What is Datasurfr?
Datasurfr is an integrated operational risk intelligence and response platform. It monitors external risk events worldwide, identifies which of your people and assets are exposed, and lets security teams act on that from one workflow. Built and run by MitKat Advisory.
No question matches that search. Try a broader term, or ask us directly.
Risk intelligence and threat monitoring
Near-real-time threat monitoring across 12 non-financial risk domains, with AI detection and human analyst validation.
What is Datasurfr risk intelligence?
Datasurfr risk intelligence continuously monitors external risk events that may affect an organisation's people, assets, travel, routes or operations. AI identifies and structures relevant events from a large volume of open-source information, while analysts provide additional validation and deeper intelligence for selected events.
How quickly are risk events available on Datasurfr?
Datasurfr provides near-real-time risk intelligence. AI-generated Heads-Up alerts are designed to give early awareness as an event surfaces, while analyst-developed Intelligence Alerts follow with deeper analysis for events that require additional context.
What is the difference between a Heads-Up and an Intelligence Alert?
A Heads-Up provides near-real-time awareness of an identified risk event without detailed analyst analysis. An Intelligence Alert goes further, adding assessment, context, potential impact and recommendations developed or validated by the Datasurfr analyst team.
What risk categories does Datasurfr monitor?
Datasurfr monitors 12 non-financial risk domains: Technology, Extremism, Civil Disturbances, Environment, Health, Critical Infrastructure, Crime, Travel Risks, Natural Hazards, External Threats, Political and Regulatory risks.
How is event severity determined on Datasurfr?
Every event on Datasurfr is classified as Informational, Warning or Critical. The classification is based on factors including magnitude, casualties or damage, the area affected, duration and escalation potential.
How does Datasurfr verify information and reduce misinformation?
Datasurfr combines AI-based source processing with source reliability checks and human analyst validation. Important developments may be corroborated across multiple reliable sources, with official sources prioritised where available. The methodology also includes ongoing source review and analyst verification.
Can users monitor specific risks, locations, people or assets?
Yes — users can create monitoring subscriptions in Datasurfr using parameters such as traveller, asset, region, distance, risk category, sub-risk, event severity, alert type, event and duration.
Can monitoring rules be created using natural language?
Yes. With SamAI, a user can describe what they want to monitor in plain language — for example, "Monitor Warning and Critical civil disturbances for the Mumbai office for the next seven days." SamAI converts the request into a structured monitoring subscription for the user to review and activate.
Can Datasurfr risk intelligence be integrated with other systems?
Yes. Datasurfr can expose relevant intelligence through APIs for integration with enterprise platforms and downstream workflows, including HR, travel, business continuity, SIEM and communication tools.
Risk exposure and impact assessment
Correlating events with traveller and asset locations to produce a five-level risk exposure rating you can act on.
What is the difference between event severity and risk exposure?
Event severity describes how significant the event itself is. Risk exposure describes what that event means for a specific traveller or asset. A single event therefore carries one severity but can produce many different exposure levels across your people and locations.
How does Datasurfr determine whether a traveller or asset is affected?
Datasurfr correlates the event with the location of the traveller or asset, then assesses factors including event severity, proximity and the specific sub-risk involved to establish whether that entity is affected.
What are the risk exposure levels in Datasurfr?
Datasurfr represents exposure on a five-level scale: Very Low, Low, Medium, High and Very High. The scale lets security teams quickly prioritise the people and assets that require attention.
Can a Critical event result in Low exposure for a traveller?
Yes. Severity belongs to the event, while exposure is contextual. A Critical event occurring far from a traveller may result in lower exposure than the same event occurring immediately beside them.
What happens when several events affect the same traveller or asset?
Datasurfr evaluates all relevant events affecting the entity. In the current model the highest calculated event risk determines the displayed exposure level, which ensures a serious nearby threat is not diluted by lower-risk events.
Can I see why an entity has been classified as High or Very High risk?
Yes. Users can drill into the affected traveller or asset to view the contributing event, its proximity, the event classification and the calculated exposure behind the rating.
Can Datasurfr automatically identify all people and assets affected by an event?
Yes. When an event is opened, Datasurfr correlates its location with monitored travellers and assets and presents the affected entities, so impact is understood before any action is initiated.
Can risk impact be visualised geographically?
Yes. Events, travellers and assets can be viewed together on the Datasurfr map, including event impact areas and the proximity of exposed entities.
AI-assisted analyst reports and advisories
Travel advisories, incident briefs, predictive assessments and TVRAs, written by analysts with SamAI assistance.
