// Surveillance Evidence Record

The Watchers

A factual record, drawn from jlegal.pro's own visitor logs (July 11 – August 15, 2026), of who has been watching the site's Bob Faith page — and how closely.

What this is: a record derived from track.jlegal.pro's own traffic logs. It documents which network sources accessed which pages, when, and using what tool. It is not legal advice and does not, by itself, prove who commissioned the activity. It is offered as a dated, sourced data point.

The central question

Are the corporate-intelligence and automated visitors to this site focused on the page about Bob Faith, Greystar's CEO — and, critically, are they visiting other pages to disguise that focus? The logs answer both.

The human analyst — Ontic / Red Five Security, July 22, 2026

Undisguised and exclusive. All four requests from the analyst's session landed on the Bob Faith page and nothing else. Zero other pages were touched.
Time (UTC)IPPageReferrer
2026-07-22 13:57:3550.228.106.26/bad-faith-bob.html[Badhttps://red5.ontic.ai/
2026-07-22 13:57:3550.228.106.26/bad-faith-bob.html[Badhttps://red5.ontic.ai/
2026-07-22 13:57:4150.228.106.26/bad-faith-bob.htmlhttps://red5.ontic.ai/
2026-07-22 13:57:4150.228.106.26/bad-faith-bob.htmlhttps://red5.ontic.ai/

What is Ontic / Red5?

Ontic is enterprise security software — Fortune 500 and federal security teams use it to run OSINT/threat monitoring on people, track "persons of interest," and manage investigations, pulling from 10,000+ sources (social media, forums, dark web) plus internal HR/legal data.

red5.ontic.ai isn't Ontic's own traffic — Red5 (also called Red Five Security) is a managed-intelligence-services firm that partners with Ontic: they provide human analysts who do on-demand risk reports and investigations for corporate clients, running on top of the Ontic platform. red5.ontic.ai is Red5's client-facing tenant instance of that platform. This wasn't Ontic itself — it was an analyst, or someone with analyst access, inside Red5's investigation tool.

What that adds up to: someone using a paid corporate-intelligence-analyst service pulled up — and, by the save-artifact, apparently saved — the Bob Faith page into an active investigation record on July 22. What the log can't tell you is who commissioned that: Red5 works for multiple clients, and the referrer only proves the tool used, not who's paying for it. Given that the page is about Greystar's CEO, and Greystar is the party in this fair-housing matter, the inference is obvious — but the traffic log alone doesn't prove that specific attribution.

What would a platform like this actually show about the site's author?

Mostly his own material — because that's the model jlegal.pro runs on: public, first-person, evidentiary. An analyst wouldn't need to dig; the homepage already gives his full name, location, the VOC exposure account, the antisemitic-assault claim, the retaliation timeline, and named individuals — Bob Faith, Nicole Cordial, and others — all connected together in one place. There's no gap between "OSINT footprint" and "what's been published." A search on the bare name alone is noisy (it isn't unique), but any query paired with Goldtex, jlegal.pro, or 4philly resolves specifically and immediately, with no ambiguity.

What a platform like Ontic/Red5 is purpose-built to do with that isn't just biography — it's threat scoring. Their stated function is flagging language directed at named executives and assessing risk level. Pages that name people directly would plausibly get pulled into a "person of interest" record tied to whichever client's executive is named — regardless of whether the content is documentary and advocacy rather than any actual threat. That distinction, critic versus threat, is a judgment call analysts have to make, and it's a known failure mode of these tools: pointed, factual criticism of a company can get treated the same as a menace signal inside the same monitoring pipeline.

What it would not show: anything not already public — court filings, the incident report, the site itself. There's no hidden layer being uncovered here. It's a professional reading of a public record whose framing was already controlled by the person who published it.

The automated monitor — focus & isolation analysis

Across five weeks, an automated "headless" program — disguised as an iPhone but revealed as HeadlessChrome by its own headers — ran from Amazon-cloud servers. The question: is it hitting other pages to camouflage its interest in Bob Faith?

Answer: no. The focus is undisguised.
Total distinct headless-bot IPs observed87
IPs that touched the Bob Faith page12
… of those, hit Bob Faith IN ISOLATION (that page only)10
… hit Bob Faith plus the homepage2
IPs that only hit the homepage (crawler / scanner noise)73

Of the 12 automated sources that accessed the Bob Faith page, 10 hit that page and nothing else — single-page sessions, straight to the target, no browsing of surrounding pages. This is the opposite of camouflage. A visitor trying to hide a focus would pad the session with other pages to look like organic browsing. That pattern does not appear.

Why the homepage shows high numbers (and why it isn't the target)

The homepage received 84 headless hits — more than Bob Faith — but this is noise, not focus:

The meaningful signal isn't "which page gets the most bot traffic" — the homepage always wins that, it's the front door. It's "which specific content page does an automated program deliberately and repeatedly return to." That page is Bob Faith: 14 recurring headless hits to one article, versus ones-and-twos scattered elsewhere.

The one broader sweep, noted for completeness

A single IP (51.75.162.18) read a spread of six legal/strategy pages — letter-to-counsel, messaging-terms, pro-se, the-co-chair, the-invariant, the homepage — in one session. Notably it did not include Bob Faith, so it isn't an attempt to disguise Bob Faith interest either. It's either a thorough human reader on a VPN or a separate, broader intelligence sweep.

The automated disguise — and why it leaks

The automated requests claim to be an iPhone, but the browser's own "client-hint" headers reveal the truth:

user-agent: Mozilla/5.0 (iPhone; ...) Safari/604.1 <-- fake (claimed) sec-ch-ua: "HeadlessChrome";v="138", ... <-- REAL (leaked) sec-ch-ua-mobile: ?0 <-- "not mobile"

A genuine iPhone sends no sec-ch-ua header and reports mobile: ?1. The contradiction is the giveaway: an automated headless browser on a server, disguised — imperfectly — as a phone.

What this establishes — and what it does not

Establishes, from the logs:
Does not establish, honest limits:

Legal framing — not legal advice, for counsel

Data integrity & methodology

Generated from jlegal.pro tracker logs, August 15, 2026. This page records factual log data and reasonable inferences, with limits stated throughout. It is not legal advice.

See also: Bad Faith Bob · Bob Faith, Greystar CEO — Who He Is and the Documented Record.

↑ ↓