Isolated sandboxes — a Linux detonator for files, a headless-Chromium renderer for URLs. Neither is shared and neither reaches your network.
Static analysis, two sandboxes and an indicator graph, in one screen an analyst works down rather than four they switch between.
Being built to run entirely within the European Union — storage, analysis and support under EU jurisdiction.
Your samples are never shared, resold or published. No community tier, no exceptions.
Isolated sandboxes — a Linux detonator for files, a headless-Chromium renderer for URLs. Neither is shared and neither reaches your network.
Detection engines on every file: ClamAV signatures and YARA rules you write yourself, matched at ingest and again on the whole corpus.
Of the interface is a documented REST endpoint. A route that is not documented fails our build, which is why the guide never drifts.
Storage, processing, and the company itself — Austrian, with an Impressum that says so.
Two things put a sample outside your control, and they are different problems. A public multi-scanner makes your sample everyone's sample — including the sender's. A US-owned cloud puts it under the CLOUD Act whichever region you picked. Threatera is being built so that neither applies.
| Your samples | EU object storage. Never shared, resold or published — no exceptions and no "community" tier, because a tier that trades your samples for a discount is the business model this exists to avoid. |
|---|---|
| Analysis and detonation | EU compute. A throwaway container with no capabilities and hard CPU, memory and time caps — the sample runs, the container is destroyed, and the network never leaves the host. |
| Your encryption key | Optionally held by you, wrapped by a key management service you run. So "can the vendor read our samples?" is answerable in the product rather than by asking the vendor. |
| Support access | A Threatera operator holding a membership appears in your member list, marked as the vendor's account, and every member sees it — not only admins. Time-boxed grants are being built; today the access is visible for as long as it lasts and only an operator can end it. |
| Third-party lookups | Passive only, and labelled as such. Nothing contacts a host you are investigating unless you ask it to — no resolution, no WHOIS, no fetch that tells an attacker they are being looked at. |
| user | role | status |
|---|---|---|
| ana@example.com | owner | active · MFA on |
| lena@example.com | analyst | active · no MFA |
| support@threatera.eu vendor | admin | active · MFA on |
Every member sees this list, not just admins — because verifying that no unexpected account has access is not an administrative task, it is an assurance one.
If a capability cannot be shown, it probably is not ready to be sold.
A lookup tells you whether somebody has seen this exact file before. This tells you what it is. Two sections here are packed — .data at 7.91 and .rsrc at 7.99, where compiled code sits around 6 — which is the difference between a build and something hiding inside one.
| section | vsize | rawsize | entropy | flags |
|---|---|---|---|---|
| .text | 168.0 KB | 167.5 KB | 6.41 | r-x |
| .rdata | 40.0 KB | 39.5 KB | 5.12 | r-- |
| .data | 8.0 KB | 3.5 KB | 7.91 | rw- |
| .rsrc | 2.0 KB | 2.0 KB | 7.99 | r-- |
A throwaway Linux container with no capabilities and hard CPU, memory and time caps. The network is sinkholed here, so DNS is answered and traffic captured, and nothing leaves. Every process, file and connection is recorded as it happens rather than summarised afterwards.
Not a count in a box. This address has 184 sightings across your organisation, and they read as seven sources rather than 184 lines — which file, which sandbox run, which reported message, and when each of them last saw it.
| source | artefact | times | last |
|---|---|---|---|
| file | Rechnung_2026-08_4471.exe | 92 | 22 min ago |
| sandbox | run #4471 · sinkhole | 41 | 22 min ago |
| Invoice overdue — action required | 28 | 3 h ago | |
| feed | URLhaus | 14 | 1 d ago |
Detonate a file or render a URL in fully isolated, throwaway environments — and capture everything they try to do.
Actually execute a sample in a locked-down, non-root container with no capabilities and hard CPU, memory and time caps — then read back exactly what it did.
Render any URL in an isolated headless Chromium and record the screenshot, final URL after redirects, page content and every network request it makes.
A reportable incident is a deadline and a paper trail before it is anything else. Threatera is built to be the record as well as the tool, so that producing one is a matter of exporting what was already written down rather than an archaeology exercise across four systems and somebody's memory.
Who uploaded, who re-analysed, who changed a verdict, who exported. Searched on the server, over the whole log — "did anyone touch this hash" answered against the most recent twenty-five events is a no that means nothing.
NIS2 and DORA clocks, with the early warning at 24 hours and the notification at 72. Each runs from when you became aware, not from when the case was opened — that is a judgement somebody has to make and record, so it is a field a person fills in. The draft is prepared for you. Threatera never files on your behalf, and none of it is legal advice.
One organisation, one boundary, enforced by the database rather than by the code that queries it — a forgotten filter returns nothing rather than somebody else's rows. And the member list is visible to every member, so who has access is checkable without asking us.
A case as STIX 2.1 for a TIP, MISP or a CERT; a report as Markdown or PDF. Your evidence is not hostage to a subscription.
| time | user | action |
|---|---|---|
| 14:22:07 | ana@example.com | case.export.stix |
| 14:09:51 | ana@example.com | verdict.decided |
| 13:47:12 | lena@example.com | file.detonate |
| 13:41:36 | lena@example.com | file.upload |
| 13:38:02 | ana@example.com | case.open |
24 hours from the moment your team recorded becoming aware — 4 h 36 m ago — not from when the case was opened. The draft is ready to review; filing it is yours.
Not a subset, not a partner tier. Upload, analyse, detonate, pivot and search are the same documented REST calls the interface itself makes — behind a key any member can mint, which carries that member’s own role and never more. Anything you can do by hand, you can put in a pipeline.
Threatera is looking for design partners: a small number of security teams willing to run it against real work and say where it is wrong. That is what early access actually is here — you get the product before it is finished and a direct line to the people building it, and we get the only kind of feedback that has ever made a tool like this good.
No trial cluster to provision, no credit card. A conversation and a walkthrough.