See who is really
on the other end.Then cut them off.

Whisper holds the internet as one graph, so one query shows everything an address touches, and one command cuts it off. It runs beside your EDR and SIEM: they watch the machine, Whisper watches who it talks to.

scroll
DNSns1.greengeeks.net
RoutingAS14061 · DigitalOcean
WHOISwithheldforprivacy.com
Threatphishing · 4 feeds
Policyblocked at DNS and egress
One query · read 2026-09-20

Two products. One graph behind them.

Both run beside the EDR and SIEM you already have. Nothing gets replaced.

  1. Whisper Graph XDR

    Every machine and AI agent you enrol gets its own address on our network. Rules about who it may talk to apply as its traffic leaves, and one command cuts a host off from outside the box.

    Sensors on Linux and Windows today; on macOS, connection telemetry. Runs beside your EDR.

    See Graph XDR

  2. Whisper Intelligence

    Start from an IP, a domain or a network and get its owner, its network, its host and whatever else shares them, with the evidence attached. In the console, or inside Splunk, Sentinel, OpenCTI, MISP and Wazuh.

    Where a registrant is privacy-redacted, the graph says so and pivots on what is published.

    See Whisper Intelligence

  3. The engine, in your own tools

    The same graph through the query API, the CLI and the MCP server, so your scripts and AI agents ask what an analyst would ask.

    WhisperGraph, the engine both products run on.

    Read the docs

Compare the two products

What happens when a machine you enrol reaches out

A rule like "nothing hosted in a bulletproof neighbourhood" is checked against the live graph at the moment of the connection, not against a list you wrote last month.

  1. The address is the identity

    Each machine, container or AI agent gets its own IPv6 address on AS219419, Whisper's own network. Anyone can check it with dig and whois, with no account.

    One address is one identity: a laptop, a server, a container or an agent, all the same.

  2. Policy at DNS and egress

    Rules written in owners, countries, hosting neighbourhoods, Tor exits, new registrations and RPKI apply as the name resolves and as the packet leaves.

    The block lands before the connection exists.

  3. Cut off from off the host

    Revoke the identity and the machine loses its reach, whether or not its local agent still answers. Preview the blast radius first; every action reverses.

    Root on the box does not get it back.

Read the endpoint docs

Every rule and every verdict is checked against the whole internet

Routing, DNS, hosting, ownership, certificates and the intelligence feeds are modelled as one graph. "Who owns this host" and "where does it really sit" are one query, and there is no list to maintain.

47.3B
objects in one graph7.5B nodes plus 39.8B edges
7.5B
nodes: addresses, names, networks, owners, certificates3.8B stored, 3.7B computed at query time
39.8B
edges joining them31.7B stored, 8.1B computed at query time
134
intelligence feeds, joined in one graph112 threat feeds, 22 reputation, anonymiser and popularity lists

Measured

From one vendor name to a decision

A vendor turns up in a review with nothing but a name. This is what the graph returns.

  1. The name

    acme-vendor.com is all you have. Nothing yet says who runs it, or from where.

    A stand-in for a vendor of your own.

  2. The chain

    It resolves to ALEXHOST SRL on AS200019, in Moldova, at the Trabia facility.

    Read from the graph on 2026-09-07. Flagged there for bulletproof hosting.

  3. The decision

    Owner, network, country and facility arrive together, with the path that produced them.

    Enough to open a ticket that anyone can check.

See more worked runs

Same graph. Very different Tuesdays.

Pick a seat.

Security Analysts & Researchers
SOC / Threat Intel

The alert arrives with an address and nothing else, and the one that matters looks like the other thirty-nine.

You open a WHOIS lookup, a certificate search, an ASN lookup and a feed check, then join the answers by hand.

One query returns the owner, the network, the certificate and the feeds together, with the path that produced them, in Splunk, Sentinel or the console.

OutcomeThe pivot you would run by hand across five tools returns as one traversal, with the evidence attached.

See the SOC solution

We run the network we are telling you about.

Whisper operates its own RIPE-allocated autonomous system, AS219419. Everything we claim about routing, you can check yourself.

AS219419 · verify on RIPE

  • Our own network

    AS219419 is allocated by RIPE and signed with exact-length RPKI ROAs, and announces its prefixes into the same public tables the graph reads. Every routing claim on this page is checkable in the RIPE database.

  • An advisory board you can look up

    Geoff Huston of APNIC, Jeff Osborn of ISC, former ICANN board chair Maarten Botterman, Merike Kaeo and Jonathan Cave.

    Meet the board

  • Founded by the architect of K-root

    Kaveh Ranjbar, our co-founder and CEO, was CIO of RIPE NCC. K-root is one of the internet's thirteen DNS root servers.

    Read the team's background

What people ask us first

Short answers to the questions we hear most often.

Start with five machines, free.

Five identities and one seat are free for good. After that, Graph XDR is from €3.99 per endpoint per month, billed yearly. Whisper Intelligence starts free too.