A phishing website begins its working life in silence. Before the convincing logo, the urgent email and the customer typing a password, someone has to arrange its address and hosting. That preparation is Bfore’s hunting ground. The company, formerly BforeAI, asks a deceptively useful question: why wait for the trap to look like a trap?
- PreCrime watches external infrastructure for signs of attacker preparation.
- Its products supply intelligence, protect brands and intercept stolen credentials.
- Customer stories make the case through time saved and earlier intervention.
- Prediction earns its keep when a team can turn the warning into action.
The crime has a rehearsal
Bfore’s founders, Luigi Lenguito, Luciano Allegro and Sebastian Cesario, established the company in southern France in 2020. Lenguito has described the inspiration through Minority Report, the film whose police intervene before a crime. The borrowing is cheeky. The mechanism is considerably more prosaic: internet metadata, behavioral analysis and software that watches infrastructure change.
On its Intelligence product page, Bfore describes examining domains, DNS activity, hosting patterns and certificate behavior. Machine learning looks for preparation associated with malicious campaigns; analysts validate potential threats. A suspicious address is therefore a starting point for investigation, rather than a conviction delivered by an algorithm in a judge’s wig.
The homepage claims an average 18-day lead over conventional threat-intelligence sources. That comparison matters: it measures arrival relative to other feeds, not a universal countdown to an attack. The commercial proposition is earlier visibility. Whether that visibility is useful depends on what the customer can do before the window closes.
- 01RegisterDomains and infrastructure appear
- 02PrepareBehavioral signals accumulate
- 03LaunchCampaign reaches its targets
The queue broke first
In 2022, Volksbank’s security team faced mounting phishing and impersonation work. Its problem included the labor of triage, escalation and analysis. The company-published case study puts the average breach cost at $42,000. Protection had become an expensive administrative occupation.
A 15-day proof of value persuaded the bank to adopt PreCrime. The published account reports alerts up to 72 hours before malicious activity and remediation in less than 24 hours. Implementation included manually validated takedowns and weekend automation. That detail is revealing: adoption involved deciding which decisions people would retain.
“BforeAI was the only solution that would allow us to not only address issues swiftly, but amazingly to detect threats before they even occurred.”
Petra Chiste · Volksbank · published customer case study
Atlassian’s anti-abuse team provides a second, less theatrical measure. In Bfore’s published account, finding reports and pursuing removals took three engineering hours weekly and at least ten days of waiting. Dashboard review reduced that weekly effort to one hour; removal could happen within days or hours. The attraction was a shorter queue as much as a cleverer prediction.
Three ways to interrupt the rehearsal
PreCrime Defense watches for impersonation, disrupts access to malicious infrastructure and pursues takedowns. The buyer is often responsible for a brand’s customers as well as its employees. A fake bank website can hurt somebody who never touches the bank’s corporate network. The perimeter follows the name on the door.
PreCrime Intelligence supplies predictive indicators to existing security systems. Security operations teams can use the feed to enrich investigations or block connections. This makes Bfore both a digital risk protection vendor and an intelligence supplier, depending on which work the customer needs done.
PreCrime Credentials introduces a different lure: managed HoneyPortal decoy login pages. The product captures credentials attackers submit, checks them against an identity provider and can trigger password remediation. Bfore describes integrations including Entra and Okta. Its appeal rests on catching stolen credentials while somebody is testing them.

A prediction needs somewhere to go
Bfore’s partnership with Quad9 began in 2022. Quad9 takes predictive indicators into its protective DNS service and returns filtering telemetry. That is a practical distribution arrangement: intelligence can help stop a connection where the connection is being resolved. In June 2025, Quad9 announced an expanded relationship and BforeAI sponsorship.
NetWitness announced its integration in April 2025. It brings Bfore’s external indicators together with logs, network traffic and endpoint telemetry. The point is to give an earlier warning a place inside an existing operational workflow. An alert arriving sooner but sitting untouched has merely enjoyed a longer holiday.
ZeroFox, Doppel and Recorded Future occupy overlapping territory in external protection and threat intelligence. Automation is hardly Bfore’s private property. Its distinctive sales argument is the stage at which it observes attacker preparation. Buyers should compare that claim alongside coverage, investigation effort and the ability to finish a removal.
The price of an earlier warning
Bfore sells subscriptions with packages, add-ons and guarantee options. Its pricing page publishes customer investments of $50,000, $150,000 and $350,000 across different scopes. These examples describe a serious enterprise purchase. The useful calculation combines exposure reduced with the recurring work taken off a team’s hands.
Different customer scopes, not three universal price tiers.
The company announced $15 million in Series A funding in April 2024 and a $10 million Series B in January 2025, bringing disclosed total funding above $30 million. The later announcement earmarked expansion into utilities, pharmaceuticals and healthcare, alongside product, sales and partnership investment.
The PreCrime Guarantee offers reimbursement up to ten times a service contract’s value for qualifying prediction failures, with Munich Re backing. Bfore calls it a performance pledge. Eligibility and exclusions live in the agreement. The promise gives procurement something tangible to discuss; it does not make every possible incident predictable.
Borrow the experiment
A useful lesson from these customer stories is to test the workflow. Record when a warning arrives, when harmful activity begins, when blocking takes effect and when infrastructure disappears. Count analyst minutes too. Otherwise, an impressive lead-time number can conceal a team still doing all the chasing.
Bfore’s own explanation places boundaries around the approach: external communications and infrastructure are its focus. Internal or off-network attacks require other defenses, and incomplete metadata can weaken prediction. Keep endpoint protection and response capabilities. For teams repeatedly fighting impersonation and domain-based campaigns, the opportunity is quite specific: intervene while the criminal is still furnishing the shop.