Endpoint and AI Agent Security
See who is really
on the other end.Then cut them off.
Whisper holds the internet as one graph, so one query shows everything an address touches, and one command cuts it off. It runs beside your EDR and SIEM: they watch the machine, Whisper watches who it talks to.
Two products. One graph behind them.
Both run beside the EDR and SIEM you already have. Nothing gets replaced.
Whisper Graph XDR
Every machine and AI agent you enrol gets its own address on our network. Rules about who it may talk to apply as its traffic leaves, and one command cuts a host off from outside the box.
Sensors on Linux and Windows today; on macOS, connection telemetry. Runs beside your EDR.
Whisper Intelligence
Start from an IP, a domain or a network and get its owner, its network, its host and whatever else shares them, with the evidence attached. In the console, or inside Splunk, Sentinel, OpenCTI, MISP and Wazuh.
Where a registrant is privacy-redacted, the graph says so and pivots on what is published.
The engine, in your own tools
The same graph through the query API, the CLI and the MCP server, so your scripts and AI agents ask what an analyst would ask.
WhisperGraph, the engine both products run on.
What happens when a machine you enrol reaches out
A rule like "nothing hosted in a bulletproof neighbourhood" is checked against the live graph at the moment of the connection, not against a list you wrote last month.
The address is the identity
Each machine, container or AI agent gets its own IPv6 address on AS219419, Whisper's own network. Anyone can check it with dig and whois, with no account.
One address is one identity: a laptop, a server, a container or an agent, all the same.
Policy at DNS and egress
Rules written in owners, countries, hosting neighbourhoods, Tor exits, new registrations and RPKI apply as the name resolves and as the packet leaves.
The block lands before the connection exists.
Cut off from off the host
Revoke the identity and the machine loses its reach, whether or not its local agent still answers. Preview the blast radius first; every action reverses.
Root on the box does not get it back.
Every rule and every verdict is checked against the whole internet
Routing, DNS, hosting, ownership, certificates and the intelligence feeds are modelled as one graph. "Who owns this host" and "where does it really sit" are one query, and there is no list to maintain.
Measured
From one vendor name to a decision
A vendor turns up in a review with nothing but a name. This is what the graph returns.
The name
acme-vendor.com is all you have. Nothing yet says who runs it, or from where.
A stand-in for a vendor of your own.
The chain
It resolves to ALEXHOST SRL on AS200019, in Moldova, at the Trabia facility.
Read from the graph on 2026-09-07. Flagged there for bulletproof hosting.
The decision
Owner, network, country and facility arrive together, with the path that produced them.
Enough to open a ticket that anyone can check.
Same graph. Very different Tuesdays.
Pick a seat.
The alert arrives with an address and nothing else, and the one that matters looks like the other thirty-nine.
You open a WHOIS lookup, a certificate search, an ASN lookup and a feed check, then join the answers by hand.
One query returns the owner, the network, the certificate and the feeds together, with the path that produced them, in Splunk, Sentinel or the console.
OutcomeThe pivot you would run by hand across five tools returns as one traversal, with the evidence attached.
See the SOC solutionA vendor, a subsidiary or a new SaaS turns up in a review with nothing but a name.
Someone spends an afternoon in registries and still cannot say who runs it, or from where.
Owner, network, country and facility arrive together, with the path that produced them.
OutcomeYou answer in the meeting, with evidence an auditor accepts.
See the risk viewA client asks how many AI agents run inside their business, who started them and what they reach, and nobody can say.
You stitch per-client consoles and exports together, and the auditor gets a summary you wrote about yourselves instead of evidence.
One partner portal runs your book of clients under your own brand: onboard them, triage one queue, search an indicator across every estate and contain it.
OutcomeYou enrol a client fleet in an afternoon, answer the shadow-AI question with a number, and enforce a rule that stays true when the addresses change.
See the MSSP solution
Your agents leave the network with whatever identity the proxy gives them, and no off switch that works on one of them.
You cannot tell a stranger which requests were yours, and a compromised agent keeps its reach until you find the host.
One command gives an agent its own address on AS219419; one command takes it away. Anyone can verify the address with dig.
OutcomeAgents that know what they are talking to, and an off switch that works on one of them without touching the fleet.
Read the API docsWe run the network we are telling you about.
Whisper operates its own RIPE-allocated autonomous system, AS219419. Everything we claim about routing, you can check yourself.
Our own network
AS219419 is allocated by RIPE and signed with exact-length RPKI ROAs, and announces its prefixes into the same public tables the graph reads. Every routing claim on this page is checkable in the RIPE database.
An advisory board you can look up
Geoff Huston of APNIC, Jeff Osborn of ISC, former ICANN board chair Maarten Botterman, Merike Kaeo and Jonathan Cave.
Founded by the architect of K-root
Kaveh Ranjbar, our co-founder and CEO, was CIO of RIPE NCC. K-root is one of the internet's thirteen DNS root servers.
What people ask us first
Short answers to the questions we hear most often.
What is Whisper Security?
Whisper Security gives every machine and AI agent you enrol a network identity you can cut off, and decides what they may reach against a graph of the whole internet: routing, DNS, hosting, ownership, certificates and intelligence feeds. Two products run on that graph. Whisper Graph XDR is the identity, the policy and the off-host cut-off. Whisper Intelligence tells you who is on the other end of any address.
What does Whisper Graph XDR do that an EDR does not?
An EDR watches what happens on a machine. Graph XDR controls where the machine can connect, from outside it. Each machine and AI agent gets its own routable address on Whisper's network, and policy applies to its traffic as it leaves. If an attacker takes the host and stops its local agent, you can still revoke that address, and the machine loses its reach. Graph XDR runs alongside your EDR. It does not replace it.
What is in the Whisper graph?
Every layer an internet address passes through, joined into one object. At the bottom are submarine cables, data centres and exchange points. Above them sit the networks and routes that carry traffic, the IP addresses and hostnames on those routes, and the certificates they present. Then come the companies and registrants that own it all, their mail setup, and the feeds that list them. You can start from any record and follow its links in either direction.
How is Whisper different from a threat intelligence feed?
A feed tells you whether one indicator has been reported. Whisper tells you what that indicator is connected to: the network that routes it, the company that owns it, the certificate it presents and the other domains the same owner runs. From one alert you can find the rest of a campaign. Whisper does not replace your feeds. The graph holds no file hashes and no leaked credentials.
How do AI agents use Whisper?
Through the Whisper MCP server at mcp.whisper.security. Any MCP client, such as Claude, Cursor or VS Code, connects with an API key or a sign-in. From there an agent can query the graph in Cypher, get a verdict on an indicator, find out who runs a host, and run prepared investigations that come back as a written report with the evidence behind each finding. Every tool the server offers is read-only.
How current is the data?
Most sources update continuously: BGP routing, DNS, certificate transparency logs and the intelligence feeds. A few, such as WHOIS and physical infrastructure, refresh on a slower schedule. The graph also keeps registration and routing history, so you can see who held a domain, or which network announced a prefix, at an earlier date.
Can I try Whisper without an account?
Yes, through the query API. Send a Cypher query to the graph with no key and you get real rows from the live graph. Running an example or a use case on this site takes a free account, and the MCP server always takes a key.