| Source | Used for | Licence or terms |
|---|---|---|
| Certificate transparency logs (via SSLMate certspotter) | New certificates and hostnames, every 15 minutes | Logs are public by design; certspotter is MPL-2.0, run unmodified |
| crt.sh | Nightly CT backstop sweep | Public service operated by Sectigo |
| RDAP (IANA bootstrap registries) | Registrar, expiry, EPP lock status | Public registry data |
| Google Public DNS and Cloudflare DNS-over-HTTPS | DNSSEC validation, NSEC walking | Free public resolvers |
| NVD CVE API 2.0 (NIST National Vulnerability Database) | CVE version ranges, CVSS scores, CWE identifiers | US government work, public domain (see notice below) |
| retire.js vulnerability repository | Vulnerable front-end JavaScript library versions | Apache License 2.0 |
| CISA Known Exploited Vulnerabilities catalog | Exploited-in-the-wild prioritisation | US government work, public domain |
| FIRST EPSS | Probability of exploitation | Free to use with credit to FIRST (see notice below) |
| endoflife.date | Vendor end-of-life dates | MIT licence |
| iptoasn.com | IP to ASN and network owner | Public Domain Dedication and License (PDDL) |
| Cloud and CDN published IP ranges | Provider attribution: AWS, Google Cloud (cloud.json and goog.json), Azure Service Tags, Cloudflare, Fastly, Oracle Cloud, DigitalOcean geofeed, GitHub Pages (meta API) | Published by each provider for customers to use |
| Internet Archive Wayback Machine CDX API | Historical hostnames for discovery | Public API, used within its rate limits |
| Common Crawl index | Historical hostnames for discovery | Common Crawl terms of use |
| abuse.ch Feodo Tracker | Botnet C2 IPs (reputation) | CC0; always on |
| abuse.ch URLhaus and ThreatFox | Malware hosts and indicators (reputation) | Additional abuse.ch feeds, used when enabled with an abuse.ch Auth-Key under abuse.ch's terms |
What is sent where
- Bulk feeds (NVD, retire.js, KEV, EPSS, EOL dates, IP ranges, ASN data, abuse.ch feeds) are downloaded nightly and matched on our side. Your hostnames never leave our infrastructure for these.
- RDAP, DNS-over-HTTPS, crt.sh, the Wayback Machine and Common Crawl are queried per registrable domain, as any member of the public can query them.
Deliberately not used
Sources whose licence forbids commercial use without a paid agreement are not used: Spamhaus blocklists, the Google Safe Browsing API and the OpenPhish community feed. We do not use paid internet-scan datasets either: every check against your hosts is run by us, against hosts you have verified.
Attribution notices
This product uses the NVD API but is not endorsed or certified by the NVD.
EPSS scores are provided by FIRST, the Forum of Incident Response and Security Teams (https://www.first.org/epss).