Ten Year Anniversary

Celebrating a Decade of Analyst-Driven Intelligence

10 years of building tools and tradecraft for defenders

Limited Series Podcast

TLDR: Key Takeaways

Why Synapse Is a Central Intelligence System

For the final episode of Signals & Stories, we return to where the series began: a conversation with Vertex Project co-founders visi stark and John “whippit” Rodgers.

This time, the subject is Synapse itself including why it was built, the problems its creators thought intelligence technology wasn't solving, what they've learned from analysts using it over the past decade, and where they think intelligence analysis is headed next.

On the Vertex website, Synapse is described as a central intelligence system rather than a threat intelligence platform (TIP). That distinction reflects a much bigger difference in philosophy.

For visi, the traditional TIP paradigm became too narrowly focused on managing indicators and performing relatively basic enrichment. Intelligence analysis requires something broader: a workspace where analysts can investigate theories, structure knowledge, work in isolated layers, review changes, and ultimately build on what they and their teammates already know. Threat intelligence is part of that mission, but it isn't the boundary around it.

The Cost of Intelligence Silos

The frustrations that eventually led to Synapse weren't rooted in one investigation that went particularly badly - they accumulated across many investigations.

Analysts were collecting valuable information, but that knowledge was scattered across different systems, formats, teams, and individual workflows. Different disciplines couldn't easily benefit from one another's findings. Even analysts returning to their own previous work might have to search through old reports and reread prose simply to reconstruct what they already knew.

The problem became increasingly obvious as the volume of intelligence work grew. Analysts weren't just being asked to solve difficult problems. They were spending significant amounts of their expertise organizing the information required to solve them.

Whippit compares it to buying a great meal and throwing half of it away: organizations had already paid the cost of collecting information and performing analysis, but much of the potential value disappeared because the resulting knowledge couldn't easily be reused or shared. Structured intelligence changes that equation.

Instead of beginning every investigation from scratch, analysts can “leapfrog” from their own previous findings, their coworkers' findings, and other available intelligence. The organization gradually accumulates knowledge rather than accumulating documents.

Between an Empty Graph and an Overfit Tool

When Vertex began building Synapse, visi argues there wasn't really a unified analytical workbench for interdisciplinary intelligence analysis in the private sector. Instead, organizations largely had a few choices.

There were highly specialized systems designed around a particular domain. There were graph databases that provided the technology but essentially left organizations to invent the analytical model themselves. And there were vendors willing to build a custom model, often turning what looked like a product into an ongoing services engagement. Synapse was intended to occupy the space between those extremes.

It would provide analysts with an existing structure for representing analytically relevant information while remaining extensible enough to accommodate an organization's own data and use cases. That flexibility matters because intelligence questions don't respect product categories.

A cyber threat intelligence investigation might suddenly need to represent a person occupying a particular seat on an airplane. Fraud, trust and safety, CTI, and other disciplines may encounter the same entities from completely different perspectives. A system built too narrowly around one discipline can reach its limits precisely when an investigation becomes most interesting.

Model the Truth, Not the Use Case

That leads to one of the central design ideas behind Synapse: the data model should represent structural truths about analytically relevant things and their relationships without overly prescribing what analysts must do with them. That balance is difficult.

A model with too little structure forces every organization to invent its own representation of reality. A model that's too rigid becomes useful only for the scenarios its designers anticipated.

The goal is something in between: enough structure that analysts share a common language, but enough generality that the same underlying concepts can support investigations the Vertex team never imagined. For visi, one sign that the model is working particularly well is when a user arrives with a completely new use case and discovers that the existing model already represents it cleanly.

Sometimes a new problem requires extending the model. Other times, it simply reveals a capability that was already there.

What Synapse Intentionally Is Not

Building a broadly applicable intelligence system also requires deciding what not to build. Vertex made an early decision that it wasn't going to become an intelligence data provider. Instead, Synapse would remain neutral across providers (what visi jokingly describes as “Data Switzerland.”) That allows organizations to integrate and analyze information from many different sources without Synapse competing with those sources.

Similarly, Synapse isn't intended to become an organization's telemetry database, SIEM, data lake or, as whippit puts it, “data swamp.” Those systems have their own jobs. Synapse's job is analysis.

It can leverage those platforms and the information they contain, but the objective is to give analysts a common environment for connecting, modeling, investigating, and reasoning about that information.

The Structured Data Light Bulb

What happens after an analyst has been using Synapse for six months or a year? Sometimes, whippit says, an entirely new world opens up and users initially want to put everything into the platform. But the more consequential change tends to happen when analysts begin experiencing the cumulative benefits of structured knowledge.

