Mallory
Mallory is an Austin-based AI-native threat intelligence and exposure management SaaS platform that correlates global adversary activity with each customer's attack surface, serving enterprise SOC, threat intelligence, and vulnerability management teams through a natural-language AI agent and scheduled autonomous investigations.
- Company typePrivate
- Founded2025
- HeadquartersAustin, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Mallory does
Mallory Intelligence, Inc. (operating as Mallory, DBA Mallory.ai) is an Austin-based, AI-native threat intelligence and exposure management SaaS vendor founded in September 2025 and launched to general availability in March 2026. Its platform aggregates thousands of disparate threat sources — vendor advisories, dark web forums, research blogs, GitHub disclosures, and government feeds — into a structured graph of threats, actors, and exposures, then uses OpenAI GPT-4/GPT-5 models routed through the Portkey AI gateway to correlate that global adversary activity against each customer's actual attack surface, drawn from connected code repositories, cloud, EDR, identity, SaaS, SIEM, and ticketing systems. The core user experience is a natural-language AI agent (Mallory Agent) with scheduled autonomous agents that continuously run exposure questions and deliver pre-answered verdicts — affected or not affected, with owners notified and actions queued — rather than raw alerts.
The company sells through a hybrid product-led and field-sales motion: self-service signup with a 14-day free trial at app.mallory.ai for the Free tier, with quote-based Team and Enterprise subscriptions that include SAML SSO (Okta, Microsoft Entra ID, Google Workspace), advanced integrations, and an MSA. Distribution is augmented by a remote MCP server at app.mallory.ai/api/mcp that exposes the platform's intelligence as native tools for Claude Code, Cursor, and Claude Desktop, plus webhook and app integrations into Slack, Microsoft Teams, Google Chat, and GitHub. Marketing relies on content, community Slack, developer relations, and presence at Black Hat USA 2026, with a recently launched Compromised Package Audit tool extending the platform into software supply-chain exposure monitoring.
Mallory is a venture-backed private company that closed a seed round in April 2026 led by Decibel Partners with Live Oak Venture Partners and individual investors from Google, Robinhood, Cisco, Fastly, GreyNoise, HD Moore (Metasploit creator, runZero CEO), and Dan Hubbard. The company achieved SOC 2 Type 2 certification less than 60 days after GA in May 2026, has 1–10 employees, is led by CEO Jonathan Cran (former Google and Mandiant executive), and lists Texas Mutual Insurance, a Fortune 500 healthcare organization, and runZero as named reference customers.
Mallory firmographics
Firmographics- Name
- Mallory
- Legal name
- Mallory Intelligence, Inc.
- Website
- https://mallory.ai
- Company type
- Private
- Founded year
- 2025
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Mallory is an Austin-based AI-native threat intelligence and exposure management SaaS platform that correlates global adversary activity with each customer's attack surface, serving enterprise SOC, threat intelligence, and vulnerability management teams through a natural-language AI agent and scheduled autonomous investigations.
- Ownership category
- akta.pro rank
Mallory industry classification
Industry- Product category
- Threat Intelligence Platform
- NAICS
- Software Publishers (513210)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Deception Technology & Threat Hunting (HDADAGAI)
Keywords
Where Mallory is headquartered
LocationHeadquarters
- HQ city
- Austin
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Mallory business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Operations, Marketing or Sales, Infrastructure
Revenue model
- SaaS Platform Subscription: Subscription-based SaaS platform with tiered plans (Free, Team, Enterprise). Available with 30-day free trial initially, now 14-day free trial. Paid subscriptions with automatic renewal at end of billing periods. Enterprise plans include Master Service Agreement with enhanced data handling commitments.
- Enterprise Licenses: Enterprise-tier subscriptions with custom pricing, Single Sign-On (SAML 2.0), advanced integrations, and contractual data handling commitments including no model training on customer content.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Pay-as-you-go | Free trial with full platform access |
| Subscription | Monthly | Team and Enterprise paid tiers |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels6 records
Mallory product offering
Product offeringCore offering
Mallory sells a SaaS-based AI-Native Threat & Exposure Management platform that continuously ingests thousands of threat sources (vendor advisories, dark web forums, research blogs, GitHub disclosures, government feeds) and correlates that activity against a customer's connected stack of code repos, cloud, EDR, identity, SaaS, SIEM, and ticketing systems. The platform surfaces prioritized, pre-investigated verdicts via a natural-language agent, a structured threat-intelligence graph, and integrations into Claude Code, MCP, REST APIs, and webhooks so security teams can move from raw alert triage to answer-driven exposure response.
