Evidence, not flags
Inspect why a connection was classified: known ASN, dataset match, PTR evidence or location contradiction.
Network intelligence
Turn an IP address into explainable network evidence: geography, ASN, hosting context and probabilities for VPN, proxy, residential proxy, TOR, datacenter and anonymizer use.
Current analysis
Connection
6
network risk classes
CIDR
curated threat datasets
Every
probability carries evidence
Built for the full investigation
The same evidence powers API decisions and investigator views, so policy changes stay connected to the behavior behind them.
Inspect why a connection was classified: known ASN, dataset match, PTR evidence or location contradiction.
Compare server-observed IP geography with browser timezone and locale without trusting client-supplied IP data.
Use subnet, ASN, rarity and account history to separate a normal campus or office from coordinated abuse.
Import TOR exits, abuse feeds and commercial proxy CIDRs into the same classification pipeline.
The operating flow
The API uses the request IP from the trusted server boundary; backend-only checks may explicitly send an IP.
Local datasets, ASN context, geography and heuristics produce probabilities with confidence and evidence.
IP, subnet and ASN edges become part of the temporal graph and risk history for each account.
Start with one protected workflow
Investigators see the source evidence. Engineers receive stable, typed signals. Rules can act on both.