Endpoint and AI Agent Security
See who is really
on the other end.Then cut them off.
Whisper holds the internet as one graph, so one query shows everything an address touches, and one command cuts it off. Most teams start by investigating, then build, then move to control. Nothing forces the order and nothing gets replaced.
Measured
Three ways in. One graph behind them.
Drops into the stack you already run, with nothing to rip out.
Investigate
See who is behind any IP, domain or network, and everything else they run, in one query.
Whisper Intelligence, in the console and the SIEM you already run.
Build
Put the same graph inside your own tools and AI agents through the query API, the CLI and the MCP server.
The engine both products run on.
Control
Turn the answer into a rule enforced at DNS and egress, and cut a host off from outside the box.
Whisper Graph XDR, for endpoints and AI agents.
What happens when you ask about an address
DNS, BGP, WHOIS, certificates, hosting and intelligence feeds are joined before you ask, so one lookup crosses all of them.
Ask
Type a hostname, IP, ASN or CIDR block into the console.
Or send it from your own code, through the query API or the MCP server.
Resolve
One traversal returns the owner, the network, the building it sits in and whatever shares them.
Five layers in one statement, with no joins to write.
Act
Send the verdict to your SIEM, or turn it into a rule that blocks the host at DNS and egress.
An analyst and an agent read the same answer.
From one vendor name to a decision
A vendor turns up in a review with nothing but a name. This is what the graph returns.
The name
acme-vendor.com is all you have. Nothing yet says who runs it, or from where.
A stand-in for a vendor of your own.
The chain
It resolves to ALEXHOST SRL on AS200019, in Moldova, at the Trabia facility.
Flagged by the graph for bulletproof hosting.
The decision
Owner, network, country and facility arrive together, with the path that produced them.
Enough to open a ticket that anyone can check.
Same graph. Very different Tuesdays.
Pick a seat.
OutcomeYou enrol a client fleet in an afternoon, answer the shadow-AI question with a number, and enforce a rule that stays true when the addresses change.
See the MSSP solutionOutcomeYou answer in the meeting, with evidence an auditor accepts.
See the risk view
OutcomeThree addresses classified with a full evidence trail in eight seconds, against forty-five minutes by hand.
See the integrations
OutcomeAgents that know what they are talking to, and an off switch that works on one of them without touching the fleet.
Read the API docsWe run the network we are telling you about.
Whisper operates its own RIPE-allocated autonomous system, AS219419. Everything we claim about routing, you can check yourself.
Our own network
AS219419 is RPKI signed and MANRS compliant, and announces its prefixes into the same public tables the graph reads.
An advisory board you can look up
Geoff Huston of APNIC, Jeff Osborn of ISC, former ICANN board chair Maarten Botterman, Merike Kaeo and Jonathan Cave.
Founded by the architect of K-root
Kaveh Ranjbar, our co-founder and CEO, was CIO of RIPE NCC. K-root is one of the internet's thirteen DNS root servers.
What people ask us first
Short answers to the questions we hear most often.
What is Whisper Security?
Whisper Security maps the internet as one connected graph and uses it to decide what your machines may reach. The graph joins routing, DNS, hosting, ownership, certificates and intelligence feeds, so a single domain, IP address or network leads to everything linked to it. Two products run on it. Whisper Intelligence tells you who is on the other end of an address. Whisper Graph XDR gives each machine and AI agent a network identity you can cut off.
What is in the Whisper graph?
Every layer an internet address passes through, joined into one object. At the bottom are submarine cables, data centres and exchange points. Above them sit the networks and routes that carry traffic, the IP addresses and hostnames on those routes, and the certificates they present. Then come the companies and registrants that own it all, their mail setup, and the feeds that list them. You can start from any record and follow its links in either direction.
How is Whisper different from a threat intelligence feed?
A feed tells you whether one indicator has been reported. Whisper tells you what that indicator is connected to: the network that routes it, the company that owns it, the certificate it presents and the other domains the same owner runs. From one alert you can find the rest of a campaign. Whisper does not replace your feeds. The graph holds no file hashes, no URLs and no leaked credentials.
Can I try Whisper without an account?
Yes, through the query API. Send a Cypher query to the graph with no key and you get real rows from the live graph. Running an example on this site takes a free account, and the MCP server always takes a key. Every use case here also shows a recorded run with its evidence, so you can see what an investigation returns before you sign up.
What does Whisper Graph XDR do that an EDR does not?
An EDR watches what happens on a machine. Graph XDR controls where the machine can connect, from outside it. Each machine and AI agent gets its own routable address on Whisper's network, and policy applies to its traffic as it leaves. If an attacker takes the host and stops its local agent, you can still revoke that address, and the machine loses its reach. Graph XDR runs alongside your EDR. It does not replace it.
How do AI agents use Whisper?
Through the Whisper MCP server at mcp.whisper.security. Any MCP client, such as Claude, Cursor or VS Code, connects with the same API key the REST API uses. From there an agent can query the graph in Cypher, get a verdict on an indicator, find out who runs a host, and run prepared investigations that come back as a written report with the evidence behind each finding. Every tool the server offers is read-only.
How current is the data?
Whisper takes in its sources continuously: BGP routing, DNS observation, WHOIS and RDAP records, certificate transparency logs and the intelligence feeds. The graph also keeps history. Resolutions, route announcements and certificates carry the dates they were valid, so you can ask what a domain resolved to on a given day, or which network announced a prefix six months ago.