# Exint

*/Startups/Exint*

## Startup Overview

This threat intelligence engine maps external exposures directly to internal identity graphs. By linking compromised credentials and leaked data to specific employee profiles and access privileges, it calculates the immediate blast radius of outside breaches. Security teams receive precise risk vectors mapped directly to their organizational structure.

Security operations centers struggle to translate vague external threat feeds into concrete internal vulnerabilities. When a data dump surfaces, analysts spend hours manually tracing an external alias to an internal employee to determine their network access. This gap between external intelligence and internal identity delays critical response actions and leaves infrastructure exposed.

Rather than relying on the broad intelligence feeds of Recorded Future or CrowdStrike Falcon Recon, or defaulting to manual open-source intelligence gathering, this system relies on deterministic evidence graphs. It proves exactly how an external threat connects to internal systems before an analyst even opens the ticket. To align cost with actual risk reduction, the platform is outcome-priced per remediated threat.

## Startup Founding Hypothesis

**Approach**: that maps external exposures directly to internal identity graphs
**Competitors**:
- [Recorded Future](/Competitors/Recorded_Future)
- [CrowdStrike Falcon Recon](/Competitors/CrowdStrike_Falcon_Recon)
- [manual open-source intelligence](/Competitors/manual_open-source_intelligence)
**Differentiator2x2**: outcome-priced per remediated threat and backed by deterministic evidence graphs

## Startup Solution Coordinate

**Solution**: [Identity Exposure Engine](/Services/Identity_Exposure_Engine)

## Startup Position2x2

```mermaid
quadrantChart\n    title Market Positioning: Exint vs Competitors\n    x-axis Fixed Subscription --> Outcome-Priced\n    y-axis Disconnected Alerts --> Deterministic Evidence Graphs\n    quadrant-1 Uniquely Defensible\n    quadrant-2 Premium Niche\n    quadrant-3 Crowded Legacy\n    quadrant-4 Manual Services\n    Exint: [0.85, 0.88]\n    Recorded Future: [0.15, 0.35]\n    CrowdStrike Falcon Recon: [0.25, 0.55]\n    Manual Open-Source Intelligence: [0.10, 0.20]
```

## Startup Offer

**Proof**:
- Target: Mid-market financial services firms reducing credential leakage response times from days to under an hour.
- Target: Enterprise security teams eliminating false-positive OSINT alerts by requiring deterministic internal identity maps before triage.
- Target: Healthcare providers migrating from expensive, noisy threat feeds to an outcome-only pricing model.
**Tiers**:
- Name: Verified Exposure · Price: ~$150–$300 per mapped exposure · Inclusions: Automated OSINT scanning, deterministic evidence graph generation, and positive attribution to a specific internal identity.
- Name: Remediated Threat · Price: ~$800–$1,500 per confirmed resolution · Inclusions: Full takedown of external infrastructure or verified automated credential reset, backed by a post-incident evidence log.
- Name: Enterprise Pool · Price: ~$40k–$80k/yr annual commitment · Inclusions: Prepaid pool of remediated threats, SLA-backed response times, and intended integrations with core IAM platforms like Okta and Entra ID.
**Guarantee**: If an externally identified threat mapped to your internal identity graph is not successfully taken down or internally neutralized within 48 hours, the remediation is completely free.
**Business Function**: ProvideService
**Objection Handlers**:
- Objection: How do you access our internal identity graph without creating a new attack vector? Rebuttal: Exint is designed to use read-only, least-privilege API access to your IAM, mapping external data without extracting or storing your directory records.
- Objection: We already pay for Recorded Future or CrowdStrike Recon, why add this? Rebuttal: Traditional recon tools sell raw alert feeds; we sell the resolution by charging only when a threat is deterministically neutralized.
- Objection: What exactly counts as a 'remediated threat' for billing? Rebuttal: A threat is only billed when a malicious domain is taken down, a leaked credential is force-reset via API, or an adversary IP is verified blocked at your edge.
**Pricing Architecture**: UsageMeter
**Agent Checkout Support**:
- agentic-commerce-protocol

