Use cases
Infrastructure, supply chain & compliance
Nobody joins routing to physical presence, so concentration risk and ICT dependency stay invisible until they fail — which is exactly what NIS2, DORA, and ISO 27001 ask you to evidence. WhisperGraph maps dependency down to the datacenters, internet exchanges, and submarine cables a vendor actually rides on.
The concentration that no questionnaire surfaces becomes a query you can run and a map you can hand to an auditor.
Why this is hard without a graph
Third-party risk stops at the contract. The layers that determine real resilience — which networks a vendor announces, which facilities those routes pass through, which cable systems carry them — are in datasets that were never meant to join, and certainly not to a sanctions list or a jurisdiction map.
What changes with WhisperGraph
Network, physical, and ownership layers are one connected graph, so a single traversal walks from a vendor domain to the datacenters and cables it depends on, and crosses ownership against sanctions and jurisdiction in the same pass. The workflows below turn that into the concentration and due-diligence evidence the frameworks require.
5 workflows in Infrastructure & supply chain
Each one runs live on the graph — no signup.
Anycast DNS-Root Sovereignty
Could a country still resolve names if it were isolated? This assesses a nation's DNS-root resilience — how many of the core root servers have a copy inside its borders, and who operates them — the sovereignty read for national-resilience and policy analysis.
Attack-Surface Mapper
See your organisation the way an attacker does. Give it a domain and it maps the full external footprint — every subdomain, the name and mail servers, who registered it, the third-party services it leans on, and the wider web of sites it connects to — and scores the exposure. The starting point for shrinking what's reachable from the outside.
Digital Infrastructure Mapping
Map the digital estate an indicator belongs to. Starting from any domain, IP, ASN or prefix, this works out the true owner — even behind privacy WHOIS and CDNs — via the atlas operator, the canonical registrant organization and the registrant email, then enumerates everything that owner owns: the subdomain namespace, the rest of its domain estate, the networks and prefixes that host it, and the facilities it physically sits at. Assets run by someone else (CDN, managed DNS, cloud) are marked as the vendor border, not owned.
Network & Routing Report
The full picture of how a network is put together and reaches the internet. Give it a network or address block and get a health card: what it announces, who it peers and buys transit from, whether it leans dangerously on a single upstream, and how well its routes are protected. The one-look report for network engineers assessing reach and resilience.
Supply-Chain Dependency Mapping
Maps every external provider a domain depends on — nameservers, mail exchangers, third-party email senders (SPF), CDN and hosting networks, registrar and DKIM vendors — by reading each layer of the graph and keeping only providers whose registrable apex differs from the target’s own. Each dependency is grouped by function and the flow flags single-vendor concentration: one DNS operator, one mail provider or one hosting network is a single point of failure whose outage takes the whole function down. The mirror of Digital Infrastructure Mapping: that flow maps what an entity owns, this maps what it depends on.