Genesis/Cybersecurity, Identity & Threat Intelligence
SaaS ideas for Cybersecurity, Identity & Threat Intelligence
62 researched directions Genesis invented for this market. Every one is free to read and free to take.
- AgentCheckpointAn enterprise agent-identity and delegated-authorization registry that evaluates exact action requests against versioned policy and human approval.
- AgentCustodyAn agency-facing identity and action ledger that binds each agent event to client scope, credential authority, approval evidence and destination readback.
- AgentPassportA managed issuer and verifier for open agent credentials, bounded delegation and revocation with enterprise-owned policy and keys.
- AgentscopeA read-only inbound automation traffic registry for regulated organizations that correlates minimized web and interface observations with signed identity claims and owner policies, then routes unknown or mismatched sessions through human review.
- AgentveinA hosted identity and credential control plane for small AI teams that issues each agent a distinct cryptographic identity, exchanges narrowly delegated tokens, isolates secrets, revokes access in real time, and preserves a verifiable action trail.
- AuthflareA managed authentication surface for small product teams that combines sign-in, multi-factor authentication and role controls with source-aware identity-risk signals, recovery safeguards and auditable human response.
- BreachgridAn authorization-first monitor that correlates permitted exposure and impersonation signals to a founder's verified product surface and tracks remediation evidence.
- BriefCastA protective-intelligence workflow that turns authorized public and licensed signals into analyst-reviewed, source-linked written and spoken briefs for named executive risk surfaces.
- CallSealCall-center deepfake detection and caller-trust scoring that taps inbound audio, returns a sub-500ms trust score, triggers step-up verification, and writes a tamper-evident evidence record aligned to EU AI Act Article 50 for every call.
- ClawSentryA mid-market agent detection-and-response layer that baselines tool use, explains suspicious sequences, and executes policy-approved containment.
- ClawWatchAn endpoint integrity sensor for authorized developer fleets that baselines agent connection configuration, verifies destination identity and routes explainable drift for response.
- ClawWatch SovereignAn offline-first threat-intelligence and configuration-integrity appliance with signed update media, provenance, enclave-local search, drift alerts, and operator-owned remediation for disconnected environments.
- CmmckitA white-label CMMC 2.0 Level 2 evidence kit that lets a solo security consultant run compliance for up to eight DoD-contractor clients from a single seat — auto-collected MFA evidence, OSCAL artifacts, and a one-click assessor packet.
- ConsentGraphA web traffic policy layer that combines client and server evidence, verifies presented agent credentials, routes uncertain sessions to challenge or review and emits a bounded decision receipt.
- CRAIncidentWireA counsel-controlled reporting workspace that versions regime requirements, maps confirmed incident facts, drafts forms and reconciles submission acknowledgments.
- DorapackA lightweight evidence-pack workspace for software vendors selling to EU-regulated buyers that inventories approved code and cloud sources, produces versioned SBOM and architecture candidates, maps evidence to buyer-requested DORA and NIS2 questions, and signs a bounded release manifest while keeping source observation, generated artifact, reviewer approval, supplier representation, buyer assessment, auditor work, authority decision, correction, and compliance outcome separate.
- EchelaneAn isolated security-questionnaire and trust-content workspace for defense contractors and security vendors that indexes only approved evidence, drafts bounded answers through local inference, and emits per-answer provenance receipts while keeping source control, applicability, draft, reviewer approval, company attestation, customer acceptance, assessment, certification, contract decision, correction, and security outcome separate.
- EssentialsProofA Cyber Essentials 2026 evidence workbench for UK small businesses that inventories cloud services tied to business identities, collects authorized identity-provider and service observations, maps current MFA coverage and gaps to sourced scheme questions, and exports a reviewer-approved snapshot without claiming certification.
- FiltravelA regional identity-exposure signal service that matches minimized indicators from authorized threat feeds and proposes policy-controlled step-up authentication.
- GrantReaperA scoped grant-review workspace that inventories authorized team connections, explains effective access and routes downscope or revocation through accountable owners.
