Where does enforcement actually happen?
In most setups, enforcement happens in your own infrastructure, such as backend logic, API gateways, or middleware. For Cloudflare integrations, enforcement can happen at the edge and is directly configurable via the Monocle UI.
Similar questions
If Spur identifies a provider such as NetNut, does that mean the traffic originated directly from that provider's customer?
Not necessarily. Proxy ecosystems often involve resellers, downstream providers, SDK operators, and shared infrastructure. A provider label identifies infrastructure associated with the traffic but should not be treated as attribution of a specific end user without additional evidence and investigation.
Do you have a confidence score or last seen date?
Spur operates on a "high confidence" only model to reduce the likelihood of false positives ever making it into our data. Our mentality is that our customers should trust us to decide if something is true rather than providing an arbitrary score to constantly adjust higher or lower. Every API request or Monocle session provides the latest true information for that moment in time. On-prem solutions are updated at their purchased cadence (daily or real-time). We actively purge any result that is no longer true and maintain smart age-offs to maintain the most accurate snapshot of data each day.
What products does Spur offer?
Spur delivers IP intelligence as bulk daily downloads, through API integration into existing security pipelines, and via real-time session enrichment.
How can I download data on all IPv4 and IPv6 addresses?
IP location, routing, and ownership information is produced at the network level and presented into netblocks. Other data such as client fields or service attributions are produced on an individual IP address basis. For our API customer this coverage is automatically merged to produce full IPv4 and IPv6 coverage. For on-prem services, a combination of these two granularities must be used to cover all IP space.
Can Spur enrich large volumes of IP addresses?
Yes. Organizations commonly use the Spur Context API and data feeds to enrich IP addresses at scale, enabling proxy detection, VPN identification, infrastructure classification, and geolocation analysis across large datasets.