Flare
Flare is a Montreal-based threat exposure management company that monitors dark web forums, Telegram channels, and stealer log markets to detect exposed credentials and automate remediation for 300+ enterprise and government security teams across 40+ countries.
- Company typePrivate
- Founded2017
- HeadquartersMontréal, Canada
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Flare does
Flare is a Montreal-based threat exposure management company founded in 2017 by red teamers, operating under the legal entity Flare Systems, Inc. The company monitors external digital footprints across dark web forums, stealer log markets, and 58,000+ Telegram channels to detect exposed enterprise credentials, session tokens, and brand threats for enterprise security teams across financial services, healthcare, technology/SaaS, e-commerce/retail, and government/law enforcement verticals. Its dataset spans 25B+ leaked credentials, 70M+ stealer logs (with 1M+ added weekly), 160+ forums in 6+ languages, and 2M+ threat actor profiles accumulated over nearly a decade.
The core platform combines cyber threat intelligence with identity exposure management. Its proprietary Threat Flow AI engine translates multilingual dark web discussions into intelligence reports in under 5 seconds, with 98% accuracy validated by the University of Montreal. The platform integrates natively with Microsoft Entra ID, Okta, Splunk, Azure Sentinel, CrowdStrike, SentinelOne, and ITSM tools (Slack, Jira, ServiceNow), enabling automated credential validation and remediation workflows (password resets, session revocations, account lockouts) that collapse the detection-to-remediation cycle. Supplementary products include Account & Session Takeover Prevention (ASTP) for consumer fraud, Flare PRISM for data visualization, and Foretrace (acquired March 2024) for B2B2E employee identity protection.
Flare operates a multi-channel SaaS business model with annual subscriptions for enterprise platform licenses, MSSP/reseller channel licensing on a multi-tenant architecture, and OEM/embedded intelligence partnerships that report 3x ARPU uplift for partners. The company serves 300+ organizations across 40+ countries, employs 101-250 people, and has raised approximately $39.5M CAD/USD across a CAD$9.5M Series A (June 2022, Inovia Capital led) and a $30M November 2025 round combining a $15M Series B extension with $15M debt from BMO. Its go-to-market combines direct enterprise field sales, a 14-day product-led free trial, an MSSP program reporting 114% YoY growth, and an OEM program embedding its data into SIEM, SOAR, identity, and AI SOC platforms.
Flare firmographics
Firmographics- Name
- Flare
- Legal name
- Flare Systems, Inc.
- Website
- https://flare.io
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Flare is a Montreal-based threat exposure management company that monitors dark web forums, Telegram channels, and stealer log markets to detect exposed credentials and automate remediation for 300+ enterprise and government security teams across 40+ countries.
- Ownership category
- akta.pro rank
Flare industry classification
Industry- Product category
- Threat Exposure Management
- NAICS
- Investigation and Security Services (5616)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Threat Intelligence Services (BPAEADAC)
- akta.pro secondary industries
- Third-Party & Supply Chain Exposure Monitoring (HDADAHAJ), Security Operations Center (SOC) as a Service (BPAEADAB)
Keywords
Where Flare is headquartered
LocationHeadquarters
- HQ city
- Montréal
- HQ country
- Canada
- HQ region
- North America
Offices1 record
Markets served
Flare business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Infrastructure, Marketing or Sales, Operations
Revenue model
- Subscription-based SaaS (Platform License): Annual or multi-year subscription licensing for the Flare Threat Exposure Management platform. Enterprise pricing based on organization size and features accessed. Includes platform access, data feeds, integrations, and support.
- Partner/Reseller Licensing: MSSP and reseller partners purchase platform licenses to deliver threat exposure management services to their end customers. Multi-tenant architecture supports partner-delivered services.
- OEM/Embedded Intelligence Licensing: Technology partners embed Flare's threat exposure data into their security platforms. Flexible licensing models including flat-fee, usage-based, or revenue share arrangements. Partners typically see 3x ARPU uplift on bundled tiers.
