ThreatQuotient
ThreatQuotient, founded in 2013, provides the ThreatQ Threat Intelligence Platform that aggregates, scores, and operationalizes threat intelligence for enterprise SOCs, government agencies, MSSPs, and critical infrastructure operators. Acquired by Securonix in June 2025.
- Company typePrivate
- Founded2013
- HeadquartersReston, United States
- Headcount101–250
- GTM typeB2B
- OfferingSoftware
What ThreatQuotient does
ThreatQuotient, Inc., founded in 2013 and headquartered in Ashburn/Reston, Virginia, develops the ThreatQ Threat Intelligence Platform (TIP), an enterprise cybersecurity solution that ingests, normalizes, scores, correlates, and operationalizes threat intelligence from internal and external sources for security operations centers (SOCs). The platform is built on a proprietary DataLinq Engine and an Adaptive Context Engine (ACE), and is modularized into ThreatQ Investigations, ThreatQ Data Exchange, and ThreatQ TDR Orchestrator, with a ThreatQ Marketplace offering 450+ pre-built integrations. Deployment options include on-premises, cloud, and air-gapped environments; named customers span US Department of Defense, MINTIC Colombia, EDF, Thales, Sysdig, Saudi Investment Bank, Cyderes, Jizo AI, and Sesame IT, covering government, defense, energy, financial services, and MSSP segments.
ThreatQuotient generates revenue primarily through annual subscription licenses paid annually in advance on auto-renewing 12-month terms, supplemented by SKU-based professional services for deployment, configuration, training, and tuning, plus the ThreatQ Academy training program. Distribution combines a direct enterprise sales motion with a Securonix-led authorized reseller and global SI/consulting partner network (PwC, OPTIV, Accenture Security), and a Marketplace-driven ecosystem model. Pricing is quote-based and not publicly disclosed. The company was acquired by Vista Equity Partners-backed Securonix in June 2025, and the ThreatQ brand continues to operate as both a standalone solution and an integrated component of Securonix's AI-powered unified SIEM, with a 2026 product roadmap that adds the generative-AI Securonix Threat Research Agent and the predictive-analytics ThreatWatch module.
ThreatQuotient firmographics
Firmographics- Name
- ThreatQuotient
- Legal name
- ThreatQuotient, Inc.
- Website
- https://threatq.com
- Company type
- Private
- Founded year
- 2013
- Operating status
- Acquired
- Headcount range
- 101–250 employees
- Short description
- ThreatQuotient, founded in 2013, provides the ThreatQ Threat Intelligence Platform that aggregates, scores, and operationalizes threat intelligence for enterprise SOCs, government agencies, MSSPs, and critical infrastructure operators. Acquired by Securonix in June 2025.
- Ownership category
- akta.pro rank
ThreatQuotient industry classification
Industry- Product category
- Threat Intelligence Platform
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Threat Intelligence Platforms (TIP) (HDADAGAD)
- akta.pro secondary industries
- Threat Intelligence Services (BPAEADAC), Deception Technology & Threat Hunting (HDADAGAI), Vulnerability Intelligence & Exploit Prediction (HDADAHAI), Endpoint Forensics & Incident Response (DFIR) (HDADAEAJ)
Keywords
Where ThreatQuotient is headquartered
LocationHeadquarters
- HQ city
- Reston
- HQ country
- United States
- HQ region
- North America
Offices4 records
Markets served
ThreatQuotient business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Software Subscription (ThreatQ Platform): Annual subscription licenses for ThreatQ Platform software, paid annually in advance, with auto-renewing 12-month terms. Sold as subscription, term, or SaaS licenses per End User License Agreement.
- Professional Services (SKU-based): Standardized short-term commercial services (SKU-based Services) covering installation, configuration, operation, implementation, training, testing and tuning of the ThreatQ Software, delivered by ThreatQuotient.
- Training and Education (ThreatQ Academy): Training and learning solutions offered through ThreatQ Academy via onsite instructor-led, virtual instructor-led, and online self-paced delivery, generating service revenue from clients and partners.
- Reseller Channel Sales: Sales through authorized resellers and distributors, with non-refundable list-price renewals based on then-current published pricing.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Quote-based annual subscription / term / SaaS licensing with SKU-based professional services add-ons; prices not publicly listed. |
| Other | Annual | ThreatQ Academy training and learning services sold as professional services. |
Go-to-market motion4 records
Distribution channels4 records
Marketing channels11 records
ThreatQuotient product offering
Product offeringCore offering
ThreatQuotient sells the ThreatQ Threat Intelligence Platform (TIP), a purpose-built enterprise software platform that ingests, normalizes, scores, correlates, and operationalizes threat data from internal and external sources. The platform uses adaptive AI and automation to prioritize intelligence and accelerate threat detection, investigation, and response for security operations centers. ThreatQuotient also sells related professional services and training (ThreatQ Academy).
