Threat Intelligence Platform
Threat Intelligence Platform is a US-based private company that provides six RESTful threat intelligence APIs and a web analysis interface for cybersecurity teams, SOCs, and journalists to detect malware, phishing, and SSL vulnerabilities across domain infrastructure.
- Company typePrivate
- Founded2016
- HeadquartersWalnut, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Threat Intelligence Platform does
Threat Intelligence Platform (TIP) is a US-based, privately-held technology provider founded in 2016 and headquartered in Walnut, California, that delivers threat intelligence APIs and a web-based analysis interface for cybersecurity teams. The platform aggregates multiple external threat feeds and combines them with proprietary datasets built from more than a decade of continuous data crawling, then performs real-time host configuration analyses to produce actionable intelligence on malware distribution, phishing infrastructure, command-and-control servers, and SSL/TLS weaknesses. Its core product is a suite of six RESTful APIs covering domain infrastructure analysis, SSL certificate chain inspection, SSL configuration analysis, malware domain checking, connected-domain reverse lookups, and a 120-parameter domain reputation scoring engine, all returning unified JSON output capable of 100 queries per minute.
The company monetizes through subscription-based API access on a freemium model with a credit-card-free trial, distributing primarily via self-serve web signup and direct API integration into customer SIEM, CTI, and digital risk protection workflows. Target customers include enterprise security operations centers, financial services institutions, cybersecurity product vendors that resell enriched threat data, and a distinct sub-brand (Media Investigative Platform) aimed at journalists investigating phishing and disinformation. The firm operates as a small team (1-10 employees) with no disclosed outside funding, and is positioned as a complementary product alongside the affiliated WHOISXMLAPI.com domain research suite.
Threat Intelligence Platform firmographics
Firmographics- Name
- Threat Intelligence Platform
- Legal name
- Threat Intelligence Platform
- Website
- https://threatintelligenceplatform.com
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Threat Intelligence Platform is a US-based private company that provides six RESTful threat intelligence APIs and a web analysis interface for cybersecurity teams, SOCs, and journalists to detect malware, phishing, and SSL vulnerabilities across domain infrastructure.
- Ownership category
- akta.pro rank
Threat Intelligence Platform industry classification
Industry- Product category
- Cybersecurity Threat Intelligence
- NAICS
- Other Computer Related Services (541519), Computer Systems Design and Related Services (54151), Computer Systems Design and Related Services (5415), Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (5182)
- SIC
- Services-Computer Integrated Systems Design (7373), Services-Computer Programming, Data Processing, Etc. (7370), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Threat Intelligence Services (BPAEADAC)
- akta.pro secondary industries
- Vulnerability Intelligence & Exploit Prediction (HDADAHAI), Security Analytics & Detection Engineering (HDADAGAE)
Keywords
Where Threat Intelligence Platform is headquartered
LocationHeadquarters
- HQ city
- Walnut
- HQ country
- United States
- HQ region
- North America
Markets served
Threat Intelligence Platform business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Infrastructure, Marketing or Sales, Operations
Revenue model
- API Subscription and Usage: Threat Intelligence Platform generates revenue through API subscription tiers. The platform offers a free trial with no credit card required. Users can integrate APIs into their systems for threat intelligence enrichment. Revenue is derived from programmatic API access to threat data and analysis capabilities.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | Free trial available for API access |
Go-to-market motion1 record
Distribution channels2 records
Marketing channels5 records
Threat Intelligence Platform product offering
Product offeringCore offering
Threat Intelligence Platform provides API-based cyber threat intelligence that combines multiple threat feeds with 10+ years of proprietary crawled data to deliver real-time analysis of domains, IPs, DNS, and SSL certificate configurations. The product is a suite of six RESTful APIs (Domain Infrastructure Analysis, SSL Certificate Chain, SSL Configuration Analysis, Domain Malware Check, Connected Domains, and Domain Reputation) plus an Attack Surface Management solution, used by security teams, SOCs, and cybersecurity product vendors for threat detection, mitigation, and remediation.
Product overview
Threat Intelligence Platform is a modular threat intelligence solution consisting of a core web-based platform plus a suite of 6 specialized APIs. The APIs can be used independently or combined as a complete threat intelligence solution. Core offerings include the Domain Infrastructure Analysis API, SSL Certificate Chain API, SSL Configuration Analysis API, Domain Malware Check API, Connected Domains API, and Domain Reputation API. Additional products include Attack Surface Management Solutions for attack surface reduction and the Media Investigative Platform for journalistic investigations.
