For MSSPs
A feed you can defend to your own customer
When you run security for someone else, a threat feed is not just data, it is something you will have to justify. Every block you apply on a customer's edge is a decision they can question, and "the vendor said so" is not an answer that survives the second time it takes a site down. What an MSSP needs from a feed is not the largest number of indicators, it is a defensible chain from an observation to an action.
CTIF is built around that chain. Every address is there because one of our own sensors recorded it attacking a real service, and the log line that flagged it travels with the indicator. The score that ranks it is published, not proprietary. And the freshness is measured and shown rather than described as "real time".
The evaluation checklist, answered
Is the data first-party, or resold?
Our own sensors produce it. Imported public lists are kept separate, labelled by source, and can be dropped entirely with first_party_only=true so you are not paying us for a list you already ingest.
Is freshness published or claimed?
Published. Collection runs every 6 hours and the real per-sensor age is on the status page, which also answers as JSON and returns 503 during an outage so you can alert on it.
Is the scoring explainable to a customer?
The weights, the CDN and scanner cap and the 30-day half-life are written out on the methodology page. Every indicator carries the log line that flagged it, so an escalation can quote evidence rather than a vendor score.
Does it fit tooling you already run?
REST JSON, STIX 2.1 bundles, and a scored list as text or CSV over an authenticated URL. Guides exist for Splunk, Palo Alto, FortiGate, MISP, OpenCTI and Linux hosts. No proprietary connector.
Are there per-customer sub-accounts and per-tenant keys?
No. One account carries one key and one daily quota. An MSSP today runs a single key across its customers, which is fine for enrichment but gives you no per-tenant usage split. If you need isolation, a private instance per customer is the honest answer, and that is a conversation rather than a checkout button.
Is there a reseller or white-label programme?
Not yet. There is no partner portal, no margin schedule and no rebranding of the dashboard. If you want to build a service on top of this, tell us the shape you need and we will answer specifically rather than pretend a programme exists.
What we would actually recommend today
Buy one SOC plan at 10,000 requests a day and use it for enrichment across your customers, where a shared key costs you nothing. For enforcement, pull the scored blocklist once and distribute it to each customer edge at a threshold you set per customer, rather than giving each of them a key. If a customer contractually needs their data and their feed isolated, that is a private instance, priced per deployment.
Try it against your own queue first
The 7-day trial gives a working key with every sensor, the API, STIX 2.1 and the blocklist, with no payment. Point it at one customer's alert queue for a week. If it does not change what your analysts open first, do not buy it.