FAQ
Questions and answers
Not here? Email support@intelmcp.io. We answer questions before you subscribe, too.
Coverage
Which channels does IntelMCP collect from?
Only public Telegram channels and groups, the ones anyone can find and join. Never private chats or invite-only groups. The collection is chosen by hand for threat-intelligence value, with the deepest coverage of the Gulf and the wider Middle East, Iran–Israel, Russia–Ukraine hacktivism, and leak, ransomware and CVE trackers. See coverage for dated figures.
Can I see the channel list?
No. We publish topics and regions rather than a channel list. Every search result and match names the channel its message came from, and Claude can list the source topics with how many sources and posts a day each has.
Which languages?
Posts are kept in their original language, mostly Arabic, Persian, Russian, Hebrew and English. You don't need to read them: Claude turns your question into searches in those languages and reads the results back to you in English.
A channel I need is missing. Can you add it?
Ask Claude to request it, with its @username or t.me link. You can make up to 10 channel requests a month. Every request is reviewed by hand before a collection account joins the channel, and some are declined. If the channel is already collected, Claude says so, with its last post and the date its stored history starts, and no request is filed.
How far back can I search?
Up to the last 90 days of collected messages.
Is the content verified?
No. Messages are third-party posts as published, and claims in them can be false or exaggerated. Treat them as leads to check, not as facts.
Alerts and triage
What is an incident?
Reposts and copies of the same event within 72 hours are grouped into one incident. The first post is marked new; a later post that adds something: an identifying indicator or a country new to the event, a step up in exploitation (proof of concept, then exploited), a reply in the same channel, a channel posting it a second time, or a match for another of your rules is marked update; the rest are repeats. You review one entry per event instead of one per repost, and webhooks skip repeats.
Who decides whether a match matters?
Your Claude does. A rule match is a candidate, not a finding. The Triage matches prompt has Claude read your watch profile, judge each new match against it and record a verdict: relevant or not, with a severity and a one-line reason.
How do matches reach me?
They wait in IntelMCP until you ask Claude about them. If you want them pushed, add a webhook: each match is posted as signed JSON to your HTTPS endpoint as it is matched, before any triage.
What does the dashboard look like?
The Dashboard prompt has Claude draw a one-page overview of your monitoring from your own data: matches per day by severity, top indicators, how often each rule fires, the busiest sources and the latest high-severity matches. In claude.ai it is an artifact; in Claude Code, an HTML file. Claude builds it fresh each time, so the layout varies.
Data and security
Do you train AI on the data?
No. IntelMCP does not train or fine-tune AI models, and does not run one. The analysis happens in your own Claude.
Can other customers see my rules or matches?
No. Each customer's rules, watch profiles, matches and verdicts are separated by row-level security in the database. See security.
Someone posted about me. Can you remove it?
Yes. Email support@intelmcp.io with the message and we remove it from IntelMCP. A post that is still on Telegram may be collected again, so removal of a live post may need repeating. We cannot remove it from Telegram itself.
Is IntelMCP affiliated with Telegram?
No. IntelMCP is an independent service that uses Telegram's API. It is not affiliated with or endorsed by Telegram.
Is IntelMCP affiliated with Anthropic?
No. IntelMCP is an independent service and is not affiliated with or endorsed by Anthropic. It connects to Claude as a custom connector, the way any MCP server can.
Claude
What do I need?
A Claude account that can add custom connectors (claude.ai or Claude Desktop), or Claude Code, and an IntelMCP subscription. On Team or Enterprise plans, an organization owner may need to add the connector first.
Does it use my Claude usage?
Yes. Claude does the reading and judging, so it runs on your own Claude plan. Long triage sessions use more of it.
Should I use the connector or the Claude Code plugin?
One of them, not both. In claude.ai and Claude Desktop, add the connector. In Claude Code, either add the connector with one command or install the plugin, which adds the connector plus the four guides as commands: /intelmcp:setup, /intelmcp:triage, /intelmcp:dashboard and /intelmcp:investigate. See the setup guide.
Billing
How much does it cost?
$25 per month for one analyst, billed monthly by Polar, our merchant of record. See pricing.
Is there a free trial?
Can my team share one subscription?
No. One subscription is for one analyst's sign-in. For more analysts, email support@intelmcp.io.
How do I cancel?
From the link in your Polar receipt email. Access continues to the end of the month you have paid for. There are no refunds for partial months; see the refund policy.
What happens to my data when I cancel?
Your rules, matches and settings are kept for 90 days after your subscription ends, then deleted. Subscribing again with the same email in that time restores them.