Every other threat platform is a destination you must feed with your data — months of integration and a data-governance review before you see value. Threadlinqs SecOS inverts the model: the world's live threat picture comes to your team, and nothing of yours ever leaves your environment. That isn't a compliance checkbox — it's the architecture.
We do not ingest your logs, telemetry, alerts, or infrastructure. There is no customer data to reside anywhere — so the single slowest step in enterprise security procurement simply doesn't apply.
No agents, no collectors, no connectors reaching into your network. SecOS is a browser-delivered workspace over our curated threat corpus. Your team is operational in an afternoon, not a quarter.
Every threat, detection, IOC, and attribution is drawn from a continuously-updated, human-reviewed corpus. Answers cite real records — not hallucinated ones.
SecOS runs entirely on Cloudflare Workers + D1 at the network edge. There is no origin server holding a copy of your data because there is no copy of your data. The application your analysts use is a static, browser-side workspace; the backend serves only our shared threat intelligence and each organization's own account state (members, saved hunts, case files) — logically isolated per tenant.
What we store is limited and purpose-bound: your account and organization membership, the hunts and case files your team chooses to create, and an activity trail for your own administrators' accountability. What we never store: your networks, your endpoints, your logs, your alerts, your customers.
Row-level logical multi-tenancy. Every organization-scoped query is bound to your tenant server-side — never from a client-supplied value. One org can never see another's members, hunts, or case files.
Organization admins manage members, invitations, seats, and settings. Shared case files and hunts are read-and-fork for the team; only the owner mutates the original.
Removing a member revokes their live sessions at once — not on their next request — and reverts anything they shared with the team.
A tenant-scoped audit log of every administrative action, exportable to CSV for your compliance and access reviews — without opening a support ticket.
Activity inside SecOS is attributed to the acting user for your admins' live oversight, with a server-authoritative origin tag that a client cannot forge.
Outbound webhooks are HMAC-signed and SSRF-guarded (private and reserved address ranges blocked). Feed exports (STIX 2.1, TAXII 2.1, MISP, ATT&CK Navigator) use tiered, revocable keys.
We'd rather tell you what isn't built yet than imply it is. The following are on our near-term roadmap for team tenants:
Okta / Azure AD / Google Workspace sign-in with email-domain auto-join. Today: individual Google & GitHub sign-in plus invite-based tenant join.
TOTP-based MFA for all accounts. Today: session-based auth with immediate admin-driven revocation.
Analyst / viewer / billing roles and directory-driven provisioning beyond today's admin / member model.
Third-party attestation is in progress. In the meantime, the zero-ingestion architecture removes most of what an attestation would need to cover.
When there's no customer data to ingest, most of the questions answer themselves.
Request team access Talk to us