What is Monocle?
Monocle is a traffic intelligence tool that identifies anonymized traffic such as VPNs, proxies, and datacenter connections, and provides insights into how users are connecting to your application.
Similar questions
If Spur identifies a provider such as NetNut, does that mean the traffic originated directly from that provider's customer?
Not necessarily. Proxy ecosystems often involve resellers, downstream providers, SDK operators, and shared infrastructure. A provider label identifies infrastructure associated with the traffic but should not be treated as attribution of a specific end user without additional evidence and investigation.
Do you have a confidence score or last seen date?
Spur operates on a "high confidence" only model to reduce the likelihood of false positives ever making it into our data. Our mentality is that our customers should trust us to decide if something is true rather than providing an arbitrary score to constantly adjust higher or lower. Every API request or Monocle session provides the latest true information for that moment in time. On-prem solutions are updated at their purchased cadence (daily or real-time). We actively purge any result that is no longer true and maintain smart age-offs to maintain the most accurate snapshot of data each day.
What does Spur do?
Spur provides IP intelligence that helps organizations identify anonymization technologies to make more informed security, fraud prevention, and trust decisions.
How fast does Spur detect a VPN or Proxy?
New VPNs or proxies are typically identified within 24-48 hours depending on where it is hosted and how it is being used. Monocle will detect all new VPNs and proxies on first use. All new identifications are available immediately in our API products. On-prem solutions will be update on their next update cadence or in real-time if that option has been added.
How can Spur IP intelligence improve authentication security?
Infrastructure-aware signals from Spur can strengthen adaptive authentication and risk-scoring systems by identifying login attempts originating from VPNs, residential proxies, hosting providers, or other anonymized environments commonly associated with credential abuse.