Flashpoint
Flashpoint is a privately-held threat intelligence company that aggregates primary-source data from illicit communities and applies AI and human analysts to deliver cyber, fraud, vulnerability, physical, and national security intelligence to Fortune 500 enterprises, financial institutions, and government agencies globally.
- Company typePrivate
- Founded2010
- HeadquartersNew York, United States
- Headcount251–500
- GTM typeB2B
- OfferingSoftware
What Flashpoint does
Flashpoint is a privately-held threat intelligence company founded in 2010 and headquartered in Washington, DC (with a New York presence per third-party sources), operating globally with Points of Presence across 40+ regions and customer footprints in North America, Europe, the Middle East, Asia-Pacific, and Latin America. The company serves Fortune 500 enterprises, US federal agencies (including the US Department of Defense and Intelligence Community), state and local law enforcement, defense industrial base contractors, and financial institutions, with named logos including Microsoft, Kaiser Permanente, Wells Fargo, EY, UKG, Pluralsight, and National Geographic. Backed by private-equity firm Audax Group, Flashpoint completed two strategic acquisitions in 2022 — Risk Based Security (VulnDB) and Echosec Systems — to extend into vulnerability intelligence and geospatial OSINT respectively. Customer-attested outcomes include $80M+ annual fraud loss prevention at a large US financial institution and $500M fraud loss avoidance in less than four months at a public-sector customer.
Flashpoint's core product is the Flashpoint Ignite platform, an AI-enhanced threat intelligence workspace that aggregates over 3.6 petabytes of primary-source data collected from closed forums, illicit marketplaces, encrypted chat services, and transient platforms, augmented by embedded human analysts. The platform is modular, with specialized modules for Cyber Threat Intelligence, Physical Security Intelligence (powered by Echosec), Vulnerability Intelligence (incorporating VulnDB's 435K+ vulnerabilities including 105K+ pre-CVE), National Security Intelligence, Fraud Intelligence, Brand Intelligence, External Attack Surface Management (EASM, launched 2026), and Managed Attribution (an isolated virtual environment with 40+ regional POPs for anonymous research). Native integrations span all major SIEM, SOAR, TIP, and case management platforms (Splunk, IBM QRadar, Microsoft Sentinel, Cortex XSOAR, ServiceNow, Anomali, ThreatConnect, ThreatQuotient, Cyware, EclecticIQ), plus STIX/TAXII 2.1 and MISP endpoints, REST API and Firehose data delivery, and a 2026-launched MCP Server for agentic AI workflows.
The company monetizes primarily through annual subscription licensing of the Ignite platform and its modular components (quote-based enterprise pricing obtained via demo/sales engagement), supplemented by recurring Managed Intelligence services (Curated Alerting, Proactive Acquisitions, Tailored Reporting, RFI), professional services (Threat Response & Readiness, Threat Actor Engagement, Enhanced Monitoring), Data-as-a-Service via API/Firehose, and Premium Managed Attribution subscriptions. Distribution combines direct enterprise field sales (with prominent 'Get a Demo' CTAs), a channel partner ecosystem including Optiv, Guidepoint, Herjavec Group, Carahsoft, and Atlantic Data Security, public-sector distribution through Carahsoft, and self-guided product tours. Recognized as a Challenger in the inaugural 2026 Gartner Magic Quadrant for Cyber Threat Intelligence Technologies, Flashpoint has historically raised approximately $49M in venture funding across 2015-2019 (Bloomberg Beta, Cisco Investments, Georgian, Greycroft, Jump Capital, Leaders Fund, TechOperators, K2 Integrity, Portage Partners) before transitioning to PE ownership under Audax Group.
Flashpoint firmographics
Firmographics- Name
- Flashpoint
- Legal name
- Flashpoint Technologies
- Website
- https://flashpoint.io
- Company type
- Private
- Founded year
- 2010
- Operating status
- Operating
- Headcount range
- 251–500 employees
- Short description
- Flashpoint is a privately-held threat intelligence company that aggregates primary-source data from illicit communities and applies AI and human analysts to deliver cyber, fraud, vulnerability, physical, and national security intelligence to Fortune 500 enterprises, financial institutions, and government agencies globally.
