RelayShield MCP is a security monitoring service focused on what happens after a data breach. It watches for the attack chain that can follow exposed email addresses, phone numbers, and dates of birth, including SIM swaps and session theft that can defeat two-factor authentication.
The service says it monitors the full attack chain, from breach exposure through SIM swap and session hijack, and then walks users through fixes in a permission-based, step-by-step conversational channel in WhatsApp. It also lists real-time breach and dark web monitoring, WhatsApp alerts with severity scoring, a Telegram bot, email security sweep, SIM/eSIM swap monitoring, near real-time infostealer malware monitoring, active session audit and revocation, suspicious SMS text analysis and smishing warnings, instant file and link virus scanning, vishing preparedness, and connected app protection for Google and Microsoft accounts. For infostealer alerts, it says users receive the infection date, device OS, and credential count exposed, and it guides them through remediation that starts with device isolation and then password changes from a clean device.
RelayShield is described for individuals, families, sole proprietors, freelancers, teams, and security teams. The plan table includes Personal Shield, Business Starter, Starter + Domain, Business Basic, and Business Shield, with business features such as quarterly sweep reminders, monthly security digests, contractor or employee seats, team seat management, and domain monitoring. It also says onboarding and interactive security alerts require WhatsApp, and that the official Telegram bot is @RelayShield_bot.
For security teams, RelayShield offers a REST API for SOAR playbooks, SIEM enrichment, and incident response workflows. The page says the intelligence pipeline monitors 37 criminal Telegram channels in real time and surfaces indicators of compromise 24 to 72 hours before they appear in public databases. Pricing is shown as pay-as-you-go from $0.10 per call, with an unlimited subscription option. The page also includes links to Terms of Service and Privacy Policy.
In the Threat intelligence, SIEM & detection space, RelayShield MCP takes a focused approach. It focuses on detecting breaches, SIM swaps, phishing, and infostealer threats for security teams. It is built as an open-source project for security teams and developers. RelayShield MCP is commercial open source (MIT). It runs on the web, the command line, and API, and it can be self-hosted.
RelayShield builds and maintains RelayShield MCP, and it first shipped in 2026. The project is developed in the open on GitHub with 18 commits in the last 90 days. Among its 6 catalogued features are breach detection, SIM swap detection, and OAuth watchlist. It exposes integrations via an MCP server and a public API.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Closest matches by what these projects do