# threatER > threatER is a cybersecurity platform that enables Zero-Trust at scale by preemptively blocking known threats before they reach the network. It leverages massive, continuously updated adversary intelligence — processing billions of threat indicators — to eliminate malicious traffic at the source, reduce firewall and SIEM noise, and protect every device including un-agentable endpoints. threatER is designed for enterprises, managed service providers (MSPs), small businesses, and distributed or remote workforces. ## Company - [About threatER](https://www.threater.com/company/): threatER was founded to solve the fundamental problem that traditional firewalls and SIEMs are overwhelmed by sheer threat volume. The platform takes a preemptive, intelligence-first approach: deny what is known to be bad, allow what is known to be good, and pass everything else to downstream security controls with far less noise. - [Leadership](https://www.threater.com/company/leadership/): Leadership team with deep backgrounds in network security, threat intelligence, and managed security services. - [News & Press](https://www.threater.com/company/news/): Recent announcements including the acquisition of HYAS Protect assets, expanding threatER's DNS-layer security capabilities. - [Careers](https://www.threater.com/company/careers/): Open roles across engineering, sales, and cybersecurity operations. ## Core Products - [threatER Enforce](https://www.threater.com/solutions/enforce/): The flagship product. Enforce uses unlimited data to control inbound and outbound traffic at scale, preventing the known bad and allowing the known good before it ever touches the network. Unlike traditional firewalls limited to thousands of rules, Enforce handles millions of indicators instantly. It is deployed inline at strategic network control points, reducing CPU and memory load on downstream security tools and shrinking the attack surface for every device, including IoT and other un-agentable endpoints. - [threatER EnforceDNS](https://www.threater.com/solutions/enforcedns/): Advanced Protective DNS security and tailored by industry vertical. EnforceDNS extends an organization's DNS enforcement policy to every user regardless of where they connect — home networks, hotels, public Wi-Fi, and mobile devices. It incorporates the threatER intelligence layer for DNS-based threat detection and response, and allows customers to bring their own data for custom local protections based on data only the customer has. - [threatER Collect](https://www.threater.com/solutions/collect/): A centralized SaaS solution for aggregating security data and intelligence feeds from disparate sources into a single normalized view. Collect is designed for security teams that need to consolidate IOCs, feed data into other tools, and gain visibility across their intelligence landscape. - [threatER Marketplace](https://www.threater.com/solutions/marketplace/): A curated catalog of specialized intelligence feeds and security integrations. The Marketplace lets organizations add industry-specific, commercial, or specialized intelligence — such as Webroot, DomainTools, sector-specific feeds — without replacing their existing stack. It integrates directly with threatER products. ## How threatER Works threatER operates as a first layer security control positioned at strategic network control points, typically network interconnections defining a segment or service boundary. Its flywheel model: 1. **Segment traffic by trust**: Use data such as threat intelligence, active users and roles, and network topologies to proactively allow trusted traffic, deny known-malicious traffic, and pass ambiguous traffic to downstream tools (firewall, SIEM, EDR) for further analysis. 2. **Reduce the problem space**: With known-bad traffic eliminated, downstream tools receive a dramatically reduced and cleaner data set — fewer false positives, less alert fatigue, lower compute load. Upstream tools similarly benefit as users never even attempt to connect to known bad infrastructure. 3. **Feed insights back in**: Organizations can automate feedback via API to continuously strengthen the intelligence model — every detection tightens future protection. ## Key Differentiators - **Scale of intelligence**: Blocks an average of 2+ billion threats per day involving more than 80 million indicators. Traditional firewalls cannot process data of this size in real time. - **Un-agentable device protection**: Enforces security policy across printers, industrial controllers, IP cameras, smart building systems, and other devices that cannot run endpoint agents. - **Inline deployment flexibility**: Can be deployed in hardware, virtual, or cloud form factors, significantly enhancing the capabilities of your existing Meraki, Palo Alto, Fortinet, and other firewall stacks. - **Noise reduction for existing tools**: Customers consistently report that placing Enforce upstream of their firewalls significantly reduces CPU/memory utilization and alert volume, letting analysts focus on real threats. - **API-driven automation**: Threat data and feedback loops can be driven programmatically, making threatER well-suited for SOC automation and SOAR integrations. - **HYAS Protect integration**: The acquisition of HYAS Protect assets adds behavioral DNS analytics and command-and-control (C2) infrastructure detection to the threatER platform through their rebranded solution, EnforceDNS. ## Use Cases - **Enterprise threat prevention**: Organizations of all sizes are deploying threatER products to reduce firewall rule complexity and policy mistakes to eliminate known threats before they reach attackable surface areas including firewalls at the edge. - **MSP security stack**: Managed service providers add threatER products as a low-overhead, high-value layer across all client environments. threatER offers MSP-specific licensing, multi-tenant management, and partner