General

About the alliance

What is OneFirewall Alliance?

A UK-based cybersecurity company headquartered in London, operating a crowd-sourced Cyber Threat Intelligence platform built on an alliance of 290+ organisations worldwide. Member organisations share vetted threat indicators — malicious IPs, domains, URLs, and malware signatures — consolidated, enriched, and distributed in real time as actionable feeds for automated blocking, covering the full defensive lifecycle from ingestion through enforcement at the firewall, IPS, WAF, mobile endpoint, and DNS layer.

Who is OneFirewall designed for?

Enterprise security teams, MSSPs, critical infrastructure operators, and government organisations that need to automate threat blocking, consolidate intelligence from multiple sources into a single feed, gain MITRE ATT&CK-mapped context for every indicator, and contribute intelligence in exchange for collective protection. Existing members span telecoms, finance, defence, utilities, and government sectors across Europe and beyond.

Where is OneFirewall based?

OneFirewall Alliance LTD is registered in the United Kingdom, headquartered at 5 Greenwich View Place, London, E14 9NN. The company is Cyber Essentials Certified, recognised among the Top 27 funded cybersecurity startups in the UK, and an alumnus of the Cyber Runway Scale programme and Barclays Eagle Lab Cyber Bridge cohort. Partner offices operate in India, Southeast Asia, and Latin America.

How many alliance members are there?

The alliance now surpasses 290 member organisations worldwide, spanning telecoms, finance, defence, utilities, and government. Members include organisations such as Leonardo, TIM, Telepass, Terna, AlmavivA, Cy4Gate, and Olidata, among many others — every member both contributes to and benefits from the collective intelligence pool.

What's the difference between the CTI feed and the WCF Agent?

The CTI feed is the data — IOC intelligence delivered via API, STIX 2.1, or TAXII 2.1. The WCF Agent is the software that pulls that data and converts it into native enforcement rules on your firewall. Intelligence without an agent is just a feed; an agent without intelligence has nothing to enforce.

Does OneFirewall publish pricing?

Pricing is scoped per deployment — member count, integration footprint, and support tier — so there's no fixed public price list. A free, risk-free Proof of Value is available before any commercial commitment.

Threat Intelligence

How the feeds actually work

What types of indicators does the CTI feed contain?

Four core types: IP addresses (scanning hosts, C2 infrastructure, botnet nodes, Tor exit nodes), domains (phishing, malware delivery, C2 command domains), URLs (malicious endpoints and redirect chains), and malware hashes (file-level indicators for endpoint correlation). Each is enriched with a Crime Score, MITRE ATT&CK mappings, geolocation, ASN data, sector targeting, and a historical reputation score.

What is the Crime Score and how is it calculated?

A proprietary risk value from 0 to 1000 assigned to every indicator, combining the number and recency of alliance sightings, historical behaviour and repeat-offence patterns, sector targeting profile, associated MITRE ATT&CK technique severity, and community confidence weighting. A score of 700+ is generally high-confidence for automated blocking; thresholds are configurable per environment.

How often is intelligence updated?

In real time. New indicators submitted by alliance members are validated and distributed to all connected members within <200ms sync latency. The WCF Agent pulls updated block-lists continuously, so enforcement policy stays current without manual intervention or scheduled batch imports.

Does the CTI feed support STIX / TAXII?

Yes. The API returns indicators in STIX 2.1 format and is compatible with TAXII 2.1 for SIEM and SOAR ingestion — connect directly to Splunk, Microsoft Sentinel, IBM QRadar, or any STIX/TAXII-compliant platform without writing custom parsers.

Which MITRE ATT&CK techniques are covered?

20+ techniques across key tactics including Reconnaissance, Initial Access, Credential Access, Discovery, Command & Control, and Impact. Every API response includes the relevant technique IDs (e.g. T1595, T1133) and descriptions, so analysts understand not just what an IP is, but how it behaves during an attack.

How is submitted intelligence validated?

A multi-stage pipeline: automated de-duplication (merges repeated sightings), false-positive filtering (cross-referenced against known-good lists such as CDNs and cloud providers), an enrichment layer (geo, ASN, MITRE, historical data), and community weighting (indicators corroborated by multiple independent members score higher). What reaches your firewall is actionable intelligence, not raw noise.

Can we submit our own indicators, or is the feed read-only?

Both. The F3D Agent and CTI API accept submissions — IPs, domains, hashes, and URLs — which are validated and distributed back to the alliance. Contributions also earn OFA Coins, redeemable for API quota and platform access.

