Free, and most of it needsno account.

Whisper gives away a browser extension, a citable page for every entity on the internet, a scam checker, a CLI, SDKs and an MCP server.

Guard, isitsc.am and Canon need nothing at all. Querying the graph takes a free key.

That domain looks right. Guard checks whether it is.

Guard puts a mark in your toolbar that answers one question on every page: is this site really who it says it is? It checks the name against 800+ imitated brands on your device, and against the Whisper graph. Only the hostname ever leaves your browser.

Only the hostname is checked. Never the page, the path, what you type or your history.

  • How the verdict is reached

    Guard checks the site's name on your device first, then confirms with a graph lookup that sends only the hostname.

  • Free, no account needed

    Install it and Guard works right away. Sign in free to add the fleet view across every device you manage.

  • For teams and MSSPs

    Roll Guard out to a fleet and read every verdict in one console.

examp1e-login.comLOOK-ALIKEembeds the name example.com, caught on this deviceNAMEexamp1e-login.comregistered 9 days agoADDRESS192.0.2.66NETWORKAS645003 flagged neighbourssent to the graph: the hostname, nothing else

Needs no account.

  • isitsc.am

    Paste a suspicious email and get a plain-English verdict.

  • Canon

    Every host, network and provider on the internet, each with its own citable page.

  • The query catalog

    Browse the investigation flows, filed by role and by job.

Install and go.

  • The CLI

    One signed binary: Cypher, named recipes and a local MCP server.

  • Node SDK

    npm i whisper-id: a routable Whisper identity for any Node agent.

  • Python SDK

    pip install whisper-id: the same identity for any Python agent.

  • Edge SDK

    whisper-edge: dependency-free, for serverless and edge runtimes.

  • Homebrew and Scoop

    brew install whisper-sec/tap/whisper, or the Scoop bucket on Windows.

  • GitHub Action

    setup-whisper installs the CLI in a workflow and can connect an identity.

Inside your stack.

  • Kubernetes operator

    One namespace label gives a pod its own Whisper identity, via a Helm chart.

  • n8n community node

    Verify and resolve agent identities inside an n8n workflow, with no code.

  • Dify plugin

    Agent-identity verification and RDAP lookups for Dify agents and workflows.

  • OpenCTI connector

    Enrich OpenCTI observables from the Whisper graph.

  • MISP module

    An expansion and hover module, shipped inside misp-modules.

  • Wazuh connector

    Installed from the GitHub releases. It is not in the Wazuh catalogue yet.

Inside your agent.

  • The hosted MCP server

    Seven read-only tools over the whole graph, at mcp.whisper.security.

  • Agent Skills

    A SKILL.md file that teaches an agent runtime to use the graph well.

  • Six framework adapters

    Claude Code, Gemini CLI, Antigravity, OpenAI Codex, GitHub Copilot CLI and Pi.

  • Programmatic sign-up

    Two HTTP calls to a working key, built for agents: no browser and no human in the loop.

Everything for AI agents

Datasets.

  • visual-confusables

    Look-alike codepoint pairs, rendered through the fonts browsers actually paint. CC BY 4.0.

Querying the graph takes a free key.

The console issues one when you sign up, and the Community plan stays free. See what the paid plans add on Pricing.

Start with the tools. Add a key to query.

Community is free forever.