- Ownership category
- akta.pro rank
Flashpoint industry classification
Industry- Product category
- Threat Intelligence Platform
- NAICS
- Software Publishers (513210)
- SIC
- Services-Computer Programming Services (7371)
- akta.pro primary industry
- Threat Intelligence Services (BPAEADAC)
Keywords
Where Flashpoint is headquartered
LocationHeadquarters
- HQ city
- New York
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
Flashpoint business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Infrastructure, Marketing or Sales, Operations, Supply Chain
Revenue model
- Subscription / SaaS Licensing: Primary revenue stream based on annual or multi-year subscriptions to the Flashpoint Ignite platform and its modular components (Cyber Threat Intelligence, Physical Security Intelligence, Vulnerability Intelligence, National Security Intelligence, Fraud Intelligence, Brand Intelligence, EASM). Pricing is quote-based with a 'Request Pricing' / 'Get a Demo' model.
- Managed Intelligence Services: Recurring professional services revenue from Managed Intelligence engagements including a Dedicated Engagement Manager, Curated Alerting, Proactive Acquisitions, Tailored Reporting Service, Request for Information (RFI), and Person of Interest/Executive Investigations.
- Professional Services & Threat Response: Professional services revenue from Threat Response & Readiness, Threat Actor Engagement & Procurement, Enhanced Monitoring (Extortion Monitoring), and Staff Augmentation engagements for both enterprise and government customers.
- Data-as-a-Service (DaaS): Revenue from delivering Flashpoint's global collections via API, Firehose, or custom delivery methods to government and enterprise customers needing tailored, timely datasets for critical missions.
- Premium Managed Attribution: Subscription revenue from the Managed Attribution isolated virtual environment, including dedicated environments, multi-hop gateway obfuscation, and POP coverage in 40+ regions for anonymous online investigations.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Quote-based enterprise subscription for Flashpoint Ignite platform modules (CTI, PSI, Vulnerability Intel, NSI, Fraud, Brand, EASM, Managed Attribution) |
| Subscription | Annual | Managed Intelligence / Professional Services (Managed Attribution, Curated Alerting, Proactive Acquisitions, RFI, Tailored Reporting) |
| Usage-based | Annual | Data-as-a-Service (API / Firehose / custom delivery) |
Go-to-market motion4 records
Distribution channels6 records
Marketing channels8 records
Flashpoint product offering
Product offeringCore offering
Flashpoint sells an AI-enhanced threat intelligence platform (Flashpoint Ignite) that aggregates over 3.6 petabytes of primary-source data collected from illicit online communities, closed forums, encrypted messaging platforms and marketplaces, then enriches it with human-vetted analysis and delivers it through modular subscriptions covering Cyber Threat Intelligence, Physical Security Intelligence, Vulnerability Intelligence, National Security Intelligence, Fraud Intelligence, Brand Intelligence and External Attack Surface Management. Revenue comes from enterprise SaaS subscriptions, REST API/Firehose Data-as-a-Service, and recurring managed intelligence and professional services engagements.
Product overview
Flashpoint operates as a platform-plus-modules architecture anchored by its core Flashpoint Ignite threat intelligence platform, which unifies multiple specialized intelligence modules. The Ignite platform aggregates over 3.6 petabytes of primary-source data and combines AI-powered analysis with human expert validation across six primary modules: Cyber Threat Intelligence, Physical Security Intelligence (powered by Echosec), Vulnerability Intelligence (incorporating the acquired VulnDB), National Security Intelligence, Fraud Intelligence, and Brand Intelligence. These modules are supplemented by Managed Attribution (an isolated virtual environment for secure investigations), External Attack Surface Management (EASM, an add-on module launched in 2026), and a layered services portfolio including Managed Intelligence, Curated Alerting, Proactive Acquisitions, Tailored Reporting Service, Request for Information (RFI), Person of Interest/Executive Investigations, and Professional Services such as Threat Response & Readiness and Threat Actor Engagement. The platform is accessible via REST API, Firehose, STIX/TAXII, and the new MCP Server, integrating natively with leading SIEM, SOAR, and TIP platforms.
Differentiator
Problem solved
Functional benefit
Brands
- Flashpoint Ignite: AI-enhanced threat intelligence platform that combines data collection, human expertise, and automated analysis across cyber, physical, vulnerability, national security, fraud, and EASM use cases.