Differentiator
Problem solved
Functional benefit
Brands
- Media Investigative Platform: A specialized platform for journalists to perform internet website domain research and deep-dives into sources making and promoting news, part of the ThreatIntelligencePlatform.com product suite
Products and services
- Domain's Infrastructure Analysis API For a given domain name, retrieves web, mail, and name servers as well as known subdomains, and for each infrastructure entry returns IP address, geolocation, and subnetwork information. Used by security teams for host infrastructure mapping.
- SSL Certificate Chain API Returns detailed information about a domain's SSL Certificate and the complete SSL Certificate chain in unified JSON format, including certificate chain, issued to/issued by details, certificate details, validity, and OCSP check results. For security teams verifying SSL posture.
- SSL Configuration Analysis API Establishes and tests SSL connections to a host and analyzes the configuration to detect common configuration issues that can lead to vulnerabilities. Used by security teams for SSL hardening assessments.
- Domain Malware Check API Checks if a domain is considered dangerous across different security data sources, identifying domains related to malware distribution networks or hosting malicious code. For security teams and product vendors detecting malware infrastructure.
- Connected Domains API Performs reverse IP lookup to retrieve domain names (including subdomains) resolving to a given IP address, helping identify shared hosting risks and research infrastructure connections of malicious domains.
- Domain Reputation API Evaluates domain reputation based on numerous security data sources and an instant host audit procedure, collecting and evaluating over 120 parameters to calculate a reputation score from 0–100 for a domain or IPv4 address.
- Attack Surface Management (ASM) Solutions Helps organizations reduce their potential attack surface by subjecting digital properties to comprehensive checks for vulnerabilities, dangling records, misconfigurations, and malware database listings. Built on top of the core Threat Intelligence Platform APIs.
- Media Investigative Platform A specialized platform for journalists to perform deep-dives into internet sources making and promoting news, providing website domain research tools for investigating phishing sites, fake news, and disinformation campaigns.
- Threat Intelligence Platform (core web interface and API platform) Web-based threat intelligence platform that combines multiple threat intelligence sources with exhaustive in-house databases (10+ years of crawling) to provide in-depth insights on threat hosts and attack infrastructure, performing real-time host configuration analyses for detection, mitigation, and remediation.
Quantifiable outcome
- Real-time actionable threat intelligence for detection, mitigation, and remediation workflows
- +2 more outcomes
Companies that use Threat Intelligence Platform
Customer profileSegments5 records
Ideal customer profiles4 records
Threat Intelligence Platform technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability1 record
Feature7 records
Threat Intelligence Platform partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- WHOISXMLAPI.comcoreWHOISXMLAPI.com and ThreatIntelligencePlatform.com are associated products providing complementary domain research and threat intelligence capabilities. WHOISXMLAPI offers the Domain Research Suite (WHOIS Search, WHOIS History Search, Reverse WHOIS Search) while TIP provides Domain Name Analysis for cybersecurity forensics investigations.
Scale indicators5 records
Recent moves5 records
Expansion highlights5 records
Threat Intelligence Platform competitors and assessment
Company assessmentDirect peers
- Censys: Censys provides API-driven internet intelligence scanning hosts, certificates, and domains for threat hunting and ASM. Its data overlaps directly with TIP's Domain Infrastructure, SSL Certificate Chain, and Connected Domains APIs, serving similar SOC and security researcher use cases.
- VirusTotal: VirusTotal is a free file and URL/domain scanning service backed by Google, aggregating dozens of threat intelligence feeds to score maliciousness. It directly overlaps TIP's Domain Malware Check, Connected Domains, and Domain Reputation APIs, serving the same SOC and security researcher audience.
- SecurityTrails: SecurityTrails offers API-based access to historical DNS, WHOIS, and domain/IP intelligence for security investigations and ASM. Its API-first model, historical data depth, and use cases map directly onto TIP's Domain Infrastructure and Connected Domains APIs.
- Recorded Future: Recorded Future is a leading commercial threat intelligence platform (now owned by Mastercard) that ingests and correlates data from across the open, dark, and deep web to deliver real-time threat intel. It competes head-to-head with TIP's domain/IP/SSL threat intelligence feeds for enterprise SOC and security team budgets.
