# Gatherstar

*/Startups/Gatherstar*

## Startup Overview

Aggregates and structures continuous open-source intelligence feeds into a high-fidelity threat telemetry stream. Security analysts routinely drown in a deluge of unverified internet chatter, wasting critical response time sifting legitimate risks from background noise.

The engine replaces manual collection and untargeted data firehoses by passing incoming data through strict deterministic rules. It systematically strips out false positives and drops only verified, structured threat indicators directly into security operations workflows.

While legacy platforms like Dataminr and Recorded Future charge steep recurring fees for raw data volume, this architecture aligns cost directly with value. The system is priced strictly per confirmed threat event, allowing security teams to pay for actual intelligence rather than the noise surrounding it.

## Startup Founding Hypothesis

**Approach**: that aggregates and structures continuous open-source intelligence feeds
**Competitors**:
- [Dataminr](/Competitors/Dataminr)
- [Recorded Future](/Competitors/Recorded_Future)
- [manual OSINT collection](/Competitors/manual_OSINT_collection)
**Differentiator2x2**: noise-filtered through deterministic rules and priced per confirmed threat event

## Startup Solution Coordinate

**Solution**: [Gatherstar Intelligence Feed](/Services/Gatherstar_Intelligence_Feed)

## Startup Position2x2

```mermaid
quadrantChart
    title OSINT Feeds Positioning
    x-axis Subscription Pricing --> Pay-Per-Event Pricing
    y-axis High-Noise Alerting --> Deterministic Rules
    quadrant-1 Pay for Signal
    quadrant-2 Fixed Cost Precision
    quadrant-3 Subscription Noise
    quadrant-4 Empty
    "Gatherstar": [0.85, 0.85]
    "Manual OSINT Collection": [0.15, 0.80]
    "Recorded Future": [0.25, 0.40]
    "Dataminr": [0.10, 0.25]
```

## Startup Offer

**Proof**:
- Mid-market security teams aiming to receive validated threat alerts within 15 minutes of initial open-source publication.
- Corporate risk offices targeting a 90% reduction in daily alert noise compared to raw feed ingestion.
- Financial institutions seeking to transition from flat-fee intelligence retainers to pure per-event billing.
**Tiers**:
- Name: Targeted Perimeter · Price: ~$100–$150 per confirmed threat event · Inclusions: Up to 5 custom deterministic rule sets monitoring standard open-source feeds for a single organization footprint, billed strictly on matched events.
- Name: Extended Coverage · Price: ~$60–$90 per confirmed threat event · Inclusions: Up to 25 custom rule sets with intended webhook integration designed to push structured alerts directly to your team's incident response system.
- Name: Enterprise Landscape · Price: ~$30–$50 per confirmed threat event · Inclusions: Unlimited rule configurations across global OSINT sources, featuring configurable daily velocity caps to prevent budget exhaustion during major incidents.
**Guarantee**: If an alert is billed but fails to match the strict deterministic rules established during setup, the event charge is refunded and the rule logic is recalibrated at no cost.
**Business Function**: ProvideService
**Objection Handlers**:
- How do you define a 'confirmed threat event' so we aren't overcharged? Events are defined by deterministic Boolean logic you set before ingestion; if an alert doesn't match your exact parameters, you aren't billed.
- Does this integrate with our existing SIEM or SOAR? Gatherstar is designed to push structured JSON alerts directly to standard endpoints for Splunk, Sentinel, or webhook ingestion.
- What if an adversary attacks across hundreds of endpoints at once, causing a billing spike? Billing structures include configurable daily and monthly velocity caps to prevent alert storms from exhausting your budget.
- Why not use Dataminr for broader coverage? Dataminr charges high flat annual fees for noisy probabilistic scoring; we strip the noise using hard logic and only charge for the validated signal.
**Pricing Architecture**: UsageMeter
**Agent Checkout Support**:
- agentic-commerce-protocol

## Startup Brand

**Voice**: Clinical intelligence briefing characterized by strict adherence to verified facts.
**Tagline**: Pay only for confirmed open-source threat events.
**Icon Concept**: antenna
**Palette Intent**: institutional-cool
**Visual Identity**: Muted slate grays and tactical navy blues contrast with sharp signal-white typography, evoking the austere environment of a secure operations center.
**Archetype Reference**: the-sage

