Skip to content
Uncover threats before they strike your region.
reconn is the authorized Criminal IP distributor for the Middle East and Africa. We license, deploy and support Criminal IP TI and Criminal IP ASM for MSSPs, channel partners, SOC teams, threat analysts and government security operations across the GCC, the Levant, North Africa and Sub-Saharan Africa.
Two products, one intelligence layer: Criminal IP TI for IP intelligence, domain intelligence and threat actor tracking, Criminal IP ASM for attack surface management across everything you own and did not know you owned. Regional licensing, procurement and support handled by reconn as distributor.
reconn is the authorized Criminal IP distributor for the Middle East and Africa. Criminal IP is a cyber threat intelligence search engine and attack surface management platform built by AI SPERA. reconn holds regional distribution, which means licensing, procurement, deployment, integration, partner enablement and support all happen in-region, in your time zone, under contracts your finance team can actually process.
The region needs that combination. Organizations here run hybrid cloud estates across multiple jurisdictions, under regulators that do not share a rulebook, while state-aligned and criminal actors work through the same critical infrastructure, financial and government networks year after year. Global tooling rarely reflects that picture, and global vendors rarely answer the phone at the right hour.
Criminal IP scans the entire public IPv4 space continuously, runs its own honeypot network, and folds in more than a hundred OSINT sources plus dark web collection. The output is not a pile of raw indicators. It is a decision-ready record for an IP, a domain or a threat actor, with the context an analyst needs to triage, hunt, attribute and contain without leaving the tool.
This page covers both halves of the platform: Criminal IP TI for IP intelligence, domain intelligence and threat actor tracking, and Criminal IP ASM for attack surface management across everything your organization exposes to the internet. It also covers how we work with MSSPs and channel partners across the region.
Authorized Criminal IP distributor for the Middle East and Africa.
MSSPs, resellers, system integrators and consultancies, with deal registration.
GCC, Levant, North Africa and Sub-Saharan Africa.
Regional pre-sales, deployment, integration and escalation.
Regional Demand
Three cities are driving most of the threat intelligence and attack surface management spend in the region, for three different reasons. If you run a security team, an MSSP, or a channel business in any of them, the pattern below will be familiar.
The regional headquarters city. Financial services, aviation, logistics, hospitality and the largest concentration of MSSPs, integrators and security distributors in the Middle East. Dubai government entities work to the Dubai Electronic Security Center's Information Security Regulation, DIFC firms sit under their own data protection regime, and federal entities under the UAE Information Assurance Regulation.
The practical effect is that a Dubai security team is usually answering to more than one framework at once, across an estate spread over free zones, multiple clouds and a long tail of third parties. That is an attack surface problem before it is a threat intelligence problem, and most teams discover it in that order.
Critical national infrastructure and sovereign capital. Energy, utilities, aviation, healthcare and government sit here, alongside ADGM as a financial free zone and ADHICS as a sector-specific standard for healthcare. The exposure profile skews heavily toward operational technology, industrial systems and long-lived infrastructure that was never designed to be internet-reachable.
Two consequences follow. Exposed OT and IoT assets need to be found continuously rather than audited annually, and deployment often has to be on-premise or air-gapped because the data cannot leave the environment. Both are buying requirements before they are feature preferences.
The fastest-growing security market in the region, and the most prescriptive. The National Cybersecurity Authority's Essential Cybersecurity Controls apply to government and critical national infrastructure, with separate cloud and critical systems controls layered on. SAMA's framework governs financial services, the Personal Data Protection Law is administered by SDAIA, and CITC covers telecom and ICT.
On top of that sits Vision 2030. Giga-projects and rapid cloud migration are creating new external attack surface faster than any manual inventory can track it, and much of it is greenfield infrastructure standing up in months rather than years. Local presence and data residency expectations also make in-region distribution and on-premise deployment close to mandatory.
What Is Driving It
Continuous monitoring, threat intelligence and asset inventory are no longer implied by regional control catalogues. They are line items an auditor asks you to evidence.
Cloud migration, giga-projects, acquisitions and shadow IT add external assets faster than a spreadsheet-based inventory can absorb them. Nobody knows the real number.
State-aligned espionage against energy, government and finance, plus hacktivism that spikes with regional events. Generic global feeds under-represent both.
Hiring cannot keep pace with alert volume anywhere in the region. Decision-ready intelligence beats a raw indicator feed when there is nobody free to enrich it.