## Startup Brand

**Voice**: Authoritative and precise, favoring forensic exactness over alarmist cybersecurity rhetoric.
**Tagline**: Map external digital exposures directly to internal identity graphs.
**Icon Concept**: fingerprint
**Palette Intent**: electric-signal
**Visual Identity**: Stark terminal backgrounds and monospace typography contrast with sharp neon green data lines that illustrate deterministic identity linkages.
**Archetype Reference**: the-sage

## Startup Buyer Chain

**Chain**: Exint → Enterprise Security Operations Center → Corporate Workforce Identities
**Gtm Motion**: Acquires enterprise security teams by running a zero-install external exposure scan that links a leaked credential to an active internal identity. Expands revenue through an outcome-based pricing model that scales per remediated threat using deterministic evidence graphs.
**Agent Channel**: Designed to list as a queryable endpoint in the Microsoft Security Copilot plugin registry, allowing autonomous SOC agents to retrieve deterministic evidence graphs for compromised identities.
**Primary Channel**: Targeted outbound to CISOs and threat intelligence directors triggered by public dark web credential drops affecting their corporate domain.

## Startup Customer Journey

```mermaid
flowchart LR; A[Dark Web Credential Alert] --> B[Zero-Install Exposure Scan]; B --> C[Deterministic Evidence Graph]; C --> D[Remediated Threat]; D --> E[Enterprise Threat Pool]; E --> F[Microsoft Security Copilot];
```

## Startup Proof Points

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Pilot Goals**:
- 30-day read-only IAM integration pilot: Aim to prove the deterministic mapping of existing OSINT data to internal identities without extracting or storing raw directory records.
- 14-day live remediation pilot: Target demonstrating at least one successful malicious domain takedown or automated credential force-reset within the 48-hour guarantee window.
**Target Metrics**:
- Target: 48-hour maximum time-to-remediation for verified external infrastructure threats.
- Aim: 100 percent elimination of false-positive OSINT alerts sent to SOC analysts by requiring deterministic internal identity maps.
- Target: Under 60-minute automated credential reset execution time following a verified external credential leak.
- Aim: $0 enterprise spend on unresolved or unmapped threat intelligence alerts.
**Target Case Studies**:
- Mid-market financial services firm: Target transformation demonstrates reducing credential leakage response times from days to under an hour via deterministic internal identity mapping.
- Enterprise healthcare provider: Target transformation involves migrating from expensive threat feeds to an outcome-only pricing model, completely eliminating false-positive OSINT alerts.
- High-growth SaaS security team: Target transformation proves the ability to automatically map external infrastructure threats to internal identities and achieve full takedowns within a 48-hour SLA without increasing analyst headcount.
**Testimonial Targets**:
- Chief Information Security Officer (CISO): Seeking a testimonial highlighting the financial predictability of paying exclusively for confirmed threat resolutions rather than raw alert feeds.
- Security Operations Center (SOC) Manager: Aiming for a testimonial that validates the elimination of alert fatigue because external threats are deterministically mapped to internal identities prior to triage.
- Identity and Access Management (IAM) Lead: Targeting a testimonial confirming trust in the read-only, least-privilege API architecture that enables automated credential resets without exposing directory records.

