Embed threat intelligenceyour users can check.

WhisperGraph's query API puts threat intelligence and internet infrastructure answers inside your own product. Your users paste an address and see who runs it and what sits beside it, with the path that produced the answer.

YOUR PRODUCTstops at the addressWHISPERGRAPHfollows it layer by layerHOSTNAMEHOSTNAMEIPV4IPV4PREFIXPREFIXASNASNORGANIZATIONORGANIZATIONCOUNTRYCOUNTRYFEED_SOURCEFEED_SOURCEstops here

Building threat intelligence data in-house is a project of its own.

Every address your users paste comes with an expected story: who owns it, what else they run, whether it is listed anywhere, and how current that answer is. Joining naming, routing, ownership, certificate, physical and threat data across the internet, and keeping it current, takes its own team, separate from the product you are trying to ship.

Threat intelligence for the product you build.

  • Threat intelligence platforms

    Pivot from one indicator to the infrastructure behind it, inside the workflow your users already run.

  • SIEM platforms

    Enrich an alert when it fires with the owner, the network, its RPKI status and the feeds behind the indicator.

  • EDR and endpoint security

    Show who runs the remote address a process reached, which network announces it, what else sits on that address and which feeds list it.

  • Email security

    Look past the headers: who hosts the sending domain, who registered it, what shares its address and which feeds list it.

  • Brand protection

    Take a look-alike your users found and show who hosts it, who registered it, what else sits on its address and which feeds list it.

  • Exposure management

    Show a domain's names, hosting, routes and RPKI status in one pass.

Known clean is not the same as no data.

Every verdict carries a coverage value beside its score: known clean, malicious-evidenced, ambiguous or no data. Gate automation on coverage. The score alone cannot tell known clean from no data, and ambiguous belongs with a person.

a host checked, nothing founda host registered yesterdaya host on two threat listsA YES/NO FEEDWHISPERcleancleanbadknown cleanno datalisted · with sourcesthe feed calls it clean; it is only new

One graph behind every verdict your users see.

Every figure comes from the graph itself, stamped with the date it answered. Whisper runs its own network, AS219419, which you can check in the RIPE database.

Run a query, no key

7.5B
Nodeshostnames, addresses, networks, owners, facilities and feed listings
39.8B
Edgesthe relationships that join every layer to the next
134
intelligence feeds112 threat feeds, 22 VPN, proxy, Tor, ad-tracking, reputation and popularity lists
14.2M
Threat listingsfeed listings joined to the names and addresses they point at

Measured

Your first threat intelligence API call.

One Cypher question over HTTPS. Your key goes in the header and the indicator goes in parameters, kept out of the query string. The values shown are reserved examples.

bash
curl -s -A "your-product/1.0" \
  -X POST https://graph.whisper.security/api/query \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $WHISPER_API_KEY" \
  -d '{"query": "MATCH (ip:IPV4 {name: $ip})-[:ANNOUNCED_BY]->(p:ANNOUNCED_PREFIX)-[:ROUTES]->(a:ASN) RETURN ip.name AS ip, p.name AS route, p.rpkiStatus AS rpki, a.name AS asn, ip.verdictCoverage AS coverage LIMIT 1", "parameters": {"ip": "203.0.113.24"}}'

Live now, behind one endpoint.

Query API

Read-only Cypher over one endpoint.

Live
MCP server

Read-only, for any MCP client.

Live
API reference

Headers, parameter binding, the response envelope and every error, with code in five languages.

Live
SIEM and TIP connectors

Splunk, Sentinel, OpenCTI (STIX 2.1), MISP and Wazuh.

Live
On-prem and OEM

Talk to us about OEM and on-prem deployment.

Talk to us

Embed threat intelligence in four steps.

  1. Try the question your users ask

    Run it with a free key, against the same endpoint your product will call.

  2. Book a call

    Bring the questions your product needs answered.

  3. Get a key scoped to your product

    Separate from a normal account.

  4. Ship

    Your product calls the endpoint you tested against, and status.whisper.security reports its health.

What security vendors ask first.

Bring the question your users ask most.

Try it against the same endpoint your product will call, or talk it through with us first.