TLP:CLEARUTC --:--:--
Support

Frequently Asked Questions

Everything you need to know about Cyntelligence. Can't find what you're looking for? Contact us.

General

What is Cyntelligence?
Cyntelligence is a self-hosted, single-tenant threat intelligence and exposure management (CTEM) platform. It fuses threat intel, attack surface monitoring, leak detection, brand protection, ransomware tracking, and detection engineering into one product — with AI that runs on your own hardware, so nothing leaves your network.
Who is Cyntelligence designed for?
Cyntelligence is built for small and mid-size security teams who need enterprise-grade threat intelligence without the complexity or cost of traditional solutions. It serves SOC analysts, threat hunters, security engineers, and CISOs across any industry.
How is Cyntelligence different from other CTI platforms?
Unlike traditional tools that focus on a single data source, Cyntelligence consolidates multiple intelligence modules — vulnerability tracking, IOC management, ransomware monitoring, dark web surveillance, attack surface discovery, and AI-powered analysis — into one unified platform with built-in privacy by design.
Does Cyntelligence replace my SIEM?
No — Cyntelligence complements your existing security stack. It provides the external threat context and intelligence that feeds into your SIEM, EDR, and other tools. Think of it as the intelligence layer that tells you what to look for.

Features & Capabilities

What intelligence modules are included?
Cyntelligence covers the full intelligence lifecycle: vulnerability intelligence with exploit enrichment, automated IOC collection and validation, ransomware tracking, security news aggregation, dark web monitoring, attack surface discovery, code leak detection, credential exposure monitoring, phishing domain detection, threat actor profiling, detection engineering, AI-powered chat and automated digests.
What AI capabilities does Cyntelligence have?
The platform includes a privacy-first AI engine that runs entirely within your environment. Capabilities include natural language queries over your threat data, automated intelligence digests, vulnerability impact assessment, indicator context analysis, risk scoring, and report generation.
What data sources does it integrate with?
Cyntelligence aggregates data from multiple public threat intelligence feeds, vulnerability databases, exploit repositories, dark web channels, certificate transparency logs, code repositories, and curated security news sources. You can also import your own indicators and configure custom monitoring.
Can I generate reports and briefings?
Yes. The platform generates AI-powered threat briefings, professional PDF advisories, and data exports across all modules. Automated digests provide regular executive summaries of your threat landscape.

Security & Privacy

Where is my data stored?
All data is stored in your own database within your infrastructure. Cyntelligence is self-hosted — your threat intelligence data never leaves your environment, ensuring complete data sovereignty.
Does any data leave my network?
The only outbound connections are to public threat intelligence feeds for data collection. All AI processing and analysis happens locally within your environment. No telemetry, analytics, or user data is sent externally.
What authentication and access controls are available?
Cyntelligence includes role-based access control with multiple permission levels, per-user module assignments, two-factor authentication, brute-force protection, and industry-standard web security protections throughout the platform.
Is Cyntelligence suitable for regulated industries?
Yes. The self-hosted architecture with no external data transmission meets data residency and sovereignty requirements. All processing stays within your infrastructure, making it suitable for organizations with strict compliance needs.

Deployment & Getting Started

How do I get started with Cyntelligence?
Cyntelligence is deployed on your own infrastructure. Our team will guide you through the setup process, including environment preparation, configuration, and onboarding your security team. Register your interest to get started.
What environments are supported?
Cyntelligence runs on Linux and Windows servers. Detailed system requirements and deployment guidance are provided during onboarding. The platform is designed to run efficiently on modest hardware.
Can I use the AI features without specialized hardware?
Yes. All core monitoring, alerting, and data collection features work without any special hardware. AI features can be configured to match your available resources, with flexible options to suit different deployment sizes.
Can MSSPs run this for many clients?
Not yet — on purpose. The platform supports multiple organizations with data isolation, but it is single-host by architecture and data freshness degrades past a handful of tenants. MSSP-grade multi-tenant hardening is on the roadmap; until it's real we won't sell it. MSSPs can join the waitlist or apply for the single MSSP slot in the design-partner cohort.

Pricing & Licensing

How is Cyntelligence licensed?
Per organization, not per analyst — and never per token. Because you host it, there is no metered AI-usage bill and no per-seat license creep. Current plan details are on the pricing section of the homepage; annual billing is standard.
Do you offer support?
Yes — and it's direct-to-builder: the person answering your ticket wrote the code. All plans include documentation and email support; the Assured tier adds an SLA, assisted install, source-code escrow, and quarterly tuning.
Can I try before I buy?
Yes — request a structured 14-day POC on your own hardware with your own data, with success criteria agreed in writing before install. That's the honest way to evaluate a self-hosted platform; a hosted click-around wouldn't prove the claims that matter.

Trust & Continuity

Isn't this built by one person? What happens if you get hit by a bus?
Yes — solo founder-engineer, and we'd rather you hear it from us. Three answers: the software is self-hosted, so it keeps running on your hardware regardless of vendor events; documentation runs unusually deep, because one person had to be able to operate everything; and the Assured tier includes source-code escrow. The full continuity answer is written down on the Trust & Continuity page.
Do you have reference customers?
Not yet, and you won't find invented ones here — no logos, no testimonials, no 'trusted by'. We're recruiting 3–5 design partners at roughly half price for 12 months, with founder-direct support, in exchange for deployment feedback and contractual reference rights. Names get published only with written permission.
Do you ingest STIX/TAXII?
Honest answer: export only, today. We export STIX 2.1, MISP-compatible feeds, and Sigma/Snort/Suricata rules; bi-directional STIX/TAXII ingest is on the roadmap. If two-way TAXII interop is a hard requirement right now, we're not your tool yet — we'd rather tell you that here than after a POC.
Is it compliant with GDPR / NCA / NESA / CERT-In?
We don't claim certifications we don't hold. The platform is architected for data-residency and sovereignty requirements: single-tenant, self-hosted, zero-egress by design. This deployment model supports obligations under frameworks such as GDPR, Saudi NCA ECC, UAE IA standards, and India's CERT-In directions — compliance outcomes depend on your deployment and processes; we provide the architecture documentation to support your assessment.

Still have questions?

We're here to help. Reach out to our team for personalized assistance.