Identity Threat Detection and Response built for MSPs

See what’s lurking in your customer environments. Let’s go back in time and scan for identity threats you didn’t know existed.

Blackpoint ITDR: A Native Module in CompassOne

Let us show you how to protect the identity layer with a historical scan.

Why Identities are the New Perimeter

Learn about how identities have expanded the attack surface and why EDR is no longer enough.

Watch the Video

We Know You are An Existing Partner

Are you ready to grow your business with identity protection?

Read the Buyers Guide
Explore the Historical Scan

shield with expansion lines

Why MSPs Select Blackpoint ITDR Over Petra

One platform.
M365, Google Workspace, and Duo 24/7 SOC that triages for you.

Blackpoint ITDR vs. Petra

<2min
Average time to contain a compromised M365 or Google Workspace account, in as little as 21 seconds
Blackpoint SOC Operations Data, 2026
80%+
Of credential-based breaches involve identity as the primary entry point
Palo Alto Unit 42 Incident Response Report, 2026
$2.77B
In reported losses from business email compromise in 2024
FBI IC3 Annual Report, 2024
29min
Average attacker breakout time from initial access to lateral movement
CrowdStrike Global Threat Report, 2026
How It Works

ITDR: Identity Threat Containment at Machine Speed

The AI SOC Agent detects threats, evaluates behavioral signals against trained threat patterns, and acts only when confidence thresholds are met. When thresholds are met, it suspends compromised accounts, terminates active sessions, and forces password resets in as little as 21 seconds, with an average containment time of under two minutes. Every action outside those defined boundaries routes to a human SOC analyst, along with the Agent’s full reasoning. The Agent was trained on over a decade of real SOC data and validated against human analyst judgment before autonomous action was ever enabled.

01
Continuous

Continuous Monitoring

The AI SOC Agent monitors identity signals across cloud environments, correlating behaviors like impossible travel, anomalous access hours, off-baseline application activity, and known attacker TTPs against a model trained on more than a decade of real SOC decisions.

02
Confidence-Led

Confidence-Led Action

High-confidence threats trigger immediate autonomous action, no ticket, no approval queue. Everything below the confidence threshold routes instantly to a human SOC analyst with the Agent’s full reasoning. Acts on certainty, routes on doubt.

03
Contained

Threat Contained in <2 Minutes

The AI SOC Agent suspends the account, forces a password reset, disrupts sessions, and logs a full summary. The human SOC is notified and a SOC analyst is available for questions.