Product overview
ThreatQuotient delivers a single, integrated threat intelligence platform architecture rather than a portfolio of standalone products. The ThreatQ Threat Intelligence Platform is the core offering, built on the DataLinq Engine and augmented by a set of tightly coupled modules — ThreatQ Investigations for collaborative analysis, ThreatQ Data Exchange for intelligence sharing, and ThreatQ TDR Orchestrator for response automation — that extend the platform's capabilities. The ThreatQ Marketplace serves as the ecosystem layer delivering pre-built integrations and data feeds from partners such as Splunk, CrowdStrike, SentinelOne, Mandiant, and ANY.RUN, while ThreatQ Academy and Professional Services deliver the enablement and operational services needed to operationalize Threat Intelligence Management and Security Automation across security operations teams. Following Securonix's June 2025 acquisition, ThreatQ is positioned alongside Securonix analytics to deliver an end-to-end threat detection and intelligence stack, including AI-driven capabilities like the Securonix Threat Research Agent and ThreatWatch.
Differentiator
Problem solved
Functional benefit
Brands
- ThreatQ: ThreatQ Threat Intelligence Platform — a purpose-built threat intelligence platform for optimized threat detection, investigation, and response, which is offered both as a standalone solution and as an integrated component of the Securonix AI-powered unified SIEM.
Products and services
- ThreatQ Threat Intelligence Platform A purpose-built threat intelligence platform for optimized threat detection, investigation, and response. Ingests, normalizes, scores, correlates, and operationalizes threat data from internal and external sources using adaptive AI for prioritization, targeting enterprise Security Operations Centers and security teams.
- ThreatQ Academy Training and learning solutions for ThreatQ customers and partners, delivered as onsite instructor-led, virtual instructor-led, and online self-paced programs covering platform administration, threat intelligence operations, and best practices.
- ThreatQ Professional Services Expert deployment, integration, customization, and operational support services for organizations implementing the ThreatQ platform, sold as SKU-based professional services.
Quantifiable outcome
- Reduces false positives and response times in security operations (per acquisition rationale)
- +3 more outcomes
Companies that use ThreatQuotient
Customer profileNamed customers10 records
Segments7 records
Ideal customer profiles6 records
ThreatQuotient technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration47 records
AI capability8 records
Feature10 records
ThreatQuotient partnerships and signals
Strategic signalPartnerships
41 partnerships are on record, tiered moderate, flagship and minor.
- ANY.RUNmoderateANY.RUN announced the launch of an integration feature for ThreatQ Threat Intelligence Platform that connects their malware analysis solutions to security operations centers, enabling real-time threat indicators from sandbox investigations to be shared with over 15,000 organizations worldwide.
- Securonix (Vista Equity Partners-backed)flagshipSecuronix acquired ThreatQuotient in June 2025 to build an integrated AI-powered Unified SIEM platform. Combined entity offers integrated threat detection, investigation, and response capabilities. Senior ThreatQuotient executives stepped into strategic roles at Securonix. Plans to expand globally across USA, Singapore, EMEA, and Australia while maintaining the ThreatQ brand as both a standalone and integrated solution.
- Securonix (SIEM integration)flagshipSecuronix promotes an on-demand webinar focused on integrating its SIEM platform with ThreatQuotient's threat intelligence capabilities to improve signal clarity, accelerate investigations, and enable more confident incident response.
- RST CloudmoderateRST Cloud and ThreatQuotient forged a strategic partnership to strengthen threat detection and response capabilities, with a dedicated Partner Brief for tactical and operational CTI from RST Cloud in the ThreatQ Platform.
- Ask SagemoderateThreatQuotient and Ask Sage partnered to assist governments in achieving cybersecurity efficiencies.
- SplunkflagshipPartner Brief published for Splunk; webinar coverage on Elevate Your CTI Operations; Splunk Phantom integration partner brief also available. ThreatQ integrates with Splunk as a key SIEM/data analytics partner.
- CrowdStrikeflagshipPartner Brief published for CrowdStrike; integration of CrowdStrike threat intelligence with ThreatQ Platform.
- Palo Alto NetworksflagshipPartner Brief published for Palo Alto Networks, integrating Cortex/MISP-style threat intel feeds with the ThreatQ Platform.
- MandiantflagshipPartner Brief published for Mandiant Intelligence; integrates Mandiant threat intelligence into the ThreatQ Platform.
- CiscoflagshipMultiple Partner Briefs published: Cisco Umbrella and Cisco 'Super' Brief. Integration of Cisco security telemetry with ThreatQ.
