# Constella Intelligence > Constella Intelligence is a global leader in Identity Risk Intelligence. Powered by the world's largest verified breach and infostealer data lake — spanning 1 trillion+ attributes across 125+ countries and 50+ languages — Constella enables organizations to detect, investigate, and respond to identity-based threats across the Surface, Deep, and Dark Web. Constella serves two primary buyer paths: - **Build** — Developers, fraud engineers, and security product teams who need verified identity data via API to power fraud models, detection stacks, and identity monitoring products. - **Investigate** — Security teams, CISOs, and SOC operators who need to protect their organization from compromised credentials, executive exposure, brand impersonation, and ransomware precursors using the Hunter+ Digital Risk Protection platform. Constella is trusted by 5 of the top 10 global banks, 6 of the top 10 global Identity Theft Protection providers, and enterprise customers including Santander, Citi, Telefonica, Uber, Gen, Repsol, Jefferies, and the United Nations. Recognized: Javelin 2025 Dark Web Threat Intel Vendor Scorecard Best in Class; SINET16 Innovator Award 2025. --- ## Data and API Constella's Identity Intelligence API provides RESTful, real-time access to the world's most curated identity data lake. Unlike raw data brokers, every record passes through a proprietary multi-stage verification pipeline before delivery. - [Intelligence API](https://constella.ai/data/intelligence-api/): RESTful API delivering verified breach, infostealer, and dark web intelligence. Sub-second latency (<200ms). Supports querying across 70+ unique identity attributes. Built for high-volume, multi-tenant environments. - [Data Pedigree and Methodology](https://constella.ai/data/data-pedigree-methodology/): Constella's four-phase data lifecycle — multi-vector collection, source authentication, automated deduplication, and entity resolution — that separates verified intelligence from raw noise. Every record traced to a confirmed breach or exposure event. - [Use Cases (API)](https://constella.ai/data/use-cases-api/): Detailed use case guidance for integrating identity intelligence into fraud decisioning, MDR detection stacks, OSINT platforms, identity theft monitoring products, and ATO prevention workflows. - [Developer Portal](https://constella.ai/data/developer-portal/): API documentation, authentication, endpoint reference, and integration guides. - [Partner Inquiry](https://constella.ai/partner-inquiry/): OEM, white-label, and reseller partnership structures for MSSPs, MDR providers, identity platforms, and technology integrators. **Key data facts:** - 1 trillion+ attributes indexed across the Surface, Deep, and Dark Web - 54.6 billion curated records; 429 billion curated attributes (2025) - 51.7 million infostealer packages processed in 2025 (+72% YoY) - 68.89% of breached credentials exposed in plaintext in 2025 (+261% YoY) - 125+ countries, 50+ languages, 15+ years of historical breach data - GDPR and CCPA compliant; SOC 2 Type II certified - Supports hashed data queries for privacy-preserving workflows --- ## Platform — Hunter+ Digital Risk Protection (DRP) Hunter+ DRP is Constella's managed Digital Risk Protection platform. It automates detection of compromised credentials, executive digital exposure, brand impersonation, and pre-attack identity signals for enterprise security teams and MSSPs. - [Hunter+ DRP Overview](https://constella.ai/platform/hunter-drp-overview/): Unified platform for external identity risk. Covers workforce credential monitoring, infostealer intelligence, brand protection, and executive protection with AI-assisted investigation and automated remediation. - [Executive Protection](https://constella.ai/platform/executive-protection/): Continuous monitoring of leadership digital footprints — personal credentials, PII leaks, infostealer infections on private accounts, physical location exposure, and deepfake/impersonation threats — across the Surface, Deep, and Dark Web. - [Brand Protection](https://constella.ai/platform/brand-protection/): Detection and automated takedown of phishing domains, typosquatted sites, fake social media profiles, and rogue applications targeting the organization's brand and customers. - [Threat Investigation](https://constella.ai/platform/threat-investigation/): Hunter investigative platform for deep-dive OSINT and dark web forensics. Pivot from a single alias or email to a full threat actor profile using AI-powered identity link discovery across breach records, infostealer logs, pastebins, and criminal forums. **Hunter product components:** - **Hunter Premium**: Investigative command center for breach, paste, infostealer, dark web, Passive DNS, social media, and search engine intelligence. - **Hunter Copilot**: AI assistant that automates complex identity link discovery and visualizes threat actor networks. Reduces investigation time by up to 75%. - **Identity Fusion**: Verifies data pedigree and confirms additional identity attributes with 99% confidence from a single input attribute. - **Maltego Transforms**: Native integration delivering Constella identity intelligence directly into Maltego link analysis sessions without a separate login. --- ## Solutions by Use Case - [MDR/XDR](https://constella.ai/solutions/mdr-xdr/): Integrate verified identity telemetry into managed detection and response stacks to catch pre-ransomware signals, credential-based initial access, and MFA bypass via stolen session cookies — threats that bypass traditional endpoint