Does OneFirewall only block in real time, or can it catch threats retrospectively?

Both. Real-time feeds block known-bad indicators as they arrive; NetFlow Security Analysis separately re-checks previously allowed traffic against the live threat database, surfacing connections that looked clean at the time but are now known malicious.

Products

Platform & deployment

What is the WCF Agent and how does it work?

The World Crime Feeds (WCF) Agent is a lightweight software component installed on or alongside your existing firewall or IPS. It connects to the OneFirewall intelligence platform and continuously pulls updated block-lists, translating them into native enforcement rules for your specific device — no manual configuration. What arrives as a STIX indicator from the alliance leaves as a native rule on your Check Point, FortiGate, Forcepoint, or other appliance.

Which firewalls does OneFirewall integrate with?

Purpose-built plugins for Check Point (with SecureXL acceleration), Fortinet FortiGate, Forcepoint NGFW, and 163+ additional firewalls, IPS, XDR, WAF, and router platforms — see the full list on Integrations. If your platform isn't listed, custom integration development is available.

What is the OneDevice Firewall?

A dedicated IPS hardware appliance for organisations that prefer a physical enforcement layer, available in Parallel mode (runs alongside pfSense as a passive out-of-band blocker) or Standalone in-series mode (deployed inline as a full IPS gateway). Both modes run on real-time alliance intelligence feeds.

What is OFA Mobile?

An iOS and Android application that creates a local VPN on the device to intercept and filter traffic in both directions. Any connection attempt to an IP or domain in the alliance threat feed is blocked before it reaches the application or the user — extending enterprise-grade protection to phones and tablets with no network-level changes.

What is the AI Gateway?

A specialised firewall for AI services. As organisations adopt tools like ChatGPT and Copilot, the AI Gateway sits between the user and the service to prevent accidental data leakage in prompts, block connections to known malicious AI-adjacent infrastructure, and enforce usage policy for safe, compliant AI adoption.

Does OneFirewall offer a WAF?

Yes. The OneFirewall Web Application Firewall protects public-facing web applications against OWASP Top 10 attacks, injection, XSS, and bot abuse — powered by the same alliance threat intelligence as the network-layer controls.

Does the WCF Agent need a public IP or inbound internet access?

No. The only outbound requirement is TCP 443 to the Alliance. Nothing needs to be exposed to the public internet for the agent to pull feeds and push enforcement.

Can we run more than one agent across multiple sites?

Yes. Most multi-site deployments run one agent per location, each syncing independently to the same OneFirewall server — so a threat seen at one site reaches every other site automatically.

Security Assurance

Testing, not just tooling

What's included in a Security Assurance engagement?

Six disciplines available independently or combined: Penetration Testing, OpenSAMM Assessment, Threat Modeling, Offensive Security (Vulnix0), Code & Infrastructure Assessment (AquilaX), and Phishing Simulation.

What is Vulnix0?

OneFirewall's offensive security platform — continuous DAST, dark-web exposure monitoring, and attack-surface testing, enriched with the same alliance threat intelligence used across the platform.

What is AquilaX?

A partner platform used for code and infrastructure assessment — SAST, software composition analysis, secrets detection, and infrastructure-as-code review.

What is OpenSAMM and why does it matter?

An OWASP SAMM-based maturity review of your software security practices, scored across governance, design, implementation, verification and operations — it tells you how mature your security program is, not just how clean your code is.

Deployment, Data & Trust

Where it runs and who owns what

Can OneFirewall run fully on-prem or air-gapped?

Yes. OneFirewall Server runs as a single instance that can be deployed on-prem, in a private cloud, or fully air-gapped, with threat feed updates brought in through whatever controlled transfer process your accreditation requires.

Who owns the data we contribute or generate?

You do. Sharing intelligence with the Alliance is always voluntary — you choose what to contribute, and nothing leaves your perimeter without that choice.

Does OneFirewall guarantee immunity from attacks?

No. OneFirewall reduces risk through intelligence, detection, and enforcement — it does not, and cannot, guarantee complete immunity. Threats evolve; you remain responsible for your own security program.

What's the platform uptime commitment?

99.99% SLI on the standard architecture. For deployments that need more, a three-node Kubernetes clustering option is available, pushing availability toward four to eight nines.

Still have a question?

Ask us directly — a real engineer will answer.

Ask Us Directly