The Liberty91 platform, part by part.
Liberty91 runs the whole threat intelligence job. You write down what you need to know and what your organisation owns, and from there a set of agents reads everything that comes in against it and gets the result to the people who act on it.

Intelligence Requirements.
Where everything starts
An Intelligence Requirement is a specific question your organisation needs answered about threats, written in your own words. Each one gets its own agent that reads every new piece of reporting, keeps its own knowledge base on the subject, and tells you what the latest development means for you.
If you call these Priority Intelligence Requirements, it is the same thing with prioritising added, and the platform does the prioritising for you.
Requirements are not only about attackers. They cover the suppliers you depend on, the technology you run, your executives, and confidential interests such as a deal in progress. They also read each other, so one question comes back as one answer with its sources, drawn from everything relevant. Anything you write, and any data you add, stays private to your organisation.
How Intelligence Requirements work →
What sits around it.
Three more parts turn a requirement into something your team can use.
Document Upload.
What your organisation actually owns
Send over the documents your team already keeps: vendor contracts, lists of the systems you run, network diagrams, security policies. Liberty91 reads them into a private store, picks out the systems and suppliers they mention, and shows you what it found before anything is saved. From then on it can tell you whether a given threat touches you, and point at the document that says so.
How Document Upload works→The agents.
The reading and the analysis
The platform runs a stack of specialised agents rather than one model. Some call out to VirusTotal, Shodan and GreyNoise to enrich indicators, some pull the entities out of a report, and some work out when two reports are describing the same thing. Others apply tradecraft such as ACH and the Admiralty scale, keep each knowledge base current, judge how much of a development applies to you, and draft what comes out the other end. Your analysts keep the judgement calls.
How the agents work→Mailroom.
Getting it to the person who acts on it
Intelligence only lowers risk once it reaches whoever can do something about it. Mailroom is where you send things out: written reports, indicator lists formatted for the SIEM, Sigma detection rules mapped to MITRE ATT&CK, and STIX 2.1 bundles for MISP or OpenCTI. Every send is written to a log you can search per organisation.
How Mailroom works→How the parts fit together.
Set-up is two steps, and the analysis carries on from there on its own.
You say what you need to know
Write your Intelligence Requirements in plain language: a sector, a ransomware crew, a supplier, a group of systems, an executive, an acquisition you are working on. There is no code and no rules to write.
You say what you own
Upload the documents that describe your estate and your dependencies. Confirm what Liberty91 picked out of them, and each organisation in your account now has a profile to measure threats against.
The agents read everything against it
New reporting arrives around the clock and is read against every requirement it touches. When something matters to two of them, both look at it, and each writes it up for its own audience.
It goes out to whoever needs it
The same requirement can produce a short brief for the board, detection rules the SOC can load, an answer to a stakeholder question, and a customer report under your own brand. Mailroom is where you send it, and it keeps the record.
Working with it directly.
Plenty of teams want to reach the platform from their own tooling, or to see how the work is done before they buy anything.
Public API.
Query threat events, the threat library, and your own organisations from your own tooling. Authentication, pagination, rate limits, and credits are all documented.
Read the API docs→CTI Skills.
Our free, MIT-licensed pack of 75 threat intelligence skills for Claude Code and other Agent Skills-compatible tools, covering investigation, tradecraft, detection writing, and lookups against the tools you already pay for.
Browse the skills→Documentation.
The full manual: core concepts, the dashboards, how threat events and entities behave, and the day-to-day workflows for analysts and MSSP teams.
Open the docs→The same platform, described for your role.
The platform works the same way underneath, but what you get out of it depends on the job you are doing.
Frequently Asked Questions.
Put this to work on your own threats.
Our free Community Tier is on the way, so any analyst can put AI-powered threat intelligence to work with no budget and no team. Join the waitlist to be first in line: the first 100 sign-ups get a month of our Analyst Tier free. Or grab our free, open-source CTI Skills for your AI coding agent today.
Want to see this on your own organisation?
Request a demo or start your free trial, and you will be looking at threat intelligence built around your own organisation rather than a generic one.