Do More Threat Intelligence, Faster.
Our AI agents learn what your organisation runs and who is likely to come after it, then collect security news as it breaks, work out what it means for you, and write up reports you can act on and pass on.
Start Free Trial
What is Liberty91?
Keeping up with what is happening in security takes hours nobody has. Liberty91 is built to drastically reduce the time you spend on threat intelligence and security research.
It gathers security events, works out what they mean, and writes them up for you, so your time goes to the work only you can do. Our AI agents know what your organisation looks like and apply the same methods a trained analyst would, so they rapidly identify and prioritise critical threats and you can respond instantly.
7x
Faster intelligence
85%
Quicker response
24/7
Threat monitoring
An AI Analyst That Never Sleeps.
Liberty91 is a group of AI agents that works alongside you as a real-time junior threat intelligence analyst. It is not one model but several specialists: knowledge agents that stay current on the threats that matter to you, and tradecraft agents that put every event through the methods a trained analyst uses, from rating how reliable a source is to weighing each possible explanation against the evidence (Analysis of Competing Hypotheses).
What comes back is analysis at both the big-picture and the day-to-day level, indicators of compromise (the IP addresses, domains, and file hashes tied to an attack), detection rules and more. You get it as written reports, as STIX bundles, or pushed into the security tools and workplace apps you already use.
And it scales indefinitely. Whether that is one dedicated analyst for your own organisation or hundreds across your MSSP customers, each one gets its own set of agents that knows that customer's environment.

Analyst or team of one?
Our free Community Tier is on the way, so any analyst can put AI-powered threat intelligence to work with no budget and no team. Join the waitlist to be first in line: the first 100 sign-ups get a month of our Analyst Tier free. Or grab our free, open-source CTI Skills for your AI coding agent today.
Built for Your Role.
For Analysts.
The gathering is done before you sit down: sources pulled together, checked, and given context from elsewhere, with a plain description of why each threat event matters to you and what it could do. Answer Requests for Intelligence, the questions colleagues send you, in minutes, turn what you find into Sigma, YARA, and KQL detection rules, and keep your time for the genuinely interesting work.
Learn more →For MSSPs.
Sell threat intelligence under your own brand without building the practice first. Every customer gets reports written for them, surfaced, prioritised, and drafted in real time, so you get to them with it before anyone else does. Two days of manual work becomes seven minutes.
Learn more →For Security Leaders.
Stand up a working threat intelligence capability without the cost, the complexity, or the long wait, and get something you can use on day one. Serve everyone with a stake in security, not only the SOC, and see developing threats set against the controls you already have, so you know which ones to shore up first.
Learn more →Intelligence Requirements.
An Intelligence Requirement is simply a question your team needs answered on an ongoing basis: about a sector, a malware family, a threat actor, a supplier, a group of systems, a senior executive, anything that matters to you. Liberty91 turns each question into a knowledge base that keeps itself current and reads every incoming event against every requirement it touches, so each event arrives carrying everything learned on that topic so far.
We keep our own Intelligence Requirements up to date as a shared knowledge base, and you can add your own on top, which stay private to you, whether you run them for your own organisation or, as an MSSP, on behalf of your clients. They also refer to each other, so a single question comes back as one answer with citations across everything relevant.

Platform Features.

Real-time collection.
We watch hundreds of sources for security news and threat reporting, all day, every day.
- Security News & Blogs, Vendor Reports
- Premium Intelligence Sources
- Darkweb
- Social Media

Instant analysis based on your profile.
Every event goes through the methods a trained analyst would use, from rating how reliable the source is to weighing each possible explanation against the evidence, and is then judged on how much it matters to you specifically. Connect your attack surface, supply chain, and asset inventory tools, and that picture of your environment keeps itself up to date.

Actionable reports and alerts.
Get an alert the moment there is something you need to know, or send it straight into any of thousands of platforms you already run: your ticketing system, SIEM, SOAR, or threat intelligence platform.

Get intelligence to the people who act on it.
Mailroom sends reports, indicators of compromise, Sigma detection rules, and STIX bundles to the people who need them, and keeps an auditable Sent log of everything that went out, across every organisation in your account. It covers the last step of the intelligence cycle, actually getting the work into the right hands.

Set up an organisation in minutes.
Skip the manual data entry. Upload documents you already have, asset inventories, supplier registers, network diagrams, or a corporate profile, and Liberty91 pulls out the Assets and Suppliers for you to confirm in a couple of clicks. The agent looking after each organisation remembers all of it, so every new event is judged against your real environment.

Use detection rules to take immediate action.
Every intelligence package gives you more than indicators of compromise (IOCs). You also get Sigma detection rules written for the specific threat the package covers, ready for your SIEM and your next hunt. We'll tell you what to look for, where to find it, and what might trigger a false positive.
Liberty91 Morning Report
to: security-team@acme.com
Daily Cybersecurity Morning Report, April 2, 2026
Tailored Threat Intelligence Report
Executive Summary
Critical cybersecurity threats including actively exploited Google Chrome vulnerabilities, regional scams targeting travelers and grieving families in the UK, and a complex web of data breaches and phishing campaigns impacting major technology companies.
Attack Surface Threats
Google Chrome, CVE-2026-5281
Actively exploited zero-day, CVSS 8.8. Patch by April 15.
EvilTokens Phishing-as-a-Service
New kit targeting Microsoft accounts via device code phishing.
SLSH / Scattered Spider Data Exfiltration
3M+ Salesforce records from major U.S. tech company.
Regional: United Kingdom
Reservation hijack scams targeting travelers via compromised booking systems.
Arrive at the office in-the-know.
The daily email is more than a round-up of the latest security news. It summarises everything published in the last 24 hours, works out what it means, and says how much of it applies to you. You arrive at the office already knowing how the latest events touch your own organisation, your sector, and the systems you actually run.
Frequently Asked Questions.
Want to see this on your own organisation?
Request a demo or start your free trial today, and get straight to AI-powered threat intelligence built around your organisation.