Atomburst
Atomburst is a security platform focused on detecting identity and AI/browser threats at their smallest point of impact and containing them in real time. Its parent brand sits above Network Security Cloud Analytics (NSCA), the cloud-native, multi-tenant analytics engine, and is built first for managed service providers (MSPs) and lean security teams.
At a Glance
- Managed service providers (MSPs)
- Lean in-house security teams
- Small and mid-sized businesses served by MSPs
- Organizations using Microsoft Entra ID/Microsoft 365
- +2 more
AI Tools by Atomburst
(1)Geiger
CLI AI Agent Scanner
Discussions
No discussions yet
Be the first to start a discussion about Atomburst
Latest News
Geiger 0.3.0 released with installed-client presence detection, AI-browser coverage, and Cursor/Codex/Gemini CLI hook detection.
Geiger repository removed its one-shot release backfill workflow after release work was completed.
Atomburst announced Geiger, its first open-source, MIT-licensed read-only scanner for the AI-agent surface.
Geiger was publicly presented on Hacker News as a tool to see every AI agent on a machine and what it can touch.
Products & Services
Identity Threat Detection & Response using Microsoft Graph-powered signals from Microsoft Entra ID and Microsoft 365, continuous identity risk scoring, unified alert and incident response, and managed-device posture insights.
A browser extension and endpoint agent that monitors browser URLs and domains and enforces AI and web policy across the endpoint fleet, including standalone applications when the endpoint agent is used.
A self-serve GitHub posture and access-certification product. Its read-only GitHub App inventories members and privileges, 2FA gaps, outside collaborators, OAuth/app grants, and dormant accounts, then records review decisions and creates evidence-grade reports.
An optional managed detection and response layer with 24/7 monitoring, investigation, expert judgment, and hands-on response on top of Atomburst automation.
Market Position
Atomburst positions itself against legacy security platforms that are commonly single-tenant, alert-centric, retrofit for AI/browser controls, enterprise-contract oriented, and migration-heavy. Its differentiators are MSP-first multi-tenancy, modular per-endpoint/volume packaging, detection connected directly to containment, native coverage of the AI surface, cloud-native additive rollout, and optional rather than mandatory MDR. Geiger is positioned as a standalone open-source inventory layer, while DomainGuard is the commercial policy-enforcement layer.
Founding Story
Atomburst says it was started to give teams defending small and mid-sized businesses the same early-detection and instant-containment capabilities available to enterprises, without enterprise weight, cost, or migration. Its stated philosophy is to detect a first particle such as a stolen token, risky prompt, or anomalous login, contain it before a second step, and add human observation only when wanted.
Business Model
Revenue Model
Subscription and quoted B2B software/service model: Access Review & Evidence is self-serve and billed monthly through Stripe; the core platform is quoted per endpoint; MSP and volume plans are custom; MDR is an optional add-on.
Pricing Tiers
Three scans included per calendar month; month-to-month; cancel anytime.
Quoted engagement pricing.
Volume tiers across clients and endpoints; optional MDR add-on.
Open-source MIT-licensed scanner with no account and no telemetry.
Target Markets
- Managed service providers (MSPs)
- Lean in-house security teams
- Small and mid-sized businesses served by MSPs
- Organizations using Microsoft Entra ID/Microsoft 365
- Engineering and security teams managing GitHub organizations
- Organizations adopting AI agents, MCP servers, AI browsers, and AI-enabled developer tools
- MSPs protecting multiple client tenants from one console
- Lean in-house security teams seeking additive, cloud-native detection and response
- Identity takeover detection involving stolen credentials, tokens, sessions, privilege changes, and anomalous behavior
- Organization-wide browser and endpoint AI-use policy enforcement
- Quarterly or recurring GitHub access reviews and audit evidence
- Inventorying AI-agent and MCP-server exposure on developer or employee machines