
Many attacks begin outside the systems a security team controls. Credentials appear in an infostealer log, personal information is assembled from a breach, or an employee’s exposed identity gives an adversary enough context to impersonate them. None of those events needs to trigger an alert inside the corporate network. The risk accumulates in public, underground and criminal data sources until an attacker is ready to log in, commit fraud or target a person directly.
That shift makes identity exposure a continuous intelligence problem. Organisations need to know which information has escaped, how separate records connect to the same person, and whether those connections indicate an emerging threat. A perimeter tool cannot answer those questions on its own.
Constella Intelligence collects, verifies and connects breach, infostealer and open source data from the surface, deep and dark web. The company reports that its data lake spans more than one trillion attributes across over 125 countries and more than 50 languages. That history gives security and fraud teams a way to investigate exposed identities, discover relationships between records and identify risk that would remain invisible in a single incident feed.
Constella makes that intelligence available through products and APIs used by enterprises, governments and technology providers. Customers apply it to identity posture, threat intelligence, investigations, employee and executive protection, and fraud use cases. The value is not simply the volume of records. It is the ability to establish provenance, connect transient evidence and turn it into intelligence that another security product or analyst can use.
The company traces back to Survela, founded by Julio Casal and a technical team led by Alberto Casares. Survela built the initial version of its identity intelligence and proprietary data lake at the core of the platform. The company rebranded as Constella Intelligence and moved its HQ to Silicon Valley while keeping the core technology and development functions in Granada, Spain. A leadership team spanning finance, commercial operations and threat research is executing on the task of turning a data asset built over many years into a dependable intelligence layer for customers and security partners. The company has increasingly concentrated its positioning on identity risk intelligence as exposed credentials, infostealers and synthetic identities become more important attack vectors.
We first backed the company at the seed stage in 2013 and continued investing through later rounds, including its Series A, B and C. A $35 million Series C preceded the name change, and the incorporation of new leadership and product emphasis over that period, while the core conviction has remained: carefully gathered identity data becomes more valuable as the threat environment grows more fragmented.
Constella has an asset that is very hard to replicate: a long running, verified record of identity exposure and criminal infrastructure. Each new record can add context to the records already held, strengthening investigations and the products built on top. As AI makes impersonation cheaper and identity based attacks easier to scale, that proprietary intelligence becomes a deeper source of defensibility. Constella is a clear example of Trusted AI Infrastructure: data and security capabilities that help organisations decide which identities, interactions and signals they can trust.