What is the difference between using Monocle to monitor vs. enforce traffic decisions?
Monitor is passive: Monocle provides visibility into how users connect to your application without impacting users or taking any blocking action. Enforce applies actions such as blocking or allowing traffic based on Monocle's assessments. Most users start with a monitoring phase before configuring and enabling enforcement.
Similar questions
Do you have a confidence score or last seen date?
Spur operates on a "high confidence" only model to reduce the likelihood of false positives ever making it into our data. Our mentality is that our customers should trust us to decide if something is true rather than providing an arbitrary score to constantly adjust higher or lower. Every API request or Monocle session provides the latest true information for that moment in time. On-prem solutions are updated at their purchased cadence (daily or real-time). We actively purge any result that is no longer true and maintain smart age-offs to maintain the most accurate snapshot of data each day.
If Spur identifies a provider such as NetNut, does that mean the traffic originated directly from that provider's customer?
Not necessarily. Proxy ecosystems often involve resellers, downstream providers, SDK operators, and shared infrastructure. A provider label identifies infrastructure associated with the traffic but should not be treated as attribution of a specific end user without additional evidence and investigation.
What is the difference between online subscriptions and enterprise tiers?
Our enterprise tiers are specifically designed to provide other businesses with package offerings, robust SLAs, custom volumes, support, commercial licensing, and onboarding. Online subscriptions are designed for smaller teams with lower volume and support needs.
Should Spur data be used as a blocking list?
Generally, no. Spur is designed to provide context and intelligence rather than a simple allow/block decision. Most organizations achieve the best results when Spur data is incorporated into broader risk models and decisioning workflows.
How is Spur different from traditional IP reputation feeds?
Traditional reputation feeds focus primarily on known malicious activity. Spur focuses on understanding the infrastructure, routing, anonymization technologies, and contextual characteristics behind an IP address, enabling organizations to make more informed decisions even when no prior abuse history exists.