Visi describes a recurring “light bulb” moment: an analyst asks an important question and realizes the answer can be expressed as a Storm query against the knowledge they've already accumulated. They don't need to locate a collection of reports, reread them, manually collate the relevant details, and reconstruct the relationships even if they wrote those reports themselves.

The answer exists because the underlying knowledge exists in a form the system can reason across. Getting there requires some investment. Analysts have to structure the portions of their knowledge that only they can structure. But once that work begins compounding, the alternative (returning to spreadsheets, documents, and repeatedly researching your own research) becomes increasingly difficult to imagine.

That may explain one of Vertex's most meaningful measures of success: analysts who learn Synapse at one organization and then advocate for it when they move somewhere else.

Building What Analysts Need, Not Necessarily What They Asked For

Many Synapse features can be traced directly to analyst pain points. Forking and merging views gave analysts the ability to work with and review data before committing changes to production intelligence. Spotlight grew from the need to ingest and work with third-party prose reporting. But solving a user's problem doesn't always mean building exactly what they request.

Users are experts in the pain they're experiencing, but the product team still has to determine the best way to address it within the larger system. Visi invokes the familiar “faster horses” idea to make the point: if you simply built what users explicitly requested, sometimes you'd end up giving them a bigger spreadsheet. Instead, features are developed around the underlying need, then designed in a way that works with the larger architecture and analytical model.

The Next Decade: LLMs Without Outsourcing Analysis

Looking forward, both visi and whippit see enormous potential in LLMs, but not as replacements for analysts. One particularly interesting opportunity is using them to help convert information currently trapped in prose into structured data.

Threat reporting can contain campaigns, time periods, behaviors, infrastructure, threat clusters, and relationships that currently require an analyst to read carefully and manually model. LLMs may be able to assist with extracting that information into structured representations that can then be reviewed and validated by an analyst.

Visi draws a clear line around allowing an LLM to perform analysis or make unvalidated inferences. The opportunity is to use the technology to reduce the mechanical burden around structuring information while keeping human judgment where it belongs. In that model, AI doesn't eliminate the need for structured intelligence, it helps organizations create more of it.

Intelligence Is Becoming More Interdisciplinary

The other major opportunity for the next decade may have less to do with a particular technology and more to do with how organizations define intelligence work. CTI teams are beginning to work more closely with fraud teams. Trust and safety teams encounter information relevant to security investigations. Protective intelligence missions overlap with other analytical disciplines.

These functions have historically existed in separate pockets, often with separate tools and data, but the underlying analytical work isn't necessarily as different as the organizational chart makes it appear.

Visi and whippit see an opportunity for Synapse to increasingly support those interdisciplinary environments and eventually for organizations to discover intelligence use cases inside functions they may not even think of as “intelligence” today.

Powerful Tools and the Complexity Problem

Of course, broad capability comes with a challenge: there are folks who have said Synapse can be difficult to learn. Visi doesn't entirely reject that criticism. Good intelligence analysis is complicated, and a tool capable of supporting complicated work will inevitably expose some of that complexity. His analogy: driving a Formula One car is going to be more complicated than driving a scooter.

But that doesn't mean every analyst needs to see every capability all the time. One of the lessons the team has learned is that sometimes the most important interface decision is knowing what not to show. Purpose-built profiles, workflows, and workspaces can present the subset of relationships and pivots most relevant to a particular analyst while leaving the broader graph available when needed. The goal isn't to make intelligence analysis artificially simple. It's to keep the underlying power while making the experience appropriately focused.

We're Here to Help

After ten episodes looking back at ten years of The Vertex Project, Kali closes the series with one final question: If someone remembers only one thing about The Vertex Project, what should it be?

Whippit's answer is simple: We're here to help.

Visi's answer expands on the mission behind it. The Vertex Project is trying to unify intelligence disciplines that have traditionally been separated from one another and solve interdisciplinary intelligence challenges rather than optimizing for a single narrowly defined problem.

That idea has been present throughout Synapse's history: help analysts preserve more of what they know, connect work that previously existed in silos, and spend more of their expertise actually analyzing.

And the fact that Vertex is still doing that work ten years later isn't only a reflection of its founders. Whippit credits the team that has built Synapse alongside them and the customers who were willing to invest the effort required to learn a different way of working and then, in many cases, bring that way of working with them to their next organization. Ten episodes later, that's a fitting place to end this season of Signals & Stories: not with intelligence as a finished problem, but with ten years of lessons about how to make the work better and plenty of problems left to solve.