AI-enabled intelligence management platform built on prioritised intelligence requirements. Automated collection, analysis, and dissemination, and source-checked reporting, so you always have the answers that matter.
Automated, Open-Source Cyber Threat Intelligence Cross-Referenced against
MITRE ATT&CK® is a registered trademark of The MITRE Corporation.
The gap between what gets published and what anyone has observed being exploited. Counted from the public catalogues, not estimated.
Disclosed in the last twelve months, across every vendor and product.
Added to CISA's Known Exploited Vulnerabilities catalogue over the same period.
Which is the whole argument for working from requirements rather than from a feed.
Every vulnerability CISA has recorded as exploited since the catalogue opened in 2021.
Counted from CISA KEV and FIRST.org EPSS, as held on 21 September 2026. Conundrum ingests both daily; these figures are read from that data rather than written into the page.
Direction through feedback, with the evidence attached at every step.
You decide what the platform cares about. Requirements come first, and collection, scoring and reporting follow from them.
Learn more →Intelligence arrives without anyone fetching it, and you can see when it stops arriving, which matters more than the volume that does.
Learn more →Your analysts work the intelligence: triaging it, questioning it and mapping it against the frameworks they already use.
Learn more →Your team writes intelligence rather than only reading it, and what the platform generates is checked before it reaches anyone.
Learn more →Finished intelligence reaches the people who need it, and the systems they work in, on the routing rules you set.
Learn more →What your team does with the intelligence comes back into it, visibly, with the evidence attached.
Learn more →PIRs at organisation, sector and global tiers, tuned to your industry.
Open-source collection across the five major attack vectors, plus geopolitics.
Reports scored against their own sources before publication.
Ask questions of your own intelligence and get cited answers, or a refusal.
CISA SSVC decisions with KEV and EPSS, personalised by your requirements.
Ransomware leak-site listings tracked and matched against your watchlists.
Edit, annotate and publish, with version history on every published report.
Signed outbound webhooks and a read-only agent interface over your intelligence.
Every report the platform generates answers a requirement you set, and is checked before anyone reads it.
The judgements that carry consequences stay with your analysts. This is a design position rather than a roadmap gap, and it is the part of the product we are least likely to change.
Nothing reaches a recipient on a machine's initiative. Routing follows rules your admins set, and a person decides who is told what.
Naming the actor behind an intrusion is an analytic judgement with consequences. It is made by an analyst who can defend it, never inferred on your behalf.
We do not show a number a model produced about its own certainty. Where sourcing strength matters, it is described in the terms analysts already use.
Asked something your intelligence cannot answer, the assistant says so. On the benchmark we hold it to, nothing was invented to fill the gap.
Software alone doesn't make an intelligence capability. The methodology comes first; the platform operationalises it.
The requirement comes first. Everything the platform collects, scores and reports is answerable to a question somebody actually asked.
Tools change. The intelligence cycle does not, and a team that runs it well outperforms a team with better software and no discipline.
Priority intelligence requirements, collection planning, intelligence gaps, the intelligence cycle, explained properly by the author of the methodology and cross-linked so it reads as a reference library rather than a blog.
A demo runs on your sector's intelligence, not a canned dataset.