- HipaaspanA HIPAA Security Rule 2026 readiness platform built for the 30-300-FTE HealthTech ISV — auto-MFA audit, immutable access logs, and a vendor-certification workflow in one self-serve package.
- HoneyHarborA hosted deception fleet for SMBs that deploys isolated decoy services, captures minimized attacker observations, clusters evidence across consenting tenants, and stages reputation reports for analyst approval.
- InterorgWardenAn issuer-side partner-credential inventory and response workflow that joins approved scope, attributable usage evidence and reversible security policy.
- KeyHorizonA non-human credential lifecycle actuator that inventories metadata without secrets, builds an evidence-backed dependency graph, stages expiry or revocation plans, and executes only approved provider-supported actions with health readback and recovery.
- LeaverProofAn access-lifecycle evidence layer for regulated mid-market firms that joins human, service, and agent identities to grants, reviews, revocations, incidents, and annual certification support.
- MailshroudA supplemental read-only email triage layer for mid-market security teams that uses scoped message access, technical and organizational evidence, and analyst review to identify possible business-email compromise and impersonation missed by existing controls.
- MatanoLiftA managed migration and operations layer for an open security lake that emphasizes dual-run validation, sector detection packs and measured cost displacement rather than generic hosting.
- McpregistryA signed trust registry for the MCP-server ecosystem: each server is detonated in a sandbox, its real capability usage is traced, an attestation is signed and anchored, and the whole thing is exposed as a queryable risk API for the platforms running AI agents.
- MeshFirewallA hosted multi-client agent-tool gateway for agencies that enforces tenant policy, secret and capability boundaries, approval rules, redaction, and signed event evidence at verified paths.
- NhipostA multi-tenant identity-governance workspace that discovers supported service identities, routes ownership and access findings, and assembles scoped evidence for qualified assessment.
- NoxHarborA managed, tenant-isolated case layer around a confirmed open-source intelligence engine, adding authorized source policy, reviewable correlation candidates, role controls and evidence exports without treating public data as permission or identity truth.
- NPMTraceA pre-install and pull-request evidence check that identifies package lifecycle behavior targeting agent configuration, then applies repository-owned review and merge policy.
- OAuthPilfer CheckA client-side authorization test workspace that inventories approved MCP clients, executes bounded OAuth and PKCE scenarios against controlled servers, preserves requests, responses, versions, failures, remediation, retests, and signed evidence with explicit coverage limits.
- OffboardProofAn HR-triggered access-removal workflow that discovers managed grants, requests scoped revocations, confirms destination state, queues human exceptions, and signs a per-leaver evidence certificate.
- OrbitaledgeA managed evidence-cutover service for software companies under 50 employees that inventories existing controls and artifacts, connects approved sources, maps reusable observations across selected frameworks, and hands off an owned operating cadence while keeping source observation, control interpretation, evidence candidate, reviewer approval, remediation, auditor test, certification, customer acceptance, correction, and compliance outcome separate.
- OrphanloomA lightweight offboarding control plane for organizations with 50–500 employees that turns an authorized leaver event into per-application account candidates, reviewable disable-or-retain decisions, governed provider actions, and signed bounded receipts while keeping employment status, identity match, entitlement, approval, provider acknowledgment, destination readback, data transfer, billing effect, audit conclusion, appeal, and correction separate.
- PentestrelayA consultant-facing threat-intelligence gateway that binds every allowed query to a client engagement, verifies provider rights and scope, normalizes source-attributed observations, meters cost, and exports correction-preserving findings evidence.
- PhishDojoA white-label awareness platform for managed security providers that runs consented, bounded synthetic vishing exercises, measures process-level controls, delivers accessible training, and keeps individual responses out of disciplinary and employment decisions.
- PixaverifyA per-use verification orchestration API for fintech teams that obtains explicit authority, collects minimum evidence, runs separately sourced document, face, liveness, sanctions, PEP, adverse-media, and wallet-risk checks, and returns explainable candidates for program-specific review while keeping identity proofing, legal status, customer risk, onboarding decision, account action, appeal, and correction separate.