Data residency expectations in Saudi Arabia and the UAE make on-premise and air-gapped options a requirement, and make an in-region distributor the practical route to buy.
Regional SOCs are being built at pace. Every one of them needs an intelligence layer it can license, automate against and resell inside its own managed service.
For MSSPs and channel partners in Dubai, Abu Dhabi and Riyadh: this demand is landing in your pipeline as questions you already get asked. What is exposed on our perimeter, who is targeting us, is this indicator worth escalating, and can you prove it. Criminal IP answers all four with evidence, and it attaches to services you already sell rather than requiring a new one. reconn handles the licensing, enablement and pre-sales so your team can lead with the outcome. See the partner program.
Criminal IP TI
Criminal IP TI brings IP intelligence, domain intelligence and emerging threat data into a single platform. Rather than aggregating raw indicators, it surfaces the context analysts across the Middle East and Africa actually need to triage alerts, hunt threats, investigate incidents and decide, without switching tools or sources.
Scanned and indexed through proprietary global infrastructure, a distributed honeypot network and 100+ OSINT sources.
Real-time domain and URL scanning returns structured domain intelligence across every key risk dimension.
Deep insight into advanced persistent threats and the infrastructure they operate against this region.
Coverage
Access Methods
Interactive threat hunting with advanced filters for vulnerability, location, product, service and behavioral signals. Pivot across related infrastructure and pull historical data for trend analysis.
Structured JSON responses for direct integration into SIEM, SOAR, XDR and custom security workflows. Documented, versioned and built for automation at volume.
Self-hosted threat intelligence for instant, scalable investigation with no external calls. Built for air-gapped, classified and high-performance requirements common across regional government and defense.
Threat intelligence feeds. Continuously updated feeds on malicious IPs, domains and infrastructure, formatted for direct ingestion into firewalls, proxies and orchestration tooling. Customizable to the indicator types and confidence thresholds your team actually acts on. Ask about feed formats.
Criminal IP ASM
Traditional attack surface management tools hand you an asset list. Criminal IP ASM enriches every discovered asset with live threat intelligence, so the output is not an inventory to work through but a ranked set of things that actually matter. Deployed and supported across the region by reconn.
One domain or IP is enough to start. Everything connected to it is found, classified and kept current.
The same intelligence layer behind Criminal IP TI assesses every asset ASM finds.
Beyond CVE discovery. Risk is prioritized from context, not from a severity score alone.
Hidden and exposed assets, surfaced from three layers of the web rather than one.
SSL/TLS lifecycle tracked automatically, so an expiry never becomes an incident.
Most of what compromises an organization is not sitting in a vulnerability database.
Daily continuous monitoring, with alerts that arrive already carrying their context.
Automated High, Medium and Low tiering driven by threat intelligence, not by CVSS in isolation.
Findings move into the workflow your team already runs, with a record of what was decided.
Three Layers of Exposure
Google Hacking results, public databases, exposed documents, leaked API keys and configuration files that any search engine can already reach.
Hidden assets and sensitive data behind authentication, forms and unindexed paths, routinely missed by conventional ASM tooling.
Continuous monitoring of dark web sources for leaked accounts and credentials tied to your organization, so exposure is caught before it is used.
Manual or automatic. Manual Asset Registration ASM scans the IP ranges and domains you register. Automatic Asset Detection ASM takes a single domain or IP and discovers every related IP and subdomain within two to three days, then keeps finding new ones. Most organizations start automatic and add manual entries after an acquisition or for a subsidiary audit. Ask which fits your estate.
Distribution & Channel
Criminal IP is built by AI SPERA. reconn holds authorized distribution for the Middle East and Africa, which means every commercial and technical step happens in-region: licensing, procurement, deployment, integration, enablement and escalation.
Partner Program
Register an opportunity and it is protected. Margin is predictable, and you are not competing against the vendor or against another partner on the same account.
Not-for-resale access so your team can learn the platform properly, plus demo reports on a prospect's real attack surface to open the conversation with evidence.
We join your calls. Scoping, architecture, proof of concept and technical objection handling, so a smaller channel team can still sell a technical product.
Training for your analysts and engineers on Criminal IP TI and ASM, delivered on-site or online, so delivery does not depend on one person who read the docs.
Joint campaigns, regional events, webinars and content built around your accounts rather than a generic vendor template.
For MSSPs building a productized offering, help shaping what the service includes, how it is priced per client, and how the API automation is structured.
