Threatwhere is built for organisations that handle sensitive intelligence. Every layer — from authentication to data storage — is designed to meet the highest security standards.
Enterprise-grade security controls your compliance team can trust.
Hosted on enterprise cloud infrastructure that is independently certified to SOC 2 Type II for security, availability, and confidentiality. Attestations available to enterprise customers under NDA.
Full data subject rights support including access, rectification, erasure, and portability. Data processing agreements available for all enterprise customers.
Information security managed to ISO 27001 principles, on infrastructure independently certified to ISO 27001, 27017, and 27018. A risk-based approach protects intelligence data at every layer.
Defence in depth at every layer. From network edge to database row.
AES-256 encryption at rest and TLS 1.2+ in transit. All intelligence data is encrypted before storage and during every network hop.
Logical tenant isolation enforced on every request. Each organisation's data is segregated with no cross-tenant access.
Strict Content Security Policy, HSTS preloading, X-Frame-Options, and automatic HTTPS redirect. Every request is hardened by default.
Granular permission model with organisation owner, admin, analyst, and viewer roles. Restrict access to intelligence by clearance level.
Threatwhere supports multiple authentication methods to fit your organisation's security posture. Enforce MFA across your team, manage active sessions, and integrate with your existing identity provider.
Complete audit trail across your organisation. Know who accessed what, when, and from where.
Purpose-built infrastructure for intelligence-grade data handling.
Serverless database infrastructure with automatic scaling, point-in-time recovery, and encryption at rest. Data isolated per tenant.
High-dimensional vector embeddings for semantic intelligence search and AI-powered analysis. Purpose-built for threat correlation.
In-memory session management, rate limiting, and request caching. All transient data encrypted at rest with automatic expiry.
Multi-region edge deployment with enterprise DDoS protection, automatic failover, and zero-downtime deployments.
Need our security whitepaper, questionnaire responses, or infrastructure attestations? Get in touch and we'll share what your compliance team needs — detailed attestations available under NDA.