For security vendors
Embed threat intelligenceyour users can check.
WhisperGraph's query API puts threat intelligence and internet infrastructure answers inside your own product. Your users paste an address and see who runs it and what sits beside it, with the path that produced the answer.
Building threat intelligence data in-house is a project of its own.
Every address your users paste comes with an expected story: who owns it, what else they run, whether it is listed anywhere, and how current that answer is. Joining naming, routing, ownership, certificate, physical and threat data across the internet, and keeping it current, takes its own team, separate from the product you are trying to ship.
Threat intelligence for the product you build.
Threat intelligence platforms
Pivot from one indicator to the infrastructure behind it, inside the workflow your users already run.
SIEM platforms
Enrich an alert when it fires with the owner, the network, its RPKI status and the feeds behind the indicator.
EDR and endpoint security
Show who runs the remote address a process reached, which network announces it, what else sits on that address and which feeds list it.
Email security
Look past the headers: who hosts the sending domain, who registered it, what shares its address and which feeds list it.
Brand protection
Take a look-alike your users found and show who hosts it, who registered it, what else sits on its address and which feeds list it.
Exposure management
Show a domain's names, hosting, routes and RPKI status in one pass.
Known clean is not the same as no data.
Every verdict carries a coverage value beside its score: known clean, malicious-evidenced, ambiguous or no data. Gate automation on coverage. The score alone cannot tell known clean from no data, and ambiguous belongs with a person.
One graph behind every verdict your users see.
Every figure comes from the graph itself, stamped with the date it answered. Whisper runs its own network, AS219419, which you can check in the RIPE database.
Measured
Your first threat intelligence API call.
One Cypher question over HTTPS. Your key goes in the header and the indicator goes in parameters, kept out of the query string. The values shown are reserved examples.
curl -s -A "your-product/1.0" \
-X POST https://graph.whisper.security/api/query \
-H "Content-Type: application/json" \
-H "X-API-Key: $WHISPER_API_KEY" \
-d '{"query": "MATCH (ip:IPV4 {name: $ip})-[:ANNOUNCED_BY]->(p:ANNOUNCED_PREFIX)-[:ROUTES]->(a:ASN) RETURN ip.name AS ip, p.name AS route, p.rpkiStatus AS rpki, a.name AS asn, ip.verdictCoverage AS coverage LIMIT 1", "parameters": {"ip": "203.0.113.24"}}'{
"columns": ["ip", "route", "rpki", "asn", "coverage"],
"rows": [{"ip": "203.0.113.24", "route": "203.0.113.0/24", "rpki": "valid", "asn": "AS64511", "coverage": "no-data"}]
}Live now, behind one endpoint.
- Query API
Read-only Cypher over one endpoint.
- Live
- MCP server
Read-only, for any MCP client.
- Live
- API reference
Headers, parameter binding, the response envelope and every error, with code in five languages.
- Live
- SIEM and TIP connectors
Splunk, Sentinel, OpenCTI (STIX 2.1), MISP and Wazuh.
- Live
- On-prem and OEM
Talk to us about OEM and on-prem deployment.
Embed threat intelligence in four steps.
Try the question your users ask
Run it with a free key, against the same endpoint your product will call.
Book a call
Bring the questions your product needs answered.
Get a key scoped to your product
Separate from a normal account.
Ship
Your product calls the endpoint you tested against, and status.whisper.security reports its health.