- Echosec
- VulnDB
- Flashpoint Managed Attribution
- Flashpoint EASM
Products and services
- Flashpoint Ignite AI-enhanced threat intelligence platform combining superior primary-source data, human expertise and automated analysis to identify and remediate cyber threats, fraud, vulnerability, physical and national security risks across a unified workspace for enterprise and government customers.
- Flashpoint Cyber Threat Intelligence Industry-leading CTI module providing contextual insights from primary-source data, AI-powered analysis and expert human context to detect ransomware, fraud, account takeover and brand abuse threats across CTI/SOC teams.
- Flashpoint Physical Security Intelligence Geospatial OSINT and AI-powered threat intelligence providing context to mitigate threats to people, assets and operations globally, with translation across 100+ languages and AI-powered research assistance.
- Flashpoint Vulnerability Intelligence Vulnerability intelligence module fusing NVD-independent data, real-time exploit analysis, non-CVE visibility and advanced scoring across 435K+ vulnerabilities including 105K+ pre-CVE and 7,000+ known exploited vulnerabilities, on average 2 weeks faster than NVD.
- Flashpoint National Security Intelligence OSINT technology, data and intelligence services for mission-driven government teams in defense, law enforcement, public safety, federal civilian agencies and the Intel Community, including geospatial OSINT, CTI and managed attribution.
- Flashpoint Fraud Intelligence Financial fraud intelligence providing early-warning signals by monitoring illicit communities, card shops, data breaches and infostealer logs to detect compromised credentials, stolen credit cards, fraudulent bank accounts and illicit cryptocurrency activity.
- Flashpoint Brand Intelligence Brand protection module monitoring domains, logos, social media and mobile apps for abuse, typosquatting, phishing and impersonation, with one-click domain takedown services.
- Echosec by Flashpoint Geospatial OSINT platform filtering global social media and defense forums to provide real-time threat monitoring with interactive maps, geofencing and AI-powered summarization.
- Flashpoint Managed Attribution Fully managed isolated virtual environment with 40+ regions of Points of Presence for conducting primary source research, threat actor engagement and technical investigations while protecting operator identity and digital footprint.
- Flashpoint External Attack Surface Management (EASM) Add-on module within Flashpoint Ignite that continuously discovers unknown internet-facing assets (domains, subdomains, IPs) and maps them to Flashpoint vulnerability intelligence to prioritize remediation based on actively exploited vulnerabilities.
- Flashpoint Managed Intelligence Specialized managed service that augments security teams by owning service engagement, reviewing content, detecting threats and delivering tailored intelligence using Flashpoint collections and human expertise, including a Dedicated Engagement Manager, Curated Alerting, Proactive Acquisitions, Tailored Reporting and RFI workflows.
- Flashpoint Curated Alerting Multilingual intelligence team service that analyzes illicit community content, conducts risk analyses and delivers concise analyst-crafted assessments with high signal-to-noise ratio.
- Flashpoint MCP Server Model Context Protocol server product that exposes Flashpoint threat intelligence datasets to AI agents so they can programmatically consume and act upon cyber threat data in agentic security operations.
Companies that use Flashpoint
Customer profileNamed customers8 records
Segments5 records
Ideal customer profiles4 records
Flashpoint technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration26 records
AI capability12 records
Feature8 records
Flashpoint partnerships and signals
Strategic signalPartnerships
18 partnerships are on record, tiered flagship and core.
- Echosec SystemsflagshipFlashpoint acquired Echosec Systems in August 2022 to enhance its OSINT capabilities for security and risk assessment. Echosec's social media and geospatial insights now underpin Flashpoint's Physical Security Intelligence (PSI) product and the 'Echosec by Flashpoint' geospatial OSINT offering.
- Risk Based SecurityflagshipFlashpoint acquired Risk Based Security (RBS), the vulnerability intelligence company behind VulnDB, in January 2022. The acquisition integrated over 90,000 vulnerabilities not listed in public registries into Flashpoint's platform and became the foundation of Flashpoint Vulnerability Intelligence, now covering 435K+ vulnerabilities including 105K+ pre-CVE.
- Anomali (ThreatStream)coreTIP integration connecting Flashpoint's finished intelligence with Anomali ThreatStream to provide industry-specific threat visibility. Supported datasets: Alerting, Compromised Credentials, Intelligence Reports, Technical Indicators, Vulnerabilities.
