One account.
Every client.

ThreatCluster's MSSP tier is multi-tenant from the database up. Customers are first-class records, each with their own feeds, alert rules, webhooks, scheduled digests, and PDF reports. Same product, with the multi-customer plumbing turned on.

Built for the agency model.

Every feature below ships in the MSSP tier today. No roadmap items, no stubs. What's on this page is what's in the product.

Customers as records.

Each client gets a customer record with name, domain, contact email, free-text notes, and a logo. Everything that needs to be scoped to that client (feeds, alert rules, webhooks, digests, reports) keys off it. Customers can be deactivated without losing their history.

  • Search, paginate, edit from Settings → Customers
  • Logo upload (PNG, JPEG, SVG, WebP, up to 5 MB)
  • Per-customer notes for context only your team sees
  • Soft-delete preserves historical digests and reports
Customer setup →

Per-customer scheduled digests.

Daily, weekly, or monthly digests for each customer, tied to a feed you've set up for them. Recipients are configurable per digest. An optional AI prompt biases each digest toward what that client cares about. Healthcare wants HIPAA enforcement, logistics wants maritime CVEs. Same engine, different output.

  • Daily, weekly, or monthly cadence
  • Configurable recipient list per digest
  • Per-digest AI prompt for emphasis
  • Test-send before activating
Digest configuration →

PDF reports with the customer's branding.

ThreatCluster's report generator accepts a brand name and logo URL on export. Pair that with the customer's uploaded logo and the rendered PDF carries their identity, not yours. Same scoring, same entity extraction, same source links. Output you can send as the deliverable.

  • Customer logo and name in the header
  • HTML for archive, PDF for delivery
  • Generate on-demand or schedule
Report generation →

Each client's signal stays theirs.

ThreatCluster has org-scoped feeds, alert rules, and webhooks underneath. The MSSP layer extends that with customer records that aren't tied to a sign-up, so you can run a customer's pipeline without them ever logging in. Per-org alerts route to the client's SIEM, Slack, or ticketing, not yours. No shared workspace, no cross-client bleed.

  • Custom feeds tuned to each client's industry, vendors, or threat profile
  • Alert rules that fire only on their entities or thresholds
  • Webhooks routed to their integrations, with retry and status tracking
  • Member roles (viewer, analyst, admin) per org for delegation
Feeds and alert rules →

API access at MSSP rate limits.

Everything in the dashboard is in the API: customer records, digests, feeds, alert rules. Pull a per-customer threat list into your existing reporting tooling, sync customer state from your billing system, automate onboarding with the baseline alert rules and feeds you'd otherwise click through. MSSP accounts get higher rate limits than Business; specific limits are set per contract.

  • REST API and tc CLI access
  • Higher rate limits than Business
  • Custom limits available per contract
API reference →

When MSSP is the right tier.

If you serve more than one client, the Business tier doesn't have the plumbing for it. No customer record, no per-customer digest, no branded report. MSSP is the same product with that layer turned on.

Researcher

individual
  • Track 100 interests
  • 1 webhook, 3 alert rules
  • 3 reports per day
  • REST API and tc CLI
  • Customer records
  • White-label digests
  • Branded reports

Business

single org
  • Unlimited interests
  • 3 webhooks, 25 alert rules
  • 10 reports per day
  • Dark-web breach matching
  • Org-scoped feeds, rules, webhooks
  • Customer records
  • Per-customer scheduled digests
  • Branded reports per customer

MSSP

multi-client agency
  • Everything in Business, plus:
  • Customer records (name, domain, contact, notes, logo)
  • Per-customer scheduled digests
  • AI-prompt-shaped digests per customer
  • Branded PDF reports per customer
  • Higher API rate limits
  • Custom limits available

Every feature, in one place.

The full MSSP-tier capability matrix. No asterisks, no "coming soon". Every row below is shipping today.