- McAfee (multiple)flagshipMultiple Partner Briefs published: McAfee, McAfee-TIE, McAfee-MAR, McAfee-ESM, McAfee-ATD. Integration with McAfee's threat intelligence exchange, malware analysis, ESM, and ATD products.
- MISPflagshipPartner Brief for MISP (Malware Information Sharing Platform); enables threat intelligence sharing through the ThreatQ Platform.
- TenablemoderatePartner Brief for Tenable; integrates Tenable vulnerability data with ThreatQ for vulnerability prioritization use case.
- SentinelOnemoderatePartner Brief for SentinelOne; integration of SentinelOne endpoint telemetry with ThreatQ.
- FortinetmoderatePartner Brief for Fortinet; integration of Fortinet security telemetry with ThreatQ.
- VMware Carbon BlackmoderatePartner Brief for VMware Carbon Black; integration of Carbon Black endpoint telemetry with ThreatQ.
- Google Cloud SecuritymoderatePartner Brief for Google Cloud Security; integration with Google Cloud security offerings.
- SekoiamoderateOn-demand webinar 'Elevate Your CTI Operations: How Sekoia & ThreatQ Empower CTI Teams' and Sekoia partner brief.
- DomainToolsmoderatePartner Brief for DomainTools; integration of DomainTools intelligence with ThreatQ.
- DataminrmoderateTwo Partner Briefs published: Dataminr and Dataminr US Federal. Real-time alerting and threat intel integration with ThreatQ.
- Digital ShadowsmoderatePartner Brief for Digital Shadows; integration with ThreatQ for external threat intelligence.
- Recorded Future / Intel471moderatePartner Briefs for Intel471 (cybercrime intelligence) and Silobreaker; integration of premium threat feeds with ThreatQ.
- Trellix (FireEye)moderatePartner Brief 'Trellix FireEye Malware Analysis'; integration of FireEye/Trellix malware analysis with ThreatQ.
- IBM ResilientmoderatePartner Brief for IBM Resilient; integration of IBM Resilient SOAR with ThreatQ.
- PwC Threat IntelligencemoderatePartner Brief for PwC Threat Intelligence; implementation/consulting partnership for ThreatQ deployments.
- OPTIVmoderatePartner Brief for OPTIV; security solutions integrator partner.
- Accenture SecuritymoderatePartner Brief for AccentureSecurity; global SI/consulting partner for ThreatQ deployments.
- FS-ISAC (Financial Services Information Sharing and Analysis Center)moderateThreatQuotient is an affiliate member of FS-ISAC, supporting financial-sector threat intelligence sharing.
- R-CISC (Retail Cyber Intelligence Sharing Center)minorThreatQuotient is an affiliate member of R-CISC, supporting retail-sector threat sharing.
- NH-ISAC (National Health ISAC)minorThreatQuotient is an affiliate member of NH-ISAC, supporting healthcare-sector threat sharing.
- IT-ISACminorThreatQuotient is an affiliate member of IT-ISAC, supporting IT-sector threat sharing.
- OASIS OpenminorThreatQuotient is an affiliate member of OASIS Open, the standards body for STIX/TAXII and related threat intel standards.
- SINETminorThreatQuotient is an affiliate member of SINET (Security Innovation Network).
- SANSminorThreatQuotient is an affiliate member of SANS Institute.
- MAVAminorThreatQuotient is an affiliate member of MAVA (Mid-Atlantic Venture Association).
- AICPA SOCminorThreatQuotient holds AICPA SOC compliance and is an affiliate member.
- NVTC (Northern Virginia Technology Council)minorThreatQuotient is an affiliate member of NVTC, the Northern Virginia Technology Council.
- Mission LinkminorThreatQuotient is an affiliate of Mission Link, supporting national security and intelligence community connections.
- AWS (Amazon Web Services)flagshipAWS is a ThreatQuotient cloud service subprocessor, hosting customer-encrypted volumes and uploaded files across US/EU/AUS data centers.
- SalesforcemoderateSalesforce is a ThreatQuotient subprocessor used for customer relations, support, and prospect contact data management.
- MarketomoderateMarketo is a ThreatQuotient subprocessor used for marketing automation.
Scale indicators9 records
Recent moves7 records
Expansion highlights5 records
ThreatQuotient competitors and assessment
Company assessmentDirect peers
- Recorded Future: Large threat intelligence platform that combines curated intel feeds with a TIP layer for enterprise SOCs. Comparable to ThreatQ on intelligence aggregation, scoring, and integration with Splunk/SIEM/EDR ecosystems, but at significantly larger scale (Mastercard-owned).
