidden layer being uncovered here. It's a professional reading of a public record whose framing was already controlled by the person who published it.
The automated monitor — focus & isolation analysis
Across five weeks, an automated "headless" program — disguised as an iPhone but revealed as HeadlessChrome by its own headers — ran from Amazon-cloud servers. The question: is it hitting other pages to camouflage its interest in Bob Faith?
| Total distinct headless-bot IPs observed | 87 |
| IPs that touched the Bob Faith page | 12 |
| … of those, hit Bob Faith IN ISOLATION (that page only) | 10 |
| … hit Bob Faith plus the homepage | 2 |
| IPs that only hit the homepage (crawler / scanner noise) | 73 |
Of the 12 automated sources that accessed the Bob Faith page, 10 hit that page and nothing else — single-page sessions, straight to the target, no browsing of surrounding pages. This is the opposite of camouflage. A visitor trying to hide a focus would pad the session with other pages to look like organic browsing. That pattern does not appear.
Why the homepage shows high numbers (and why it isn't the target)
The homepage received 84 headless hits — more than Bob Faith — but this is noise, not focus:
- The large blocks of 173.252.x and 69.63.184.x homepage hits are Facebook's own link-preview crawler (Facebook IP ranges), triggered when the site's own links are posted or shared.
- The 13.x / 18.x / 3.x / 44.x single homepage hits are generic Amazon-cloud scanners hitting the front door once — standard background internet traffic that lands on every website's homepage.
The meaningful signal isn't "which page gets the most bot traffic" — the homepage always wins that, it's the front door. It's "which specific content page does an automated program deliberately and repeatedly return to." That page is Bob Faith: 14 recurring headless hits to one article, versus ones-and-twos scattered elsewhere.
The one broader sweep, noted for completeness
A single IP (51.75.162.18) read a spread of six legal/strategy pages — letter-to-counsel, messaging-terms, pro-se, the-co-chair, the-invariant, the homepage — in one session. Notably it did not include Bob Faith, so it isn't an attempt to disguise Bob Faith interest either. It's either a thorough human reader on a VPN or a separate, broader intelligence sweep.
The automated disguise — and why it leaks
The automated requests claim to be an iPhone, but the browser's own "client-hint" headers reveal the truth:
A genuine iPhone sends no sec-ch-ua header and reports mobile: ?1. The contradiction is the giveaway: an automated headless browser on a server, disguised — imperfectly — as a phone.
What this establishes — and what it does not
- A Red Five Security / Ontic analyst session accessed — and, by the save-artifact, apparently saved — the Bob Faith page on July 22, 2026, and visited no other page.
- An automated monitor repeatedly and directly targets the Bob Faith page, in isolated single-page sessions, without disguising that focus, and remained active as of August 15, 2026.
- The documented corporate-intelligence and automated attention on this site is concentrated on the Bob Faith page.
- Who commissioned it. The referrer proves the tool (Red5/Ontic), not the paying client. Red Five works for many customers. That a page about Greystar's CEO is the target, while the author has active complaints against Greystar, is a reasonable inference — not proof from the log alone.
- That the analyst and the automated bot are the same operator. The automated hits carry no referrer, so they can't be tied to the July 22 analyst from the log alone. They're documented as parallel facts.
- The homepage traffic is largely unrelated crawler/scanner noise and should not be counted as targeting.
Legal framing — not legal advice, for counsel
- "Warrant" is likely the wrong concept — warrants constrain government actors; Red5/Ontic is a private firm. Reading a public website needs no warrant.
- The stronger frame may be retaliation — if this monitoring occurs because the site's author filed fair-housing/HUD complaints against Greystar, it may support a retaliation claim under the Fair Housing Act (42 U.S.C. § 3617), independent of whether the monitoring itself is unlawful. The pattern and timeline are the evidentiary value.
- Escalation would change the analysis — conduct beyond reading the public website (private data, physical surveillance, following, a course of harassing conduct under 18 Pa.C.S. §§ 2709, 2709.1) would be a different and more serious matter. Nothing in this record shows that; this record is limited to website monitoring.
Data integrity & methodology
See also: Bad Faith Bob · Bob Faith, Greystar CEO — Who He Is and the Documented Record.