Threat monitoring and alerting
Real-time detection with custom alerts delivered by email, SMS or Slack.
Liferaft OSINT software is a threat intelligence platform that watches social media and the surface, deep and dark web for threats to people, places and organizations, then alerts security teams. This review covers its features, who it suits, what is public about price, and the 2026 Securitas acquisition.
Liferaft OSINT software is a SaaS platform for corporate security, executive protection and duty-of-care teams. It collects from social media and surface, deep and dark web sources, flags credible threats, and supports investigations and case files. It was long marketed as Navigator. Securitas completed its acquisition in March 2026. Prices are not public; Vendr reports a median of $36,000 a year.
A Canadian threat intelligence software company, founded in 2014 and now part of Securitas, whose platform finds and triages online threats for security teams.
Liferaft was founded in 2014 in Halifax, Canada, and trades through Social Navigator Inc. Securitas describes it as a SaaS provider of open-source intelligence threat solutions whose platform aggregates threat data from public sources around the clock and sends real-time risk alerts (Securitas, 3 February 2026).
The platform was widely known as Navigator; a 2023 partner announcement describes how "Navigator's AI filters only the most relevant data" for each customer (Kaseware). The current website presents it simply as the Liferaft platform.
Securitas acquisition. Securitas, the Stockholm-based security company, signed a binding agreement to buy Liferaft in February 2026 after five years of partnership, and completed the deal on 18 March 2026 (McCarthy Tétrault). At the end of 2025 Liferaft had annual recurring revenue of SEK 138 million (USD 15.3 million), with organic growth above 30%, and hundreds of large enterprise clients in North America. The purchase price was not disclosed. The site now describes Liferaft as "a Securitas company".
Seven modules cover the cycle from detection to reporting: monitoring and alerts, trends, situational awareness, dark web search, identity resolution, case files and dashboards.
Real-time detection with custom alerts delivered by email, SMS or Slack.
Trend analysis and geospatial views that map threat data to locations, offices and events.
Searches across deep and dark web and fringe sources alongside mainstream social media.
Links online personas to real-world individuals to help assess whether a threat actor is credible.
Central files that hold the intelligence collected on a person, threat or incident.
AI-assisted prioritization and reporting for sharing findings with security leaders and partners.
Liferaft collects from social media, surface, deep and dark web and fringe sources, with licensed data partners, and the vendor says teams receive alerts within days of deployment.
The product page lists social media, surface web, deep web, dark web and "fringe sources", and names licensed data partners X, Intelligence Fusion, GeoSure and DarkOwl. AI is described in general terms: AI-assisted analysis to prioritize credible threats and reduce noise, and AI-enabled reporting. The vendor does not publish model details.
On deployment time, the vendor's comparison page says teams can start receiving alerts "within days of deployment" and that its alert deduplication cuts alert volume by up to 60%. These are vendor claims we have not verified. The same page lists Dataminr, Ontic, AlertMedia, Fivecast, Skopenow, Babel Street and Echosec by Flashpoint as the products it compares itself with.
Executive protection is one of the platform's listed use cases: monitoring online threats, fixations and location exposure around principals, offices and events.
The vendor lists executive protection, duty of care, threat intelligence, investigations and cyber intelligence as its main use cases. In executive protection, the platform's job is early warning: spotting threatening posts, people who fixate on a principal, leaked travel details or protests near an event, and giving protective teams time to act.
Software does not make the protective decision. Someone still has to judge whether a post is a joke, a grievance or a real threat, and whether the author is the person the identity resolution suggests. That judgment is where most false alarms and missed threats happen, so budget analyst time alongside the license.
Liferaft does not publish prices; buyer data on Vendr shows a median of $36,000 a year, with a range of about $11.5K to $77K.
| Item | What is public (checked 10 October 2026) | Source |
|---|---|---|
| List prices | Not published; demo or discovery call, with a demo built around your scope | Liferaft |
| Median buyer price | $36,000 a year | Vendr |
| Reported range | About $11.5K to $77K a year | Vendr |
| Model | Subscription (SaaS), per Securitas | Securitas |
Vendr figures come from the buyers it tracks and may not reflect your sector, number of users or modules.
It suits enterprise security teams that need continuous threat detection with analysts to review alerts; it is less suited to one-off investigations.
Watch for false positives, gaps where platforms restrict data, over-collection on employees or protesters, and contract changes after the ownership change.
Comparable options include Babel Street, Skopenow, ShadowDragon and OSINT Combine, plus alerting products such as Dataminr that have no review here yet.
| Tool | Main emphasis |
|---|---|
| Babel Street | Multilingual risk intelligence and managed attribution |
| Skopenow | Automated person and company search reports |
| ShadowDragon | Social media and online identity investigations |
| OSINT Combine | Browser-based OSINT search, investigation and monitoring, plus training |
For tools grouped by investigation task, see our OSINT tools catalog.
If you need threats watched and judged rather than a dashboard to staff, a managed monitoring or protection service may fit better.
Our OSINT monitoring runs on an analyst-reviewed platform that updates hourly, so you receive verified alerts rather than raw hits. For principals and families, executive protection intelligence combines monitoring with exposure reviews, and live event monitoring covers AGMs, launches and travel. Corporate security teams can see how we support them on our corporate security page, or start with our OSINT services overview.
Tell us who and what needs watching, and for how long. We reply with a monitoring scope and a fixed quote.
Yes, it is the same platform. Liferaft's software was widely marketed as Navigator and is now presented as the Liferaft platform (Kaseware, 2023). It monitors social media and surface, deep and dark web sources, sends real-time alerts by email, SMS or Slack, and supports trend analysis, situational awareness, identity resolution, case files and reports. Its listed use cases are executive protection, duty of care, threat intelligence, investigations and cyber intelligence.
Securitas owns Liferaft. It announced a binding agreement on 3 February 2026 and completed the acquisition on 18 March 2026 (McCarthy Tétrault). Securitas said it had partnered with Liferaft for five years and plans to apply its threat intelligence across Securitas's client base. The price was not disclosed. As with any ownership change, confirm your contract terms, data hosting and support arrangements in writing at renewal.
It can surface threatening posts, fixations and location exposure early, but your team will still need to judge each alert. Executive protection is a listed use case, and the vendor says AI-assisted analysis prioritizes credible threats and that deduplication cuts alert volume by up to 60%, though that is a vendor claim. Sarcasm, quotes and look-alike accounts still produce false alarms. A two-person team should agree clear escalation rules before going live, or use an analyst-reviewed service.
Liferaft does not publish prices. Vendr reports a median buyer price of $36,000 a year, with a range of about $11.5K to $77K (Vendr). Your price will depend on users, modules and scope. On timing, the vendor says teams can start receiving alerts within days of deployment; plan extra time to tune keywords, locations and people of interest, because alert quality depends on that setup.
Monitoring public posts for credible threats to people or sites is usually defensible; watching employees' lawful opinions, union activity or private lives generally is not. In the EU and UK you need a lawful basis, a documented purpose, proportionality and transparency under the GDPR, and US employers face labor law limits on monitoring protected concerted activity. Scope the monitoring to threats, keep a written policy, and take legal advice before you configure employee-related searches.
For two short events, a subscription is probably more than you need. Platforms like Liferaft pay off with year-round monitoring and staff to review alerts. A managed event monitoring service covers the run-up and the event itself, with analysts reviewing each alert before it reaches you. OSINT-S runs live event monitoring on an analyst-reviewed platform that updates hourly, scoped in writing with a fixed quote.
Sources checked 10 October 2026. Figures about third-party firms and tools are as published by them or by the cited source on that date.