Regional Coverage
United Arab Emirates, Saudi Arabia, Qatar, Kuwait, Bahrain and Oman. Our home market and the densest concentration of regulated SOC and critical infrastructure work.
Jordan, Lebanon, Iraq and neighboring markets, typically through in-country partners with existing enterprise and government relationships.
Egypt, Morocco, Algeria, Tunisia and Libya, where financial services and telecom security programs are moving quickly.
Nigeria, Kenya, Ghana, South Africa, Ethiopia, Tanzania and beyond, largely through MSSPs and integrators building regional SOC capability.
Already selling security in the region? Threat intelligence and attack surface management attach cleanly to almost every security service, from managed detection to compliance assessments, because the output is evidence rather than another dashboard your client has to learn. Open a partner conversation and we will map it to what you already sell.
What Changes
These hold for TI and ASM alike, because both run on the same intelligence layer. The difference is only whether you are pointing it at someone else's infrastructure or your own.
Comprehensive visibility powered by real-time IP intelligence, domain scanning, and OSINT plus dark web monitoring. You see what single-source tooling structurally cannot.
Intelligent risk scoring surfaces the threats that need attention now, so analyst hours go to the queue that matters instead of the one that is longest.
Mean time to respond drops when complete threat context and remediation guidance are already attached to the indicator rather than assembled during the incident.
Continuous discovery identifies and classifies new assets as the estate expands, so the inventory does not quietly go stale between audits.
Real-time domain and IP intelligence exposes weaknesses while they are still weaknesses. Decisions get made against what is live on your perimeter today, not against a quarterly report describing what was live when it was written.
Security Operations
Criminal IP is not a new process to adopt. It slots into the six things a SOC does every day and removes the part where an analyst opens six browser tabs to build context by hand.
Analysts use threat scoring, abuse history and behavioral signals to enrich alerts from existing tooling, prioritize high-risk indicators and cut investigation noise.
Pivot from a single IP or domain to related infrastructure: connected IPs, subdomains, shared services and shared hosting that reveal the wider campaign.
During an incident, infrastructure intelligence and historical context explain attacker behavior, support containment decisions and track attacker-controlled assets.
Analyze domains and URLs for phishing behavior, suspicious redirect chains and exposed content, so a report can be validated or dismissed quickly.
Correlate IPs, domains and hosting data to identify patterns, link infrastructure to threat actors and track campaign activity over time.
Use scan data and vulnerability insight to find exposed services, misconfigurations and viable attack vectors across your own infrastructure.
Built For
Criminal IP TI and ASM give your SOC decision-ready intelligence to detect threats faster, reduce alert fatigue and hand clients richer incident context. The differentiator is scale: global threat actor tracking, real-time OSINT and dark web monitoring across every account you manage.
Integration with your existing SIEM and SOAR brings threat intelligence into the workflows analysts already live in. Detect compromised assets, investigate events with full infrastructure context and make containment calls faster.
Search-powered threat hunting, dark web monitoring and threat actor tracking put detailed context in one place, so an investigation stops being an exercise in context switching.
Automated asset discovery and risk prioritization reduce blind spots and make sure the vulnerabilities that matter get the attention, with reporting that survives a board conversation.
Track threat actors targeting the region, follow infrastructure linked to regional campaigns and stay ahead of emerging threats, with a deployment model that works inside classified environments.
