The internet as one graph.
From one bad domainto what feeds miss.

WhisperGraph joins naming, routing, ownership, hosting and threat data into one graph. Built for threat intel, SOCs, security products and AI agents to ask who runs any IP or domain, with evidence.

scroll
DNSNAMESERVERwho answers for it
RoutingASN · PREFIXwho routes it, RPKI
OwnerORGANIZATIONwho registered it
PhysicalFACILITYwhere its network is
ThreatFEED_SOURCEwhich feeds list it
One query

Pick a question. Watch it cross the graph.

Every question below is one query. Select one to see the layers it crosses, in order, and what comes back.

What comes backthe network that routes it, whether RPKI accepts the route, and the data centres and exchanges that network is in

PathHOSTNAME → IPV4 → PREFIX → ASN → FACILITY

What goes in, and how it stays current.

Every layer below holds its own kind of data, and the table names what stays current and how. Live feeds keep the fastest-moving layers current: threat intelligence, newly observed DNS resolutions, the global routing table and route-origin records reach the graph through the day, so an answer reflects what those sources most recently published.

  • Livenew data arrives continuously
  • Regularrefreshed on a schedule
  • Snapshottaken from periodic snapshots
  • Referenceslow-changing records
  • Naming & DNSLive
    hostnames, DNS records, nameservers, DNSSEC
  • Addressing & geographySnapshot
    IPv4 and IPv6 addresses, address blocks, city, country, cloud regions
  • Network & routingLive
    networks, announced routes, BGP paths and peering, RPKI, origin conflicts
  • Ownership & registrationRegular
    registrants, registrars, registries, RDAP records
  • Email securityRegular
    MX, SPF, DMARC, DKIM
  • Certificates & TLSRegular
    certificate transparency names, TLS fingerprints
  • Threat intelligenceLive
    feed listings, risk signals, Tor relays, VPN and proxy exits
  • Threat actors & ATT&CKReference
    named actors, ATT&CK techniques
  • Physical infrastructureReference
    data centres, internet exchanges, subsea cables, landing stations, CDN points of presence
  • Company & technologySnapshot
    companies, subsidiaries, peers and the technology they run
Company and technology: for accounts with company-data access.

Where the graph has never seen an indicator, the answer says no data. It never reads that as clean.

Two ways to ask the same question.

Query the graph directly in Cypher, or connect an agent over the WhisperGraph MCP server and ask in plain English. Either way, the answer carries its evidence.

In Cypher, over the query API

One HTTPS endpoint, from any language
Cypher
MATCH (h:HOSTNAME {name: $domain})
-[:RESOLVES_TO]->(ip:IPV4)
WITH h, ip LIMIT 1
CALL { WITH ip
MATCH (ip)-[:ANNOUNCED_BY]->(p)
-[:ROUTES]->(a:ASN)
RETURN p, a LIMIT 1 }
CALL { WITH a MATCH (a)-[:HAS_NAME]->(n)
RETURN n LIMIT 1 }
CALL { WITH h
MATCH (h)-[:LISTED_IN]->(f:FEED_SOURCE)
WHERE f.isThreat
RETURN count(f) AS feeds }
RETURN ip.name AS address, p.name AS route,
p.rpkiStatus AS rpki, n.name AS network,
feeds
Bind $domain to the domain you start from

In plain English, through your agent

Needs the WhisperGraph MCP server
You

Who runs login-verify.example, and does any feed list it?

WhisperGraph MCP · queryread-only
WhisperGraph MCP · explain_indicatorread-only
Agent

In this example, Example Hosting Ltd runs the network behind it, and two feeds list it for phishing.

From the graph
IPV4203.0.113.24
PREFIX203.0.113.0/24 · RPKI valid
ASNAS64511 · Example Hosting Ltd
FEED_SOURCE2 listings · phishing

Set it up once

  1. Take a free key
  2. Add mcp.whisper.security to your client
  3. Ask in plain English
Claude, Copilot or any MCP client
An example exchange. The names and addresses are reserved for documentation and can never resolve.

The graph counts itself, and dates the count.

Every figure below comes from the graph itself, stamped with the date it answered. Anchored queries return in single-digit milliseconds, server-side.

Run a query, no key

7.5B
Nodeshostnames, addresses, networks, owners, facilities and feed listings
39.8B
Edgesthe relationships that join every layer to the next
134
intelligence feeds112 threat feeds, 22 VPN, proxy, Tor, ad-tracking, reputation and popularity lists
14.2M
Threat listingsfeed listings joined to the names and addresses they point at

Measured

Two products run on it. Yours can too.

Whisper Intelligence and Whisper Graph XDR query the same graph your product can, through the query API or the MCP server.

  1. Whisper Intelligence

    IOC enrichment in the console or inside Splunk, Sentinel, OpenCTI, MISP and Wazuh: ask the graph about any address and get the evidence attached.

    When WHOIS publishes no registrant, follow what is published: the address, the network, the nameservers and the names beside it.

    See Whisper Intelligence

  2. Whisper Graph XDR

    Machines and AI agents you enrol get an identity on Whisper's own network. Graph XDR checks what each one may reach against the graph, and you can cut a host off from outside it.

    See Graph XDR

  3. Inside your product

    The same graph through one query endpoint and the MCP server, for security products and agents.

    One read-only endpoint behind your own product.

    Embed it in your product

How the products fit together

Start from the desk you sit at.

Each one has its own page, with the workflows behind it.

  • Threat intel and SOC

    Turn one indicator into the infrastructure behind it, inside your SIEM or the console.

  • Security vendors

    Put infrastructure answers inside your own product.

  • AI agent builders

    Let an agent look up any host's infrastructure over the read-only MCP server, with evidence attached.

  • Security leaders

    See where your vendors actually run, with evidence an auditor can check.

  • MSSPs and MDRs

    Run Graph XDR and Intelligence for your clients.

We run the network we are telling you about.

Whisper operates its own RIPE-allocated autonomous system, AS219419, checkable in the RIPE database.

AS219419 · verify on RIPE

  • Our own network

    AS219419 is allocated by RIPE and signed with exact-length RPKI ROAs. It announces its prefixes into the same public tables the graph reads, and every claim about it here is checkable in the RIPE database.

  • An advisory board you can look up

    Geoff Huston, Chief Scientist at APNIC; Jeff Osborn, President of ISC; Maarten Botterman, former ICANN board chair; Merike Kaeo, founder of Double Shot Security; and Jonathan Cave, economist and former Turing Fellow.

    Meet the board

  • Founded by the architect of K-root

    Kaveh Ranjbar, co-founder and CEO, former CIO of RIPE NCC and the architect of K-root, one of the thirteen root server identities at the top of the DNS.

    Read the team's background

Questions about WhisperGraph.

Short answers about WhisperGraph and how to try it.

Bring a domain or IP you are looking at today.

Query the graph on the keyless tier with no account, or take a free key to run the examples and connect the MCP server.