Threat+Constellation
Live UTC

An observation instrument, not an alerting product.

Threat Constellation watches how exposure, weak signals, vulnerabilities, and incidents begin to connect.

The constellation also keeps structural observations — questions about the threat model itself, such as ambient sensing and the supervisory layer around autonomous behavior — that are not incidents and not alerts.

Daily Incident Ingestion v0.1 runs once per day at 05:00 UTC. It fetches public sources, deduplicates observations, and grows existing records instead of inventing news.

Demonstration records from the public preview remain labeled. Sourced records are created only from retrieved public evidence. Failed fetches stay empty.