Skip to content

Product1 publisher3 min readPublished

Dataminr's detection feed now maps alerts to each Horizon client's offices and travelers

Dataminr's detection layer is now live inside Crisis24's Horizon, about six months after the two companies announced their partnership. They showed it at GSX in Atlanta and did not say when full deployment arrives.

The Product Desk · Product desk

Photograph accompanying Dataminr's detection feed now maps alerts to each Horizon client's offices and travelers
Photo: garda.com

What happened

  • Dataminr's threat detection feed and agentic AI tools went live inside Crisis24 Horizon, unveiled at the Global Security Exchange in Atlanta as the first product from a partnership announced in March.
  • Four capabilities come with it: live briefs that rewrite themselves, context from an event archive more than 10 years deep, corroboration during a developing event, and near-term predictions.
  • Crisis24 puts more than 230 intelligence analysts behind Horizon and describes that as the largest private-sector team of its kind.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision A security lead has to decide which half of the problem is theirs: alerts that arrive too late, or alerts that arrive and nobody escalates. Only the first is what this integration sells against.
  • constraint Without a deployment date, procurement cannot schedule against the complete four-capability set, so a pilot signed this quarter buys whatever subset exists that week.
  • exposure Asset-mapped alerting inherits the accuracy of the client's own facility and travel records, so a stale address list quietly caps the value of a million-source feed.
  • precedent Putting detection inside the console that fires mass notifications pushes rival platforms to be judged on whether an alert routes to an action.

The partnership was announced in March and the first joint product arrived at GSX in Atlanta, roughly six months later [1]. Crisis24 says a fully deployed Horizon will be the first critical event management platform carrying all of Dataminr's agentic AI capabilities in one product [12][14]. Later releases are meant to push intelligence out to clients' employees and travelers in the field, which both companies call a first for the travel security industry [13].

Teams shopping for risk intelligence usually describe their problem as coverage. Dataminr's numbers answer that description: 150 languages, image, video, audio and sensor signals, more than 1 million public data sources [4], plus an event archive more than 10 years deep feeding the Agentic Context feature [7]. What an analyst does on shift is narrower. They decide whether an alert is real, whether it touches a facility or a person they are responsible for, and whether it warrants waking someone. Agentic Corroboration, which scans publicly available information for confirmation while an event is still developing [7], and the mapping of intelligence against a client's offices, facilities and traveling employees [5] are aimed at the first two of those decisions.

"Too often security teams find themselves reacting to risk one step behind the information they need," said Matt Harrell, chief partner officer at Dataminr. "This new solution changes that equation entirely" [8]. Gregoire Pinton, managing director and global head of integrated risk management at Crisis24, said the addition gives clients "an even faster, deeper view" [9]. Both statements are about speed. The announcement does not include a measured detection-to-notification time for any customer.

Analysts still make the call. Alerts land in Horizon's decision interface, where a client can trigger mass notifications or call in security and medical teams without leaving the workflow [11], and Crisis24 puts more than 230 intelligence analysts behind the platform [10]. The two companies have a joint session on artificial intelligence and human judgment in corporate intelligence scheduled for Tuesday afternoon at the conference [17].

For a lead weighing a pilot, a 30-day log with three columns settles most of it: the alert, the asset it mapped to, and the action taken within the hour. If the second column is often empty because the facility and travel records are out of date, the hyper-local promise is bounded by the client's own data [5][6]. If the third column is empty on alerts that were correct and correctly mapped, the escalation policy is the constraint and a faster feed adds volume to a backlog. Dataminr closed a $290 million purchase of ThreatConnect in November and put that technology into a cyber defense suite it launched in March [15].

What to watch

  • A full deployment date, or the field release that pushes alerts to travelers, would show whether all four capabilities ship together.
  • A named customer publishing its detection-to-notification times would turn the speed claim into evidence.
  • Whether rival critical event management vendors answer by bundling their own detection feeds into the notification console.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories