Fromenance

Intelligence

Every failed verification is a sensor

Fromenance is a communication provenance platform whose second product is threat intelligence: every Not verified or Known fraud submission is a real impersonation sample delivered by the person it was written to deceive. Indicators are extracted and exportable from day one; clustering, enrichment, and cross institution early warning are the intelligence tier on the roadmap.

Why this signal is different

Threat intelligence vendors answer whether infrastructure is malicious. Fromenance answers whether the institution issued this communication, and holds both datasets: the authoritative positive set of what you sent, and a victim sourced negative set of what your customers received and doubted.

Authoritative positive dataset

Communications your institution definitely sent, registered at send time with a recipient bound code and a content fingerprint. Ground truth, not inference.

Victim sourced negative dataset

Lures convincing enough that a real customer hesitated and asked. Not a honeypot sample and not a feed of everything on the internet: the attacks that were actually reaching your customers this week.

Shipping in v1

The schema, the indicator store, and the intelligence queue exist from the first submission so nothing has to be backfilled.

The intelligence tier (roadmap)

Built only after a tenant is paying for verification, and the network layer only after an analyst has confirmed a campaign from real submissions. These are commitments to sequence, not to dates.

What closes the loop

Once an attack is identified, the indicators can feed the systems you already run.

Start with verification. The intelligence is already accumulating.

A pilot on one stream produces the first indicators in the first week. The report at day 90 includes intelligence yield: indicators not present in your existing feeds, verified by your team.