- ThreatConnectcoreTIP integration complementing ThreatConnect with intelligence reports and IoCs that include MITRE ATT&CK tags and scoring. Supported datasets: Intelligence Reports, Technical Indicators, Vulnerabilities.
- ThreatQuotient (ThreatQ)coreTIP integration offering access to a broad range of Flashpoint datasets for threat intelligence aggregation and prioritization. Supported datasets: Alerting, Card Fraud, Communities, Compromised Credentials, Intelligence Reports, Marketplaces, Media, Technical Indicators, Vulnerabilities.
- EclecticIQcoreTIP integration enabling collaborative workflows for triage, analysis, and action. Supported datasets: Communities, Intelligence Reports, Marketplaces, Technical Indicators.
- Cyware (CTIX and Orchestrate)coreTIP and SOAR integrations providing critical external threat insight via Cyware CTIX (Intelligence Reports, Technical Indicators, Vulnerabilities) and Cyware Orchestrate (Alerting, Technical Indicators, Vulnerabilities) for automation.
- Cortex XSOAR (Palo Alto Networks)flagshipSOAR integration unifying case management, automation, and threat intelligence management with Flashpoint data and finished intelligence. Supported datasets: Alerting, Communities, Compromised Credentials, Intelligence Reports, Marketplaces, Technical Indicators, Vulnerabilities.
- ServiceNow (TI, SIR, VR)coreMultiple ServiceNow integrations: ServiceNow TI (Intelligence Reports, Technical Indicators), ServiceNow SIR (Alerting, Compromised Credentials), ServiceNow VR (Communities, Marketplace, Vulnerabilities) for workflow automation.
- Splunk PhantomflagshipSOAR integration automating repetitive tasks and streamlining incident response workflows with Flashpoint data and intelligence. Supported datasets: Alerting, Communities, Compromised Credentials, Intelligence Reports, Marketplaces, Technical Indicators.
- Microsoft SentinelcoreSIEM integration via Flashpoint connector template enabling ingestion of compromised enterprise credentials. Supported datasets: Compromised Credentials.
- IBM QRadarflagshipSIEM integration via the 'Flashpoint for QRadar' app providing visibility into illicit online communities to correlate with customer log data and trigger notifications.
- SplunkflagshipSIEM integration via Flashpoint Splunk app and add-on, plus a Technical Indicators app for Splunk indexing/analysis. Notifies Splunk users when internal log indicators correspond with Flashpoint intelligence.
- SilobreakercoreAnalysis & Investigations integration combining Flashpoint data with Silobreaker's open-source intelligence and analytical tools. Supported datasets: Card Fraud, Communities, Compromised Credentials, Intelligence Reports, Marketplaces.
- MaltegocoreAnalysis & Investigations integration via Flashpoint Maltego Transforms to incorporate Flashpoint data into Maltego workflows and visualize relationships between entities.
- SlackcoreProduct integration delivering Flashpoint Ignite alerts within Slack for rapid visibility and streamlined workflows.
- STIX/TAXII 2.1coreIndustry-standard data format integration via Flashpoint Technical Indicators API providing STIX/TAXII 2.1 endpoints for automated threat intelligence sharing.
- Carahsoft
Scale indicators25 records
Recent moves6 records
Expansion highlights6 records
Flashpoint competitors and assessment
Company assessmentBroad incumbents
- Microsoft Defender Threat Intelligence: Broad incumbent offering bundled threat intelligence to Microsoft security customers. A strategic risk to standalone CTI vendors because intelligence is included with E5/Sentinel licensing, undercutting Flashpoint's enterprise wallet share.
- CrowdStrike (Charlotte AI / Falcon Intelligence): Broad incumbent that bundles threat intelligence into its Falcon endpoint/XDR platform. Competes with Flashpoint indirectly by offering integrated intelligence alongside EDR, putting pricing pressure on standalone CTI vendors in platform-leaning accounts.
- Palo Alto Networks Unit 42: Broad incumbent combining threat intelligence, incident response, and managed services within Palo Alto's platform. Competes with Flashpoint's NSI/CTI/Managed Intelligence offerings, especially in large enterprise and government accounts.
Direct peers
- Intel 471: Direct peer in adversary intelligence and primary-source collection from cybercrime forums, marketplaces, and chat services. Closely comparable operating model and customer base to Flashpoint, particularly for fraud and credential monitoring.
- Anomali: Direct peer in threat intelligence platforms, both as a competitor TIP and as a Flashpoint integration partner via ThreatStream. Comparable in serving enterprise SOC/CTI teams with curated threat feeds and analytics.
- Recorded Future: Direct competitor in commercial threat intelligence, acquired by Mastercard in 2024. Closely comparable to Flashpoint in primary-source collection, finished intelligence reporting, and integrations across SIEM/SOAR/TIP stacks.
- Mandiant (Google Cloud): Direct peer in threat intelligence and incident response intelligence, now part of Google Cloud. Competes head-to-head with Flashpoint Ignite's CTI, NSI, and Managed Intelligence offerings for Fortune 500 and government customers.
- KELA: Direct peer specializing in cybercrime intelligence from dark web forums, marketplaces, and automated infostealer logs. Comparable primary-source collection methodology and financial-fraud/credential-monitoring use cases to Flashpoint's Fraud Intelligence.
- ThreatConnect: Direct peer in threat intelligence platforms with overlapping CTI/TIP/SOAR capabilities and shared integration partnerships. Comparable enterprise SOC customer base and similar positioning as a best-of-breed intelligence orchestration layer.
- Digital Shadows (ReliaQuest): Direct peer in digital risk and threat intelligence, now part of ReliaQuest. Comparable in primary-source monitoring, brand protection, and external attack surface intelligence - directly competitive with Flashpoint's Brand Intelligence and CTI modules.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
Flashpoint social profiles
Digital presenceFlashpoint financial estimates
Financial estimateRevenue estimate
Valuation estimate
Flashpoint leadership team
Management profileNumber of profiles
Profiles12 records
Flashpoint subsidiaries and ownership
Company hierarchySubsidiaries2 records
Flashpoint funding detail
Funding detailFunding overview
Funding rounds4 records
Investors9 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Flashpoint M&A and investment
M&A and investmentM&A3 records
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Flashpoint
What does Flashpoint do?
Flashpoint sells an AI-enhanced threat intelligence platform (Flashpoint Ignite) that aggregates over 3.6 petabytes of primary-source data collected from illicit online communities, closed forums, encrypted messaging platforms and marketplaces, then enriches it with human-vetted analysis and delivers it through modular subscriptions covering Cyber Threat Intelligence, Physical Security Intelligence, Vulnerability Intelligence, National Security Intelligence, Fraud Intelligence, Brand Intelligence and External Attack Surface Management. Revenue comes from enterprise SaaS subscriptions, REST API/Firehose Data-as-a-Service, and recurring managed intelligence and professional services engagements.
Is Flashpoint a public or private company?
Flashpoint is a private company. It is classified as private equity controlled and is currently operating.
When was Flashpoint founded?
Flashpoint was founded in 2010. It employs 251 to 500 people.
Where is Flashpoint based?
Flashpoint is headquartered in New York, United States, in the North America region.
How does Flashpoint make money?
Five revenue lines are on record. Subscription / SaaS Licensing is the primary driver. The others are managed Intelligence Services, professional Services & Threat Response, data-as-a-Service (DaaS) and premium Managed Attribution.
Who are Flashpoint's main competitors?
Broad incumbents on record are Microsoft Defender Threat Intelligence, CrowdStrike (Charlotte AI / Falcon Intelligence) and Palo Alto Networks Unit 42. Direct peers are Intel 471, Anomali, Recorded Future, Mandiant (Google Cloud), KELA, ThreatConnect and Digital Shadows (ReliaQuest).
Does Flashpoint have an API?
Yes. Flashpoint offers a REST API and Firehose API for accessing its threat intelligence datasets including Alerting, Compromised Credentials, Intelligence Reports, Technical Indicators, Vulnerabilities, Card Fraud, Communities, Marketplaces, and Media. The platform supports STIX/TAXII 2.1 and MISP endpoints for automated threat intelligence sharing. The Flashpoint MCP Server is available to operationalize cyber threat data for agentic AI security workflows. APIs are designed for integration with SIEM, SOAR, TIP, and case management platforms. Developer documentation is at flashpoint.io/integrations.
What industry is Flashpoint in?
Flashpoint's product category is Threat Intelligence Platform. Its primary akta.pro industry code is BPAEADAC, Threat Intelligence Services. Its NAICS code is 513210 and its SIC code is 7371.