Independent, offensive-led intelligence.
SAFA studies how real adversaries operate and turns that into sovereign intelligence.
TeamT5: SAFA's Key Strategic Partner
TeamT5, a leading Taiwan-based research team, gives us deep visibility into Asia and China-nexus threat activity. We bring that together with our own offensive research to build intelligence for European buyers.
Three ways we work, one discipline behind them.
We understand how attackers break real systems, from mobile and desktop to IoT. That understanding is the foundation everything else is built on.

Original research
We publish technical research on how attackers break real systems, from mobile and desktop to IoT. It is the foundation everything else is built on..

Adversary-led testing
We test defences the way adversaries do, aligned to the TIBER-EU and DORA frameworks, and answer the intelligence questions your team does not have time to.

Intelligence
Intelligence that fuses our own research with trusted sources, delivered for the organisations that need it most.
Fused coverage, not a single-region feed
ThreatVision, built with our partner TeamT5, gives us close visibility into APAC threat activity, one of the regions where emerging tooling and techniques often surface first. We bring that together with our own research so European buyers get a fused picture, not a single-region feed.
Asia coverage, from a specialist source
Our Asia and China-nexus coverage is anchored by TeamT5, a leading Taiwan-based research team with deep visibility across the region. We combine their work with our own, so clients get one European-built picture rather than a single-region feed.
Talk to us about your threat intelligence needs
Tell us what you're defending and we'll show you how our intelligence fits. No product demo required.
Selected research
Selected technical research from our team. We publish deliberately rather than often.
Seeing in the Dark: Managing Cyber Threats on the Deep and Dark Web
Almost every intelligence vendor now offers dark web monitoring. That's exactly why it's not the interesting part of the story. Here's what it's genuinely useful for, and what it takes to turn that visibility into something actionable.
What is Threat Intelligence?
"Threat intelligence" gets used for almost anything with an IOC attached. Here is what actually separates intelligence from raw data, the three tiers it operates at, and why the source matters as much as the volume.
Europe's Cybersecurity Crossroads: Why Sovereignty Is Now a Procurement Question
This isn't a forecast piece. DORA is live, NIS2 enforcement is closing the gap between member states, and the threat behind both is more specific than most coverage admits. Here's what's actually changed, and what it means for procurement.