Feature Matrix
| Capability | What you get |
|---|---|
| IP Intelligence | Global scanning, honeypot network and 100+ OSINT sources. AI-based 5-tier risk scoring, open ports and service banners, CVE/CWE mapping, VPN/Proxy/Tor/C2 detection, abuse records, SSL certificates and domain history. |
| Domain Intelligence | Real-time scanning across every risk dimension: phishing detection, SSL/TLS configuration scanning, CVE mapping, sub-domain enumeration, risk scoring, redirection analysis, exposed config detection, JARM hashing and network packet analysis. |
| Threat Actor Monitoring | IOCs, IOAs, TTPs and CVEs. Kill chain indicators, MITRE ATT&CK mapping, geographic targeting and compromised asset discovery. |
| Search Engine | Interactive threat hunting with advanced filters, pivoting across related infrastructure, historical data access and flexible analysis. |
| API Access | RESTful API with structured JSON responses, custom integration and air-gapped environment support. |
| On-Premise Database | Self-hosted intelligence, scalable investigations, no external calls and classified environment support. |
| Threat Feeds | Continuously updated IOC feeds, malicious IP and domain lists, infrastructure data and straightforward integration. |
| Data Freshness | Real-time continuous updates. 4.29 billion IPs scanned in approximately 3 days, with continuous feed delivery. |
| Capability | What you get |
|---|---|
| Continuous Discovery | A single domain or IP entry triggers auto-discovery. Related IPs and subdomains identified automatically, new assets found continuously, complete inventory maintained. |
| Intelligence Integration | Advanced domain scanning and IP analysis, instant visibility into malicious activity and threat detection across the whole attack surface. |
| Vulnerability Validation | AI-driven automation, dangerous and critical port identification, connected application analysis, exploit correlation and real-time vulnerability analysis. |
| OSINT & Dark Web | Surface web exposure detection, deep web asset discovery, dark web credential monitoring, configuration file detection and public source aggregation. |
| Certificate Monitoring | SSL/TLS certificate discovery, expiration tracking, self-signed certificate detection and configuration scanning. |
| Risk Beyond CVEs | C2 detection, anonymization service detection, policy violations, abuse record tracking, real IP detection and phishing or fraud detection. |
| Real-Time Alerts | Daily continuous monitoring, contextual alerts, change notifications and an always-current asset status. |
| Risk Prioritization | AI-driven categorization into High, Medium and Low tiers, intelligent scoring and critical threat ranking. |
| Collaboration Tools | Built-in comments, team coordination, clear documentation and remediation tracking. |
| Integrations | API-first design with SIEM, SOAR and XDR integration, REST API and custom automation. |
Criminal IP TI and Criminal IP ASM share one intelligence layer. Organizations that run TI and ASM together get the same enrichment on an external indicator and on their own exposed asset, which is what makes attribution work in both directions.
Why Criminal IP
Continuously scanned data rather than a historical database. The context competitors report is often already stale.
Context-rich records built for analysts, not IOC dumps that need manual enrichment before anyone can use them.
Monitor actors targeting the Middle East and Africa, with MITRE ATT&CK mapping and infrastructure correlation.
Attack surface management powered by threat intelligence, not asset discovery with a vulnerability scan bolted on.
API-first design that fits the SIEM, SOAR, XDR and vulnerability management stack you already operate.
Detection across surface, deep and dark web in one platform, instead of three subscriptions and a spreadsheet.
On-premise for air-gapped environments, API for automation, search engine for the humans doing the hunting.
Procurement, deployment, integration and support handled in-region by reconn, in your time zone.
Trust Indicators
Global public IP addresses scanned approximately every 3 days, 24/7, by proprietary infrastructure.
OSINT sources correlated alongside a proprietary honeypot network and global scanners.
Risk scoring with no reported data reliability issues when blocking on Dangerous or Critical ratings.
Real IP detection unmasks sources behind Cloudflare, VPNs and mobile proxies. Threat actor tracking is aligned to MITRE ATT&CK. Breach history is collected through C-TAS, CTI feeds and Criminal IP's own honeypot operations.
Questions
A threat intelligence platform providing real-time, decision-ready intelligence on IP addresses, domains, threat actors and emerging threats. It combines global IP scanning, honeypot networks, 100+ OSINT sources and dark web monitoring in a single platform, covering alert triage, threat hunting, incident response and infrastructure attribution.
Criminal IP updates its intelligence by continuously scanning global IPs, monitoring ports and operating honeypot servers to detect active threats and C2 infrastructure. Rather than serving history-based data, it scans 4.29 billion IP addresses in approximately 3 days on a continuous cycle, so the record you read reflects what is live now.
AI-based 5-tier risk scoring for inbound and outbound traffic, open ports with service banners and application fingerprinting, CVE and CWE mapping with exploit references, VPN/Proxy/Tor/Anonymous VPN/Hosting/CDN/Mobile classification, C2 server identification, scanner IP detection, abuse records with threat actor attribution, SSL certificate data and domain history mapped to the IP.
Phishing detection, SSL/TLS configuration analysis, CVE and CWE mapping, sub-domain enumeration, domain risk scoring, connected IP reputation, redirection chain analysis, exposed configuration file detection, JARM hashing with tech stack vulnerability mapping, and network packet log analysis on URL access.
Collection runs continuously in real time. All 4.29 billion global public IP addresses are scanned approximately every 3 days, with continuous updates pushed to the platform between full sweeps.