Feature MSSP
Intelligence
Cluster ViewsUnlimited
Entity ViewsUnlimited
Enhanced AnalysisYes
Attack Flows (CTID Attack Flow v3)Yes
D3FEND CountermeasuresYes
CWE ExtractionYes
Public Exploit Tracking (Sonar)Yes
Sub-Article Link EnrichmentYes
X / Twitter IntelligenceYes
Rising Threats (Explore)Yes
Dark Web
Ransomware Leak-Site TrackingYes
Credential Market MonitoringYes
Underground Forum MonitoringYes
Breach MatchingYes
Company Domain MonitoringMulti-customer
Exposure Management
Per-Customer Asset InventoryYes
Asset Connectors (Tenable, Defender, CrowdStrike)Yes
Bulk Upload (CSV / JSON)Yes
API Asset PushYes
CISA SSVC RankingYes
Asset Tagging (internet-facing, crown-jewel, isolated)Yes
Threat Hunting
Industry Threat Models (17 sectors)Yes
Hunting Queries (KQL, SPL, Lucene)Yes
Hunt PlaybooksYes
ATT&CK Navigator ExportYes
Diamond Model ViewYes
IOC Watchlist ExportYes
Feeds and Alerts
Personalised Threat DigestYes
Custom FeedsCustom
Tracked InterestsUnlimited
Alert RulesCustom
WebhooksCustom
RSS FeedYes
MISP Feed50 events
Scheduled ReportsYes
Workflows
Visual Workflow EditorYes
Triggers (cluster, CVE threshold, entity, KEV)Yes
Actions (webhook, Slack, Teams, email, ticket, AI summary)Yes
Dry-Run Against Historical DataYes
Per-Workflow Audit LogYes
Reporting
Report GenerationCustom
Notion-Style EditorYes
Dynamic Content BlocksYes
White-Labelled ReportingYes
Scheduled Delivery (daily / weekly / monthly / quarterly)Yes
PDF / HTML / Markdown ExportYes
Public Shareable URLYes
Theming (dark/light, colours, fonts, logo)Yes
MSSP
Multi-Customer ScopingYes
Customer Portal (read-only client view)Yes
Aggregate MSSP DashboardYes
Customer-Scoped Alert RoutingYes
Per-Customer Exposure ManagementYes
Custom Feature DevelopmentYes
AI
Ask AI (per-cluster)99 / day
Cluster AI (global search)999 / day
Report AI (editor)Yes
Inline Source CitationsYes
Collections and Tags
CollectionsCustom
TagsUnlimited
Team SharingYes (with roles)
IOC Exports
TXT / CSV / JSONYes
STIX 2.1 Bundles (TLP-marked)Yes
Bulk IOC Export (confidence / type / time filters)Yes
Integrations
REST APIHigher limits
CLI (tc)Yes
Agent Tool SurfaceYes
SIEM Ingestion (Splunk, Sentinel, Elastic, OpenSearch)Yes
SOAR / Ticketing (webhook routing)Yes

MSSP pricing is per managed customer. No minimum, no cap. Add a customer when you win the contract, remove them when you don't.

PDF · 28 pages
For MSSPs

Platform
Overview

threatcluster.io

The full platform overview, in one PDF.

Every feature in the matrix above, walked through with screenshots, sample data, and the operational detail you need to evaluate the product against your existing stack. Send it to your underwriter, your CISO, or the client who keeps asking what they're paying for.

Behind ThreatCluster.

Built by people who've worked the SOC night-shift, briefed federal teams on APT activity, and run intelligence for critical national infrastructure.

JM

James Mockford 🇬🇧

Co-Founder & Managing Director

Security engineering background spanning defence consultancy, managed security, telecoms infrastructure, and critical national infrastructure including OT/ICS in the water sector. Petty Officer in the Royal Naval Reserve Maritime Cyber Unit.

RC

Reyben T. Cortes 🇺🇸

Co-Founder & Director of Threat Research

Network Security Engineer, Cyber Threat Intelligence Analyst, and OSINT practitioner. Former Cyber Threat Analyst for the U.S. Department of Homeland Security, delivering briefings to SLTT, CISA, and FBI InfraGard leaders on ransomware, APTs, and election infrastructure threats.

Advisory partnerships

ThreatCluster co-publishes joint threat advisories with Defused (cyber deception and early warning), Ransom-ISAC (ransomware analysis and collective defence), and detections.ai (community-driven detection rules). These partnerships bring complementary data sources into the platform where open-source scraping alone doesn't reach.

[ DEFUSED ] RANSOM-ISAC detections.ai

Run intel for many clients
without doubling headcount.

Tell us how many clients you serve, what they expect from a weekly brief, and what their stack looks like. We'll set up a working environment, not a sandbox demo.