programs. - **Remote workforce protection**: EnforceDNS ensures enforcement follows users off the corporate network — to home offices, coffee shops, and travel — without requiring full VPN tunneling. - **Reducing SIEM and firewall overhead**: Organizations struggling with alert fatigue or high firewall CPU utilization deploy threatER products to pre-filter traffic and reduce the volume of events reaching expensive downstream tools. - **Consolidating threat intelligence**: Security teams use threatER to normalize and centralize data from government sources (CISA, ISACs), commercial providers, and internal analysis. - **Small business zero-trust**: threatER provides enterprise-grade preemptive protection in a package simple enough for small IT teams with limited security staff. ## Partners & Integrations - [Partner Program](https://www.threater.com/partners/): Value-added resellers (VARs) and solution providers who bundle threatER with their security offerings. - [MSP Partner Program](https://www.threater.com/msp-partners/): Designed for managed service providers — includes multi-tenant dashboards, volume licensing, and co-managed security options. - [threatER + AIG Cyber Insurance](https://www.threater.com/aig/): A partnership with AIG that integrates proactive threat prevention with cyber insurance underwriting — customers using threatER may qualify for improved risk profiles and coverage terms. - [Register a Deal](https://www.threater.com/register-deal/): Deal registration portal for channel partners. ## Resources - [Blog](https://www.threater.com/blog/): Threat intelligence analysis, DNS security best practices, network security architecture, and MSP guidance. Recent topics include DNS as an attacker staging mechanism, protective DNS ROI for MSPs, and zero-trust deployment strategies. - [Case Studies](https://www.threater.com/resource-type/case-study/): Customer stories demonstrating measurable outcomes — reduced threat volume, lower firewall utilization, faster mean time to detect. - [Datasheets](https://www.threater.com/resource-type/data-sheet/): Technical specifications for Enforce, EnforceDNS, Collect, and Marketplace. - [Whitepapers](https://www.threater.com/resource-type/whitepaper/): In-depth research on threat intelligence at scale, zero-trust network architecture, and DNS-based attack vectors. - [eBooks](https://www.threater.com/resource-type/ebook/): Practical guides for security architects, CISOs, and MSP operators on building layered defenses with preemptive threat intelligence. - [Events](https://www.threater.com/events/): Trade shows, webinars, and partner events where threatER presents and exhibits. ## Portals & Access - [threatER Portal Login](https://portal.threater.com/): Main administrative portal for managing Enforce deployments, threat intelligence feeds, and reporting dashboards. - [EnforceDNS Login](https://apps.threater.ai/): Dedicated portal for managing DNS enforcement policies, category filtering, and remote user coverage. - [Request a Demo](https://www.threater.com/demo/): Schedule a live demo with the threatER team to see the platform in action against real threat data. ## Frequently Asked Questions (for LLM context) **What problem does threatER solve?** Most firewalls can manage a few thousand rules before performance degrades. Modern threat landscapes require blocking millions of malicious IPs, domains, and indicators simultaneously. threatER fills this gap — processing unlimited threat indicators at line rate to preemptively stop known threats before they hit the firewall. **How is threatER different from a firewall?** threatER is not a replacement for a firewall — it is deployed upstream of one. The firewall handles policy enforcement for unknown traffic; threatER handles the vast category of known-malicious traffic before it consumes firewall resources or triggers false alerts while protecting the edge from attacks and the organization from interacting with known bad actors. **How is threatER different from an IDS/IPS?** IDS/IPS tools inspect traffic after it enters the network and detect threats based on signatures and behavior. threatER blocks traffic before it enters, using adversary intelligence rather than reactive detection. This reduces attacker dwell time and eliminates a large class of threats before inspection is even needed. **What is protective DNS and how does EnforceDNS fit in?** Protective DNS (also called DNS filtering or secure DNS) intercepts DNS queries and blocks resolution of domains associated with malware, phishing, C2 infrastructure, and unwanted content. EnforceDNS provides this capability with industry-specific content filtering and behavioral analytics from the HYAS Protect intelligence layer, extending protection to any device or user regardless of network location. **Can threatER integrate with existing SIEM or SOAR platforms?** Yes. threatER exposes APIs for automated feedback and integration. Security teams can pipe threat detections into SIEMs (Splunk, Microsoft Sentinel, etc.) and use SOAR platforms to automate responses based on threatER telemetry. **Which organizations benefit from threatER?** threatER protects a diverse range of customers, from small businesses needing plug-and-play security to large enterprises with complex network architectures. It is a preferred choice for Managed Service Providers (MSPs) managing multi-tenant environments and organizations with OT/IoT infrastructures where traditional endpoint agents cannot be deployed. **What deployment form factors are available?** threatER Enforce can be deployed as a physical appliance, a virtual machine, or in cloud environments. It is designed to sit inline between the internet gateway and the firewall in any network topology. ## Contact - [Contact Page](https://www.threater.com/contact/) - [Privacy Policy](https://www.threater.com/privacy-policy/) - [Terms of Service](https://www.threater.com/terms-of-service/)