Skip to main content
Mallory
Community · $0

The Mallory Community License

If you just got access: welcome. Your license is free, it stays free, and it runs on the same intelligence graph as every paid tier. This page covers what you have, how to get moving, and where the edges are.

The Community license exists because the people who follow threats closest are often working on their own account. You track the landscape; Mallory keeps up with it for you.

What's included

The full Mallory Threat Graph

Search stories, threat actors, CVEs, malware families, and IoCs across the same intelligence graph every Mallory tier runs on. Nothing here is a sample dataset.

The Mallory Agent

Ask what moved overnight, dig into an actor, or chase a CVE across the graph. The Mallory Agent works the intel graph with you, in a thread, on your own model key.

Intelligence API + MCP

Query the graph from your own scripts and tooling, or wire it into your AI assistant over MCP. Rate-limited, and plenty for personal research and triage.

Hosted, nothing to run

Mallory hosts the platform. You sign in, add a model provider key, and the graph is yours to work.

Users / workspaces

1 / 1

Mallory Agent

Scheduled agents

Intel graph

Asset graph

Model key

Yours (BYOK)

Deployment

Hosted

License

Personal · non-commercial

Getting started

  1. 1

    Sign in

    Your workspace lives at app.mallory.ai. Use the account your license was provisioned under.

  2. 2

    Add your model provider key

    The Mallory Agent runs on your own key (Anthropic, OpenAI, or another supported provider), so inference stays under your provider agreement and Mallory never marks up tokens. Add it in workspace settings.

  3. 3

    Search the graph

    Start with something you already track: a threat actor, a CVE from this morning, a package in your stack. Every entity connects to the related actors, malware, exploits, and stories, so one search puts the whole picture in front of you.

  4. 4

    Connect the API or MCP

    Grab an API key and query the graph from your own tooling, or add the MCP server to your AI assistant. The docs cover both in a few minutes.

Questions, feedback, or something broken? The Community Slack is where practitioners and the Mallory team hang out.

The license, in plain language

The short version of what the Community license covers. The full legal text lives in our Terms of Service.

It's $0

There is no paid Community license. If someone quoted you a price for Community, they were wrong.

Personal use, one user

The license covers you, on your own account, with one workspace. It's built for individual practitioners, researchers, and students following the threat landscape.

Not licensed for commercial use

Using Mallory to deliver paid work, feed a production pipeline, or defend a company's estate needs a Team or Enterprise license.

Bring your own model key

The Mallory Agent runs on your model provider key. You pay your provider directly for inference; Mallory doesn't meter, mark up, or resell tokens.

Rate-limited API

The Intelligence API and MCP access are rate-limited. Production volume, streaming, and bulk export are Team and Enterprise capabilities.

Scheduled agents start at Team

The interactive Mallory Agent is included. Agents that run while you're away (monitors, briefs, and investigations on a schedule) are Team capabilities, along with anything that touches your own environment.

When you outgrow it

Community works the threat landscape. The moment you want agents running on a schedule, need Mallory to reason about your own environment, or want more than one person in the room, you need Team (from $999/mo). It adds:

  • Scheduled agents on your estate: investigations, monitors, and briefs that know what you're running
  • Your whole team, shared workspaces, SSO
  • Production-grade API + MCP, your own intel feeds and integrations
  • Your model key or ours, still no token markup
  • Licensed for commercial use

Community is BYOK: it runs on your model provider key, and your Mallory bill stays $0.