Contributors get it free.
Consumers fund the core.
The anonymous tier is designed to be shareable on Twitter — enough data for a threat intel pro to validate a finding without having to sign up. Upgrade is only necessary when you need to pivot, attribute, or automate.
Genuinely useful — paste an IP, get a verdict with confidence and tags. Enough to validate a finding or answer a question. Not enough to automate.
After 48h of valid telemetry, your key is promoted. Full fingerprints, per-sensor sightings, 90-day history, daily feeds. The fastest path to Pro-tier data.
Firewall / SIEM integrations, webhooks, hourly feeds, 2-year history. Funds the Verified Core fleet so the data you consume stays trustworthy.
Unlimited queries, streaming feeds, full history, dedicated support. For MSSPs and SOCs running at nation-state-grade volume.
The full capability matrix.
Exact enforcement — these values drive the rate limiter and field redactor in real time, so marketing and the API can't drift.
| Capability | Anonymous | Participant | Commercial Pro | Enterprise |
|---|---|---|---|---|
| Rate limit | 100 / day | 1,000 / hour | 100,000 / hour | Unlimited |
| History window | 7 days | 90 days | 2 years | Full |
| Data freshness | 1h delay | Real-time | Real-time | Real-time |
| Single IP lookup | ✓ | ✓ | ✓ | ✓ |
| Verdict + confidence | ✓ | ✓ | ✓ | ✓ |
| High-level tags | ✓ | ✓ | ✓ | ✓ |
| Sensor sighting totals | ✓ | ✓ | ✓ | ✓ |
| JA3 / JA4 / SSH fingerprints | — | ✓ | ✓ | ✓ |
| Per-sensor sighting list | — | ✓ | ✓ | ✓ |
| Commands & payloads | — | ✓ | ✓ | ✓ |
| Bulk lookup / CSV | — | Capped | ✓ | ✓ |
| STIX / MISP feeds | — | Daily | Hourly | Streaming |
| Webhooks & push | — | — | ✓ | ✓ |
| SIEM / firewall integrations | — | — | ✓ | ✓ |
Limits are enforced by middleware and announced in response headers. The same limiter drives X-RateLimit-* on every call.