Yes. Criminal IP TI integrates with leading SIEM, SOAR and XDR platforms through a full-featured RESTful API with structured JSON responses, dedicated integrations with platforms including Splunk and Cisco, customizable threat intelligence feeds, and custom integration support where a specific requirement is not covered. Ask us to scope the integration.
Criminal IP's 5-level risk scoring has no reported errors or data reliability issues when organizations block IPs rated Dangerous or Critical. The continuous scanning methodology is what supports that validity, and it is why customers are comfortable wiring the scores directly into firewall systems.
Yes. Criminal IP can track and identify the real source IP of malicious users hidden behind Cloudflare and similar services, and it detects IP addresses masked by VPNs, mobile proxies and other anonymization services.
Accumulated malicious activity information for an asset, including activity detected by IDS, malware, phishing and ransomware. It is collected through C-TAS (Criminal IP's Threat Advisory System), cyber threat intelligence feeds, and Criminal IP's own honeypot operations.
Universally applicable features are developed on the product roadmap. For customer-specific requirements, custom development is available, with additional cost for the customization and implementation work. Enterprise B2B contract customers also get access to Criminal IP TI training, delivered on-site or online.
Four: the interactive search engine for threat hunting, the RESTful API for integration and automation, an on-premise database for self-hosted and air-gapped environments, and customizable threat intelligence feeds for ingestion into existing tools.
Through reconn. We handle regional licensing, procurement paperwork, deployment and ongoing support, so you are not managing a vendor relationship across time zones. Open a comms channel and we will size it against your environment.
A threat intelligence-powered attack surface management platform combining continuous automated asset discovery with threat analysis and AI-driven risk prioritization. Where traditional ASM tools list assets, Criminal IP ASM enriches every discovered asset with real-time threat intelligence.
Domains and subdomains, IP addresses and ranges, SSL/TLS certificates, cloud infrastructure across AWS, Azure and GCP, IoT devices, connected applications such as MySQL instances, printers and web servers, and web services and APIs. Everything is categorized by geographic data, cloud provider, ASN and application information.
Criminal IP continuously scans ports on IP addresses worldwide in real time to extract and analyze running applications. When dangerous ports are open on a registered IP, or a vulnerability is found in a connected application, it is classified as an attack surface risk and shown on the dashboard with its threat context attached.
Manual Asset Registration ASM: you register IP ranges and domains, and you see scan data for exactly those. It will not discover new or unregistered assets. Automatic Asset Detection ASM: a single domain or IP entry triggers discovery of all related IPs and subdomains within 2 to 3 days, and new assets keep surfacing automatically, which is what eliminates unknown assets.
All of your IT assets by default. Pricing is scaled to asset volume, so talk to us with a rough estate size and we will come back with a figure.
Yes. Manual Asset Registration ASM is manual-only. Automatic Asset Detection customers have most assets discovered for them but can still add entries by hand, which matters for new IP ranges after an acquisition or when auditing a subsidiary.
No. Criminal IP ASM is fully web-based. On Manual ASM you log in and register your IP addresses and domains. On Automatic ASM you log in, enter a single domain or IP, and owned assets are discovered and registered within 2 to 3 days.
Not as a standard self-serve trial. What is available instead is a demo report on your own IT assets' attack surface, or a consultation on your current security posture. In practice the demo report is more useful, because it is your estate rather than a sandbox. Request one.
Traditional ASM provides asset visibility and stops there. Criminal IP ASM integrates real-time threat intelligence into every asset assessment, automatically correlating vulnerabilities with emerging exploits, threat actor infrastructure and observed malicious activity. The output is context-driven risk prioritization rather than an asset list you still have to triage.
Open-Source Intelligence is publicly available information that can itself constitute a security risk. Criminal IP ASM scans for exposed assets across the internet using Google Hacking techniques, public databases and forums, then presents what it finds on your dashboard in a form you can act on rather than a raw result list.
Yes, across all three layers. Surface web via OSINT, Google Hacking, public databases and exposed files. Deep web for hidden assets and sensitive data beyond the surface. Dark web for continuous monitoring of leaked accounts, credentials and exposed data related to your organization, so you can act before the credentials are used.
Daily continuous monitoring of every discovered asset. Scans update in real time as new exposures, certificate expirations and asset changes are detected.
New assets discovered, vulnerabilities identified on existing assets, SSL certificates expiring or expired, credential leaks detected, and threat context changes such as an asset becoming linked to malicious activity. Every alert carries its threat context, so prioritization does not require a second lookup.