## Startup Buyer Chain

**Chain**: Gatherstar → Security Operations Center (SOC) Manager → Threat Intelligence Analyst
**Gtm Motion**: Acquires enterprise security teams by offering a shadow-deployment proof of concept that runs alongside their existing threat feeds to demonstrate a lower false-positive rate. Expands revenue automatically via the per-confirmed-threat pricing model as the client registers more organizational assets and domains for monitoring.
**Agent Channel**: Would target listing in the Model Context Protocol (MCP) directory and autonomous AI agent tool registries, enabling autonomous security copilots to discover and query the deterministic OSINT feed during incident triage.
**Primary Channel**: Designed to list in major SIEM and SOAR integration directories (such as Splunkbase or the Cortex XSOAR marketplace) where security engineers actively search for structured threat enrichment data.

## Startup Customer Journey

```mermaid
flowchart LR; A[SIEM Directory Listing] --> B[Shadow-Deployment Environment]; B --> C[Validated Threat Alert]; C --> D[SIEM Webhook Integration]; D --> E[Registered Organizational Asset]; E --> F[Security Peer Network];
```

## Startup Proof Points

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Pilot Goals**:
- 14-day parallel run against an existing flat-fee intelligence provider to demonstrate Gatherstar delivers matching critical events within 15 minutes while generating 90 percent fewer non-actionable alerts.
- 30-day integration test routing Gatherstar structured JSON alerts into a standard SIEM endpoint to validate payload delivery and confirm zero false-positive billings based on established Boolean rules.
**Target Metrics**:
- Target: 90 percent reduction in daily alert noise compared to raw OSINT feed ingestion.
- Aim: Under 15-minute latency between initial open-source publication and validated webhook alert delivery.
- Target: 100 percent strict adherence to deterministic Boolean logic before triggering a billed event.
- Aim: Zero budget exhaustion incidents during threat spikes due to configurable daily velocity caps.
**Target Case Studies**:
- Mid-market SaaS security team replacing a noisy flat-fee threat intelligence platform with Gatherstar to pay only for alerts matching strict deterministic rules and reduce overall intelligence spend.
- Regional financial institution risk office integrating Gatherstar webhooks into an existing SIEM to eliminate raw OSINT feed ingestion and shift to a pure per-event billing model.
- Healthcare corporate network configuring 20 custom rule sets targeting specific technology stack vulnerabilities to achieve validated alert delivery from open-source publication without false positive charges.
**Testimonial Targets**:
- Chief Information Security Officer expressing relief at securing predictable per-event intelligence pricing over massive flat annual fees for probabilistic noise.
- Security Operations Center Lead praising the strict deterministic Boolean logic that ensures the SIEM only ingests actionable pre-validated threat signals.
- Director of Cyber Risk highlighting confidence in the daily velocity caps that prevent budget drain during widespread zero-day attacks.

## Startup Top Risks

**Risks**:
- Severity: existential · Description: Major OSINT data sources like X, Reddit, or Telegram revoke API access or aggressively raise tier pricing, instantly starving the aggregation feeds. · Mitigation Status: unmitigated
- Severity: high · Description: The pay-per-confirmed-threat pricing model results in unpredictable and insufficient baseline revenue during periods of low global threat activity. · Mitigation Status: unmitigated
- Severity: high · Description: Deterministic filtering rules fail to identify novel or obfuscated threat patterns, leading to critical missed events compared to machine-learning competitors. · Mitigation Status: in-progress
- Severity: moderate · Description: Ingesting and structuring feeds from fringe or dark web forums introduces unexpected legal liabilities regarding inadvertently collected personally identifiable information. · Mitigation Status: in-progress

## Startup Competitors

- [Dataminr](/Competitors/Dataminr) — Incumbent Platform
- [Recorded Future](/Competitors/Recorded_Future) — Incumbent Platform
- [Manual OSINT Collection](/Competitors/Manual_OSINT_Collection) — Status Quo
- [Babel Street](/Competitors/Babel_Street) — Threat Intel Provider
- [Flashpoint](/Competitors/Flashpoint) — Threat Intel Provider

