LifeRaft — since March 2026 a Securitas company — is a specialist: OSINT collection across social, fringe and deep-web sources, feeding an investigations workspace. Threatwhere is built for a different job: running the operation — live map, travel risk management, grounded AI documentation, alerting.
Liferaft iQ summarises what its collectors found. But nobody briefs a board on a search result. Threatwhere writes the finished product — eleven governed document types — and then runs the operation it was written for: geofences, check-ins, evacuation plans built on your own doctrine, debriefs frozen into the record. On OSINT collection depth, LifeRaft is the stronger documented offering — we put that in writing. Collection is not the deliverable.
What it takes to fill their column
The LifeRaft column draws on the core platform plus the Liferaft iQ AI layer, the Global Awareness mapping add-on and seat/data/add-on-based licensing. Our column is one platform — Overwatch for the operations room, with an Operator licence for the field included in every Overwatch seat.
Quote-only, scaled by seats, data volume and add-ons.
$1,999 /seat/month — Overwatch
Every Overwatch seat includes an Operator licence for the field at no extra cost; standalone Operator seats from $199/month. $19,990/seat billed annually. Every number is on our public pricing page.
How you buy
Published pricing and a self-serve 7-day trial — sign up and start without a sales call. Overwatch $1,999/seat/month with an Operator licence included per seat; standalone Operator seats from $199/month.
None of the five vendors on these pages publishes a price; every one routes you to a sales conversation. Third-party buyer-reported estimates — not vendor list prices — show quote-only pricing varies materially by deployment and buyer: Everbridge estimates alone span roughly $15,000 to over $300,000 a year. When the range is that wide, the price is about you, not the product. source
These are the documented reasons Liferaft belongs on a serious shortlist — from their own public materials. The matrix below shows where Threatwhere takes the operation further.
OSINT reach: mainstream social media, blogs, forums, message boards, alternative and fringe platforms, news sites, and deep and dark web content. source
Investigations workspace: Case Manager and Dossiers organise investigations, track developments and keep a complete record of intelligence and evidence. source
Momentum and backing: roughly US$15.3 million ARR at end-2025 with organic growth above 30%, acquired by Securitas in March 2026. source
AI layer: Liferaft iQ generates automated report summaries from your datasets. source
These 19 rows compare the documented route to each outcome — including separately sold modules, partner integrations and announced roadmaps. Every affirmative Liferaft cell links to its public source; a dash means not publicly documented, nothing more.
| Capability | Threatwhere | Liferaft |
|---|---|---|
| Intelligence & AI documentation | ||
| AI security documentation (multi-type) | ✓Eleven intelligence products from one platform — briefs, risk assessments, entity profiles, travel dossiers, digests, pattern detection, route analysis, event analysis, NEO evacuation plans, 7-day threat forecasts and trip debriefs. | ◐Liferaft iQ’s AI-Powered Reporting delivers automated summaries of your datasets. Multi-type intelligence documents are not publicly documented.Liferaft iQsource |
| Conversational AI grounded in its own intelligence corpus | ✓Conversational assistant grounded in the platform’s own intelligence corpus — ask in plain language, receive a finished document. | —The iQ feature set documents search, digests and reporting; a conversational assistant is not publicly documented.Liferaft iQsource |
| Country / regional risk scoring | ✓Live scored country-risk baseline held in the platform; AI risk language is anchored to it, not estimated. | ◐An announced partnership with GeoSure integrates neighborhood-level GeoSafeScores — location scoring rather than a country risk index.GeoSure partnershipsource |
| Voice-operated intelligence | ✓Speak a query, hear a summary; the full document renders on screen. | —Not publicly documented. |
| Retraction / provenance controls on AI output | ✓Retract intelligence once and it is excluded from every future document — automatically. | —Its FAQ documents tailorable data retention; retraction propagation into AI output is not publicly documented.source |
| OPSEC output governance | ✓Every deliverable protects sensitive tooling, collection and attribution details before release. | —Not publicly documented. |
| Organisation-doctrine personalisation of AI output | ✓Your own doctrine library and organisation preferences shape supported products, including evacuation plans built on your SOPs. | —Not publicly documented. |
| Operations | ||
| Geospatial common operating picture | ✓Live global threat map with an in-map AI assistant — click a threat, ask about it, generate the document. | ✓The Global Awareness feature maps the precise locations of potential risks alongside geospatial intelligence on key terms, entities and events.Global Awarenesssource |
| Travel risk management workflow | ✓Missions, pre-travel dossiers with verified emergency contacts, scheduled check-ins, and post-mission debriefs that freeze into the record. | ◐Traveler-safety alerting on risks near destinations, in near real time. Pre-trip briefs, check-ins and trip records are not publicly documented.source |
