BREAKING / FLARE
●LATEST / IGNITE PARTNER PROGRAM · SEPTEMBER 2026●PRODUCT / OKTA JOINS FLARE’S IDENTITY WORKFLOW●LEARN / DARKROOM’S FREE FOUR-HOUR INVESTIGATION LAB

Company / Cybersecurity / 001

Flare wants to close the door before a stolen login opens it

The Montreal company watches the places where stolen identities are traded. Its wager: threat intelligence earns its keep when it helps defenders take away the keys.

A burglar need not break a window if someone has thoughtfully left a key for sale. In November 2025, Socura and Flare published research finding more than 460,000 instances of stolen credentials linked to employees at FTSE 100 companies. These were credential instances, not 460,000 distinct victims. Still, the implication was uncomfortable: a company could spend heavily on its front door while access to the building circulated elsewhere.

The story in three moves
  • Flare searches criminal communities and public sources for exposures tied to an organization.
  • It helps analysts investigate the finding and validate exposed identities.
  • Integrations bring the response into existing security and identity workflows.

This is the territory Flare occupies. The Montreal company sells subscription software to security teams and service providers who need to know what attackers can see outside their networks. Stolen passwords, malware logs, exposed code and criminal conversations become searchable evidence. The valuable question is whether that evidence gives a defender something useful to do before someone else uses it.

A burglar with a receipt

Flare began in 2017. Its present company history names three founding security practitioners: Mathieu Lavoie, Israël Hallé and Yohan Trépanier Montpetit. An early investor announcement also identifies criminologist David Hétu as a co-founder and research chief. That combination is revealing. Penetration testing explains how systems can be entered. Criminology helps explain the people trading the means of entry.

Lavoie had managed a bank’s offensive security team. The founders’ frustration was practical: defenders lacked visibility into information attackers were already exploiting, while available intelligence often offered little they could act upon. They built software to collect, organize and prioritize external evidence. Banking supplied the initial problem; the resulting product could travel well beyond banking.

Flare co-founder Mathieu LavoieFlare CEO Norman Menz
Different jobs, shared quarry. Co-founder Mathieu Lavoie, left, and CEO Norman Menz. The stolen login does not care which department finds it.

The experts had to learn another language

Technical knowledge did not automatically make the business understandable. Flare landed its first customer in 2018. When it joined the Catalyst Cyber Accelerator in 2020, Lavoie was initially skeptical about doing another accelerator. Then prospective customers explained what confused them and what interested them. The program’s account reports that monthly revenue doubled in roughly three months.

“They told us what they didn’t understand about Flare”Mathieu Lavoie, in a Rogers Cybersecure Catalyst profile

The lesson is pleasantly unglamorous. A buyer should not have to study the seller’s profession before understanding the product. Flare’s emphasis on usable intelligence makes more sense against that early experience. The same account credits cautious spending and government support with extending runway between seed funding and the Series A. Expertise needed time, feedback and a comprehensible offer.

From a stolen password to a disabled session

The platform monitors both the clear web and underground sources. Customers configure identifiers, such as domains, to locate relevant events. Analysts can search historical material, investigate actors and receive alerts. Flare’s AI tools summarize posting histories and contextualize evidence. Those tools assist the investigation; an elegant summary alone does not establish that a threat is real.

An identity exposure, put to work
  1. 01DiscoverA credential surfaces in collected data.
  2. 02ValidateCheck the exposure against a supported identity provider.
  3. 03RespondTrigger the configured remediation workflow.
The useful part comes after discovery. A simplified workflow; available actions depend on the integration and configuration.

Identity Exposure Management takes the proposition closer to the login itself. Microsoft Entra ID integration can validate exposed credentials and support actions such as password resets or session revocation. Flare announced Okta support in June 2026. At that point, it reported more than 25,000 automatic identity validations across hundreds of organizations using its IEM offering.

The distinction matters when evaluating alternatives. Recorded Future offers broad threat intelligence; SpyCloud concentrates on identity exposure; KELA examines cybercrime intelligence. Flare’s argument combines underground collection, an accessible investigation interface and a connection to identity response. Buyers should compare coverage and the complete workflow for their own use case. Database size is an intriguing dinner guest and an insufficient purchasing criterion.

The customer who needed less noise

Socura, a UK managed detection and response provider, offers a concrete example. Its existing intelligence sources lacked the dark web detail it wanted. Customers wanted earlier warning, and analysts needed targeted searches for customer-specific identifiers. Flare connected to Socura’s incident-management portal; the company’s case study says the partnership became operational within weeks.

That makes the buying logic clear. A bank, healthcare provider or software business might purchase Flare directly. A service provider can use it across customers and build a commercial intelligence service around it. Socura uses the platform for threat profiling, reporting, domain takedown support and leaked-credential alerts. Intelligence becomes part of the queue people already work through.

460,000+stolen credential instances linked to FTSE 100 employeesSocura + Flare research, November 2025. Instances are not unique accounts.

Flare sells subscriptions with contractual allowances for identifiers, searches and API usage. Takedowns may be included or purchased separately. A sensible budget therefore considers monitoring scope, investigation capacity and response work alongside the subscription. The practical move readers can copy is straightforward: define what matters, send findings into an owned workflow, and measure how quickly the team removes a live exposure.

The capital behind the identity bet

The financing follows the widening ambition. Flare announced a CAD 9.5 million Series A in June 2022 and a USD 30 million Series B in December 2024, led by Base10 Partners. In November 2025 came another USD 30 million: a USD 15 million equity extension led by Inovia’s Growth Fund, plus USD 15 million in debt from BMO.

Flare said the additional capital would advance identity capabilities and support acquisitions. It had already acquired Foretrace in March 2024, adding data-exposure technology and expertise. By November 2025, it reported customers and partners in more than 50 countries. In September 2026, its Ignite program formalized support for service providers and resellers through five partner tiers.

A dark room with the lights on

Education supplies an unusually tangible expression of the company’s mission. Darkroom, launched in August 2026 through Flare Academy, is a free four-hour simulated investigation lab. Learners explore underground forums, stolen identities and criminal tradecraft, interacting with AI-powered threat-actor personas. The practice takes place in a purpose-built environment.

The commercial product still requires judgment, relevant coverage and permission to act. A finding outside collected sources may go unseen; a badly chosen identifier can miss what matters; a takedown depends on another platform’s cooperation. Those conditions make the last operational question decisive. When the alert arrives, who can turn a troubling piece of information into a locked door?