Three ways to deploy
Speculus

API, managed integration, or on-prem database. Speculus is built for you.

01

The Speculus API

Direct, programmatic access to the NIO enrichment engine. A single REST call turns any IP address into a full intelligence object: threat score, geolocation, ASN, proxy flags, and a plain-English verdict. Built for developers who want to embed network intelligence directly into their stack.

  • IP enrichment in under 50ms
  • Threat scoring from 0–100 with plain-English verdict
  • Geolocation, ASN, carrier & proxy detection
  • REST Endpoints
  • 99.9% uptime SLA with enterprise rate limits
02

The Integration Package

Everything in the API, plus a fully managed deployment into your existing security stack. We connect NIO enrichment directly into Splunk, Elastic, Microsoft Sentinel, Palo Alto, or any SIEM/SOAR your team already operates. Includes custom dashboards, alert workflows, and ongoing support.

  • All API capabilities included
  • Native connectors for Splunk, Elastic, Sentinel & more
  • Custom threat dashboards and alert rule configuration
  • Dedicated onboarding and integration engineering
  • Quarterly threat intelligence briefings
03

MMDB Database

The full Speculus threat intelligence dataset in MaxMind Database format, delivered directly to your infrastructure for offline, zero-latency lookups. No API calls, no round-trips, no external dependencies. Ideal for high-throughput environments where every millisecond counts.

  • Offline lookups with sub-millisecond query time
  • Compatible with any MaxMind-compatible reader
  • Twice-daily threat feed updates delivered to your endpoint
  • Full NIO scoring, geolocation, ASN & proxy data on-prem
  • Air-gapped and sovereign cloud deployments supported

Frequently asked questions

How the API, Integration Package, and MMDB compare, and what each deployment returns.

What is the difference between the Speculus API, the Integration Package, and MMDB?

The API gives you direct, programmatic access over REST to every data point in the Speculus database. The Integration Package is everything in the API plus a fully managed deployment into your existing security stack, with native connectors for Splunk, Elastic, Microsoft Sentinel, and Palo Alto. MMDB delivers the full dataset in MaxMind Database format to your own infrastructure for offline lookups.

Can I run Speculus without sending data to an external API?

Yes. The MMDB option delivers the complete Speculus dataset to your infrastructure for offline, zero-latency lookups with no external dependencies. It supports air-gapped and sovereign cloud deployments, so no query data leaves your environment.

How often is the MMDB threat data updated?

The MMDB feed is refreshed twice a day and delivered directly to your endpoint, so your offline lookups stay current without any manual updates.