ip/Compass™

IP Address Categorization, Reputation, and Threat Intelligence

What Is ip/Compass™?

ip/Compass™ delivers real-time categorization, threat scoring, and geolocation data for IPv4 and IPv6 addresses—enabling OEM partners to inspect, filter, and analyze network traffic even when URLs aren’t available.

Built for a world of encrypted traffic and increasing reliance on DNS, ip/Compass empowers OEMs to identify, evaluate, and respond to IP-based threats with unmatched coverage and speed.

Illustration of IP address intelligence showing geolocation, reputation, and network context for threat analysis.

ip/Compass provides security-focused intelligence on millions of IPs, including:

  • IP Reputation Score – Safety level calculated from hosted domain history, threat involvement, and behavioral risk
  • Domain Association – List of domains hosted on the IP
  • Category Data – Content category for each associated domain (from inCompass™)
  • Geolocation – Country, region, ASN, and network ownership
  • Threat Indicators – Links to malware, phishing, botnets, proxies, and other risk flags

This intelligence enables effective decision-making for filtering, access control, routing, and analytics.

  • Continuous monitoring of IPv4/IPv6 activity
  • Identification of suspicious hosting behavior
  • Pairing with inCompass™ to correlate IPs and domains with security and content categories
FeatureBenefit
Deployment OptionsSDK (Local), Cloud API, or Hybrid Model
Query ResponseDomain list, categories, reputation score, geolocation, threats
PerformancesOptimized for large-scale DNS traffic and security filtering
Integration SupportTelcos, SWG, DNS resolvers, security appliances, and analytics platforms
CustomizationMetadata field control, format customization, and region-specific tuning
  • DNS filtering and enforcement
  • Encrypted traffic visibility (VPN analysis)
  • Threat detection and IP reputation analysis
  • Policy enforcement based on hosting provider risk
  • Telco and ISP subscriber analytics and traffic classification
  • SIEM and SOAR enrichment

Global Coverage and Real-Time Accuracy

48B+

Visibility into 48B+ domains and URLs

1.8B+

Tied to NetSTAR’s 1.8B+ endpoint telemetry network

24/7

Updated continuously via SDK and API

275+

Trusted by 275+ OEM partners across security, networking, and telecom sectors

  1. Query: Partner submits IP address (IPv4 or IPv6)
  2. Lookup: ip/Compass checks against global database of IPs and hosted domains
  3. Analyze: Categorization and risk scoring calculated based on behavior and threat signals
  4. Respond: Results returned with hosted domains, categories, IP reputation, geolocation, and threats

ip/Compass™ provides real-time IP categorization, reputation scoring, domain association, and threat intelligence to help OEMs manage encrypted or DNS-layer traffic.

NetSTAR calculates IP reputation based on hosted domain history, threat detection signals, geolocation behavior, and telemetry from 1.8B+ endpoints.

Yes—by evaluating IP behavior and domain associations, ip/Compass helps partners detect threats even when URL visibility is limited (e.g., TLS or VPN scenarios).

Responses include domain list, categories, threat indicators, reputation score, geolocation (country/ASN), and related risk signals.

It can be integrated via Cloud API, local SDK, or a hybrid model. Partners choose based on performance, privacy, and architecture requirements.