Comparisec
Submit reviewFor vendors
Threat IntelligenceFlashpoint
StrongAdequateStrongStrong
4.5

VendorsThreat IntelligenceFlashpoint

Flashpoint logo

Flashpoint

Flashpoint

Founded 2015·US·PE-backed
4.5

Combined score

G2
4.480
Gartner
4.560

Editorial verdict

Flashpoint has built the deepest criminal underground intelligence of any commercial threat intelligence vendor. The human analyst network embedded in criminal forums and dark web communities goes beyond automated crawling to include context and relationships that automated collection cannot capture. For financial services, retail, and e-commerce organisations whose primary threat actors are financially motivated criminals rather than nation-state actors, Flashpoint's coverage of fraud schemes, stolen credential markets, and ransomware group operations is more directly actionable than the APT-focused intelligence that Mandiant or Recorded Future excel at.

The Carlyle Group PE ownership raises the standard questions about investment continuity and pricing trajectory that buyers should address directly.

The verdict: Flashpoint is right for financial services, retail, and e-commerce organisations facing financially motivated criminal threats who need the deepest dark web and criminal forum intelligence available. Organisations primarily concerned with nation-state and APT threats should evaluate Mandiant or Recorded Future.

Last reviewed: May 2026

G2

4.480 reviews

Gartner

4.560 reviews
Gartner MQ: Challenger (Gartner TI MQ 2024)

Threat Intelligence assessment

PROTECTIONStrong
Intelligence depth
4 / 5
Threat actor coverage
4 / 5
OPERATIONSAdequate
Workflow integration
3 / 5
Feed freshness
4 / 5
ANALYTICSStrong
Attribution & analysis
4 / 5
TRUST & ECOSYSTEMStrong
Source quality & accuracy
4 / 5

Strongest: Intelligence depth

Watch out for: Workflow integration

Strengths & limitations

Strengths

Deep illicit community coverage — 1M+ dark web and closed-source communities monitored
Ignite platform delivers actionable intelligence with analyst-written finished reports
Strong fraud and physical security intelligence alongside cyber threat data

Watch out for

Less SIEM/SOAR integration depth than Recorded Future or ThreatConnect
Narrower geographic coverage than global leaders
Pricing not transparent — requires vendor engagement

Best for

Organisations wanting the broadest dark web and illicit community monitoring with finished analyst reports.

Not suitable for: Organisations needing primary IOC feeds — Recorded Future and CrowdStrike offer more technical indicator volume.

Compliance coverage

SOC 2
HIPAA
NIST CSF
PCI-DSS
GDPR
ISO 27001
Essential Eight
AU Privacy Act
CMMC
NIS2
DORA
CIS Benchmarks

Switching intelligence

Switching from

Common migration paths based on review data

  • Manual OSINT
  • Basic dark web monitoring

Also considering

Vendors typically shortlisted alongside

← Back to Threat IntelligenceCompare with other Threat Intelligence vendors →

Quick facts

Pricing modelannual subscription per module
Pricing range$15,000-150,000+/year
Free trialNo
Min seatsNo minimum
Deployment time1-2 weeks
Complexity2 / 5
Pricing transparency2 / 5
AU presenceNo
IRAP assessedNo
Open sourceProprietary

Deployment

ModelsSaaS
OS supportCloud-native
CloudAWS
SupportEmail, Phone, Dedicated CSM
Data residencyUS, EU

Company

Flashpoint

Founded 2015 · 200-400 employees · PE-backed

HQ: US

$40M+ ARR est.

Certifications

SOC 2 Type II, ISO 27001

Integrations

SplunkMicrosoft SentinelCrowdStrikeServiceNowMISPJira