What We Are Working On
8 min
welcome to our "what we're working on" page, a behind the scenes look at the exciting projects and improvements we’re building to enhance your flare experience here, you’ll find insights into our current initiatives, the context behind them, and what you can expect in the near future we’re sharing these updates to keep you informed, gather your feedback, and invite you to collaborate with us as we shape the future of flare important note while the goals described below are certain, the definite form and capabilities of the features delivered are subject to change please reach out to your csm for more information looking ahead into q4 2026 as we continue to innovate and address your most pressing needs, here are some of the longer term projects we’re prioritizing in the coming quarter these initiatives are designed to improve workflows, expand data coverage, and deliver a more seamless experience with flare ai p owered threat intelligence with flint flint is flare's upcoming ai agent, built directly into the platform so you can get answers just by asking instead of digging through events or building complex queries, describe what you need and flint turns that into the right workflow across flare's full threat intelligence dataset, whether you're investigating an exposure, checking if something affects your organization, or exploring a trend results appear inline, and you can share the exchange with your teammates blast radius for entra id see the full scope of exposure tied to a compromised user by mapping their resources and permissions within microsoft entra id blast radius reveals the attack paths available to a threat actor and the types of data they could pursue, giving security teams a clear picture of what's truly at risk before an incident escalates non human identities uncover the api keys, non human identities (nhi), and other sensitive data types embedded within a dark web event nhi visibility helps security teams understand exactly what an attacker could leverage to extend their access and further an attack, turning a single exposed credential or token into actionable insight about downstream risk vip protection extended coverage beyond dark web monitoring to include takedowns on data broker websites, protecting vips (executives, high profile employees, and other sensitive individuals) from exposure of personal information across the open web vip protection helps organizations proactively remove sensitive data before it can be used for targeting, harassment, or social engineering update events for chats and ransom leaks development on this feature is currently paused and will be resumed soon threat actors rarely publish everything at once a chat message may gain attachments after it first appears, and a ransomware post may add file listings well after the initial leak update events will capture this activity as it happens, so you can see how an exposure evolves over time rather than only its first appearance new events will be triggered by updates to previously ingested parent events, when a new attachment is added to a chat event a new file listing is added to a ransom leak event each update will surface a new event in the events feed, linked back to its parent event so the full context stays available because update events will carry their own metadata, they can be scored, filtered, and actioned independently of the parent this lets a high risk attachment or file listing stand out on its own rather than being diluted by the parent message or post your feedback matters we’re excited about what’s ahead and look forward to your input as we shape these initiatives your insights and feedback are essential in helping us refine these projects to meet your needs and expectations stay tuned for updates and opportunities to participate in the development process!