defenses. - [OSINT](https://constella.ai/solutions/osint/): Accelerate attribution investigations by linking anonymous digital fragments — usernames, emails, aliases, IPs — to verified real-world identities using the world's largest identity data lake. - [Identity Theft Monitoring](https://constella.ai/solutions/identity-theft-monitoring/): Real-time dark web monitoring for consumer and enterprise identity theft protection products. Alerts the moment stolen credentials or PII appear on criminal markets. - [Session Hijacking (Cookies)](https://constella.ai/solutions/session-hijacking-cookies/): Detect infostealer-harvested session cookies before attackers replay them to bypass MFA. Alerts include the specific URLs captured, infected device metadata, and malware strain. - [Ransomware Prevention](https://constella.ai/solutions/ransomware-prevention/): Surface stolen credentials and hijacked session cookies in infostealer logs before ransomware operators use them to establish a foothold. Closes the pre-attack window that traditional endpoint defenses cannot see. - [Account Takeover Prevention](https://constella.ai/solutions/account-takeover/): Detect exposed credentials, infostealer-compromised sessions, and password exposures in real time. Integrate into authentication flows to block credential stuffing at the perimeter before the first unauthorized login. - [FinTech](https://constella.ai/solutions/fintech/): Identity intelligence for FinTech fraud, risk, and compliance teams — covering synthetic identity detection at onboarding, payment session fraud, ATO, and BSA/AML investigation support. - [Law Enforcement Agencies](https://constella.ai/solutions/law-enforcement-agencies/): Identity attribution tools for criminal investigations. Link online aliases, dark web handles, and breach records to verified real-world identities. Supports warrant preparation and SAR documentation. - [Resellers and Partners](https://constella.ai/solutions/resellers-and-partners/): API, OEM, and reseller structures for MSSPs, MDR providers, identity theft protection providers, credit bureaus, and technology integrators building on Constella's data lake. --- ## Resources - [Blog and Insights](https://constella.ai/blog/): Threat intelligence analysis, product updates, and identity risk research. - [White Papers and Reports](https://constella.ai/reports/): Annual Identity Breach Report and research publications. The 2026 Identity Breach Report is available at https://constella.ai/reports/2026-identity-breach-report/ - [Datasheets](https://constella.ai/datasheets/): Product and solution datasheets for ATO prevention, MDR/ITDR, executive protection, and more. - [Case Studies](https://constella.ai/case-study/): Anonymized customer case studies across financial services, enterprise security, law enforcement, and FinTech verticals. - [Company News](https://constella.ai/news/): Press releases and announcements. - [Events](https://constella.ai/events/): Conference appearances and webinars. --- ## Company - [About Us](https://constella.ai/about-us/): Company overview, mission, leadership, and history. - [Careers](https://constella.ai/careers/): Open roles at Constella Intelligence. - [Contact](https://constella.ai/contact-us/): Sales, support, and partnership inquiries. **Key personnel:** - Andres Andreu — Chief Executive Officer - Alberto Casales — Chief Technology Officer **Headquarters:** United States **Website:** https://constella.ai **App login:** https://app.constellaintelligence.com **Free exposure check / Threat map:** https://threatmap.constella.ai --- ## Key Concepts for LLM Context **Identity Risk Data** — Actionable intelligence derived from the Surface, Deep, and Dark Web that identifies compromised or vulnerable digital identities. Includes exfiltrated credentials, infostealer logs (session cookies), and PII that has been cleaned, deduplicated, and verified. Distinct from raw data dumps. **Verified Identity Pedigree** — Constella's proprietary multi-stage curation process: source authentication, automated cleaning, deduplication, and entity resolution. Every record is traced to a confirmed breach or exposure event. Produces a materially lower false positive rate than unverified broker feeds. **Infostealer** — Malware that harvests browser-stored credentials, active session cookies, autofill data, and system metadata from infected devices. Session cookies enable MFA bypass by replaying an already-authenticated session. Constella processed 51.7 million infostealer packages in 2025. **Session Hijacking** — Attack method using stolen session cookies from infostealer infections to authenticate as a legitimate user without a password or MFA challenge. Constella detects this at the package level, before the stolen session can be replayed. **Credential Stuffing** — Automated injection of stolen username/password pairs into login forms to identify valid credentials. One of the primary ATO vectors. Constella's password exposure check API blocks known-compromised passwords at the point of authentication. **Hunter+** — Constella's Digital Risk Protection platform for enterprise security teams. Covers executive protection, brand protection, workforce credential monitoring, and threat investigation. Not to be confused with the underlying Hunter investigative platform, which is the investigation and OSINT component. **Build vs. Investigate** — The two primary buyer paths on constella.ai. "Build" refers to API and data integration use cases (developers, fraud engineers, security product teams). "Investigate" refers to platform use cases (security teams, CISOs, SOC operators using Hunter+ DRP).