Why might a feed result differ from an API lookup for the same IP?
Data feeds are point-in-time snapshots, while the API can return more current, near-real-time data. A timestamp gap between feed generation and your API query is the most common cause of a difference.
Similar questions
What products does Spur offer?
Spur delivers IP intelligence as bulk daily downloads, through API integration into existing security pipelines, and via real-time session enrichment.
Do you have a confidence score or last seen date?
Spur operates on a "high confidence" only model to reduce the likelihood of false positives ever making it into our data. Our mentality is that our customers should trust us to decide if something is true rather than providing an arbitrary score to constantly adjust higher or lower. Every API request or Monocle session provides the latest true information for that moment in time. On-prem solutions are updated at their purchased cadence (daily or real-time). We actively purge any result that is no longer true and maintain smart age-offs to maintain the most accurate snapshot of data each day.
How frequently is Spur data updated?
The Context API reflects new intelligence in real time as it becomes available. Data feeds are updated daily, and organizations can also consume updates in real-time through streaming or feed-based workflows depending on operational requirements.
Can Spur enrich large volumes of IP addresses?
Yes. Organizations commonly use the Spur Context API and data feeds to enrich IP addresses at scale, enabling proxy detection, VPN identification, infrastructure classification, and geolocation analysis across large datasets.
Does Spur offer downloadable feeds, local deployments, or MMDB-style delivery?
Available delivery methods may vary by product and customer requirements. Organizations with low-latency or high-volume enrichment needs should contact Spur to discuss available deployment and data-delivery options.