## Startup Solution Stack

- [Threat Event Service](/Services/Threat_Event_Service) — Service-as-Software
- [Intelligence Aggregation Agent](/Agents/Intelligence_Aggregation_Agent) — Agent
- [Noise Filtration Worker](/Agents/Noise_Filtration_Worker) — Agent
- [Deterministic Rule Engine](/Software/Deterministic_Rule_Engine) — Software
- [Threat Feed API](/Software/Threat_Feed_API) — Software

## Startup Story Brand

**Hero**:
- **Need**: to be the strategic protector of the perimeter, not a filter for junk data
- **Want**: to receive validated threat alerts without paying for bulk noise
- **Identity**: the security lead at a mid-market enterprise
**Plan**:
- Step: Define logic · Detail: Set your deterministic rule sets to monitor only the specific assets and keywords that matter to your footprint.
- Step: Verify events · Detail: Our system matches raw feeds against your hard rules, discarding non-relevant data before it hits your desk.
- Step: Review alerts · Detail: Receive structured, actionable threat events in your Splunk or Sentinel dashboard and only pay for what matched.
**Guide**:
- **Empathy**: Does your threat monitoring still flood your Slack with irrelevant social media chatter?
**Problem**:
- **Villain**: probabilistic noise
- **External**: Monitoring open-source intelligence through Dataminr or manual Twitter feeds forces your team to sift through thousands of irrelevant false positives every day.
- **Internal**: You feel exhausted by the constant ping of alerts that have no actual bearing on your specific company assets.
- **Philosophical**: Every security team deserves signal that matches their specific risk profile — not a bill for data they never used.
**Success**: You receive high-fidelity, confirmed threat events delivered directly to your incident response system, with a budget that only scales when real threats appear.
**One Liner**: Instead of paying flat annual fees for noisy probabilistic scoring, Gatherstar delivers deterministic, rule-matched open-source intelligence — so you only pay for confirmed threat events.
**Positioning**:
- **So That**: pay only for validated events that match your deterministic rules
- **Unlike**: Dataminr and Recorded Future
- **For Whom**: security leads at mid-market enterprises
- **Category**: Usage-based OSINT threat intelligence
**Call To Action**:
- **Direct**: Launch monitoring perimeter
- **Transitional**: View sample JSON payload
**Failure Stakes**:
- Missing a critical zero-day
- Budget waste on irrelevant data
- Alert fatigue causing team burnout
**Transformation**:
- **To**: the enterprise's strategic intelligence architect
- **From**: a manual analyst buried in Dataminr alerts
**Controlling Idea**: Intelligence billing should be tied to confirmed signals, not raw data ingestion.

## Startup Token Hero

**Genre**: founding-hypothesis
**Rendered**: Instead of paying flat annual fees for noisy probabilistic scoring, Gatherstar delivers deterministic, rule-matched open-source intelligence — so you only pay for confirmed threat events.
**Mechanism**: spine-derived-v1
**Template Id**: spine-founding-hypothesis
**Vocab Fingerprint**: 626595b5c711ada3

## Startup Token Positioning

**Genre**: moore-positioning
**Rendered**: Usage-based OSINT threat intelligence for security leads at mid-market enterprises. Unlike Dataminr and Recorded Future — pay only for validated events that match your deterministic rules.
**Mechanism**: spine-derived-v1
**Template Id**: spine-moore-positioning
**Vocab Fingerprint**: c50d03d092d0071c

## Startup Token Pitch Deck

**Genre**: pitch-deck
**Rendered**: Problem: Monitoring open-source intelligence through Dataminr or manual Twitter feeds forces your team to sift through thousands of irrelevant false positives every day.
Solution: Instead of paying flat annual fees for noisy probabilistic scoring, Gatherstar delivers deterministic, rule-matched open-source intelligence — so you only pay for confirmed threat events.
Customer: security leads at mid-market enterprises
Unlike: Dataminr and Recorded Future
**Mechanism**: spine-derived-v1
**Template Id**: spine-pitch-deck
**Vocab Fingerprint**: 39c15fc9c7a24e69

## Startup Token M E D D P I C C

**Pain**: Monitoring open-source intelligence through Dataminr or manual Twitter feeds forces your team to sift through thousands of irrelevant false positives every day.
**Metrics**: Target: You receive high-fidelity, confirmed threat events delivered directly to your incident response system, with a budget that only scales when real threats appear.
**Rendered**: Pain: Monitoring open-source intelligence through Dataminr or manual Twitter feeds forces your team to sift through thousands of irrelevant false positives every day.
Economic buyer: Security Operations Center Manager
Metrics: Target: You receive high-fidelity, confirmed threat events delivered directly to your incident response system, with a budget that only scales when real threats appear.
Competition: Dataminr and Recorded Future
**Mechanism**: spine-derived-v1
**Competition**: Dataminr and Recorded Future
**Economic Buyer**: Security Operations Center Manager
**Vocab Fingerprint**: d88ac696e0090fe6

