Pricing

Plans & Pricing

From free IP lookups to enterprise-grade threat feeds. Pick the plan that fits your security operations.

Free

€0forever

Get started with basic IP lookups. Perfect for individual researchers and side projects.

  • Single IP lookup (basic verdict)
  • 10 requests/minute
  • 100 requests/day
  • Verdict + confidence + category

Starter

€99/month

Full intelligence for small teams. Risk scores, evidence, and campaign context.

  • Full IP lookup with risk score
  • 120 requests/minute
  • 10,000 requests/day
  • 10,000 monthly quota
  • Risk score + classification
  • Evidence + MITRE mapping
  • IP history (365 days)
  • Campaign context
  • Reputation export
  • Email support
Most popular

Pro

€399/month

Advanced feeds and batch operations for security teams and SIEMs.

  • Everything in Starter
  • 1,200 requests/minute
  • 200,000 requests/day
  • 100,000 monthly quota
  • Batch IP lookup (100 IPs)
  • IOC feed with cursor pagination
  • Network intel (CIDR/ASN)
  • Email support

Active Defense

€999/month

Full access for SOCs and MSSPs. Malicious feed, priority support, high throughput.

  • Everything in Pro
  • 3,000 requests/minute
  • 500,000 requests/day
  • 250,000 monthly quota
  • Malicious IP feed
  • Priority support

Enterprise

Custom

Unlimited access, custom SLAs, and dedicated support for large organizations.

  • Everything in Active Defense
  • 10,000 requests/minute
  • Unlimited daily requests
  • Unlimited monthly quota
  • Custom SLA
  • Dedicated support

Compare

Full feature comparison

FeatureFreeStarterProActive DefenseEnterprise
Single IP lookupBasicFullFullFullFull
Batch IP (100)
Rate limit/min101201,2003,00010,000
Daily limit10010,000200,000500,000Unlimited
Monthly quota10,000100,000250,000Unlimited
Risk score + classification
Evidence + MITRE
Reputation export
IOC feed
IP history (365d)
Campaign context
Network intel (CIDR/ASN)
Malicious feed
Email support
Priority support
Custom SLA

FAQ

Frequently asked questions

Sentrion is based entirely on first-party telemetry from our own honeypot sensors. We don’t aggregate third-party feeds — every verdict comes from direct observation of hostile activity against our global sensor network.
Our pipeline processes events from 22 sensors in near real-time. A new attacking IP is typically classified and available via the API within minutes of first contact.
Yes! The Free tier gives you 100 lookups per day with basic verdicts. No credit card required — just create an account and generate an API key.
We support JSON (structured with metadata), CSV (with header row), and plaintext (one IP per line). All formats are suitable for direct import into firewalls and SIEMs.
Our REST API works with any SIEM that supports HTTP enrichment. We provide code examples for Splunk, Microsoft Sentinel, and Elastic. Custom integrations available on Enterprise plans.
Plans are billed monthly via Mollie (credit card, iDEAL, SEPA). You can upgrade, downgrade, or cancel at any time. Enterprise plans are invoiced annually.