Independent, offensive-led intelligence.
SAFA studies how real adversaries operate and turns that into sovereign intelligence.
TeamT5: SAFA's Key Strategic Partner
TeamT5, a leading Taiwan-based research team, gives us deep visibility into Asia and China-nexus threat activity. We bring that together with our own offensive research to build intelligence for European buyers.
Three ways we work, one discipline behind them.
We understand how attackers break real systems, from mobile and desktop to IoT. That understanding is the foundation everything else is built on.

Original research
We publish technical research on how attackers break real systems, from mobile and desktop to IoT. It is the foundation everything else is built on..

Adversary-led testing
We test defences the way adversaries do, aligned to the TIBER-EU and DORA frameworks, and answer the intelligence questions your team does not have time to.

Intelligence
Intelligence that fuses our own research with trusted sources, delivered for the organisations that need it most.
Fused coverage, not a single-region feed
ThreatVision, built with our partner TeamT5, gives us close visibility into APAC threat activity, one of the regions where emerging tooling and techniques often surface first. We bring that together with our own research so European buyers get a fused picture, not a single-region feed.
Asia coverage, from a specialist source
Our Asia and China-nexus coverage is anchored by TeamT5, a leading Taiwan-based research team with deep visibility across the region. We combine their work with our own, so clients get one European-built picture rather than a single-region feed.
Talk to us about your threat intelligence needs
Tell us what you're defending and we'll show you how our intelligence fits. No product demo required.
Selected research
Selected technical research from our team. We publish deliberately rather than often.
What is Threat Intelligence?
"Threat intelligence" gets used for almost anything with an IOC attached. Here is what actually separates intelligence from raw data, the three tiers it operates at, and why the source matters as much as the volume.
For Clues to the Next Cyberthreat, EU Orgs Shouldn't Ignore Asia
Asia-nexus activity isn't Europe's primary threat picture, but the tooling and TTPs that surface there first have a track record of showing up in European campaigns later. Here's why that lag is worth watching, and why it's one input among several rather than the whole story.
Stay One Step Ahead with Real-Time Cyber Threat Intelligence
Speed matters, but a fast feed answering the wrong question is still the wrong answer. Here's what real-time intelligence is genuinely good for, and what still needs fusion and analysis on top of it.