- DomainTools: DomainTools is a long-established provider of WHOIS, DNS, and domain reputation data with both web interface and API access. It is one of TIP's closest competitors, particularly for the Domain Reputation and Connected Domains use cases among enterprise security teams.
- Shodan: Shodan is a search engine and API for internet-connected devices and exposed services, used heavily by security researchers for attack surface reconnaissance. It overlaps with TIP's Connected Domains and Domain Infrastructure APIs for SOC and ASM use cases.
Others
- WhoisXML API: WhoisXMLAPI is TIP's strategic partner providing WHOIS lookup, history, and reverse WHOIS data. While not a direct competitor for threat scoring, it is adjacent in the domain intelligence ecosystem and represents a complementary data provider that could also substitute for parts of TIP's offering.
Broad incumbents
- CrowdStrike Falcon Intelligence: CrowdStrike's Falcon Intelligence module delivers threat intelligence tightly integrated with its endpoint detection platform. It competes for the same enterprise spend pool as TIP, but CrowdStrike's bundling and scale make it a broader incumbent threat to independent threat intel APIs.
- Mandiant Threat Intelligence: Mandiant (now part of Google Cloud) offers comprehensive threat intelligence alongside incident response and consulting. While not a domain-reputation API specialist, it competes with TIP for enterprise threat intel budgets and frequently bundles proprietary IoC feeds into larger security engagements.
Emerging players
- AlienVault OTX: AlienVault's Open Threat Exchange is a free community threat intelligence platform operated by AT&T Cybersecurity. It overlaps with TIP on IoC sharing and domain reputation, but is positioned as a community-driven, lower-premium alternative to TIP's paid API product.
Market position
Strengths5 records
Weaknesses1 record
Competitive moat3 records
Key risks5 records
Key highlights5 records
Customer concentration
Threat Intelligence Platform social profiles
Digital presenceThreat Intelligence Platform financial estimates
Financial estimateRevenue estimate
Valuation estimate
Threat Intelligence Platform leadership team
Management profileNumber of profiles
Profiles1 record
Threat Intelligence Platform funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Threat Intelligence Platform M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Threat Intelligence Platform
What does Threat Intelligence Platform do?
Threat Intelligence Platform provides API-based cyber threat intelligence that combines multiple threat feeds with 10+ years of proprietary crawled data to deliver real-time analysis of domains, IPs, DNS, and SSL certificate configurations. The product is a suite of six RESTful APIs (Domain Infrastructure Analysis, SSL Certificate Chain, SSL Configuration Analysis, Domain Malware Check, Connected Domains, and Domain Reputation) plus an Attack Surface Management solution, used by security teams, SOCs, and cybersecurity product vendors for threat detection, mitigation, and remediation.
Is Threat Intelligence Platform a public or private company?
Threat Intelligence Platform is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Threat Intelligence Platform founded?
Threat Intelligence Platform was founded in 2016. It employs 1 to 10 people.
Where is Threat Intelligence Platform based?
Threat Intelligence Platform is headquartered in Walnut, United States, in the North America region.
How does Threat Intelligence Platform make money?
One revenue line is on record: API Subscription and Usage.
Who are Threat Intelligence Platform's main competitors?
Direct peers on record are Censys, VirusTotal, SecurityTrails, Recorded Future, DomainTools and Shodan. WhoisXML API is listed as an others. Broad incumbents are CrowdStrike Falcon Intelligence and Mandiant Threat Intelligence. AlienVault OTX is listed as an emerging player.
Does Threat Intelligence Platform have an API?
Yes. Threat Intelligence Platform offers RESTful APIs for cyber threat intelligence that can be integrated into cybersecurity products, SIEM solutions, DRP solutions, and third-party systems. The APIs are described as robust, scalable, and capable of 100 queries per minute. The platform consists of 6 different security analysis APIs: Domain's Infrastructure Analysis API, SSL Certificate Chain API, SSL Configuration Analysis API, Domain Malware Check API, Connected Domains API, and Domain Reputation API. Data is provided in unified and consistent JSON format. Developer documentation is at threatintelligenceplatform.com/threat-intelligence-api-docs.
What industry is Threat Intelligence Platform in?
Threat Intelligence Platform's product category is Cybersecurity Threat Intelligence. Its primary akta.pro industry code is BPAEADAC, Threat Intelligence Services, with a secondary code of HDADAHAI, Vulnerability Intelligence & Exploit Prediction. Its NAICS code is 541519 and its SIC code is 7373.