## Startup Top Risks

**Risks**:
- Severity: existential · Description: Outcome-based pricing model fails to generate revenue because enterprise clients dispute whether Exint's intelligence directly caused the threat remediation. · Mitigation Status: unmitigated
- Severity: high · Description: Enterprise security teams refuse to grant the deep Active Directory and Okta read permissions required to map external exposures to internal identity graphs. · Mitigation Status: in-progress
- Severity: high · Description: CrowdStrike bundles external reconnaissance with their existing endpoint agent footprint to render a standalone exposure mapping tool redundant. · Mitigation Status: unmitigated
- Severity: moderate · Description: Data ingestion pipelines fail to reliably link fragmented open-source intelligence artifacts into deterministic evidence graphs without intensive manual analyst intervention. · Mitigation Status: in-progress

## Startup Competitors

- [Recorded Future](/Competitors/Recorded_Future) — Incumbent
- [CrowdStrike Falcon Recon](/Competitors/CrowdStrike_Falcon_Recon) — Incumbent
- [Manual Open-Source Intelligence](/Competitors/Manual_Open-Source_Intelligence) — Status Quo
- [Mandiant Advantage](/Competitors/Mandiant_Advantage) — Threat Intelligence
- [Cortex Xpanse](/Competitors/Cortex_Xpanse) — EASM Platform
- [ZeroFox](/Competitors/ZeroFox) — Digital Risk Protection

## Startup Solution Stack

- [Threat Remediation Service](/Services/Threat_Remediation_Service) — Service-as-Software
- [Identity Mapping Agent](/Agents/Identity_Mapping_Agent) — Agent
- [Evidence Graph Agent](/Agents/Evidence_Graph_Agent) — Agent
- [Exposure Ingestion API](/Software/Exposure_Ingestion_API) — Software
- [Identity Graph Engine](/Software/Identity_Graph_Engine) — Software

## Startup Story Brand

**Hero**:
- **Need**: to be the strategic architect of a resilient firm, not a firefighter chasing noisy alerts
- **Want**: to neutralize external digital exposures before they turn into internal breaches
- **Identity**: the CISO at a mid-market financial services firm
**Plan**:
- Step: Review · Detail: Scan the live map of external exposures already attributed to your specific internal identities.
- Step: Validate · Detail: Confirm the forensic evidence graph linking the leak to a real user in your Entra ID.
- Step: Resolve · Detail: Trigger a one-click takedown or automated credential reset to neutralize the threat instantly.
**Guide**:
- **Empathy**: Does your threat triage process still stall during manual correlation of leaked credentials?
**Problem**:
- **Villain**: unattributed alert volume
- **External**: Security teams spend hours manually cross-referencing Recorded Future alerts against Okta logs to see if a leak actually matters.
- **Internal**: You feel buried under a mountain of contextless data while the real risks remain hidden in the noise.
- **Philosophical**: Cybersecurity expertise belongs in threat resolution, not in manual data entry and log correlation.
**Success**: You resolve threats in under an hour with forensic proof of every remediation.
**One Liner**: Every day, security leads struggle with contextless alerts. Exint maps exposures directly to internal identities so threats are remediated with deterministic proof.
**Positioning**:
- **So That**: pay only for remediated threats with forensic attribution
- **Unlike**: Recorded Future alert feeds
- **For Whom**: mid-market financial services security teams
- **Category**: Exposure Management and Remediation
**Call To Action**:
- **Direct**: Map a threat
- **Transitional**: View evidence graph
**Failure Stakes**:
- Unchecked credential leaks
- Costly manual triage cycles
- Compliance failure penalties
**Transformation**:
- **To**: free to architect systemic resilience, no longer stuck doing the drudgery
- **From**: a CISO buried in raw threat feeds
**Controlling Idea**: Remediation should be billed by outcome, not by the volume of raw alerts.

