# Check us yourself.

> Whisper runs its own autonomous system, AS219419, with RPKI-signed announcements you can check at stat.ripe.net without asking us. Our CEO was CIO of RIPE NCC and architected K-root.

*Source: https://www.whisper.security/trust*
*Last updated: 2026-09-25*

---

- [Book a demo](https://meetings-eu1.hubspot.com/rsaggar)
- [Read the docs](https://www.whisper.security/docs)

## Who built it.

Each name links to a public profile, so every credential here can be checked against a record we do not control.

- **[Kaveh Ranjbar](https://linkedin.com/in/kakooch/), Co-founder and CEO**: Former CIO of RIPE NCC and the architect of K-root, the DNS root server RIPE NCC operates. Twenty-five years in internet infrastructure.
- **[Soroush Rafiee Rad](https://linkedin.com/in/soroush-rafiee-rad/), Co-founder and CPSO**: Mathematician with doctorates in mathematical logic and in philosophy of science. Architect of Whisper's knowledge graph and the models that run on it.

## Named, not described.

- **[Maarten Botterman](https://linkedin.com/in/botterman/), Former Chair of the ICANN Board**: Nine years on the ICANN Board, three of them as its Chair, and more than 25 years in internet governance.
- **[Geoff Huston](https://linkedin.com/in/geoff-huston-89182842/), Chief Scientist, APNIC**: Internet pioneer and a leading authority on BGP routing, internet measurement and protocol design.
- **[Jeff Osborn](https://linkedin.com/in/jeff-osborn-880651/), President, Internet Systems Consortium**: Leads ISC, which maintains BIND and DHCP. Earlier at UUNET and MakerBot.
- **[Merike Kaeo](https://linkedin.com/in/merike-kaeo-52910a/), Founder, Double Shot Security**: More than 20 years in cybersecurity and a former Cisco security leader. Helped coordinate international cooperation during Estonia's 2007 cyberattack response.
- **[Jonathan Cave](https://linkedin.com/in/jonathancave/), Economist, former Turing Fellow**: More than 30 years at the RAND Corporation, working on technology policy and digital economics.

## Our network, checked from outside.

Whisper announces its own address space from AS219419. RIPE NCC's public [RIPEstat](https://stat.ripe.net/AS219419) tool shows who holds it, which prefixes it originates and whether each announcement is covered by a valid RPKI signature. You need no account, and you do not need us.

- **Who holds it**: RIPEstat lists the holder of AS219419 as viaGraph B.V.
- **What it announces**: Every prefix AS219419 originates, with its routing history.
- **Whether it is signed**: The RPKI status of each announcement. Ours read valid.

## Who is responsible for it.

| Fact | Record |
| --- | --- |
| [Controlling entity](https://www.whisper.security/terms-conditions) | viaGraph B.V., Keizersgracht 520H, Amsterdam, the Netherlands (Whisper Security is the trading name of viaGraph B.V., the party to our terms.) |
| [Network](https://stat.ripe.net/AS219419) | AS219419, held by viaGraph B.V. |

*Recorded 2026-09-25*

## What you can test from outside.

We state our posture as things you can test, not as a badge. Each point here can be checked from any machine on the internet.

- **Signed routing**: AS219419's announcements are covered by valid RPKI signatures.
- **Signed DNS**: whisper.security and whisper.online are DNSSEC-signed, with DS records in their parent zones.
- **HTTPS only**: This site sends HSTS for two years, covering subdomains, with the preload directive.
- **A signed security contact**: Our security.txt is PGP-signed and carries an expiry date, as RFC 9116 sets out.

## Uptime, in public.

The [status page](https://status.whisper.security) shows the current state of the graph, this website and the MCP server, and their incident history.

## Where to write.

The security address is the one our signed [security.txt](https://www.whisper.security/.well-known/security.txt) publishes.

- **security@whisper.security**: Vulnerability reports and security questions.
- **privacy@whisper.security**: Requests about your personal data, as our Privacy Policy sets out.

## Found something? Tell us.

Send reports to security@whisper.security, and encrypt anything sensitive with our [OpenPGP key](https://whisper.online/.well-known/openpgp-key.txt). Our [disclosure policy](https://whisper.online/.well-known/disclosure-policy.txt) sets out what is in scope, what is not, and the safe harbour we give good-faith research.

## Checked us? Now talk to us.

Book a demo with the team, or read how the graph works first.

- [Book a demo](https://meetings-eu1.hubspot.com/rsaggar)
- [Read the docs](https://www.whisper.security/docs)
