MEET FINGERLYA clearer picture of every session.Explore the signals
Network intelligence

Look beyond the IP. See the network behind it.

The address a request arrives from is the one thing a visitor cannot edit in their own browser. Every identification classifies it: VPN, proxy, Tor, hosting network or an ordinary connection, and whether it agrees with where the device says it is.

  • VPNsCommercial VPNs and mobile tunnels.
  • ProxiesDatacenter and residential.
  • TorKnown exit nodes.
  • Location mismatchDevice and address disagree.
Network intelligence

Context about the connection, not assumptions about the person. A VPN is a reason to look, not a verdict. Each network signal arrives with its own confidence and a weight you set, so a tunnelled connection can count for a little on a marketing page and for more at checkout.

  • VPNs, including tunnels over mobile data in native apps
  • Datacenter proxies told apart from residential ones
  • Tor exit nodes, at high confidence
  • Addresses with a history of abuse

Every network signal, weighted by you.

The shipped default weights, per platform. Every one can be changed or set to zero, and a zero still records that the signal fired.

SignalWebAndroidiOSWhat it means
Tor exit node141617The request came from a known Tor exit.
Datacenter proxy141215A proxy running on a hosting network.
Hosting network666A server network with no proxy or VPN label.
Residential proxy666A proxy on a consumer connection, the hardest kind to tell from a real visitor.
IP reputation888The address has a recorded history of abuse.
Commercial VPN455A known VPN endpoint.
VPN over mobile datan/a66The app’s traffic is tunnelled over a cellular connection.
Location mismatch555The device’s own region disagrees with the address’s country.

VPN and residential proxy detections can instead be priced by confidence: 2, 4 or 6 for low, medium and high.

Tor, told apart from a VPN.

A Tor exit node is a different finding from a commercial VPN, and it carries a different default weight: 14 on the web, 16 on Android and 17 on iOS, against a VPN’s 4 or 5. Both run on every request, and the one that finds nothing adds nothing.

On the web a Tor exit alone scores 14, one point under the medium level that begins at half the default threshold of 30. In an app it scores 16 or 17, which is medium. Whether that means a second factor, a review or a refusal is your policy.

  • Reported at high confidence
  • Counted once, however many lists name the address
  • Separate weights for web, Android and iOS

Context beats blanket blocking. A customer on a VPN is not the same as a script on a Tor exit. Your policy should know the difference.

Honest about what it cannot see.

Network intelligence comes from a lookup on every request. The response says when that lookup could not happen, instead of passing a guess off as a clean result.

Unavailable is not clean

If the address cannot be looked up, the response is marked state: unavailable and carries no suspect score at all, rather than a lower one computed from less.

Missing values stay silent

A device that does not report its region, or an address with no known country, never produces a location mismatch.

Shared networks are normal

Offices, campuses and mobile carriers put many real people behind one address. Weight network signals as context and combine them with device signals.

Two ways to price a VPN

Weight each detection method separately, or weight one signal by how sure the detection is. One mode applies at a time, so nothing is counted twice.

Where the network changes the answer.

The same signals read differently at different moments in a product.

  1. 01Account takeover
  2. 02SMS fraud
  3. 03Account sharing
01

Account takeover

A known password from an unfamiliar network.

A login from a Tor exit or a datacenter proxy, on a device the account has never used, is worth a second factor. The same login from a phone on mobile data is not.

Check at
LoginPassword reset
Signals
Tor exit nodeDatacenter proxyVisitor ID
Account takeover
02

SMS fraud

Codes sent to scripts cost money.

Scripts that trigger one-time passcodes usually run from hosting networks. Check the session before the code is sent.

Check at
Sending a one-time code
Signals
Hosting networkHigh activity
SMS fraud
03

Account sharing

One subscription, many countries.

A location mismatch alongside many devices on one subscription is a better reason to offer a family plan than a block.

Check at
LoginStarting playback
Signals
Location mismatchCommercial VPNVisitor ID
Account sharing prevention

About network signals.

How VPN, proxy and Tor detection behaves in production.

Talk to the team
Does a VPN mean a visitor is committing fraud?

No. VPNs are used for privacy, for work and for travel. A VPN is shipped with a small default weight so that on its own it keeps a score low, and it becomes meaningful alongside other signals such as automation or a device farm.

Can I stop scoring VPNs without losing the data?

Yes. Set the weight to zero. The signal is still recorded as a trigger on the event, so you can see that it fired while your policy ignores it.

What happens if the network lookup fails?

The response is marked state: unavailable with a short reason, and it carries no suspect score. Your application can decide whether an unscored request is allowed, reviewed or refused.

Is Apple iCloud Private Relay flagged as a VPN?

Not from the address. Private Relay is a consumer privacy setting, and the current network data carries no dedicated flag for it, so the address alone does not mark a Private Relay visitor as a VPN.

[ IDENTIFY ][ UNDERSTAND ][ DECIDE ][ FINGERLY ]
Less guessing. More knowing.

Make the next connection a trusted one.

Start with the signals, keep your own decisions, and pay only for what you identify. No credit card needed.