App

Spur Platform & Data

21 articles

What Spur provides, product capabilities, coverage, and how to consume enrichment via API, feeds, and exports.

Which delivery option is best for my organization?FAQThe best option depends on:Does Spur offer downloadable feeds, local deployments, or MMDB-style delivery?FAQAvailable delivery methods may vary by product and customer requirements. Organizations with low-latency or high-volume enrichment needs should contact Spur to discuss available deployment and data-delivery options.What is the difference between online subscriptions and enterprise tiers?FAQOur enterprise tiers are specifically designed to provide other businesses with package offerings, robust SLAs, custom volumes, support, commercial licensing, and onboarding. Online subscriptions are designed for smaller teams with lower volume and support needs.What is your geographic IP coverage like?FAQWe strive for global coverage of internet activity. Anonymization services, however, typically gravitate towards IP space and hosting space located in the United States.Do you have a confidence score or last seen date?FAQSpur operates on a "high confidence" only model to reduce the likelihood of false positives ever making it into our data. Our mentality is that our customers should trust us to decide if something is true rather than providing an arbitrary score to constantly adjust higher or lower. Every API request or Monocle session provides the latest true information for that moment in time. On-prem solutions are updated at their purchased cadence (daily or real-time). We actively purge any result that is no longer true and maintain smart age-offs to maintain the most accurate snapshot of data each day.How can I download data on all IPv4 and IPv6 addresses?FAQIP location, routing, and ownership information is produced at the network level and presented into netblocks. Other data such as client fields or service attributions are produced on an individual IP address basis. For our API customer this coverage is automatically merged to produce full IPv4 and IPv6 coverage. For on-prem services, a combination of these two granularities must be used to cover all IP space.What formats do you offer on-prem data in?FAQOur API and on-prem solutions default to JSON format. Some on-prem tiers can also be downloaded in mmdb or CSV format. Please see our Exports API for examples of server-side pre-processing or filtering.How can I download all IP addresses for a certain VPN or proxy provider?FAQThis functionality is reserved for our on-prem data customers. Our API access only allows for individual IP Address lookups.Can a Spur IP classification be reviewed or corrected?FAQYes. Customers who believe a classification is inaccurate can contact Spur for review. Investigations may include validation of infrastructure ownership, routing characteristics, provider relationships, and other relevant signals.How frequently is Spur data updated?FAQThe Context API reflects new intelligence in real time as it becomes available. Data feeds are updated daily, and organizations can also consume updates in real-time through streaming or feed-based workflows depending on operational requirements.How accurate are Spur's classifications?FAQSpur continuously updates classifications using automated systems and ongoing research. Accuracy can vary depending on infrastructure changes and evolving proxy technologies, but classifications are designed to provide actionable intelligence rather than relying on a single static signal.Does Spur support IPv6?FAQYes. Spur supports IPv6 intelligence and continues to expand visibility and classification capabilities as IPv6 adoption grows.Should Spur data be used as a blocking list?FAQGenerally, no. Spur is designed to provide context and intelligence rather than a simple allow/block decision. Most organizations achieve the best results when Spur data is incorporated into broader risk models and decisioning workflows.If Spur identifies a provider such as NetNut, does that mean the traffic originated directly from that provider's customer?FAQNot necessarily. Proxy ecosystems often involve resellers, downstream providers, SDK operators, and shared infrastructure. A provider label identifies infrastructure associated with the traffic but should not be treated as attribution of a specific end user without additional evidence and investigation.What information does Spur provide about an IP address?FAQDepending on the product and integration, Spur may provide intelligence related to:How is Spur different from traditional IP reputation feeds?FAQTraditional reputation feeds focus primarily on known malicious activity. Spur focuses on understanding the infrastructure, routing, anonymization technologies, and contextual characteristics behind an IP address, enabling organizations to make more informed decisions even when no prior abuse history exists.Can Spur enrich large volumes of IP addresses?FAQYes. Organizations commonly use the Spur Context API and data feeds to enrich IP addresses at scale, enabling proxy detection, VPN identification, infrastructure classification, and geolocation analysis across large datasets.What use cases are most common?FAQCommon use cases for Spur intelligence include:What types of organizations use Spur?FAQSpur is used by security and threat hunting teams, fraud prevention teams, and trust and safety organizations in cybersecurity vendors, software companies, financial services companies, e-commerce platforms, law enforcement agencies, and organizations that need deeper insight into IP-based activity.What products does Spur offer?FAQSpur delivers IP intelligence as bulk daily downloads, through API integration into existing security pipelines, and via real-time session enrichment.What does Spur do?FAQSpur provides IP intelligence that helps organizations identify anonymization technologies to make more informed security, fraud prevention, and trust decisions.

Showing 121 of 21