| Evacuation / NEO planning | ✓Generated NEO evacuation plans with facility-validated extraction points and doctrine retrieved from your own library. | —Not publicly documented. |
| Geofencing and location alerting | ✓Draw a geofence; events and incidents inside it trigger alerts with your threat-score threshold, in real-time or digest. | ◐Its materials discuss monitoring geo-tagged posts inside a fixed virtual perimeter as an OSINT use case. Alerting tied to a moving person or device is not publicly documented.source |
| Intelligence document workspace | ✓A shared intelligence workspace with folders, team sharing at view, comment or edit, and organisation-scoped permissions on every document. | ✓Case Manager and Dossiers keep a complete record of intelligence and evidence in one place.Case Managersource |
| Auto-filing of generated intelligence | ✓Completed reports file themselves — mission reports into the mission workspace, personal research kept private. | —Not publicly documented. |
| Branded export with report-type banners | ✓Consistent branding across print, PDF and email export, with report-type banners and links back into the platform. | ◐Stakeholder-ready reporting with customizable dashboards and visualizations; branded PDF export is not publicly documented.source |
| Platform & reach | ||
| Enterprise access control | ✓Enforced multi-factor authentication, per-seat entitlement and organisation-scoped access across every intelligence surface. | ◐Its product page displays ISO 27701:2022, AWS, CIS V8, Microsoft SSPA and NIST CSF 2.0 marks. SSO/SAML is not publicly documented.Platformsource |
| OSINT collection & public-web augmentation | ✓Multi-source intelligence across open news at global scale, the open web, social platforms and closed messaging channels — without publishing a source inventory. See the note on “dark web” below. | ✓Collection across mainstream social, blogs, forums, fringe platforms, news, and deep and dark web content — the product’s core function.Core platformsource |
| Real-time multi-source intelligence feed | ✓Continuous multi-source intelligence delivered live to the dashboard as events, incidents and country risk develop. | ✓Continuous automated monitoring of global public sources with real-time alerting.Core platformsource |
| Mass notification | ◐Multi-channel alerting driven by intelligence triggers — routed to the people the intelligence actually affects. Life-safety broadcast to an entire population is a different category of product. | ⧉Analyst notifications via email, text and Slack; mass notification is reached through its documented Everbridge integration.Everbridge integrationsource |
| Mobile field / operator app | ✓Threatwhere Operator: acknowledged SOS, scheduled safety check-ins, and dependable background location for field teams. | —Its mobile app is described as supporting alert-based workflows; SOS, check-in and lone-worker functions are not documented in the store listing.Mobile appsource |
When a vendor says “dark web”, they mean unindexed websites and .onion services. It photographs well on a datasheet. But for geopolitical and physical-security intelligence — the job this platform does — the signal overwhelmingly lives in the open: news at global scale, social platforms, and the closed messaging channels where events are reported first. Even most breach chatter surfaces faster in the open than in the markets themselves.
So we spend collection where the signal is — and, deliberately, we don’t list our sources on a marketing page. The same output-security layer that stops our documents revealing collection applies to how we talk about it: a vendor that itemises its sources to impress you is telling adversaries the same thing. If credential-market or brand-protection monitoring is your primary requirement, test specialist depth directly. For geopolitical and physical-security operations, Threatwhere turns intelligence into the assessments, plans and field workflows your organisation acts on.
LifeRaft does not publish pricing — plans scale by seats, data volume and add-ons. Threatwhere publishes its pricing — Overwatch at $1,999/seat/month, an Operator licence included with every seat, standalone Operator seats from $199/month — all on a public pricing page.
Securitas AB. The acquisition was announced in February 2026 and completed on 18 March 2026.
Its documented strength is OSINT monitoring and investigations. TRM workflow elements — pre-trip briefs, traveler check-ins, trip records — are not publicly documented.
LifeRaft’s documented strength is OSINT collection and investigations — if a search index is the deliverable, it is a serious tool. Nobody briefs a board on a search result. Threatwhere writes the finished intelligence and runs the operation: live map, documentation with provenance, travel risk management, alerting — at a published price.
All competitor information on this page was verified against the linked public sources as of 15 August 2026, and is re-verified quarterly. “Not publicly documented” means exactly that — it is never a claim that a vendor lacks a capability. Third-party price figures are buyer-reported or analyst estimates, never vendor list prices. All product names and trademarks belong to their respective owners; comparisons are provided for evaluation purposes. See something outdated? Tell us via our contact page and we will correct it.
Use the 7-day trial to generate a finished intelligence product from your own operating picture — or book a demo and make us prove the claims that matter to your operation.