Privacy Policy

Speculus LLC(“Speculus,” “we,” “us,” or “our”) is a network threat intelligence company. This policy describes how we collect, use, and share information through the speculus.co website, through accounts on our platform, through our sales and support channels, and through our products and data services (together, our “Offerings”).

1. Information We Collect

Account information. When you create an account we collect your business email address, your password (stored only in hashed form), and the multi-factor authentication factors you enrol. We require a corporate email address at signup. We also record account activity such as signup, verification, sign-in, and password reset, together with the IP address and browser details associated with them, for security and abuse prevention.

Contact and sales information. If you submit our contact form or correspond with us about a trial, a quote, or support, we collect your name, email address, company name, and the contents of your message, and we retain that correspondence.

Billing information. Payments are handled by a third-party PCI-compliant payment processor. Speculus does not receive or store your full card number. We receive only what we need to operate the account, such as plan, billing status, the last four digits and brand of the payment instrument, and the billing contact and country.

Product usage and query logs.When you use our lookup interface, our API, or our integrations, we log the queries you make, including the indicators you submit, the account and credential used, and the timestamp, volume, and status of each request. We keep these logs to meter usage for billing, enforce rate limits, detect credential abuse, and support you. Your query history is associated with your account. We treat it as confidential customer data: we do not sell it, publish it, or use one customer’s queries to inform another customer’s results.

Website and device information. As with most websites, our servers and infrastructure providers automatically receive your IP address, browser type and version, operating system, referring page, and the pages you request. We use this to serve the site, maintain security, and distinguish human visitors from automated traffic.

2. Why We Use This Information

We use the information above to provide and operate our Offerings, authenticate you and secure your account, process payments and administer subscriptions, meter and bill usage, provide support, prevent fraud and abuse of our platform, maintain and improve our products, send service and administrative messages, send marketing communications where permitted and where you have not opted out, comply with our legal obligations, and establish or defend legal claims.

3. Our Network Intelligence Data

Our Offerings are built on a dataset describing internet infrastructure: IP addresses and ranges, network and ISP attribution, approximate geolocation, infrastructure classification, and indicators of malicious or automated activity associated with an address. Some privacy laws treat an IP address as personal information, so we describe it here.

This data comes from three categories of source: telemetry from internet-facing systems that Speculus owns and operates, which records connection metadata from hosts that contact those systems without invitation; network and reputation data we license from commercial providers and partners; and publicly available sources, including internet registry records, routing data, and open threat intelligence feeds.

Where licensed data includes information that may be considered personal information, it was collected by those providers under their own notices and terms. Speculus generally has no direct relationship with the individuals or organizations to which an address may relate.

We do not attempt to identify by name the individual behind an IP address. We do not combine this data with consumer identity graphs, advertising identifiers, or marketing lists. We do not use it to contact or market to the operators or users of the addresses it describes, and we do not license it to others for that purpose. It is built and licensed for information security, fraud prevention, and network defense.

If you believe an address or range you operate is misclassified, or you want to know what our data records about infrastructure you control, contact us at [email protected]. We will need enough information to verify that you are responsible for the address. We review disputes and correct records we determine to be inaccurate.

4. How We Share Information

We do not sell, trade, or rent the personal information we collect from our website, from your account, or from your communications with us. We disclose it only as follows.

Service providers. We use vendors to operate our business and our platform, and they process information on our behalf under contract and only for the purposes we specify. They fall into these categories: cloud hosting and content delivery; authentication and database services; payment processing; email and communications; security, bot detection, and fraud prevention; and business and analytics tooling.

Professional advisers. We provide information about our business to our auditors, accountants, and legal counsel, who may use it only to provide their professional services.

Legal and safety. We may disclose information where required by law, such as in response to a subpoena, court order, or similar legal process, or where we believe disclosure is necessary to protect our rights, protect the safety of any person, investigate fraud or abuse, or respond to a lawful government request.

Business transfers. If we are involved in a merger, acquisition, financing, or sale of all or part of our business or assets, information we hold may be transferred as part of that transaction.

Our Offerings. We license the network intelligence data described in Section 3 to our customers. That is our product. It does not contain the account, billing, contact, or query log information we collect about you.

5. Cookies and Tracking

We use cookies and similar technologies that are strictly necessary for the website and platform to function, including session and authentication cookies and those used to distinguish human visitors from automated traffic. These cannot be disabled without breaking the service.

