Exposure first
Known-exploited CVEs matched to your software and devices, ordered by what is confirmed on your estate.
Targeted threat intelligence for small security teams
Most threat feeds hand a small security team thousands of items. FoeLens scores every item against your company and gives you the short list, sorted most urgent first, with the reasons where we have them.
The demo is a fictional building society with sample data. It needs no account and nothing you do is saved.
Reads the open sources every morning
From noise to a short list
Sector, country, domains, suppliers and the software you run. Import devices if you have them.
Exploited vulnerabilities, threat actors, leaked credentials, lookalike domains and supplier incidents are scored against your profile every morning.
Each item is scored against your company profile and sorted so the most urgent come first. Where we know why, we say so. Lower-priority items stay out of the main list but remain searchable.
One place for the threats that are about you
Known-exploited CVEs matched to your software and devices, ordered by what is confirmed on your estate.
Profiles matched to your sector and technology, with the suppliers and software they touch.
Breaches, incidents and domain changes per supplier, with a portfolio of who is overdue.
Breach and leaked-credential mentions of your domains from public sources, and newly registered lookalike domains, grouped into campaigns and exportable as a list for your mail gateway.
Indicators that apply to you, exported as block lists for your firewall, Defender or mail filter, with expiry so lists do not grow forever.
Quarterly figures written as sentences, with the numbers behind each one.
Same data, the view each person needs
A work queue ordered by relevance, with response targets and indicator lookup that shows everything known.
Team workload, ownership, shift handover and coverage gaps in one overview.
One page with the verdict, the few decisions that need you, and whether anything could need reporting.
An analyst can see why an item ranks where it does, and disagree.
Row-level security in the database separates every organisation; integration keys sit in a vault.
How data is handledA managed Postgres database in London. The providers involved and what is not in place yet are listed openly.
Providers and retentionStraight answers
Public and open sources: CISA known-exploited vulnerabilities, abuse.ch, MISP and TAXII feeds, certificate transparency and registration data, plus any feeds you connect. We do not claim a private feed we do not have. Ingest health shows each source and when it last ran.
No. It tells you what is relevant and what to do. It exports indicators to the tools you already use.
Every organisation is isolated by row-level security in the database, and integration keys are held in a vault. See the security page for detail.
No. Every score shows its reasons so an analyst can disagree. Reporting prompts for leaders are guidance, not legal advice.
Pricing is being finalised with the first teams. Request access and we will talk through your size and needs.
In a managed Postgres database in London. The Trust page lists the providers involved, what is kept and for how long, and what we do not yet have (certifications, a signed processing agreement template).
Early access
Access is by invitation while we onboard the first teams. Tell us a little about yours and we will reply by email.
Prefer to look first? Open the demo. No account needed.