Pricing
Plans & Pricing
From free IP lookups to enterprise-grade threat feeds. Pick the plan that fits your security operations.
Free
€0forever
Get started with basic IP lookups. Perfect for individual researchers and side projects.
- Single IP lookup (basic verdict)
- 10 requests/minute
- 100 requests/day
- Verdict + confidence + category
Starter
€99/month
Full intelligence for small teams. Risk scores, evidence, and campaign context.
- Full IP lookup with risk score
- 120 requests/minute
- 10,000 requests/day
- 10,000 monthly quota
- Risk score + classification
- Evidence + MITRE mapping
- IP history (365 days)
- Campaign context
- Reputation export
- Email support
Most popular
Pro
€399/month
Advanced feeds and batch operations for security teams and SIEMs.
- Everything in Starter
- 1,200 requests/minute
- 200,000 requests/day
- 100,000 monthly quota
- Batch IP lookup (100 IPs)
- IOC feed with cursor pagination
- Network intel (CIDR/ASN)
- Email support
Active Defense
€999/month
Full access for SOCs and MSSPs. Malicious feed, priority support, high throughput.
- Everything in Pro
- 3,000 requests/minute
- 500,000 requests/day
- 250,000 monthly quota
- Malicious IP feed
- Priority support
Enterprise
Custom
Unlimited access, custom SLAs, and dedicated support for large organizations.
- Everything in Active Defense
- 10,000 requests/minute
- Unlimited daily requests
- Unlimited monthly quota
- Custom SLA
- Dedicated support
Compare
Full feature comparison
| Feature | Free | Starter | Pro | Active Defense | Enterprise |
|---|---|---|---|---|---|
| Single IP lookup | Basic | Full | Full | Full | Full |
| Batch IP (100) | — | — | |||
| Rate limit/min | 10 | 120 | 1,200 | 3,000 | 10,000 |
| Daily limit | 100 | 10,000 | 200,000 | 500,000 | Unlimited |
| Monthly quota | — | 10,000 | 100,000 | 250,000 | Unlimited |
| Risk score + classification | — | ||||
| Evidence + MITRE | — | ||||
| Reputation export | — | ||||
| IOC feed | — | — | |||
| IP history (365d) | — | ||||
| Campaign context | — | ||||
| Network intel (CIDR/ASN) | — | — | |||
| Malicious feed | — | — | — | ||
| Email support | — | ||||
| Priority support | — | — | — | ||
| Custom SLA | — | — | — | — |
FAQ
Frequently asked questions
Sentrion is based entirely on first-party telemetry from our own honeypot sensors. We don’t aggregate third-party feeds — every verdict comes from direct observation of hostile activity against our global sensor network.
Our pipeline processes events from 22 sensors in near real-time. A new attacking IP is typically classified and available via the API within minutes of first contact.
Yes! The Free tier gives you 100 lookups per day with basic verdicts. No credit card required — just create an account and generate an API key.
We support JSON (structured with metadata), CSV (with header row), and plaintext (one IP per line). All formats are suitable for direct import into firewalls and SIEMs.
Our REST API works with any SIEM that supports HTTP enrichment. We provide code examples for Splunk, Microsoft Sentinel, and Elastic. Custom integrations available on Enterprise plans.
Plans are billed monthly via Mollie (credit card, iDEAL, SEPA). You can upgrade, downgrade, or cancel at any time. Enterprise plans are invoiced annually.