ThreatMatch
ThreatMatch is a threat intelligence and sharing platform that centralises reports, alerts, and threat profiles, continuously monitors your digital footprint, supply chain, and brand, and delivers actionable operational and strategic insights, enabling prioritised response, improved decision-making, and secure information sharing for leadership and security teams.
Features
- Real-time alerts and analyst recommendations via ThreatMatch
- Bespoke vulnerability alerts with tailored mitigation guidance
- Alerts prioritised by real-world exploitation and risk impact
- High-confidence IOC feed and comprehensive investigation feed
- Dark web coverage: forums, marketplaces, Telegram
- Detect code leaks, sensitive data exposure, credentials.
- Phishing page reporting and brand monitoring
Benefits
- Consume intelligence faster with digestible analyst written summaries
- Brief leaders quickly with clear direction and assessment
- Prioritise vulnerabilities using real-world exploitation data
- Reduce remediation time with tailored mitigation guidance
- Detect third-party threats early to reduce exposure
- Prevent brand abuse and customer fraud
- Neutralise credential leaks before reputational damage escalates
- Automate blocking to enrich detections and streamline investigations
- Save operational time with end-to-end takedowns
- Proactively block payment fraud and accelerate investigations
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 8 1 7 8 9 4 7 8 4 8 8 0 0 8
Contact
SECURITY ALLIANCE LIMITED
Robert Dartnall
Telephone: 020 7148 7475
Email: info@secalliance.com
About your service
- Service categories
-
Applications
Collaborative
- Enterprise community
- Team collaboration
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No limitations, the maintenance windows will be communicated when as and when needed, usually no longer than an hour down-time. These are typically scheduled for off peak time to minimise disruption to the service.
- System requirements
- A modern browser such as Chrome, Microsoft Edge or Firefox
User support
- Email or online ticketing support
- Yes
- Support response times
- Monday to Friday between 8am and 5pm, we respond in about an hour. No customer support on weekends, tickets will be resolved as priority on Monday.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Support is included within the ThreatMatch platform, allowing you to submit and track tickets for prompt assistance. If you are unable to log in, you can contact our dedicated support email for help with access issues. We also offer Intelligence Support through the Ask an Analyst feature, which can be scoped separately, to help you interpret intelligence and answer threat-related questions. In addition, a Client Engagement Manager provides periodic check-ins to support adoption and ensure you continue to get the most value from the product.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Once the organisation has been onboarded to ThreatMatch and user accounts have been created, we contact the users to arrange an online training session of approximately 60 minutes. During this session, we provide a comprehensive walkthrough of the platform’s features and address any questions they may have. Prior to the training, we also discuss their specific use cases for the portal to ensure they derive maximum value from the product.
- Service documentation
- No
- End-of-contract data extraction
- We can provide all user contributed data via a common format.
- End-of-contract process
-
• Coordinated disabling of user access at or shortly after contract end date.
• Provision of reasonable assistance to export customer data (alerts, reports, watchlists and relevant configuration) in commonly-used formats (e.g., CSV, PDF), via the portal or through a managed export.
• Retention of customer data for a defined period after termination to allow export (as specified in agreement), followed by deletion in line with internal policies and legal requirements.
• Backups containing customer data are expired and deleted on their normal lifecycle schedule.
• The offboarding is performed at no additional cost
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Some more advanced features are unavailable such as the scenarios module. Basic reading access only.
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
- Users have access to an API where they can access the core functionalities that are offered on the ThreatMatch platform. Content can be created or flagged through our APIs and content can be loaded into different products that support the STIX and TAXII standards.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
- Provide internal/external reporting requirements; select cadence and dashboard needs.
- Share technology stack details to tailor alerts and mitigation.
- Submit RFIs via ThreatMatch, specifying scope and preferred outputs.
- Integrate feeds to existing SIEM/TIP/devices and apply local rules.
- Configure monitoring priorities in ThreatMatch and receive email alerts
- Select from a number of service modules to create a service that meets business needs.
Scaling
- Independence of resources
- We continuously monitor system performance and proactively scale our infrastructure to maintain consistent service levels.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide detailed user engagement metrics, including; Portal logins, Content views within the portal, Content downloads from the portal, API usage and activity levels
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Other
- Other data at rest protection approach
- ISO27001
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Through support users can request a copy of their data in a CSV format. When the request comes through we can agree with the user the specifics of this export.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- We commit to a minimum uptime of 99.7% for the ThreatMatch service, including planned maintenance windows.
- Approach to resilience
- This information is available on request.
- Outage reporting
- Email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access is only granted to internal authorised users, admin access is not provided to customers.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- We are ISO27001 and Cyber Essentials Plus certified. Our ISO27001 certification covers all business operations and services.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- ThreatMatch components are recorded as managed assets with defined owners, environments and data classifications, and configurations are maintained as code in version control. All changes follow a formal change process with tickets, priority and category, risk and outage assessments, and required approvals. Security impact is evaluated using CIA-focused risk assessment, DPIA where needed, testing in non‑production, immutable deployments, rollback plans and post-change monitoring.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We run a continuous, risk‑based vulnerability management process. Threats to our services are identified via automated internal and external scanning, security monitoring, code review, penetration testing and formal risk assessments. Findings are triaged by impact and likelihood; high and critical issues are prioritized for rapid remediation, with patches deployed as quickly as safely possible through change management and CI/CD. We use internal threat intelligence, vendor advisories, cloud-provider feeds, CERTs and industry sources.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We use continuous protective monitoring across our infrastructure and services, including security tooling, telemetry and alerts, to detect anomalies, policy violations and indicators of compromise. When a potential compromise is identified, it is triaged, assigned a severity level and an incident manager, and handled under our formal incident management process, including containment, eradication, recovery and communication to affected stakeholders. For critical incidents we respond in minutes, with recovery time objectives of under 30 minutes for critical and within a few hours for lower severities.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We operate a formal incident management process with predefined runbooks for common events (service outages, security incidents, performance degradation and access issues). Incidents can be reported by users via our normal support channels (service desk/ticketing and support email or phone, as specified in their contract and onboarding material). All incidents are logged, triaged by severity and assigned an incident manager. We communicate progress via agreed channels and, once resolved, provide incident reports or reasons for outage summarising impact, timeline, root cause and corrective actions.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- All features are included, these are typically running as a pre-defined proof of concept over a one month period.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7.5%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 12.5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Wednesday 5 June 2013
- What the ISO/IEC 27001 doesn’t cover
- Covers all services offered by us.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- British Assessment Bureau
- ISO 9001 accreditation date
- Wednesday 5 June 2013
- What the ISO 9001 doesn’t cover
- Covers all services offered by us.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Bc2b6494-6964-461d-bb72-9c473507b0e1
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-