THINKPOL
Pricing

Three deployment models.
No per-seat pricing.

Flat-fee licensing. No per-call costs. From hosted API access to sovereign on-premise deployments and project-based investigations.

Data Pipeline

Flat fee/annual

Full API access for teams integrating grey web data into their stack.

Talk to sales
What's included
  • Full REST API (OAS 3.0)
  • Sub-300ms response times
  • 10-second data refresh
  • No per-call costs
  • White-label available
  • Hetzner EU hosting

Sovereign Instance

Custom/on-premise

Dedicated compute and storage. Air-gap support. Five Eyes / classified ready.

Request scoping
What's included
  • On-premise or sovereign cloud
  • Air-gap deployment
  • Custom algorithms & alerts
  • Scoping → Deployment → Calibration
  • Dedicated compute & storage
  • Agentic AI add-on included

Custom Intelligence

Per project/fixed-scope

Analyst-led investigations with automated discovery. Strict NDA, secure delivery.

Brief us
What's included
  • Leak tracing & attribution
  • Bot network mapping
  • Threat actor profiling
  • Digital footprint audits
  • Timelines & network graphs
  • Evidence packs

Data Pipeline

Flat fee · annual license

Sovereign Instance

Custom · on-premise / sovereign cloud

Custom Intelligence

Per project · fixed-scope engagement

Access
REST API
Streaming feed
Web console
MCP server (Agentic AI)
White-label endpoint
Deployment
Hosted EU (Hetzner)
Sovereign cloud
On-premise / air-gap
Customer-controlled residency
Coverage
30B+ post archive
Reddit · Telegram · Discord · forums
Custom source onboarding
Deleted content recovery
Support & SLA
99.9% hardware uptime
Empty-result SLA reimbursement
Named technical contact
Critical-change notifications (30 min)
FAQ

Frequently asked questions

Those platforms aggregate hundreds of sources at shallow depth — Reddit is one source among many, with no historical archive. THINKPOL is purpose-built for the grey web: 30B+ posts, full deletion history preserved at the point of collection, and sub-300ms query performance on the entire corpus. For operations where Reddit, Telegram, and grey web forums are the primary threat surface, there is no comparable alternative.

Threat actors delete posts after disseminating them — to clean their trail. Credential leaks, pre-attack coordination, recruitment messages, and disinformation seeds disappear from Reddit's own API within hours. Our archive captures and indexes content before deletion. For investigations, this is often the difference between a full behavioral record and a gap in the timeline.

Yes. The legal framework rests on five pillars. (1) GDPR Art. 6(1)(f) legitimate interest: the three-part test is met — legitimate purpose (security intelligence, threat detection, investigative support), necessity, and proportionality (only publicly accessible data, no individual commercial profiling). All collection occurred without bypassing authentication controls. An Art. 14 GDPR notice is published on our site with a deletion request mechanism. (2) Terms of service are unenforceable against a non-signatory: CA Paris, 2 Feb. 2021 (LBC France v. DIRECTANNONCES, n° 17/17688) rejected all of LeBonCoin's ToS, sui generis and unfair competition claims despite scraping 89% of its listings multiple times daily. Meta Platforms v. Bright Data (N.D. Cal., Jan. 2024) confirmed ToS do not apply to logged-off scraping of public data — Meta subsequently dropped all remaining claims including for millions of Instagram records. (3) Ghost data was lawfully collected: content was publicly accessible at the point of archiving; no authentication barrier was crossed. hiQ Labs v. LinkedIn (9th Circuit, Apr. 2022) confirms public data scraping does not constitute unauthorized access. (4) Sui generis database rights (CPI Arts. L.341-1/L.342-1, EU Directive 96/9/CE): substantial investment in building and maintaining the archive creates an independent layer of protection. (5) No US CLOUD Act exposure: data is hosted and incorporated in Europe under French law and is not compellable by the US DOJ (18 U.S.C. §2523) — a structural requirement for European government and defence customers.

Nothing. We do not collect, track, store or process any inbound or outbound customer data. Only API request volume and type are counted, for billing purposes.

Yes. The Sovereign Instance tier deploys on-premise or in your sovereign cloud, with dedicated compute and storage. No multi-tenancy, no data egress, full air-gap support; built for classified and Five Eyes-compliant environments.

THINKPOL is not a consumer product. Access requires vetting and a contractual agreement. We work with national security, law enforcement, CTI teams, defense agencies, regulated financial institutions and corporate security functions.

Sub-300ms API response times, 99.9% hardware uptime SLA, 10-second data refresh rate. Hosted on Hetzner EU. Empty or zero results are eligible for prorated SLA reimbursement on request.

The space between the open internet and the dark web. Reddit, Telegram, Discord and unindexed forums where threats, counterfeits, leaked credentials and coordinated campaigns take shape — in plain sight, but outside the reach of conventional monitoring tools.

Stop reading about
it in the news.

Request access to THINKPOL. We respond within one working day. A 30-minute scoping call follows, and a sandbox tenant is provisioned within five working days of contract signature.

Contractual agreement requiredSandbox in 5 working days
© 2026 THINKPOL SAS
Backed byFrance 2030APOK InvestLa French Tech