# Filigran

**Canonical:** https://apis.io/providers/filigran/  
**Website:** https://filigran.io/  
**APIs profiled:** 2

Filigran is a cybersecurity company founded in 2022 that builds the eXtended Threat Management (XTM) suite of open-source and enterprise products for cyber threat intelligence, adversary simulation, and crisis management. Its flagship OpenCTI platform exposes a full GraphQL API for structuring, storing, and disseminating STIX 2.1 threat-intelligence knowledge, while OpenAEV (formerly OpenBAS) provides a RESTful API for breach-and-attack simulation and adversarial exposure validation. Filigran maintains official Python clients (pycti, pyobas), a native embedded Model Context Protocol (MCP) server, TAXII 2.1 and SSE live-stream data sharing, webhooks, and a React component / design-system library. The company is SOC 2 Type 2 and ISO/IEC 27001:2022 certified and is backed by Accel and Insight Partners.

## Kin Score — 45.0 / 100 (developing)

Scored 2026-08-30 under rubric 0.17.2. Trend: flat (+0.0 from 45.0).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 42.7 |
| Governance | 18.2 |
| Contract Governance | 18.2 |
| Operational Transparency | 34.2 |
| Developer Ergonomics | 71.4 |
| Commercial Clarity | 28.9 |
| Access Clarity | 28.9 |

## Agent readiness — 23.2 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | documented |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (2)

- **OpenCTI GraphQL API** — The OpenCTI platform exposes a full GraphQL API on the /graphql endpoint for programmatic access to cyber threat intelligence knowledge modeled on STIX 2.1. Authentication uses ...
- **OpenAEV REST API** — OpenAEV (formerly OpenBAS) is an ISO 22398-aligned platform for planning and running crisis exercises, adversary simulations, and breach-and-attack simulation. It ships a RESTfu...

## MCP servers (1)

- **Filigran MCP Server**

## Security (2)

- **Filigran Authentication** — http · 2 schemes
- **Filigran Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC

## Tags

Company, Cybersecurity, Threat Intelligence, OpenCTI, OpenAEV, STIX, GraphQL, Breach and Attack Simulation, Open-Source, Security

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/filigran/). Scores are computed from the provider's own public artifacts under a published rubric.
