Founded on a simple idea: firewalls that don't talk to each other are firewalls that lose.
OneFirewall Alliance was incorporated in England in 2018. It started with one client's server — and a question that changed everything.
One server, one question
A client needed their server secured. We ran the usual playbook — hardening, monitoring, blocklists of known-bad IPs. Then came the question that mattered: what about the IPs we personally know are bad, the ones caught trying to break in, but that nobody else has flagged yet? That was the seed of private, first-hand threat intelligence.
We were running multiple servers at the time, each logging attacks in isolation — a security guard who never talks to the guard next door. The obvious next question followed: what if they shared what they knew? What if the whole network acted as one? Coordinating threat data across machines, pooling knowledge, making the network smarter than any single node — that idea became the company.
No product had done this before: bring the Security Operations Centres of separate, independent organisations into a single alliance, sharing what each was seeing in real time. A single vendor's firewall — no matter how well engineered — only ever sees its own customers. It took a genuine alliance of heterogeneous SOCs, each watching a different slice of the internet, to see the whole picture. That's the gap OneFirewall was built to close.
From "Firewall Trust Alliance" to OneFirewall
The working name was FTA — Firewall Trust Alliance. Solid concept, forgettable name. In one of the late meetings where the concept was being argued over again, someone put it simply: "it's like they're all one firewall." The name stuck, the concept grew into a company, and OneFirewall Alliance was incorporated in England.
What followed was a longer argument, inside the company, about identity: was this simply a CTI vendor competing against much larger marketing budgets? The answer that stuck was that intelligence sitting unused in a report protects nothing. What matters is whether it's actionable — not "here's a list of bad IPs, good luck," but a firewall that has already blocked them, automatically, in real time.
From a whiteboard to a global alliance
OneFirewall Alliance incorporated
Founded in England after outgrowing a proof of concept built to solve one client's perimeter security problem.
From CTI feed to enforcement platform
The mission narrowed to one word: actionable. Intelligence was rebuilt around automated enforcement, not static reports.
Global members and government partners
The network grew to include telecoms, financial institutions, and government bodies — including Telecom Italia, the Italian Ministry of Defence, Leonardo, AlmavivA, and the Cyber Threat Alliance.
Accelerator cohorts & industry recognition
Selected for Plexal's Cyber Runway Scale programme and the Barclays Eagle Lab Cyber Bridge cohort; named among Beauhurst's Top 27 funded cybersecurity startups in the UK.
Strategic partnership with BondMesh
Joined forces with BondMesh, creator of the world's first autonomous AI security analyst, connecting alliance-wide threat data directly into autonomous detection-to-remediation workflows.
Eight years in, the numbers behind the platform
8
Years of platform development
280M
Malicious sources, live
998M
Public actors tracked · ~23% of the internet
26
Plug-ins developed
51
Attack types intercepted and blocked
96
Public and private sources
290+
Organisations in the Alliance
<30s
From report to protection of all members
290+ organisations, one collective defence network
Governments, telecoms, financial institutions, and security partners who take collective defence as seriously as we do.
Including a long-standing relationship with the Ministry of Defence, Italy.
