.png&w=3840&q=75)
AI-Powered Threat Intelligence & Situational Awareness Platform for Emergency Teams
A real-time threat intelligence platform for Regroup that automatically aggregates alerts from hundreds of sources, classifies them with AI, and displays them geospatially so safety teams can detect threats and dispatch mass notifications faster than ever before.
- ReactJS
- NodeJS
- Python / Django
Duration
months
Team
Project Manager
QA
2 Backend developers
1 Front end developer
Overview
Regroup is a leading mass notification platform trusted by thousands of organizations to reach their people instantly during emergencies. As their user base grew and the threat landscape became more complex, Regroup identified a critical gap: their clients needed not only the ability to send notifications, but also the intelligence to know when and why to send them.
BeeWeb was brought in to design and build TIP, the Threat Intelligence Platform, a standalone product that sits alongside Regroup's notification engine and gives safety teams the real-time situational awareness they had been missing.
TIP automatically discovers, aggregates, and classifies alerts from across the web, surfaces them geospatially on an interactive map, and lets teams dispatch Regroup mass notifications directly from any alert - all without switching tools.
Business Challenge
Safety and emergency management teams face a core problem: threats move faster than the tools designed to track them. Before TIP, Regroup clients were manually monitoring news feeds, social media, and government alerts across dozens of separate platforms — fragmented, slow, and error-prone.
🔹Information Overload Without Structure
Monitoring hundreds of sources manually was not scalable. Teams missed critical alerts buried in noise, or wasted time filtering content irrelevant to their geographic area — with no system to help them prioritize.
🔹No Geographic Context
Alerts existed as plain text. There was no way to instantly see whether a threat was 5 miles away or 500. Teams had no way to assess proximity or prioritize response based on location.
🔹Disconnected Tools
Even when a threat was identified, dispatching a notification required switching platforms entirely. The gap between detection and action cost critical response time during fast-moving situations.
🔹No Accountability Trail
With notifications sent from multiple places across multiple tools, teams had no unified history of what alerts were acted on, when, and by whom — a significant problem for compliance and post-incident review.
Our Solution
BeeWeb designed and developed TIP as a fully integrated threat intelligence platform that transforms how safety teams monitor, assess, and respond to threats.
🔹AI-Powered Aggregation Engine
TIP continuously pulls data from hundreds of external sources — X (Twitter), government feeds, web scrapers, and alert services — automatically enriching each alert with severity, category, territory, and risk score. No manual tagging required.
🔹Geographic Dashboard System
Each dashboard is scoped to a specific address or county, bringing in only the intelligence relevant to that location. Teams stay focused on what matters to them, not everything happening everywhere.
🔹Customizable Alert Channels
Within each dashboard, alert channels organize incoming alerts by category — allowing teams to monitor different threat types from a single, fully configurable workspace, with each channel managed independently.
🔹Interactive Geospatial Map
Every alert appears on a fully interactive map with support for ESRI Feature Services, GeoJSON overlays, and custom asset labels — giving teams immediate location context for every threat without leaving the platform.
🔹One-Click Mass Notification
Teams trigger a Regroup mass notification directly from any alert detail view in a single action — no platform switching, no copy-pasting, no delay between detecting a threat and acting on it.
🔹Notification History & Audit Trail
Every notification dispatched from TIP is automatically logged with timestamp, alert reference, and sender — a complete accountability record for post-incident review and compliance requirements.
Development Process
Technology & Architecture
🔹Frontend — React.js
A responsive, real-time interface handling continuous alert updates across multiple active dashboards simultaneously, without performance degradation.
🔹Mapping — Mapbox
Interactive geographic display with custom layer support, territory filtering, and precision geospatial rendering for situational awareness at any zoom level.
🔹Backend — Node.js / Express
Manages dashboard configurations, alert channels, user sessions via Regroup OAuth 2.0 SSO, and the full notification dispatch flow.
🔹Real-Time — WebSockets
Alerts are delivered to the frontend the moment they are classified — no page refresh, no polling delay. Teams see threats as they emerge.
🔹Data Aggregation — Python
A dedicated service handles continuous source discovery and scraping across social media, government APIs, and web sources around the clock.
🔹AI Classification — OpenAI API
Each collected alert is automatically assigned a severity rating, category label, territory tag, and risk score before being stored and displayed.
🔹Database — PostgreSQL
Structured for efficient geographic filtering, multi-dashboard queries, and full notification history logging with audit-ready records.
🔹Infrastructure — AWS
Auto-scaling configured to handle traffic spikes during active events — precisely the moments when performance matters most.
Key Features
🔹Automated Source Discovery
TIP automatically identifies relevant X (Twitter) accounts, local alert sites, and government feeds for each dashboard's geographic area — eliminating the need to manually configure and maintain sources.
🔹AI-Powered Alert Classification
Every alert is enriched automatically with severity rating, category label, territory tag, and risk score — allowing teams to prioritize threats at a glance rather than reading through raw content.
🔹Geospatial Dashboard with Map Layers
Alerts display on a fully interactive map supporting ESRI Feature Services, GeoJSON overlays, and custom asset labels. Teams control what's visible through a dedicated map layers panel.
🔹Customizable Alert Channels
Each dashboard supports multiple channels organized by alert category, independently configurable and filterable — a fully personalized monitoring workspace for every team.
🔹One-Click Mass Notification
From any alert detail view, teams send a Regroup mass notification in one action — collapsing the gap between threat detection and response.
🔹Notification History & Audit Trail
Every notification dispatched from TIP is logged with timestamp, alert reference, and sender — a complete record for compliance and post-incident accountability.
🔹Regroup SSO Integration
TIP authenticates entirely through Regroup's existing login system. Users access TIP without a separate password, fitting naturally into the workflows they already use.
Result
🔹Faster Response, Less Manual Work
The gap between threat detection and notification dispatch — previously measured in minutes of filtering and tool-switching — was reduced to seconds. AI classification removed the manual tagging burden entirely.
🔹Broader Awareness with Smaller Teams
Geographic scoping and alert channels eliminated the noise problem. Teams see only what's relevant to their area and role, allowing smaller teams to maintain broader coverage without additional headcount.
🔹Built-In Compliance
The notification history and audit log addressed a long-standing accountability gap — every action taken in response to a threat is automatically documented, meeting compliance and post-incident review requirements.
🔹Stronger Product for Regroup
TIP launched as a native Regroup extension, deepening the platform's value and giving Regroup a meaningful competitive differentiator in the emergency management market.
Get an estimate
Describe your project by providing a written description or recording a voice message.
Free 30 minutes. A senior engineer, not an SDR. NDA-ready. Replies within one business day.