Product overview
Mallory offers a unified AI-native threat intelligence and exposure management platform. The core offering is the AI-native threat intelligence platform which correlates global adversary activity with customer attack surfaces. Key product modules include: Mallory Agent (AI conversational agent for intelligence queries), Mallory Threads (contextual conversation interface with scheduling and sharing), Mallory Feed (curated threat/vulnerability overview), Mallory Library (entity browser for actors, malware, CVEs, IOCs), and Mallory Stories (contextualized breaking threat narratives). The platform provides a remote MCP server for AI assistant integration, a REST API for programmatic access, and various communication integrations (Slack, Teams, Google Chat). Free utilities include a PURL parser and RSS feeds.
Differentiator
Problem solved
Functional benefit
Products and services
- Mallory AI-Native Threat Intelligence Platform SaaS platform that correlates worldwide adversary activity with the customer's connected attack surface and delivers prioritized, evidence-based answers instead of raw alerts, for enterprise security operations, threat intelligence, and vulnerability management teams.
- PURL Parser Utility Free, standalone security utility that parses a Package URL (purl) into component parts and looks up known vulnerabilities via the OSV database.
- Mallory RSS Feeds Free, standalone RSS feed subscriptions for Mallory blog posts and breaking threat-intelligence stories, usable in any standard RSS reader.
Companies that use Mallory
Customer profileNamed customers3 records
Segments4 records
Ideal customer profiles3 records
Mallory technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration16 records
AI capability7 records
Feature6 records
Mallory partnerships and signals
Strategic signalPartnerships
17 partnerships are on record, tiered primary and secondary.
- OpenAIprimaryLLM provider used for AI-native threat intelligence features. Mallory routes through OpenAI API (not consumer products) with commitment that prompts are not used for model training. Processing occurs in United States.
- Portkey AIprimaryLLM gateway and request routing provider that adds observability and trace metadata to LLM calls. Enables reliability and request routing across AI models.
- Amazon Web Services (AWS)primaryPrimary cloud infrastructure provider for Mallory. AWS hosts all customer data and account data in us-east-2 (Ohio) region.
- VercelsecondaryWeb application and frontend hosting provider. Account data, usage, device data, and request metadata processed through Vercel's infrastructure.
- CloudflaresecondaryDNS, CDN, web application firewall, and DDoS protection provider. Processes request metadata, IP addresses, and device data.
- ClerksecondaryAuthentication, identity, and session management provider. Handles account information (name, email) and authentication credentials.
- StripesecondaryPayment processing and billing provider. Handles billing contact details and transaction history.
- Temporal TechnologiessecondaryWorkflow orchestration provider (Temporal Cloud). Processes metadata in connection with service workflows.
- PostHogsecondaryProduct analytics provider. Collects usage data, device data, and pseudonymous identifiers to help improve the product.
- Anthropic (Claude)secondaryClaude Code integration enables developers to use Mallory intelligence from command line. MCP (Model Context Protocol) support allows integration with Claude Desktop and other AI assistants.
- CursorsecondaryAI code editor that supports MCP integration with Mallory. Users can query vulnerabilities and threat intelligence directly from Cursor IDE.
- OktasecondaryEnterprise identity provider for SAML SSO integration. Mallory supports Okta Workforce Identity Cloud for enterprise single sign-on.
- Google WorkspacesecondaryEnterprise identity provider for SAML SSO integration. Mallory supports Google Workspace for enterprise single sign-on authentication.
- Microsoft Entra IDsecondaryEnterprise identity provider (formerly Azure AD) for SAML SSO integration. Mallory supports Microsoft Entra ID for enterprise single sign-on.
- SlacksecondarySlack webhook integration for sending alerts and agent results to Slack channels. Also available as interactive Slack app for two-way agent experience via @mention.
- Google ChatsecondaryGoogle Chat webhook integration for sending alerts and agent results to Google Chat spaces via incoming webhooks.
- GitHubsecondaryGitHub integration connects organization repositories to scan for vulnerable dependencies and enable code-aware investigations via GitHub Personal Access Token.
Scale indicators5 records
Recent moves6 records
Expansion highlights6 records
Mallory competitors and assessment
Company assessmentDirect peers
- Anomali: Threat intelligence platform offering threat data ingestion, correlation, and integration with SIEM/SOAR. Directly comparable to Mallory in delivering contextualized intelligence to enterprise SOC teams, with a longer track record and broader customer base.