## Startup Token Hero

**Genre**: founding-hypothesis
**Rendered**: Every day, security leads struggle with contextless alerts. Exint maps exposures directly to internal identities so threats are remediated with deterministic proof.
**Mechanism**: spine-derived-v1
**Template Id**: spine-founding-hypothesis
**Vocab Fingerprint**: dfa13fd7903e5b14

## Startup Token Positioning

**Genre**: moore-positioning
**Rendered**: Exposure Management and Remediation for mid-market financial services security teams. Unlike Recorded Future alert feeds — pay only for remediated threats with forensic attribution.
**Mechanism**: spine-derived-v1
**Template Id**: spine-moore-positioning
**Vocab Fingerprint**: d26052299f371d72

## Startup Token Pitch Deck

**Genre**: pitch-deck
**Rendered**: Problem: Security teams spend hours manually cross-referencing Recorded Future alerts against Okta logs to see if a leak actually matters.
Solution: Every day, security leads struggle with contextless alerts. Exint maps exposures directly to internal identities so threats are remediated with deterministic proof.
Customer: mid-market financial services security teams
Unlike: Recorded Future alert feeds
**Mechanism**: spine-derived-v1
**Template Id**: spine-pitch-deck
**Vocab Fingerprint**: be4720b844d5a8b3

## Startup Token M E D D P I C C

**Pain**: Security teams spend hours manually cross-referencing Recorded Future alerts against Okta logs to see if a leak actually matters.
**Metrics**: Target: You resolve threats in under an hour with forensic proof of every remediation.
**Rendered**: Pain: Security teams spend hours manually cross-referencing Recorded Future alerts against Okta logs to see if a leak actually matters.
Economic buyer: Enterprise Security Operations Center
Metrics: Target: You resolve threats in under an hour with forensic proof of every remediation.
Competition: Recorded Future alert feeds
**Mechanism**: spine-derived-v1
**Competition**: Recorded Future alert feeds
**Economic Buyer**: Enterprise Security Operations Center
**Vocab Fingerprint**: dfedf7569d43335c

## Startup Token Cold Email

**Genre**: cold-email
**Rendered**: Subject: Exposure Management and Remediation for mid-market financial services security teams

mid-market financial services security teams — Security teams spend hours manually cross-referencing Recorded Future alerts against Okta logs to see if a leak actually matters. Every day, security leads struggle with contextless alerts. Exint maps exposures directly to internal identities so threats are remediated with deterministic proof.
**Mechanism**: spine-derived-v1
**Template Id**: spine-cold-email
**Vocab Fingerprint**: 03931fef8b807a83

## Startup Token Agent Spec

**Genre**: ai-agent-spec
**Rendered**: Exposure Management and Remediation. Every day, security leads struggle with contextless alerts. Exint maps exposures directly to internal identities so threats are remediated with deterministic proof. Serves mid-market financial services security teams.
**Mechanism**: spine-derived-v1
**Template Id**: spine-ai-agent-spec
**Vocab Fingerprint**: 05681068e5699743

## Neighborhood

### Candidate solutions

- [Optimize Film Roll Yield](/Problems/Optimize_Film_Roll_Yield) — candidate solution for · Problems

### Composed of

- [YieldWeaver Service](/Services/YieldWeaver_Service) — composes · Services
- [Geometric Packing Engine](/Software/Geometric_Packing_Engine) — composes · Software
- [Plotter Translation API](/Software/Plotter_Translation_API) — composes · Software
- [Queue Batching Agent](/Agents/Queue_Batching_Agent) — composes · Agents
- [Scrap Allocation Worker](/Agents/Scrap_Allocation_Worker) — composes · Agents
- [Pattern Allocation Agent](/Agents/Pattern_Allocation_Agent) — composes · Agents
- [Queue Tessellation Service](/Services/Queue_Tessellation_Service) — composes · Services
- [Algorithmic Packing Engine](/Software/Algorithmic_Packing_Engine) — composes · Software
- [Offcut Recovery Worker](/Agents/Offcut_Recovery_Worker) — composes · Agents
- [Identity Mapping Agent](/Agents/Identity_Mapping_Agent) — composes · Agents
- [Threat Remediation Service](/Services/Threat_Remediation_Service) — composes · Services
- [Identity Graph Engine](/Software/Identity_Graph_Engine) — composes · Software
- [Exposure Ingestion API](/Software/Exposure_Ingestion_API) — composes · Software
- [Evidence Graph Agent](/Agents/Evidence_Graph_Agent) — composes · Agents