Asset inventory and status dashboards, risk prioritization reports across High, Medium and Low tiers, vulnerability and exposure summaries, certificate monitoring reports, credential leak notifications, and custom reports for compliance and stakeholder communication. The automated discovery, vulnerability mapping and risk prioritization together give you the evidence base most attack surface compliance questions ask for.
Continuous discovery picks up new assets as they appear, whether from an acquisition, a new cloud deployment or an infrastructure change, and adds them to your dashboard within 2 to 3 days on Automatic Detection ASM.
API-first, with integration into SIEM platforms, SOAR platforms, XDR solutions, vulnerability management tools and custom security workflows. All integrations use the REST API with structured JSON responses.
reconn is the authorized Criminal IP distributor for the Middle East and Africa. Criminal IP is built by AI SPERA; reconn holds regional distribution and handles licensing, procurement, deployment, integration, partner enablement and support across the GCC, the Levant, North Africa and Sub-Saharan Africa.
The GCC (United Arab Emirates, Saudi Arabia, Qatar, Kuwait, Bahrain, Oman), the Levant and wider Middle East (Jordan, Lebanon, Iraq and neighboring markets), North Africa (Egypt, Morocco, Algeria, Tunisia, Libya) and Sub-Saharan Africa (Nigeria, Kenya, Ghana, South Africa, Ethiopia, Tanzania and beyond). Coverage outside the GCC is usually delivered together with an in-country partner.
Six things at once: regional control catalogues now name continuous monitoring and threat intelligence as auditable line items, attack surface is outgrowing the inventory, the region is specifically targeted, analyst hiring cannot keep pace, data residency pushes deployment on-premise, and the MSSP market is scaling fast. The full breakdown by city is here.
Yes, and those three cities are where most of our work sits. Dubai for the MSSP and integrator concentration, Abu Dhabi for critical national infrastructure and air-gapped deployment, Riyadh for NCA and SAMA-driven programs and Vision 2030 giga-projects. We also cover Doha, Kuwait City, Manama, Muscat, Cairo and Sub-Saharan Africa, usually alongside an in-country partner.
Yes, and it is a large part of what we do. We work with MSSPs and MDR providers, resellers and VARs, system integrators, consultancies, government and defense integrators, and telcos building their own security services. The partner program covers deal registration, NFR and demo access, pre-sales engineering, technical enablement, co-marketing and service design support.
Register the opportunity with us before you engage. Once registered it is protected, so your margin is predictable and you are not competing against us or against another partner on the same account. Tell us about the opportunity.
Yes. MSSPs commonly wrap Criminal IP TI enrichment and ASM monitoring into a productized managed service rather than reselling licenses directly. We help shape what the service includes, how it is priced per client, and how the API automation is structured so one analyst can cover many tenants.
Yes. The on-premise database is self-hosted with no external calls, which is what makes it viable for classified environments, defense integrators and organizations with data residency obligations. We scope and deploy these in-region. Ask us to scope one.
Criminal IP TI is priced by access method and query volume. Criminal IP ASM is priced by asset scale, and you can monitor all of your IT assets by default. Partner pricing and multi-tenant models differ from end-user pricing. Tell us your rough estate size and we will come back with a figure rather than a range.
Yes, and it is the fastest route. We produce a demo report on your own IT assets' attack surface, so the conversation is about what was actually found rather than about a feature list. Partners can request the same report for a prospect. The search engine is also free to try with no commitment.
Yes. Enterprise B2B contract customers get access to Criminal IP TI training, on-site or online. Channel partners get technical enablement for their own analysts and engineers, so delivery capability does not sit with a single person.
Send an enquiry through the contact form, email hello@reconn.io, or message us on WhatsApp. Tell us whether you are evaluating for your own organization or looking at the partner route, and we will route it accordingly.
Open a comms channel
Two routes in. If you are securing your own organization, we will size Criminal IP against your environment and show you what it finds before you commit to anything. If you sell security in Dubai, Abu Dhabi, Riyadh or anywhere across the region, we will map the partner program to what you already sell. Either way you are talking to the authorized distributor, not a reseller of a reseller.
Direct Lines
Criminal IP is built by AI SPERA. reconn is the authorized distributor for the Middle East and Africa, handling licensing, procurement, deployment, integration, partner enablement and support in-region. A demo report on your own attack surface is the fastest way to see whether this is worth your time.