## Startup Token Cold Email

**Genre**: cold-email
**Rendered**: Subject: Usage-based OSINT threat intelligence for security leads at mid-market enterprises

security leads at mid-market enterprises — Monitoring open-source intelligence through Dataminr or manual Twitter feeds forces your team to sift through thousands of irrelevant false positives every day. Instead of paying flat annual fees for noisy probabilistic scoring, Gatherstar delivers deterministic, rule-matched open-source intelligence — so you only pay for confirmed threat events.
**Mechanism**: spine-derived-v1
**Template Id**: spine-cold-email
**Vocab Fingerprint**: 4a87fe0e3d2e3ca2

## Startup Token Agent Spec

**Genre**: ai-agent-spec
**Rendered**: Usage-based OSINT threat intelligence. Instead of paying flat annual fees for noisy probabilistic scoring, Gatherstar delivers deterministic, rule-matched open-source intelligence — so you only pay for confirmed threat events. Serves security leads at mid-market enterprises.
**Mechanism**: spine-derived-v1
**Template Id**: spine-ai-agent-spec
**Vocab Fingerprint**: cd998f50947b5192

## Neighborhood

### Candidate solutions

- [Untangle Intercompany Eliminations](/Problems/Untangle_Intercompany_Eliminations) — candidate solution for · Problems

### Composed of

- [Threat Event Service](/Services/Threat_Event_Service) — composes · Services
- [Intelligence Aggregation Agent](/Agents/Intelligence_Aggregation_Agent) — composes · Agents
- [Noise Filtration Worker](/Agents/Noise_Filtration_Worker) — composes · Agents
- [Deterministic Rule Engine](/Software/Deterministic_Rule_Engine) — composes · Software
- [Threat Feed API](/Software/Threat_Feed_API) — composes · Software

### What it offers

- [Gatherstar Intelligence Feed](/Services/Gatherstar_Intelligence_Feed) — offers · Services

### Embodies

- [Service-as-Software](/Theses/Service-as-Software) — embodies · Theses

### Competitors

- [Flashpoint](/Competitors/Flashpoint) — competes with · Competitors
- [Babel Street](/Competitors/Babel_Street) — competes with · Competitors
- [Dataminr](/Competitors/Dataminr) — competes with · Competitors
- [Recorded Future](/Competitors/Recorded_Future) — competes with · Competitors
- [Manual OSINT Collection](/Competitors/Manual_OSINT_Collection) — competes with · Competitors

### Similar Startups

- [Triage](/Startups/Triage) — similar · Startups
- [Detectionyard](/Startups/Detectionyard) — similar · Startups
- [Cyberlume](/Startups/Cyberlume) — similar · Startups
- [Forgescreen](/Startups/Forgescreen) — similar · Startups
- [Triagehaven](/Startups/Triagehaven) — similar · Startups
- [Exint](/Startups/Exint) — similar · Startups
- [Anomalyload](/Startups/Anomalyload) — similar · Startups
- [Shadowlounge](/Startups/Shadowlounge) — similar · Startups
- [Security](/Startups/Security) — similar · Startups
- [Triageridge](/Startups/Triageridge) — similar · Startups
- [Zenvolumetrics](/Startups/Zenvolumetrics) — similar · Startups
- [Problemgate](/Startups/Problemgate) — similar · Startups
- [Probluard](/Startups/Probluard) — similar · Startups
- [Cascadeharbor](/Startups/Cascadeharbor) — similar · Startups
- [Sociphan](/Startups/Sociphan) — similar · Startups
- [Cfervices](/Startups/Cfervices) — similar · Startups
- [Triagestar](/Startups/Triagestar) — similar · Startups
- [Clearhive](/Startups/Clearhive) — similar · Startups
- [Telemetrytide](/Startups/Telemetrytide) — similar · Startups
- [Flarestorm](/Startups/Flarestorm) — similar · Startups