We do not currently use analytics, advertising, or cross-site tracking technologies. If we add them, we will update this policy before they go live and, where consent is required by law, ask for it before setting non-essential cookies.

Do Not Track and opt-out signals. Because we do not track visitors across third-party websites, we do not currently respond to Do Not Track browser signals. If we later use technologies that constitute sharing for cross-context behavioral advertising, we will honor the Global Privacy Control and comparable opt-out preference signals.

6. Data Retention

We keep information for as long as needed for the purpose we collected it, and for a reasonable period afterwards to meet audit, contractual, tax, and legal requirements or to establish and defend legal claims. Account records are retained for the life of the account and for a period after closure. Query logs are retained for 24 months, after which they are deleted or reduced to aggregate counts. Billing records are retained for the period required by tax and accounting law. Our network intelligence data is retained on an ongoing basis, because its value lies in the historical record of how infrastructure has behaved over time. We may retain aggregated or de-identified data indefinitely.

7. Security

We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction, including encryption in transit, access controls, and multi-factor authentication. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe you have found a vulnerability in our systems, please report it to [email protected].

8. Your California Privacy Rights

If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you the rights described below. In the preceding twelve months we collected the following categories of personal information:

CategoryExamplesSource
IdentifiersName, business email, company, IP address, account IDYou, your device, our systems, licensed providers
Commercial informationPlan, billing status, purchase historyYou, our payment processor
Internet activityPages requested, API queries, browser and device detailsYour device, our platform
GeolocationApproximate location inferred from IP addressYour device, licensed providers
Account credentialsHashed password, MFA factorsYou
InferencesInfrastructure classification and risk scoring for an addressOur analysis of the above

We collect these categories for the purposes described in Sections 2 and 3, and disclose them to the categories of recipients listed in Section 4. We do not collect or process sensitive personal information as defined by the CCPA, and we do not knowingly collect personal information from minors.

Selling and sharing. We do not sell, or share for cross-context behavioral advertising, the personal information we collect from our website, your account, or your communications with us. We do license the network intelligence data described in Section 3, which contains IP addresses and may therefore be treated as a sale of personal information under California law. That data is licensed for security and fraud prevention purposes only, and never for advertising or marketing to the individuals it may relate to.

Your rights. Subject to verification, you may request to know the categories and specific pieces of personal information we hold about you, request deletion, request correction of inaccurate information, and opt out of the sale or sharing of your personal information. You have the right not to receive discriminatory treatment for exercising these rights, and you may use an authorised agent to submit a request on your behalf.

To make a request, email [email protected]with the subject line “California Privacy Request.” We will verify your identity before acting on it and will respond within the timeframes required by law.

9. Other US State Privacy Rights

Residents of other US states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana, have comparable rights to access, correct, delete, and obtain a portable copy of their personal information, and to opt out of targeted advertising, sale, and certain profiling. Use the same address above to exercise them. Where your state provides a right to appeal our decision on a request, you may appeal by replying to our response, and we will inform you of the outcome in writing.

10. Visitors from the EEA and the United Kingdom

Speculus is based in the United States and our Offerings are directed at business customers. If you are in the European Economic Area or the United Kingdom, our legal basis for processing depends on the information concerned. We process account, billing, and support information because it is necessary to perform our contract with you. We process security telemetry, query logs, and our network intelligence data on the basis of our legitimate interests and those of our customers in preventing fraud and securing networks. We process marketing information on the basis of consent where consent is required. You may object to processing carried out on the basis of legitimate interests, request access, rectification, erasure, restriction, or portability, withdraw consent where we rely on it, and lodge a complaint with your local supervisory authority.

11. International Transfers

We are based in the United States and our service providers operate globally. Information you submit may be transferred to, stored in, and processed in the United States and other countries whose data protection laws differ from those of your own. Where we transfer personal information out of the EEA or the United Kingdom we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and the UK Addendum.

12. Children

Our website and Offerings are directed at businesses and are not intended for anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

13. Changes to This Policy

We may update this policy to reflect changes in our practices or in the law. If the changes are material we will notify account holders by email or by a notice on this website before they take effect.

14. Contact Us

Questions about this policy, or about how we handle information, should go to [email protected].

Speculus LLC