Liberty91

A threat intelligence platform that does the work.

Many platforms hand you the tools and leave the actual work to your team. Liberty91 does the work: the gathering, the analysis, the writing, and the sending, tailored to each organisation it covers. Real intelligence at machine speed, with no team to build.

Start for Free

What a threat intelligence platform should do.

A threat intelligence platform is meant to carry the job from end to end, not just store indicators. Liberty91 does every part of it and keeps what comes out specific to you.

01

Collect

Pull from hundreds of sources without stopping: security news, vendor reporting, paid intelligence, the dark web, and social media, with nobody stitching feeds together by hand.

02

Analyse

Read every event against the Intelligence Requirements that matter to each organisation, add context to the indicators from other sources, and work out what it means for that organisation rather than for the world in general.

03

Produce

Turn what matters into finished work: written reports, lists of indicators of compromise, Sigma detection rules, and STIX 2.1 bundles, drafted and ready to use rather than left as raw data for someone to work through.

04

Deliver

Send the right thing to the right person and the right system through Mailroom, with a record of every send. Intelligence only lowers your risk once it reaches whatever acts on it.

Platform, feed, tool, or service?

People use these words as if they mean the same thing, but they do different jobs. A threat intelligence feed is raw input, a stream of indicators that someone still has to collect, strip of duplicates, and turn into something a colleague can act on. A threat intelligence tool or platform brings those inputs together, adds context from other sources, works out what is relevant, and produces finished intelligence.

Threat intelligence as a service means all of that is run for you as an ongoing service, rather than something you build and staff yourself. Liberty91 sits where those two ideas meet: a platform delivered as a service, so you get finished intelligence written for you without running the machinery behind it.

Read the full explainer: what is a threat intelligence platform (TIP)? →

What makes Liberty91 different.

Plenty of platforms collect and store. What counts is what happens next: how specific the intelligence is to you, and how little work it leaves on your desk.

Tailored to each organisation

Every organisation has its own Intelligence Requirements, built from the systems it runs, its suppliers, its industry, and where it operates, and the platform keeps them up to date. Two organisations in the same industry get different reports because what they need to know is different. The judgement about what matters is made for them, not for a general audience.

Finished intelligence, not just feeds

A feed hands you indicators that someone still has to collect, clean up, and explain. Liberty91 does that work and hands over finished reporting with the background, the detection rules, and what to do about it attached.

Delivered to people and to tools

Reports for the people who need the read, plus lists of indicators, Sigma rules, and STIX 2.1 bundles for the SIEM, SOAR, firewall, and threat intelligence platform further down the line. Structured and scored, so automated and AI security tools can take them in directly.

Real intel at machine speed, no team to build

You get what a mature threat intelligence team produces without hiring one, without licensing sources one by one, and without a 12-month build. The platform does the work end to end, so your people spend their time on judgement rather than plumbing. If you already have a team, it makes them go further: the same analysts cover far more ground, faster, and what they produce is more relevant and easier to act on.

Built for MSSPs and mid-sized budgets

Run it across a whole customer base under your own brand, with each customer kept separate, or run it for one mid-sized team that could never justify a dedicated intelligence programme before. The price works either way.

A record of everything delivered

Mailroom writes every report, list of indicators, detection rule, and STIX bundle to a Sent log you can filter per organisation. That is what you bring to a review, a renewal, or an internal audit of what was shared and when.

Built around Intelligence Requirements.

What makes the output specific to you is the idea the whole platform is built on. Intelligence Requirements are knowledge bases on the topics you care about: sectors, malware families, threat actors, suppliers, the systems you run, and the worries particular to your organisation. The platform keeps them up to date and reads every incoming event against the ones it touches, so each report arrives carrying everything known so far instead of starting from a blank page.

Anything you write, and any data you add, stays private to you. You may know these as Priority Intelligence Requirements, the questions you need answered, put in order of importance. They are the same thing, and Liberty91 keeps that order up to date for you.

How Intelligence Requirements work →

Not just for enterprises.

A threat intelligence platform should not be out of reach for one analyst or a small team. Liberty91 gives a working analyst what they need to move faster: the gathering and the reading already done, indicators that arrive with context from other sources, and finished reporting, with a free tier on the way. If you would rather work on the command line, our open-source CTI Skills pack puts the same analyst methods inside your own AI coding agent today.

A free tier for analysts is on the way. Put your name down to be first in line, try the open-source CTI Skills you can use today, or see how the platform fits into an analyst's week.

Comparing threat intelligence platforms?

If you are weighing up the options, it helps to look at each one on its own merits and work out which fit your team and your budget. We keep a set of straight, factual comparisons for the platforms people ask about most.

See the comparisons →

Frequently Asked Questions.

Want to see this on your own organisation?

Request a demo or start your free trial today, and get straight to AI-powered threat intelligence built around your organisation.