What reports and advisories can Datasurfr generate?
Datasurfr provides advisories, travel advisories, predictive assessments, incident briefs, risk reviews, TVRAs (Threat, Vulnerability and Risk Assessments) and other structured intelligence products. They are created by human analysts with AI assistance.
How is a Datasurfr advisory different from using a generic AI chatbot?
Datasurfr analysts work with SamAI, which is grounded in Datasurfr's structured risk-event data and purpose-built risk taxonomy. Its output structures, tone, recommendations and analytical frameworks are designed for security and intelligence workflows rather than generic conversational responses.
Can SamAI perform scenario analysis?
Yes. For each risk alert, predictive analysis by SamAI can assess the current situation, the potential impact on people and operations, the relevant risk drivers and plausible escalation scenarios.
Can we request human analysis?
Yes. Human analyst involvement remains available for situations requiring additional verification, contextual assessment or expert judgement. This human-plus-AI model is central to how Datasurfr is built.
Crisis communication and mass notification
Impact-based targeting, multi-channel dispatch, two-way check-ins and a full audit trail — from the same screen as the risk event.
Can Datasurfr communicate directly with people affected by a risk event?
Yes. Once affected entities are identified, authorised users can initiate targeted notifications directly from the risk workflow, without moving to a separate mass notification tool.
How are notification recipients selected?
Recipients can be selected based on actual event impact, or users can add specific individuals, traveller groups, asset stakeholders or other predefined groups.
Which communication channels does GoSafe support?
GoSafe's communication architecture is designed to support channels such as email, SMS, WhatsApp, Microsoft Teams, Slack, web and app notifications, and voice — subject to the integrations and channels configured for your organisation.
Can communications be sent only to affected travellers rather than the entire workforce?
Yes. Impact-based targeting is a core part of the workflow, allowing teams to communicate only with the people who actually require the information.
Can communication templates be customised?
Yes. Users can select standardised templates such as Incident Alert, Travel Impact Alert or Intelligence Alert, or configure templates specific to your organisation.
Can SamAI draft crisis communications?
Yes. SamAI can use the event context to draft the communication content, which an authorised user reviews and modifies before dispatch.
Does GoSafe support two-way communication?
Yes. Two-way workflows can collect structured responses such as "Are you safe?", "Do you need assistance?" and "Have you acknowledged the instruction?" — so responders work from confirmed status rather than assumed status.
Can non-responders be identified?
Yes. Response tracking can identify recipients who have acknowledged, requested assistance or not responded, which enables targeted follow-up and escalation.
Can notifications be scheduled?
Yes. Authorised users can send a notification immediately or schedule it for a later time.
Can communication workflows be automated?
Yes. Predefined monitoring and communication rules allow recurring scenarios to reuse configured recipients, templates, channels and response settings, rather than recreating the workflow each time.
Is there an audit trail of communications?
Yes. Communication activity retains records such as sender, recipient population, dispatch time, delivery status, response status and the related event, for operational review and compliance.
Duty of care and travel risk management
Itinerary visibility, pre-travel intelligence, location-aware alerts, check-ins and a documented record of the actions you took.
How does Datasurfr support an organisation's duty of care?
Datasurfr helps organisations identify where travellers are expected to be, monitor the risks around them, assess exposure, provide pre-travel intelligence, communicate during disruption and maintain a record of the actions taken — the documented chain most duty of care programmes are measured against.
How are travellers monitored?
Travellers are treated as dynamic assets in Datasurfr. Their monitoring is linked to their active travel period, so risk exposure is assessed while they are actually travelling.
Can Datasurfr ingest travel itineraries?
Yes. Travel information can be entered directly or integrated into GoSafe to create itineraries and establish the traveller locations that risk monitoring depends on.
Does GoSafe provide pre-travel intelligence?
Yes. Destination risk information and travel advisories can be generated before departure, so both the organisation and the traveller understand the relevant risks and mitigation measures.
Can Datasurfr monitor hotels, offices and airports as well as travellers?
Yes. Static assets such as offices, hotels, airports and other critical locations can be mapped and monitored alongside travellers.
Can VIP or executive travellers receive enhanced monitoring?
Yes. Traveller groups and dedicated monitoring rules can be configured so higher-risk or priority travellers receive different proximity thresholds, event criteria or communication workflows.
How does Datasurfr prevent travellers from being overwhelmed with alerts?
Traveller communication can be filtered according to relevance — for example event severity, proximity, sub-risk, itinerary, exposure level, and whether the event is likely to affect safety or mobility.
