Spur provides security teams with real‑world behavioral and network attributes for every IP, turning blind spots in modern security stacks into visible, actionable data. By accurately identifying residential proxies, VPNs, bots and other malicious traffic, it enables CDNs, WAFs, fraud and bot management solutions to apply smarter edge enforcement and reduce false positives. The platform delivers session‑level attribution and geo‑mismatch detection to improve threat intel and user friction decisions.
Funding
$200M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.

Founders
Product
Problem
Security stacks rely on multiple tools that each detect specific threats, but they often lack visibility into traffic originating from VPNs, residential proxies, and other anonymizing services. This creates blind spots that allow attackers to masquerade as legitimate users and bypass defenses.
Solution
Spur Intelligence provides high‑fidelity IP intelligence that continuously maps global anonymization infrastructure. By observing over 230 million unique anonymized IPs every 90 days, Spur identifies more than 60 million suspect IPs daily across 1,000+ VPN and proxy services. The platform enriches each connection with over 20 attributes—including precise geolocation, ASN, device type, tunnel entry/exit context, and proxy/VPN attribution—delivered via real‑time APIs, session‑level enrichment, or on‑prem data feeds. This actionable context enables security, fraud, and threat‑hunting teams to detect hidden threats, correlate attacker activity across logs, and apply targeted controls without increasing user friction. Integrated with SIEM/SOAR, CDNs, and authentication workflows, Spur turns previously invisible network signals into transparent, verifiable intelligence.
Target Audience
Spur’s primary customers are security operations centers, fraud prevention teams, and threat‑hunting groups in enterprises such as fintech, e‑commerce, gaming, and government agencies that need precise IP context to protect against anonymized attacks.
Features
- Continuous observation of global anonymization infrastructure, detecting 230 M+ unique anonymized IPs per quarter
- Coverage of 60 M+ active suspect IPs daily from 1,000+ VPN, residential proxy, and botnet services
- Enrichment with 20+ attributes per IP, including geo‑location, ASN, device type, connection type, and tunnel entry/exit context
- Real‑time API and session‑level enrichment for authentication, fraud detection, and threat hunting
- On‑premise data feeds and bulk exports for large‑scale analysis and compliance workflows
- Native integrations with SIEM/SOAR, CDNs/WAFs, and other security tools for automated policy enforcement
- Alerting and reporting dashboards that surface traffic spikes, network anomalies, and infrastructure‑level threats