- Cybersixgill: Threat intelligence vendor specializing in deep and dark web intelligence with automated collection and analysis. Overlaps with Mallory's dark web monitoring claims and enterprise threat intelligence positioning.
- ZeroFox: External threat intelligence and digital risk protection platform covering surface, deep, and dark web. Overlaps with Mallory's threat intelligence plus attack surface monitoring positioning.
- ThreatConnect: Threat intelligence platform combining TIP (Threat Intelligence Platform) with SOAR capabilities. Comparable to Mallory in delivering structured threat intelligence to security operations, with deeper workflow automation heritage.
Emerging players
- VulnCheck: Vulnerability and exploit intelligence platform focused on prioritizing actively exploited CVEs. Closely aligned with Mallory's vulnerability prioritization and EPSS/CVSS-enriched intelligence approach.
- GreyNoise Intelligence: Threat intelligence vendor focused on filtering internet noise and identifying mass-scanning/attack activity. A seed investor in Mallory and a complementary rather than direct competitor, but competes for the same enterprise SOC budget line.
Broad incumbents
- Recorded Future: The largest independent threat intelligence platform, processing intelligence from across the open web, dark web, and technical sources. Competes head-to-head with Mallory in CTI budget lines, but at vastly larger scale (acquired by Mastercard for ~$2.6B).
- CrowdStrike: Endpoint security leader that has expanded into threat intelligence (Falcon Intelligence) and exposure management. Competes broadly with Mallory through its consolidated platform and massive enterprise footprint.
- Mandiant (Google Cloud): Premier threat intelligence brand (now part of Google Cloud) offering intelligence subscriptions, incident response, and managed defense. Directly competitive in CTI, and CEO Jonathan Cran's prior employer — provides both competitive threat and pipeline opportunity.
- Tenable: Exposure management leader (Nessus, Tenable One) competing in vulnerability management and attack surface correlation. Competes with Mallory for the exposure prioritization budget line within enterprise security organizations.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Mallory social profiles
Digital presenceMallory compliance and trust
Trust signalCompliance1 record
Mallory financial estimates
Financial estimateRevenue estimate
Valuation estimate
Mallory leadership team
Management profileNumber of profiles
Profiles1 record
Mallory funding detail
Funding detailFunding overview
Funding rounds1 record
Investors2 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Mallory M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Mallory
What does Mallory do?
Mallory sells a SaaS-based AI-Native Threat & Exposure Management platform that continuously ingests thousands of threat sources (vendor advisories, dark web forums, research blogs, GitHub disclosures, government feeds) and correlates that activity against a customer's connected stack of code repos, cloud, EDR, identity, SaaS, SIEM, and ticketing systems. The platform surfaces prioritized, pre-investigated verdicts via a natural-language agent, a structured threat-intelligence graph, and integrations into Claude Code, MCP, REST APIs, and webhooks so security teams can move from raw alert triage to answer-driven exposure response.
Is Mallory a public or private company?
Mallory is a private company. It is classified as venture growth investor backed and is currently operating.
When was Mallory founded?
Mallory was founded in 2025. It employs 1 to 10 people.
Where is Mallory based?
Mallory is headquartered in Austin, United States, in the North America region.
How does Mallory make money?
Two revenue lines are on record. SaaS Platform Subscription is the primary driver. The others are enterprise Licenses.
Who are Mallory's main competitors?
Direct peers on record are Anomali, Cybersixgill, ZeroFox and ThreatConnect. Emerging players are VulnCheck and GreyNoise Intelligence. Broad incumbents are Recorded Future, CrowdStrike, Mandiant (Google Cloud) and Tenable.
Does Mallory have an API?
Yes. REST API for programmatic access to Mallory intelligence. Supports integrations API for creating and managing connections (e.g., POST /v1/integrations with type and sensitive_data), schedule management (GET/POST/PATCH/DELETE /v1/schedules), and direct querying of all intelligence endpoints. Remote MCP server available at https://app.mallory.ai/api/mcp for AI agent integration. Developer documentation is at docs.mallory.ai/api-reference/introduction.
What industry is Mallory in?
Mallory's product category is Threat Intelligence Platform. Its primary akta.pro industry code is HDADAGAI, Deception Technology & Threat Hunting. Its NAICS code is 513210 and its SIC code is 7372.