### What it offers

- [Yield Weaver](/Services/Yield_Weaver) — offers · Services
- [Identity Exposure Engine](/Services/Identity_Exposure_Engine) — offers · Services

### Embodies

- [Service-as-Software](/Theses/Service-as-Software) — embodies · Theses

### Competitors

- [XPEL Design Access Program](/Competitors/XPEL_Design_Access_Program) — competes with · Competitors
- [CorelDRAW](/Competitors/CorelDRAW) — competes with · Competitors
- [Manual Pattern Rotation](/Competitors/Manual_Pattern_Rotation) — competes with · Competitors
- [SunTek TruCut](/Competitors/SunTek_TruCut) — competes with · Competitors
- [SunTek TruCut Software](/Competitors/SunTek_TruCut_Software) — competes with · Competitors
- [3M Pattern and Solutions](/Competitors/3M_Pattern_and_Solutions) — competes with · Competitors
- [manual drag-and-drop](/Competitors/manual_drag-and-drop) — competes with · Competitors
- [Manual drag-and-drop rotation](/Competitors/Manual_drag-and-drop_rotation) — competes with · Competitors
- [XPEL Design Access](/Competitors/XPEL_Design_Access) — competes with · Competitors
- [3M Pattern Solutions](/Competitors/3M_Pattern_Solutions) — competes with · Competitors
- [XPEL DAP](/Competitors/XPEL_DAP) — competes with · Competitors
- [manual drag-and-drop nesting](/Competitors/manual_drag-and-drop_nesting) — competes with · Competitors
- [Manual Open-Source Intelligence](/Competitors/Manual_Open-Source_Intelligence) — competes with · Competitors
- [Cortex Xpanse](/Competitors/Cortex_Xpanse) — competes with · Competitors
- [Mandiant Advantage](/Competitors/Mandiant_Advantage) — competes with · Competitors
- [ZeroFox](/Competitors/ZeroFox) — competes with · Competitors
- [CrowdStrike Falcon Recon](/Competitors/CrowdStrike_Falcon_Recon) — competes with · Competitors
- [Recorded Future](/Competitors/Recorded_Future) — competes with · Competitors

### Who it serves

- [Aftermarket Protective Film and Tint Shop](/CompanyTypes/Aftermarket_Protective_Film_and_Tint_Shop) — serves · CompanyTypes

### Similar Startups

- [Shadowlounge](/Startups/Shadowlounge) — similar · Startups
- [Gatherstar](/Startups/Gatherstar) — similar · Startups
- [Cfervices](/Startups/Cfervices) — similar · Startups
- [Cyberlume](/Startups/Cyberlume) — similar · Startups
- [Cloudint](/Startups/Cloudint) — similar · Startups
- [Intaff](/Startups/Intaff) — similar · Startups
- [Domill](/Startups/Domill) — similar · Startups
- [Forgescreen](/Startups/Forgescreen) — similar · Startups
- [Synent](/Startups/Synent) — similar · Startups
- [Triageridge](/Startups/Triageridge) — similar · Startups
- [Canopy Strike](/Startups/Canopy_Strike) — similar · Startups
- [Dalatigue](/Startups/Dalatigue) — similar · Startups
- [Astroblem](/Startups/Astroblem) — similar · Startups
- [Verow](/Startups/Verow) — similar · Startups
- [Defench](/Startups/Defench) — similar · Startups
- [Flarestorm](/Startups/Flarestorm) — similar · Startups
- [Actiondomain](/Startups/Actiondomain) — similar · Startups
- [Accirm](/Startups/Accirm) — similar · Startups
- [Porosityscaffold](/Startups/Porosityscaffold) — similar · Startups
- [Buyerpoint](/Startups/Buyerpoint) — similar · Startups
