# CounterTack (now GoSecure) > CounterTack, Inc. was a Waltham, Massachusetts endpoint detection and response (EDR) vendor. > It acquired its channel partner GoSecure in June 2018, rebranded as "GoSecure powered by > CounterTack" in March 2019, and today trades solely as GoSecure — a managed extended detection > and response (MXDR) provider whose GoSecure Titan platform covers EDR, IDR, NGAV, SIEM and > professional services. The CounterTack brand is retired. > > There is no public developer program. The Titan API host answers HTTP 401 on every path, > the marketing site publishes no documentation or pricing, and no OpenAPI, GraphQL schema, > MCP server, agent card, SDK or CLI could be found. What IS public is the identity layer: > the Titan single sign-on is a Keycloak deployment whose OpenID Connect discovery document > is served anonymously, and GoSecure serves an RFC 9116 security.txt. > > This file was generated by API Evangelist from probed evidence. It is not published by > GoSecure. Everything below carries the HTTP status observed on 2026-08-11. ## Company - [GoSecure (successor to CounterTack)](https://www.gosecure.ai/): current company website — 200 - [GoSecure Titan platform](https://www.gosecure.ai/services/titan-platform): product overview page - [Support](https://www.gosecure.ai/support): support landing page - [GoSecure on GitHub](https://github.com/GoSecure): 96 public repositories, security research — 200 - [CounterTack on GitHub](https://github.com/countertack): legacy org, 5 forks last pushed 2013-2014 — 200 - [countertack.com](https://countertack.com/): legacy apex — resolves to GoSecure infrastructure but presents a certificate that does not cover the name; no HTTPS request completes ## APIs - [GoSecure Titan Platform API](https://api.gosecure.net): live host, HTTP 401 on every path probed including /robots.txt. Credential-gated; no anonymous discovery. - [GoSecure Titan console](https://titan.gosecure.net/): Keycloak-protected web console; answers 200 with the same login page for every path (soft-200 catch-all) ## Identity and discovery - [OpenID Connect discovery — gosec-titan realm](https://login.gosecure.net/realms/gosec-titan/.well-known/openid-configuration): 200 application/json - [OAuth 2.0 Authorization Server Metadata (RFC 8414)](https://login.gosecure.net/realms/gosec-titan/.well-known/oauth-authorization-server): 200, identical document - [UMA 2.0 configuration](https://login.gosecure.net/realms/gosec-titan/.well-known/uma2-configuration): 200 - [security.txt (RFC 9116)](https://www.gosecure.ai/.well-known/security.txt): 200 text/plain — Contact mailto:security@gosecure.net - [PGP key](https://www.gosecure.ai/.well-known/pgp-key.asc): 200 application/pgp-keys ## Artifacts in this profile - [apis.yml](https://raw.githubusercontent.com/api-evangelist/countertack/refs/heads/main/apis.yml): APIs.json 0.20 profile - [well-known/countertack-well-known.yml](https://raw.githubusercontent.com/api-evangelist/countertack/refs/heads/main/well-known/countertack-well-known.yml): every /.well-known/ path probed on every host, with status - [well-known/countertack-security.txt](https://raw.githubusercontent.com/api-evangelist/countertack/refs/heads/main/well-known/countertack-security.txt): verbatim copy - [well-known/countertack-gosec-titan-openid-configuration.json](https://raw.githubusercontent.com/api-evangelist/countertack/refs/heads/main/well-known/countertack-gosec-titan-openid-configuration.json): verbatim copy - [authentication/countertack-authentication.yml](https://raw.githubusercontent.com/api-evangelist/countertack/refs/heads/main/authentication/countertack-authentication.yml): OIDC/OAuth profile derived from the discovery document - [scopes/countertack-scopes.yml](https://raw.githubusercontent.com/api-evangelist/countertack/refs/heads/main/scopes/countertack-scopes.yml): 13 scopes, 2 realm-specific (titan, service_account) - [conformance/countertack-conformance.yml](https://raw.githubusercontent.com/api-evangelist/countertack/refs/heads/main/conformance/countertack-conformance.yml): 25 standards assessed with evidence - [lifecycle/countertack-lifecycle.yml](https://raw.githubusercontent.com/api-evangelist/countertack/refs/heads/main/lifecycle/countertack-lifecycle.yml): company, brand and domain lifecycle - [security/countertack-domain-security.yml](https://raw.githubusercontent.com/api-evangelist/countertack/refs/heads/main/security/countertack-domain-security.yml): TLS/HSTS/DNSSEC/SPF/DMARC probe - [security/countertack-vulnerability-disclosure.yml](https://raw.githubusercontent.com/api-evangelist/countertack/refs/heads/main/security/countertack-vulnerability-disclosure.yml): security.txt contact - [plans/countertack-plans-pricing.yml](https://raw.githubusercontent.com/api-evangelist/countertack/refs/heads/main/plans/countertack-plans-pricing.yml): plan_count 0 — no published pricing - [rate-limits/countertack-rate-limits.yml](https://raw.githubusercontent.com/api-evangelist/countertack/refs/heads/main/rate-limits/countertack-rate-limits.yml): limit_count 0 — no published limits - [packages/countertack-packages.yml](https://raw.githubusercontent.com/api-evangelist/countertack/refs/heads/main/packages/countertack-packages.yml): package_count 0 — no first-party SDK in any registry ## Not found - OpenAPI / Swagger: probed /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs and /redoc on api.gosecure.net (401 each), titan.gosecure.net (soft-200 login page), www.gosecure.ai and www.gosecure.net (404 each) - GraphQL: /graphql returns 401 on the API host, the login page on the console host - MCP server: none published - A2A agent card: /.well-known/agent-card.json and /.well-known/agent.json miss on every host - llms.txt published by the provider: 404 on www.gosecure.ai and login.gosecure.net, 401 on api.gosecure.net - Status page, changelog, deprecation policy, SLA, CLI, sandbox, Postman collection: none found