Endpoint and AI Agent Security
See who is really
on the other end.Then cut them off.
Whisper holds the internet as one graph, so one query shows everything an address touches, and one command cuts it off. It runs beside your EDR and SIEM: they watch the machine, Whisper watches who it talks to.
Two products. One graph behind them.
Both run beside the EDR and SIEM you already have. Nothing gets replaced.
Whisper Graph XDR
Every machine and AI agent you enrol gets its own address on our network. Rules about who it may talk to apply as its traffic leaves, and one command cuts a host off from outside the box.
Sensors on Linux and Windows today; on macOS, connection telemetry. Runs beside your EDR.
Whisper Intelligence
Start from an IP, a domain or a network and get its owner, its network, its host and whatever else shares them, with the evidence attached. In the console, or inside Splunk, Sentinel, OpenCTI, MISP and Wazuh.
Where a registrant is privacy-redacted, the graph says so and pivots on what is published.
The engine, in your own tools
The same graph through the query API, the CLI and the MCP server, so your scripts and AI agents ask what an analyst would ask.
WhisperGraph, the engine both products run on.
What happens when a machine you enrol reaches out
A rule like "nothing hosted in a bulletproof neighbourhood" is checked against the live graph at the moment of the connection, not against a list you wrote last month.
The address is the identity
Each machine, container or AI agent gets its own IPv6 address on AS219419, Whisper's own network. Anyone can check it with dig and whois, with no account.
One address is one identity: a laptop, a server, a container or an agent, all the same.
Policy at DNS and egress
Rules written in owners, countries, hosting neighbourhoods, Tor exits, new registrations and RPKI apply as the name resolves and as the packet leaves.
The block lands before the connection exists.
Cut off from off the host
Revoke the identity and the machine loses its reach, whether or not its local agent still answers. Preview the blast radius first; every action reverses.
Root on the box does not get it back.
Every rule and every verdict is checked against the whole internet
Routing, DNS, hosting, ownership, certificates and the intelligence feeds are modelled as one graph. "Who owns this host" and "where does it really sit" are one query, and there is no list to maintain.
Measured
From one vendor name to a decision
A vendor turns up in a review with nothing but a name. This is what the graph returns.
The name
acme-vendor.com is all you have. Nothing yet says who runs it, or from where.
A stand-in for a vendor of your own.
The chain
It resolves to ALEXHOST SRL on AS200019, in Moldova, at the Trabia facility.
Read from the graph on 2026-09-07. Flagged there for bulletproof hosting.
The decision
Owner, network, country and facility arrive together, with the path that produced them.
Enough to open a ticket that anyone can check.
Same graph. Very different Tuesdays.
Pick a seat.
The alert arrives with an address and nothing else, and the one that matters looks like the other thirty-nine.
You open a WHOIS lookup, a certificate search, an ASN lookup and a feed check, then join the answers by hand.
One query returns the owner, the network, the certificate and the feeds together, with the path that produced them, in Splunk, Sentinel or the console.
OutcomeThe pivot you would run by hand across five tools returns as one traversal, with the evidence attached.
See the SOC solutionA vendor, a subsidiary or a new SaaS turns up in a review with nothing but a name.
Someone spends an afternoon in registries and still cannot say who runs it, or from where.
Owner, network, country and facility arrive together, with the path that produced them.
OutcomeYou answer in the meeting, with evidence an auditor accepts.
See the risk viewA client asks how many AI agents run inside their business, who started them and what they reach, and nobody can say.
You stitch per-client consoles and exports together, and the auditor gets a summary you wrote about yourselves instead of evidence.
One partner portal runs your book of clients under your own brand: onboard them, triage one queue, search an indicator across every estate and contain it.
OutcomeYou enrol a client fleet in an afternoon, answer the shadow-AI question with a number, and enforce a rule that stays true when the addresses change.
See the MSSP solutionYour agents leave the network with whatever identity the proxy gives them, and no off switch that works on one of them.
You cannot tell a stranger which requests were yours, and a compromised agent keeps its reach until you find the host.
One command gives an agent its own address on AS219419; one command takes it away. Anyone can verify the address with dig.
OutcomeAgents that know what they are talking to, and an off switch that works on one of them without touching the fleet.
Read the API docsWe run the network we are telling you about.
Whisper operates its own RIPE-allocated autonomous system, AS219419. Everything we claim about routing, you can check yourself.
Our own network
AS219419 is allocated by RIPE and signed with exact-length RPKI ROAs, and announces its prefixes into the same public tables the graph reads. Every routing claim on this page is checkable in the RIPE database.
An advisory board you can look up
Geoff Huston of APNIC, Jeff Osborn of ISC, former ICANN board chair Maarten Botterman, Merike Kaeo and Jonathan Cave.
Founded by the architect of K-root
Kaveh Ranjbar, our co-founder and CEO, was CIO of RIPE NCC. K-root is one of the internet's thirteen DNS root servers.