DugganUSA
Live threat intelligence · Speed to truth and accuracy

A breach breaks. Our analysis is already published — timestamped, before the news, with the receipts.

When the next OAuth compromise, ransomware wave, or exploited zero-day drops, the defenders searching for what actually happened find our breakdown already up — named, dated, and cross-referenced against a feed of indicators the big vendors resell but don't have (88% of ours aren't in ThreatFox). Then we price it so a defender can actually afford to act on it.

Start free — 25 lookups/day Why we're different
No credit card. Free tier is real. If it earns its keep, upgrade.
275+
orgs pulling our feed
46
countries
~75%
indicators not in ThreatFox
2
breach calls before disclosure
SAM.gov
federally registered
The moat

Four things a bigger vendor structurally can't copy by writing a check.

The incumbents are optimized to protect the customers they already have. We're optimized for the thing that actually wins: getting to a true, defensible call faster and cheaper than the attack it stops.

01. Novelty, measured

Roughly three-quarters of the indicators we publish are not in ThreatFox. We measure it weekly and show the number — it's not a slogan, it's a metric you can check.

02. Receipts, timestamped

We've named breaches in our public archive before the vendor advisories landed — with the comparator timestamp attached. Anyone can read the post and check the date. Lead time you can audit beats confidence you can't.

03. Cost asymmetry

We engineer the cost of producing a detection below the cost of the attack it defeats. That's why a $0–10K defender can run intelligence that used to require an enterprise contract.

04. AI-native, from the metal

The platform was built AI-first, not bolted on. That pace is a strength, not a dependency — every published call is human-reviewed, and the whole pipeline is instrumented to catch its own mistakes (we cap and kill abusers of our own feed, publicly and honestly).

Straight talk

How we're different from the name-brand feed.

Sells you its conclusions.
Shows you the receipt — indicator, source, and the timestamp.
Resells indicators everyone already has.
Publishes the ~75% the common feeds don't carry.
Priced for the Fortune 500.
Priced so a small team can act — free tier included.
Reports vanity volume.
Reports the honest number, even when it's smaller.
No funding · Two people · Receipts

Where we kick ass — and how you'd check it.

No venture capital. No Series A. Two people on a budget you'd mistake for a rounding error. That's not the apology — it's the point. Every claim below comes with something public you can verify.

01. We call breaches before disclosure

Six weeks before ShinyHunters disclosed 9M records stolen from Medtronic, we'd published the full medical-device attack-surface matrix. We had Nissan's C2 infrastructure 28 days before that breach surfaced. Dated, public posts — receipts, not forecasts.

02. We publish what the feeds don't

100% of the indicators we source independently — supply-chain hunts, honeypot hits, research imports, bulletproof-ASN maps, malicious packages, brand-impersonation GitHub repos — are not in ThreatFox. Computed live, weekly, at a public endpoint. A query, not a slide.

03. We beat CISA to the KEV

When we and CISA land on the same exploited vulnerability, we tend to get there first — a median ~12 days ahead, tracked live. We don't lead every time, and we publish that honesty too. But when we lead, it's the days a defender uses to close the door.

04. National-CERT scale, hobby budget

1M+ indicators. 275+ organizations across 46 countries pulling the feed — including a U.S. military branch and allied critical-infrastructure operators. ~18M documents indexed. On roughly $6,000 a year. Two people.

05. Compliance most funded startups skip

SOC 2 Type 2 (81%). DORA Elite, verified. FDA 510(k) readiness (95%). 34 patent filings. ~3,000 evidence files. Bootstrapped. The scaffolding a serious buyer needs — and most companies our size don't have.

06. Why no funding is the flex

We don't out-spend CrowdStrike; we engineer the cost of a detection below the cost of the attack it defeats — with zero outside money. A company that needs a war chest to make the math work has a fragility we don't. The lean team is what produced all of the above.

One platform

Everything under one roof — not a shelf of half-products.

Search, distribute, correlate, and defend from a single source of truth.

STIX / TAXII feed

1M+ indicators, updated continuously, with Splunk ES, OPNsense, Suricata, and DNS-sinkhole plugins. Pull it into what you already run.

Jeevesus graph

Cross-correlate an indicator across 17M+ documents — IOCs, actors, CVEs, and our own predictive coverage — through one hybrid search.

Edge Shield

A Cloudflare Worker that enforces our high-confidence blocklist at your edge, before traffic ever reaches your origin.

AIPM

See and fix how AI assistants describe your brand — the new front page nobody's watching.

See it work

Live tools & visualizations — the receipts you can click.

Not screenshots, not a demo request — the actual production surfaces, open to anyone, no key required. Toys and tools are how you demonstrate command of a topic instead of claiming it.

🔎 Jeevesus Search

Hybrid keyword+semantic search across 17.9M+ documents — IOCs, actors, CVEs, and our own predictive coverage. Keyless.

🎯 Brands Under Attack

Live view of the brands adversaries are staging impersonation infrastructure against — before the breach.

⚡ KEV Lead Tracker

Where we flagged an exploited CVE ahead of CISA — with the timestamps to prove the lead.

🏢 Vendor Risk Matrix

Where in-the-wild exploitation actually concentrates by vendor — straight from CISA's KEV catalog.

🧅 Tor Pulse

Hourly Tor consensus snapshots and operator-cluster attribution — infrastructure most feeds never touch.

🛰️ Attack Surface Scanner

crt.sh → DNS → Shodan → KEV → AIPM for any domain, rendered as one graph.

🔭 MCP Watchtower

Security posture of the MCP-server ecosystem — the supply chain AI agents pull from.

🧠 AIPM

How AI models describe your brand — audited, scored, and fixable.

📊 Platform Status

Every cron and validation axis, live — a platform that hides its own health is hiding something.

Get started

Read the feed. Check the receipts. Then decide.

Free tier is 25 lookups a day, all indexes searchable, no card. If you like it enough to lean on it, that's when you register for more.