SourceUsed forLicence or terms
Certificate transparency logs (via SSLMate certspotter)New certificates and hostnames, every 15 minutesLogs are public by design; certspotter is MPL-2.0, run unmodified
crt.shNightly CT backstop sweepPublic service operated by Sectigo
RDAP (IANA bootstrap registries)Registrar, expiry, EPP lock statusPublic registry data
Google Public DNS and Cloudflare DNS-over-HTTPSDNSSEC validation, NSEC walkingFree public resolvers
NVD CVE API 2.0 (NIST National Vulnerability Database)CVE version ranges, CVSS scores, CWE identifiersUS government work, public domain (see notice below)
retire.js vulnerability repositoryVulnerable front-end JavaScript library versionsApache License 2.0
CISA Known Exploited Vulnerabilities catalogExploited-in-the-wild prioritisationUS government work, public domain
FIRST EPSSProbability of exploitationFree to use with credit to FIRST (see notice below)
endoflife.dateVendor end-of-life datesMIT licence
iptoasn.comIP to ASN and network ownerPublic Domain Dedication and License (PDDL)
Cloud and CDN published IP rangesProvider attribution: AWS, Google Cloud (cloud.json and goog.json), Azure Service Tags, Cloudflare, Fastly, Oracle Cloud, DigitalOcean geofeed, GitHub Pages (meta API)Published by each provider for customers to use
Internet Archive Wayback Machine CDX APIHistorical hostnames for discoveryPublic API, used within its rate limits
Common Crawl indexHistorical hostnames for discoveryCommon Crawl terms of use
abuse.ch Feodo TrackerBotnet C2 IPs (reputation)CC0; always on
abuse.ch URLhaus and ThreatFoxMalware hosts and indicators (reputation)Additional abuse.ch feeds, used when enabled with an abuse.ch Auth-Key under abuse.ch's terms

What is sent where

  • Bulk feeds (NVD, retire.js, KEV, EPSS, EOL dates, IP ranges, ASN data, abuse.ch feeds) are downloaded nightly and matched on our side. Your hostnames never leave our infrastructure for these.
  • RDAP, DNS-over-HTTPS, crt.sh, the Wayback Machine and Common Crawl are queried per registrable domain, as any member of the public can query them.

Deliberately not used

Sources whose licence forbids commercial use without a paid agreement are not used: Spamhaus blocklists, the Google Safe Browsing API and the OpenPhish community feed. We do not use paid internet-scan datasets either: every check against your hosts is run by us, against hosts you have verified.

Attribution notices

This product uses the NVD API but is not endorsed or certified by the NVD.

EPSS scores are provided by FIRST, the Forum of Incident Response and Security Teams (https://www.first.org/epss).