- Anomali: Pure-play Threat Intelligence Platform offering threat aggregation, correlation, and integration with SIEM/SOAR/EDR stacks. Direct competitor to ThreatQ in the enterprise TIP category, serving SOCs and MSSPs with similar deployment models.
- ThreatConnect: Threat intelligence operations platform combining TIP, SOAR and analytics. Closely comparable to ThreatQ in target buyer (SOCs, IR teams), product architecture, and use cases (enrichment, prioritization, response orchestration).
- EclecticIQ: European-headquartered threat intelligence platform serving enterprise SOCs, governments, and MSSPs. Direct peer to ThreatQ in the TIP category with a similar focus on STIX/TAXII-based integration and intelligence sharing workflows.
Broad incumbents
- Splunk Enterprise Security: Broad security analytics/SIEM platform with embedded threat intelligence management capabilities and a deep app ecosystem. Competes with ThreatQ as a larger, more generalist incumbent that increasingly bundles TIP-like features natively, and is also a top integration partner.
- Microsoft Sentinel: Cloud-native SIEM/SOAR from Microsoft with native threat intelligence features and Defender integration. Represents the cloud-scale incumbent threat to standalone TIPs like ThreatQ, particularly for Microsoft-heavy enterprise customers.
- CrowdStrike Falcon Intelligence: Endpoint-centric security platform with a built-in threat intelligence module. ThreatQ integrates with CrowdStrike (per partner brief) and competes where customers choose a single-vendor intelligence + EDR stack over a best-of-breed TIP.
- Palo Alto Networks Cortex: Broad security operations platform (XSIAM, XSOAR, XDR) from Palo Alto Networks. ThreatQ integrates with Palo Alto (per partner brief) but Cortex competes as an end-to-end alternative that incorporates threat intelligence into a broader detection/response suite.
- Mandiant (Google Cloud): Threat intelligence and incident response provider (now part of Google Cloud) whose intelligence feeds are integrated into ThreatQ. Functions as both a content partner and an indirect competitor in the managed intelligence and TIP space.
Emerging players
- MISP (Malware Information Sharing Platform): Open-source threat intelligence sharing platform widely used by ISACs, governments, and CERTs. ThreatQ integrates with MISP (per partner brief) but MISP itself is a free, community-driven alternative that ThreatQ must differentiate against on automation and orchestration.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
ThreatQuotient social profiles
Digital presenceThreatQuotient compliance and trust
Trust signalCompliance4 records
ThreatQuotient financial estimates
Financial estimateRevenue estimate
Valuation estimate
ThreatQuotient leadership team
Management profileNumber of profiles
Profiles7 records
ThreatQuotient funding detail
Funding detailFunding overview
Funding rounds8 records
Investors17 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ThreatQuotient M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ThreatQuotient
What does ThreatQuotient do?
ThreatQuotient sells the ThreatQ Threat Intelligence Platform (TIP), a purpose-built enterprise software platform that ingests, normalizes, scores, correlates, and operationalizes threat data from internal and external sources. The platform uses adaptive AI and automation to prioritize intelligence and accelerate threat detection, investigation, and response for security operations centers. ThreatQuotient also sells related professional services and training (ThreatQ Academy).
Is ThreatQuotient a public or private company?
ThreatQuotient is a private company. It is classified as private equity controlled and is currently acquired.
When was ThreatQuotient founded?
ThreatQuotient was founded in 2013. It employs 101 to 250 people.
Where is ThreatQuotient based?
ThreatQuotient is headquartered in Reston, United States, in the North America region.
How does ThreatQuotient make money?
Four revenue lines are on record. Software Subscription (ThreatQ Platform) is the primary driver. The others are professional Services (SKU-based), training and Education (ThreatQ Academy) and reseller Channel Sales.
Who are ThreatQuotient's main competitors?
Direct peers on record are Recorded Future, Anomali, ThreatConnect and EclecticIQ. Broad incumbents are Splunk Enterprise Security, Microsoft Sentinel, CrowdStrike Falcon Intelligence, Palo Alto Networks Cortex and Mandiant (Google Cloud). MISP (Malware Information Sharing Platform) is listed as an emerging player.
Does ThreatQuotient have an API?
Yes. ThreatQuotient offers a ThreatQ Integration Framework / Open API that enables partners and customers to build integrations that ingest threat intelligence data and trigger operational actions across the ThreatQ platform. The integration framework is exposed via partner-built connectors published in the ThreatQ Marketplace. No public, externally hosted API documentation URL was identified.
What industry is ThreatQuotient in?
ThreatQuotient's product category is Threat Intelligence Platform. Its primary akta.pro industry code is HDADAGAD, Threat Intelligence Platforms (TIP), with a secondary code of BPAEADAC, Threat Intelligence Services. Its NAICS code is 54151 and its SIC code is 7372.