- Technology-Enabled Managed Services (TEM): Flare supports technology-enabled managed services where the platform powers managed threat exposure services delivered by partners or directly to customers.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise Platform - Full TEM capabilities |
| Freemium | Pay-as-you-go | Free Trial - 14-day evaluation |
Go-to-market motion4 records
Distribution channels6 records
Marketing channels8 records
Flare product offering
Product offeringCore offering
Flare provides a Threat Exposure Management platform that continuously monitors the cybercrime ecosystem—dark web forums, 58,000+ Telegram channels, stealer log markets, ransomware leak sites, and paste sites—to detect exposed enterprise credentials, session tokens, and identity information. The platform enriches this external intelligence with AI-driven analysis, validates exposures against identity providers such as Microsoft Entra ID and Okta, and automates remediation workflows including password resets, session revocations, and account lockdowns. It is delivered as a subscription SaaS with multi-tenant architecture for MSSPs and OEM/embedded integrations into third-party security platforms.
Product overview
Flare is a Threat Exposure Management company offering a unified platform combining cyber threat intelligence, identity exposure management, and automated remediation capabilities. The core offering is the Flare Cyber Threat Intelligence Platform, which monitors dark web forums, stealer log markets, and 58,000+ Telegram channels. This platform integrates with specialized modules including Identity Exposure Management (IEM) for automated credential validation and remediation, Threat Flow for AI-powered threat analysis, Account and Session Takeover Prevention (ASTP) for consumer protection, and Foretrace for employee identity protection. The ecosystem also includes Flare PRISM for data visualization, ROI calculators for business case development, Flare Academy for training, and an OEM/Embedded program for technology partners.
Differentiator
Problem solved
Functional benefit
Brands
- Foretrace: Identity protection product for employees providing enterprise-grade dark web monitoring and personal identity risk monitoring delivered through a B2B2E model.
- Flare CTI
- Threat Flow
- Flare PRISM
Products and services
- Flare Cyber Threat Intelligence Platform Core threat intelligence SaaS platform that monitors dark web forums, stealer log markets, and Telegram channels to detect exposed credentials, secrets, and brand threats, with automated remediation integrated into enterprise security stacks.
- Identity Exposure Management (IEM) Automated credential exposure detection and remediation solution that validates exposed accounts against Microsoft Entra ID and triggers password resets, session revocations, and account lockdowns in under 60 seconds.
- Threat Flow Generative AI research assistant that aggregates multilingual dark web discussions, performs semantic threat actor analysis, and produces source-linked intelligence reports in under 5 seconds with 98% accuracy validated by the University of Montreal.
- Account and Session Takeover Prevention (ASTP) API-first consumer protection solution that detects stolen session cookies and credentials from infostealer logs in near real time and enables fraud prevention teams to revoke sessions before attackers can exploit them.
- Foretrace Employee identity protection offering delivered via a B2B2E model that provides real-time digital identity risk monitoring and personal protection tools powered by Flare's threat intelligence infrastructure.
- Flare PRISM Interactive visual gateway into Flare's cybercrime dataset providing dashboards for ransomware leak data, stealer logs, unit summaries, and Telegram network analysis.
Quantifiable outcome
- 321% ROI over 3 years with payback under 6 months
- +8 more outcomes
Companies that use Flare
Customer profileNamed customers13 records
Segments7 records
Ideal customer profiles3 records
Flare technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration9 records
AI capability6 records
Feature7 records
Flare partnerships and signals
Strategic signalPartnerships
Seven partnerships are on record, tiered flagship, core and minor.
- MicrosoftflagshipDeep integration with Microsoft ecosystem including Entra ID for credential validation and automated remediation, Azure Sentinel for SIEM integration, and Microsoft Teams for communication alerts. Flagship identity integration partner.
- OktacoreIntegration partnership for identity and access management. Okta integration added to Identity Exposure Management offering alongside Microsoft Entra ID.
- SplunkcoreNative integration with Splunk for SIEM enrichment. Flare's threat intelligence data enriches Splunk's analytics for improved threat detection and response.
- CrowdStrikecoreIntegration partnership listed on Flare's integrated product partners page. Enriches CrowdStrike's endpoint security with external threat exposure data.
- SentinelOnecoreIntegration partnership for embedding Flare's external threat intelligence into SentinelOne's endpoint security platform.
- IBM X-ForcecoreCollaborative research partnership on North Korean remote IT worker threat intelligence. Published joint research in March 2026 detailing DPRK operatives using stolen identities to infiltrate Western companies.
- University of MontrealminorAcademic partnership for validating Threat Flow AI engine accuracy. Achieved 98% accuracy rate validated in collaboration with University of Montreal.