- PraxguardA provider-activity detection pipeline linking authorized audit events, deterministic rules, model-assisted triage, analyst findings and downstream case readback.
- PromptbastionA CI-oriented security test service for authorized AI endpoints and MCP servers that binds an attack suite to an exact release and environment, records observable behavior and coverage, and routes findings, remediation, exceptions, retest, expiry, and correction.
- QuestForgeA tiered abuse-risk gateway that evaluates bounded event evidence, proposes proportional friction for high-risk actions, offers non-biometric alternatives, and preserves human review, appeal and outcome readback.
- RevokeGateAn instant kill-switch for enterprise AI agents and non-human identities that propagates revocation across connected control points and returns a signed receipt.
- SentrulineAn evidence report generator that inventories an agent deployment, runs bounded static and authorized dynamic checks, maps observations to versioned agent-security risk categories, and exports signed findings, gaps and remediation status.
- SentryDeskA private assessment workspace that maps questionnaire items to scoped policies and assurance artifacts, flags gaps and routes every answer to an accountable owner.
- SolfaxA portfolio-security evidence workspace that collects only authorized breach, vulnerability and external-surface observations, preserves entity and asset confidence, routes findings to each company, and produces sanitized investment-committee briefings without credential disclosure or automated capital decisions.
- SolovaultA continuity vault for solo operators that observes authorized activity, runs a configurable challenge process and coordinates explicitly approved successor access.
- StalebreachA regulated-firm exposure-response workspace linking authorized identifiers, licensed observations, entity matching, owner review, account actions and destination confirmation.
- StealerWatchA source-governed exposure review queue that matches authorized identity rosters, minimizes stolen data, and executes approved identity actions with readback.
- ThreatrecollectA managed threat-memory workspace that extracts entities and indicators from analyst notes, reconciles aliases and serves a governed graph to approved analysis tools.
- TimelineTraceAn investigation workspace that resolves human, service and agent identity candidates into source-linked timelines with uncertainty and correction history.
- TrainforgeA multi-tenant security awareness operations platform for managed providers, with permissioned BEC, voice, text, and synthetic-media exercises plus portable learning packages.
- TriageCrewA review-first triage assistant that normalizes authorized alerts, gathers source-attributed enrichment and proposes a ranked disposition with uncertainty while leaving closure, escalation and response authority with the security team.
- VelaforjaA multi-tenant threat-intelligence operations layer separating source rights, connector health, raw observations, correlation candidates, analyst findings, dissemination and correction.
- VendorGateA multi-tenant OAuth application and AI-agent access monitor for SMBs and service providers that inventories grants, explains effective scopes, flags stale or risky access, and guides authorized revocation with evidence.
- VendorscopeA third-party evidence workbench for procurement and compliance teams that tracks authorized public changes, routes them for review and preserves vendor responses.
- VeriPanelA consented session-integrity layer for high-risk professional calls that preserves technical anomaly evidence for trained review and never scores participant honesty or employability.
- VerubastionA managed questionnaire and trust-center workspace for security-sensitive vendors that runs retrieval and drafting inside a customer-controlled isolated environment, links each answer to approved source versions, requires accountable review and exports signed provenance receipts without treating isolation, a signature or an assurance report as proof that an answer is true.
- VibescanA permissioned repository scanner separating source revision, rule versions, static findings, secret redaction, developer triage, remediation evidence, rescan results and risk acceptance.
- VoxKYCA disclosed, accessible onboarding workflow for regulated financial and insurance products that coordinates applicant statements, document and liveness checks, synthetic-audio risk signals, screening review, consent, and signed evidence.
- VoxObserveA vendor-neutral voice-agent observability and QA workspace that normalizes call states, latency, interruption, dead air, transfers, tool actions, consent, errors, and reviewer outcomes.
- WebglyphA managed dashboard for an authorized browser-security extension that applies data-minimized tenant policy, preserves local-versus-uploaded fields, aggregates versioned indicators and technique mappings, and supports incident review and export with explicit coverage and privacy limits.