Can travellers confirm their safety during an incident?
Yes. Two-way crisis-response workflows collect safety and assistance responses from travellers. Mobile capabilities such as a dedicated SOS or "I'm Safe" action depend on the GoSafe deployment in use for your organisation.
Can Datasurfr support travel-policy decisions?
Yes. Country risk ratings, current events, destination intelligence and pre-travel assessments can support decisions around approvals, restrictions, mitigation measures and enhanced monitoring.
Security, hosting and compliance
ISO 27001:2022 and SOC 2 Type II, AWS hosting, AES-256 encryption, SSO and RBAC, a 99.9% uptime SLA and documented disaster recovery — the answers procurement and InfoSec teams ask for.
Where is Datasurfr hosted?
Datasurfr is hosted on AWS in the Mumbai region (ap-south-1), running across two availability zones for resilience.
What security standards does Datasurfr follow?
Datasurfr is certified to ISO 27001:2022 and SOC 2 Type II, and undergoes annual VAPT (vulnerability assessment and penetration testing). The software development lifecycle follows OWASP Top 10 and SANS Top 25 secure coding practices.
Does Datasurfr support SSO and role-based access control?
Yes. Datasurfr supports SAML and OAuth/OIDC single sign-on, federated with the client's identity provider at onboarding. Two roles are available — Client Admin and Client User — and Client Admins manage and remove user access for their own organisation.
How is data encrypted in Datasurfr?
PII is encrypted at rest with AES-256-GCM application-level field encryption using AWS KMS customer-managed keys, and lookups use SHA-256 hashes so no plaintext PII appears in logs or cache. TLS 1.3 protects data in transit across all endpoints and APIs. Tenants are logically segregated by a unique client ID applied to every database query and cache key, so each tenant can only reach its own data.
What APIs does Datasurfr provide?
Datasurfr exposes REST APIs over HTTPS with TLS 1.3, authenticated using OAuth/OIDC with AWS Cognito-issued JWT bearer tokens.
Can Datasurfr integrate with HRIS, travel systems and third-party mass notification tools?
Yes. Datasurfr integrates with HRIS platforms, travel management systems and third-party mass notification tools through its REST APIs.
What is the Datasurfr uptime SLA?
Datasurfr operates to a 99.9% uptime SLA. Support targets are: Critical, 1 hour response and 4 hour resolution; High, 4 hours and 24 hours; Medium, 8 hours and 72 hours; Low, addressed in the next change cycle.
What disaster recovery capabilities does Datasurfr have?
Datasurfr maintains a disaster recovery environment in a separate AWS region, with cross-region database replication to a read replica for failover. The recovery time objective is 1 hour and the recovery point objective is 24 hours. DR drills are conducted annually.
How long does Datasurfr retain client data?
Client data is retained only for the duration of the active mandate and is permanently deleted within 7 calendar days of termination. Logs are retained for a minimum of one year.
How is traveller PII protected?
Traveller PII is encrypted at rest using AES-256-GCM application-level field encryption with AWS KMS customer-managed keys, with SHA-256 hash-based lookups. Data is segregated by client ID across both the database and cache layers, and the database runs in isolated private subnets.
Can clients control user roles and permissions?
Yes. Client Admins manage user access and role assignment for their own organisation directly in the platform. Two roles are available — Client Admin and Client User — and users can only access data belonging to their own tenant.
Does Datasurfr maintain an audit log?
Yes. Application-level privileged access logs record user actions with user ID and timestamp, and Client Admins can view them in the admin portal.
What prevents unauthorised code from reaching production?
Datasurfr development follows an OWASP and SANS-aligned SDLC. Nobody can push directly to the main, UAT or develop branches — every change requires an approved peer review. On merge, the CI/CD pipeline runs mandatory secret scanning, SAST, CVE scanning and code coverage checks, and a build that fails any stage never reaches deployment. Production can only be deployed through that pipeline.
How is the Datasurfr application tested?
Functional testing is carried out in a separate development environment before any production release, and regression testing is automated using Playwright. Unit and integration tests run on every branch and block the pipeline on failure.
Does Datasurfr have 24x7 monitoring, logging and alerting?
Yes. Application monitoring runs 24x7 in-house. AWS CloudWatch covers operational metrics, GuardDuty handles threat detection, WAF protects the application layer, X-Ray traces requests and Sentry captures code-level errors. Everything surfaces on an in-house Grafana dashboard, with alerts routed automatically into Jira Service Management for tracked response.