The intelligence cycle · 5 of 6

Dissemination

Finished intelligence reaches the people who need it — and the systems they work in.


What you can do

  • Digests and alerts, on their terms — Daily and weekly digests, watchlist and escalation alerts, each user controlling categories, priority thresholds, quiet hours and cadence in their own timezone.
  • Groups that route automatically — Send published intelligence to internal teams and external stakeholders by threat vector, with exclusions honoured and every delivery logged.
  • Share a single report — Send any report by email with an optional message and section-level control over what the recipient sees.
  • Connect your own agents — A read-only MCP server for your AI agents and signed webhooks for your own systems. Scoped to your tenant and metered.
  • Evidence you can hand an auditor — Generate a dated record of your programme for any period — requirements in force, collection, triage, what you published and who received it.

4

Webhook events

published, escalation, watchlist and SSVC Act

7

Evidence sections

from requirements through to reports held back

0

Report bodies sent

webhook payloads carry identifiers and links only

What our integrations deliberately do not do

Webhook payloads carry identifiers and links, never report bodies — your intelligence does not leave the platform because a delivery endpoint changed hands. The agent surface is read-only, and there is no inbound write API. When we say MCP and webhooks, we mean exactly those two things.

The rest of the cycle

See it against your own requirements

The fastest way to judge an intelligence platform is to point it at what you actually need to know.

Contact Sales