Methodology

Data sources

Every IP result combines multiple free, attributed databases. Disagreements are shown, not hidden.

Update cadence

Local databases are refreshed approximately weekly (matching upstream release cadence). Query results are cached at the edge for up to 7 days.

Scoring — signals, not a verdict

We do not publish a definitive "safe / unsafe" label. The purity number, when shown, is a provisional, versioned signal derived from weighted inputs (connection type, proxy/VPN consensus, abuse reports, human/bot ratio, source agreement). It is gated behind a flag and only enabled once a calibration set exists (see docs/runbooks/score-calibration.md). Confidence reflects coverage and source agreement.

Corrections

If a result looks wrong, compare it against the sources shown for that IP. Every page lists which source produced which field and when. Disagreement is expected for mobile, anycast, VPN and corporate-egress addresses — trust the ASN and operator more than the city pin.