Network intelligence

Know what is behindevery connection.

Turn an IP address into explainable network evidence: geography, ASN, hosting context and probabilities for VPN, proxy, residential proxy, TOR, datacenter and anonymizer use.

Live evidence
Review

Current analysis

Connection

ASN84%
Proxy62%
Location91%
RiskASNProxyLocationEvidence
Evidence attached

6

network risk classes

CIDR

curated threat datasets

Every

probability carries evidence

Built for the full investigation

Useful to engineering. Clear to fraud operations.

The same evidence powers API decisions and investigator views, so policy changes stay connected to the behavior behind them.

01

Evidence, not flags

Inspect why a connection was classified: known ASN, dataset match, PTR evidence or location contradiction.

02

Location consistency

Compare server-observed IP geography with browser timezone and locale without trusting client-supplied IP data.

03

Shared-network awareness

Use subnet, ASN, rarity and account history to separate a normal campus or office from coordinated abuse.

04

Bring your own intelligence

Import TOR exits, abuse feeds and commercial proxy CIDRs into the same classification pipeline.

The operating flow

Move from signal to action without losing the explanation.

1

Observe the connection

The API uses the request IP from the trusted server boundary; backend-only checks may explicitly send an IP.

2

Enrich and classify

Local datasets, ASN context, geography and heuristics produce probabilities with confidence and evidence.

3

Connect it to identity

IP, subnet and ASN edges become part of the temporal graph and risk history for each account.

Start with one protected workflow

Make network risk understandable at a glance.

Investigators see the source evidence. Engineers receive stable, typed signals. Rules can act on both.

Get started