Use cases
Infrastructure, supply chain & compliance
Nobody joins routing to physical presence, so concentration risk and ICT dependency stay invisible until they fail — which is exactly what NIS2, DORA, and ISO 27001 ask you to evidence. WhisperGraph maps dependency down to the datacenters, internet exchanges, and submarine cables a vendor actually rides on.
The concentration that no questionnaire surfaces becomes a query you can run and a map you can hand to an auditor.
Why this is hard without a graph
Third-party risk stops at the contract. The layers that determine real resilience — which networks a vendor announces, which facilities those routes pass through, which cable systems carry them — are in datasets that were never meant to join, and certainly not to a sanctions list or a jurisdiction map.
What changes with WhisperGraph
Network, physical, and ownership layers are one connected graph, so a single traversal walks from a vendor domain to the datacenters and cables it depends on, and crosses ownership against sanctions and jurisdiction in the same pass. The workflows below turn that into the concentration and due-diligence evidence the frameworks require.
6 workflows in Infrastructure & supply chain
Each one runs live on the graph — no signup.
Anycast DNS-Root Sovereignty
Could a country still resolve names if it were isolated? This assesses a nation's DNS-root resilience — how many of the core root servers have a copy inside its borders, and who operates them — the sovereignty read for national-resilience and policy analysis.
Attack-Surface Mapper
See your organisation the way an attacker does. Give it a domain and it maps the full external footprint — every subdomain, the name and mail servers, who registered it, the third-party services it leans on, and the wider web of sites it connects to — and scores the exposure. The starting point for shrinking what's reachable from the outside.
Digital Infrastructure Mapping
Follow the infrastructure back to who really runs it. Starting from one indicator, this works out the true operator — even behind privacy registration — de-cloaks CDN-fronted sites to their real servers, and pivots out to the rest of that owner's estate. The mapping view for research, attribution, and understanding who's really on the other end.
Infrastructure Concentration & Resilience
Resilience and compliance in one view. This grades how concentrated an organisation's infrastructure is — too much riding on one provider, one region, one data centre, one cable landing — surfacing the single points of failure that matter for resilience planning and for fourth-party risk rules like DORA and NIS2.
Network & Routing Report
The full picture of how a network is put together and reaches the internet. Give it a network or address block and get a health card: what it announces, who it peers and buys transit from, whether it leans dangerously on a single upstream, and how well its routes are protected. The one-look report for network engineers assessing reach and resilience.
Sanctions & Counterparty Due Diligence
Know who you're dealing with before you deal with them. This screens a domain, address, or network against sanctions lists and assesses the counterparty's hosting, true owner, jurisdiction, and reputation — the external due-diligence pass for compliance teams, crypto-AML checks, and vetting an acquisition or an exchange before you transact.