Evaluation
Individuals validating threat search, the versioned JSON API, browser analysis, and organization workflows before monitored coverage is activated.
Loading
Pricing
Console evaluation is self-serve. Monitoring and integration are sales-provisioned so watchlist size, delivery, API budgets, retention, support, and price are written into the order form.
Individuals validating threat search, the versioned JSON API, browser analysis, and organization workflows before monitored coverage is activated.
Security teams that need security monitoring, suspicious-login detections, reviewable alerts, case routing, and delivery history.
Operational teams connecting threat intelligence and monitored alerts to existing security workflows.
Competitive fit
The positioning is intentionally narrower than the largest dark-web platforms. Hanasand fits teams that need a fast watchlist, clear source context, and delivery into an existing workflow.
Open monitoringPilot path
Start narrow, connect one delivery path, and judge the first real matches before expanding scope.
Add companies, domains, suppliers, brands, executives, and acquisition targets.
Connect webhook or scoped API delivery to the SOC, vendor-risk, or case workflow.
Inspect source, timing, matched term, confidence, evidence summary, and recommended owner.
Record watchlist size, destinations, API budgets, retention, support, and price in the order form before activation.
Enterprise review
Self-serve access is for product evaluation. Monitoring customers should review security, data handling, contract terms, and identity requirements before activation.
Security overview, metadata-first data handling, incident-response path, and current SOC 2 / ISO gap stated plainly.
DPA, order-form notes, subprocessor details, SLA/support targets, and questionnaire responses can be packaged for review.
Roles and organization administration exist today; SSO/SAML/OIDC/SCIM should be scoped before an enterprise rollout.
Common buying scenarios
Security or IT lead
Watch your company, product names, domains, executive names, and known aliases. Use the alert to decide whether incident response, legal, or communications should review.
Vendor-risk or procurement team
Watch suppliers, portfolio companies, acquisition targets, and managed-service providers. Route only the claims that include enough source context to review.
SOC or threat-intel team
Give analysts the matched term, source, timing, confidence, claim summary, source context, and recommended next action instead of a raw feed.
Utility tool
Service checks remain available for URLs you control, but they are separate from the company exposure monitoring plans above.