Scale indicators16 records
Recent moves6 records
Expansion highlights7 records
Flare competitors and assessment
Company assessmentDirect peers
- Recorded Future: Threat intelligence platform providing dark web, credential, and brand-monitoring intelligence to enterprise security teams — Flare's closest large-scale direct competitor in the same CTI product category.
- SpyCloud: Specializes in stolen credential and identity exposure intelligence recovered from infostealer logs and criminal marketplaces — directly comparable to Flare's stealer log intelligence and IEM offerings.
- Cybersixgill: Dark web threat intelligence platform with deep Telegram and forum collection and cybercrime actor profiling — overlapping with Flare's dark web, Telegram, and stealer log coverage.
- ZeroFox: External threat and digital risk protection platform offering dark web monitoring, brand protection, and account takeover prevention — overlapping with Flare's enterprise and consumer ATO use cases.
- DarkOwl: Darknet data and intelligence provider with credential, leak, and forum datasets comparable to Flare's dark-web and stealer-log intelligence core.
- Constella Intelligence: Identity and dark web intelligence firm focused on exposed credentials, executive protection, and fraud risk — comparable to Flare's IEM and ASTP modules.
Broad incumbents
- Mandiant (Google Cloud): Google-owned threat intelligence and incident response provider with broad CTI, brand monitoring, and breach data — competes at the enterprise/government tier where Flare is expanding.
- CrowdStrike: Endpoint security leader now offering external threat intelligence and identity protection modules — competes as an embedded incumbent in the same enterprise SOC budget pool as Flare.
- IntSights (Rapid7): Rapid7-owned external threat intelligence (formerly IntSights) covering dark web and brand risk — overlaps Flare's enterprise CTI offering within a broader security platform.
Emerging players
- HUMAN Security: Bot management and fraud-prevention vendor with adjacent capabilities in stolen credential and account-takeover defense — emerging overlap with Flare's ASTP and fraud use cases.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Flare social profiles
Digital presenceFlare compliance and trust
Trust signalCompliance3 records
Flare financial estimates
Financial estimateRevenue estimate
Valuation estimate
Flare leadership team
Management profileNumber of profiles
Profiles8 records
Flare funding detail
Funding detailFunding overview
Funding rounds9 records
Investors11 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Flare M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Flare
What does Flare do?
Flare provides a Threat Exposure Management platform that continuously monitors the cybercrime ecosystem—dark web forums, 58,000+ Telegram channels, stealer log markets, ransomware leak sites, and paste sites—to detect exposed enterprise credentials, session tokens, and identity information. The platform enriches this external intelligence with AI-driven analysis, validates exposures against identity providers such as Microsoft Entra ID and Okta, and automates remediation workflows including password resets, session revocations, and account lockdowns. It is delivered as a subscription SaaS with multi-tenant architecture for MSSPs and OEM/embedded integrations into third-party security platforms.
Is Flare a public or private company?
Flare is a private company. It is classified as venture growth investor backed and is currently operating.
When was Flare founded?
Flare was founded in 2017. It employs 1 to 10 people.
Where is Flare based?
Flare is headquartered in Montréal, Canada, in the North America region.
How does Flare make money?
Four revenue lines are on record. Subscription-based SaaS (Platform License) is the primary driver. The others are partner/Reseller Licensing, OEM/Embedded Intelligence Licensing and technology-Enabled Managed Services (TEM).
Who are Flare's main competitors?
Direct peers on record are Recorded Future, SpyCloud, Cybersixgill, ZeroFox, DarkOwl and Constella Intelligence. Broad incumbents are Mandiant (Google Cloud), CrowdStrike and IntSights (Rapid7). HUMAN Security is listed as an emerging player.
Does Flare have an API?
Yes. Flare's enterprise-proven APIs enable programmatic access to threat intelligence data. Full API documentation available at docs.flare.io for REST and webhooks. Supports Python and Go SDKs with hands-on support. Enables pulling events, searching data, triggering actions, and wiring exposures into SIEM, SOAR, ticketing systems, or custom playbooks. Example endpoint: /v2/stolen-sessions for streaming session cookie data with 15-second polling. Developer documentation is at api.docs.flare.io/introduction/getting-started.
What industry is Flare in?
Flare's product category is Threat Exposure Management. Its primary akta.pro industry code is BPAEADAC, Threat Intelligence Services, with a secondary code of HDADAHAJ, Third-Party & Supply Chain Exposure Monitoring. Its NAICS code is 5616 and its SIC code is 7370.