European threat intelligence, from the attacker's perspective.
SAFA is an independent research house. We study how real adversaries operate, and turn that into intelligence European organisations can act on.
TeamT5: SAFA's Key Strategic Partner
We draw on TeamT5, a leading Taiwan-based research team, as one source feeding our Asia and China-nexus coverage. We fuse it with our own research and other sources to deliver intelligence built for European buyers.
Three ways we work, one discipline behind them.
We understand how attackers break real systems, from mobile and desktop to IoT. That understanding is the foundation everything else is built on.

Original research
We publish technical research on how attackers break real systems, from mobile and desktop to IoT. It is the foundation everything else is built on..

Adversary-led testing
We test defences the way adversaries do, aligned to the TIBER-EU and DORA frameworks, and answer the intelligence questions your team does not have time to.

Intelligence
Intelligence that fuses our own research with trusted sources, delivered for the organisations that need it most.
Fused coverage, not a single-region feed
Popular threat intelligence platforms may rely on open-source intelligence or broad, globally available data. ThreatVision is different. Focused on the APAC region, it takes you closer to hotspots for emerging threats like APTs, malicious code, and others, so you stay confidently ahead of cybercrime.
Asia coverage, from a specialist source
Our Asia and China-nexus coverage draws on TeamT5, a leading Taiwan-based research team tracking threats across the region. We fuse their coverage with our own, under a European flag, so our clients get one picture rather than a single-region feed.
Talk to us about your threat intelligence needs
Tell us what you're defending and we'll show you how our intelligence fits. No product demo required.
Selected research
Selected technical research from our team. We publish deliberately rather than often.
Seeing in the Dark: Managing Cyber Threats on the Deep and Dark Web
Almost every intelligence vendor now offers dark web monitoring. That's exactly why it's not the interesting part of the story. Here's what it's genuinely useful for, and what it takes to turn that visibility into something actionable.
What is Threat Intelligence?
"Threat intelligence" gets used for almost anything with an IOC attached. Here is what actually separates intelligence from raw data, the three tiers it operates at, and why the source matters as much as the volume.
Europe's Cybersecurity Crossroads: Why Sovereignty Is Now a Procurement Question
This isn't a forecast piece. DORA is live, NIS2 enforcement is closing the gap between member states, and the threat behind both is more specific than most coverage admits. Here's what's actually changed, and what it means for procurement.