Platform
One domain in. Twelve modules out.
PuReAI starts from a single domain and maps everything reachable from the outside — assets, weaknesses, exposed data and the suppliers behind them — then turns it into one score and one conversation. No agents, no credentials, nothing intrusive.
The 12 OSINT modules
Every module is passive. Collection uses public DNS and WHOIS, certificate transparency, public vulnerability catalogues, public repositories and breach corpora already in circulation.
Domain
Domains, subdomains and DNS records tied to the organisation, including assets no internal inventory lists.
IP
Hosts, open ports and services reachable from the internet.
Certificate
TLS certificates, issuers and expiry across the whole discovered estate.
Technology
Stack fingerprinting on each exposed asset — products, frameworks and versions.
Vulnerability
Detected products and versions matched against NVD and CISA KEV, with severity and confidence.
Misconfiguration
Weak DNS, mail (SPF/DKIM/DMARC) and TLS configuration on discovered assets.
Leaked Data
Credentials and records tied to the domain found in third-party breach corpora.
Git Leaks
Secrets, tokens and keys committed to public repositories.
Sensitive Files
Indexed documents, backups and configuration files that should not be public.
Lookalike
Typosquatted and impersonating domains registered against the brand.
Supply Chain
Vendors and dependencies scored continuously, with per-vendor evidence for DORA and NIS2.
News / Threats
Ransomware actor activity and MITRE ATT&CK TTPs correlated to your sector and stack.
One Risk Score, and the formula behind it
Four weighted segments produce a 0–100 company score. The weights are published, and a finding moves the score once, in one segment.
The same formula scores your organisation and each identified supplier, so a portfolio view and a single-domain view are directly comparable. The full breakdown, our data sources, the false-positive position and the dispute process are on the methodology page.
Ask the threat graph
Findings, assets, suppliers, CVEs and threat actors are stored as a connected graph. You query it in plain language — which actors target our sector, which supplier CVEs are on CISA KEV right now, what changed since last month — and answers are grounded in your own data with the evidence attached, not generated from general knowledge.
Actor context
Ransomware and APT groups active against your sector, with their MITRE ATT&CK techniques.
Exploitability first
CISA KEV status raises priority above raw CVSS, so remediation order reflects real-world exploitation.
Supplier attribution
Vendor CVEs and incidents are attributed to the specific supplier and contract they affect.
Fits your operation
Integrations
Splunk, Microsoft Sentinel, Jira, ServiceNow, Slack, webhooks and REST API — findings go where your team already works.
Compliance evidence
Module-to-requirement mapping for DORA, NIS2, ISO 27001, NIST CSF, PCI DSS and TIBER-EU.
Deployment
Cloud, or a sovereign deployment inside your own jurisdiction where residency is a procurement requirement.