What Gridinsoft observed on Celesti.life
A Gridinsoft threat analyst reviewed the site directly and documented the evidence behind this decision.
GMA-20260814143704-86d62645
- Reviewed
- by Gridinsoft Threat Analyst
- Analyst finding
- Safe
- Evidence basis
- First-party site analysis External vendor intelligence: Contradictory context โ not used for this decision
The independent first-party review found a coherent CelestiOS productivity service and did not identify phishing impersonation, unrelated credential collection, conditional redirection, automatic downloads, malware, or another directly malicious behavior in the reviewed public pages, forms, navigation, scripts, and published backend flow. The active Phishing classification is not supported by the current first-party evidence.
Analyst findings
Coherent CelestiOS productivity service
The product pages, policies, forms, public application resources, backend description, and company profile consistently described the same CelestiOS productivity service.
Own-brand authentication flow
The reviewed authentication flow used CelestiOS branding, the published CelestiOS backend, and Google's account service for Google OAuth; it did not imitate an unrelated organization or expose an unrelated credential recipient.
No malicious behavior identified in the reviewed public scope
The independent first-party review did not identify phishing impersonation, a conditional unrelated redirect, an automatic or suspicious download, credential forwarding to an unrelated host, a malware payload, or another directly malicious behavior in the reviewed public flow.
Current consistent infrastructure
The repeated site responses, application resources, public backend description, DNS, and TLS certificate were consistent with an active product service at the recorded time.
Review 6 documented observations View evidence
The root, privacy, terms, security, vision, sign-in, and sign-up routes consistently presented the CelestiOS AI productivity service and its own account and integration flows.
-
HTTP status
200 -
Final URL
https://celesti.life/ - Public artifact URL https://celesti.life/privacy
- Public artifact URL https://celesti.life/terms
- Public artifact URL https://celesti.life/security
- Page element The reviewed pages consistently described CelestiOS as an AI decision and productivity service using calendar, workspace, and wearable integrations.
Twelve repeated root requests across normal, command-line, Googlebot, and Bingbot user agents returned the same 200 response and same-site content without a redirect.
-
HTTP status
200 -
Final URL
https://celesti.life/ - Analyst observation All twelve responses had the same body digest; no conditional external destination, interstitial, or automatic download was observed.
The reviewed sign-in and sign-up forms were Celesti-branded and sent account operations to the published CelestiOS backend; the Google sign-in flow resolved to Google's account service with a callback to that backend.
- Public artifact URL https://celesti.life/signin
- Public artifact URL https://celesti.life/signup
- Public artifact URL https://celestios-backend-application.onrender.com/openapi.json
-
Redirect destination
https://accounts.google.com/ - Analyst observation The public code used the CelestiOS backend for email and password authentication and Google OAuth; no unrelated credential recipient was identified in the reviewed unauthenticated flow.
The reviewed public application code supported the displayed product, account, calendar, productivity, and wearable features without an automatic executable download or an unrelated credential-forwarding destination.
- Public artifact URL https://celesti.life/assets/index-DaUHerDC.js
- File SHA-256 64d625d8d2cf94720ad1f9cd68c96fcf7adcef99bd3ce51c48a651f325a5554c
- Analyst observation No specific malicious file, payload, URL, or hash was identified in the reviewed public pages, navigation, forms, scripts, or backend description.
The public CelestiOS company profile linked to celesti.life and described the same calendar, wearable, and AI decision-layer product presented on the reviewed site.
- Public artifact URL https://www.linkedin.com/company/celestios
- Analyst observation The public company description, website link, product purpose, and current product updates were coherent with the first-party pages and application resources.
The domain resolved consistently and presented a currently valid certificate covering celesti.life and its subdomains.
- DNS fact celesti.life resolved to 35.157.26.135 and 63.176.8.218 and used the dns1.p08.nsone.net, dns2.p08.nsone.net, dns3.p08.nsone.net, and dns4.p08.nsone.net name servers.
- Certificate fact A Let's Encrypt certificate covered celesti.life and *.celesti.life from 2026-08-11 through 2026-11-09.
Scope and limitations
- The review covered public unauthenticated pages, forms, resources, and published backend behavior; it did not submit credentials, complete a third-party OAuth grant, or inspect private user data.
- The service also offers its own email and password account flow, so the earlier description of Google OAuth as the only authentication method is no longer exact; this does not by itself indicate phishing.
- The result applies to the public content and behavior reviewed at the recorded time and does not predict future changes.
- Separate external security-vendor warnings remained visible after the independent review and are recorded as contradictory context rather than evidence controlling this verdict.
Help protect others by sharing this page on social media! The more people who know about celesti.life, the fewer chances they have to deceive someone else. Help others evaluate celesti.life by sharing this page on social media!