Products
One graph.Two products built on it.
WhisperGraph holds the internet's infrastructure as one graph. Whisper Intelligence answers who is behind any address, and Whisper Graph XDR decides what your machines and agents may reach and cuts them off from outside the host.
Graph XDR protects the fleet from the network in. Intelligence answers inside the tools your team already uses. One account opens both.
One graph of the internet, every layer joined.
WhisperGraph joins routing, DNS, hosting, ownership, email, certificates, threat intelligence and physical infrastructure. Graph XDR uses it to decide what a connection may reach. Intelligence uses it to answer what an address is.
Read
Which question do you need answered?
Graph XDR controls where your machines and agents can connect. Intelligence explains any address they, or an attacker, touch. Start with either.
Whisper Graph XDR
"What may this machine reach, and how do I cut it off?"
Five identities free, for goodAn identity for every machine, container, agent and device, which anyone can check with dig.
Every lookup and connection logged with the owner, network, country and risk on the other end.
Containment from the network that the host cannot veto, and a sensor for depth on the host.
Whisper Intelligence
"Who is behind this address, and what else do they run?"
Free key, for goodStart from one address, name or network and expand across every layer of the internet.
Verdicts that show their sources and weights, and say "no data" instead of guessing "clean".
In the console, over the API and MCP, from the CLI, inside Splunk, Sentinel, Wazuh, OpenCTI or MISP, or inside your own product.
Rules and logs that know who is on the other end.
An IP list only knows the address. Graph XDR checks each connection against the whole graph, so a log line names who is behind the destination and a rule can act on the owner, the network and the country behind it.
10:42:07 agent-7f3a → 203.0.113.24:443 allowed10:42:07 agent-7f3a → login-verify.exampleEvery connection, in context
Each destination with its owner, network, country and risk, and the organisations that own the networks your fleet reaches.
Who is looking at you
Lookups of your identities grouped by the operator behind them. That reconnaissance never touches the host.
Rules on what is behind it
Owners, countries, bulletproof hosting, Tor exits, sanctions, new registrations and RPKI, at resolution and egress.
Contain from outside
Revoke an identity and it stops at our edge, even when the host is fully owned.
Start with one node. Expand the internet.
Run a guided workflow on any indicator, or write your own query. Every answer arrives with the path that produced it.
One sign-in. Two consoles that share what they see.
From a connection to a dossier
Open any destination your fleet reached and get Intelligence's full answer on it: owner, network, listings and history.
The same graph
Graph XDR rules and Intelligence answers both read WhisperGraph, so what a rule acts on is what a dossier shows.
One account
The same sign-in opens both consoles. Start with one product and add the other when you need it.
Run Whisper for your clients, under your name.
The partner portal puts every client's fleet in one queue. It contains threats off-host and hands each client proof they can check without trusting you or us.
Shared exposure
See which infrastructure more than one of your clients reached, and block it for all of them at once.
Your brand, your margin
Reports carry your firm's name and colours, with your logo shipping soon. Your wholesale rate is quoted in the portal.
Your ticketing
Cases open in ConnectWise, Autotask, HaloPSA or Syncro, and events export as OCSF.
More from Whisper
Industry editions
Graph XDR for connected vehicles, energy, telecom, OT and five more industries.
Private mesh
Whalenet connects your servers and agents to each other over their public identities, with rules that can check the graph.
Free, no account
Whisper Guard checks every site you open, free in Chrome. Check any Whisper identity with dig, query the graph's keyless tier, or try Lookalikes and isitsc.am.
We run the network we tell you about.
Your enforcement point should belong to someone you can check.
- Our own network
AS219419, allocated by RIPE, with exact-length RPKI routes you can check without asking us.
- Who built it
Co-founder and CEO Kaveh Ranjbar was CIO of RIPE NCC and architect of K-root, one of the internet's thirteen DNS root servers. Advisers include Geoff Huston, Jeff Osborn, Maarten Botterman, Merike Kaeo and Jonathan Cave.
- Where it runs
Our cloud, hosted in the EU by default. Or on premise on one server, air gapped with signed graph delivery, or EU sovereign with no US cloud in the data path.
