Simple and Transparent Plans
Choose the plan that best fits your SOC. Free plan includes whitelist intelligence. Starter adds provider detection and recommendations. Pro unlocks VPN/Tor detection and investigation tools.
Free
Perfect for evaluation and testing
- 500 queries/day
- 10 indicators per request
- 20 requests per minute
- Whitelist intelligence only (180+ sources)
- Basic confidence level (high/medium/low)
- Short risk context labels
- Verified TLD detection
- REST API access
- Community support
Limitations:
- No enrichment data (upgrade to Starter)
- No provider detection or confidence scoring
- No recommendations or risk descriptions
- No VPN/Tor/Proxy detection (Pro+)
- Limited reasons (max 2 per indicator)
Starter
For individual analysts and freelancers
- 5,000 queries/day
- 10 indicators per request
- 60 requests per minute
- Whitelist + Enrichment data (full 180+ sources)
- Provider Detection (50+ providers: CDN, Cloud, AI)
- Actionable Verdicts (likely_benign, investigate, malicious)
- Full confidence scoring (0-100)
- Recommendations (action + false positive likelihood)
- Detailed risk descriptions
- Usage analytics dashboard
- Email support
Pro
💰 Best value
For small SOCs and security teams
- 25,000 queries/day
- 50 indicators per request
- 120 requests per minute
- All Starter features
- VPN/Tor/Proxy detection flags
- Investigation hints (analyst guidance)
- Forensic details (rationale, matching CIDRs)
- Email support
Team
💰 Most popular
For medium SOCs and growing teams
- 100,000 queries/day
- 100 indicators per request
- 300 requests per minute
- All Pro features
- Priority email support
- Extended rate limits
- Team collaboration features
Enterprise
💰 Contact us for pricing
For large SOCs and custom requirements
- Unlimited queries
- 100 indicators per request
- 1,000+ requests per minute
- All Team features
- Dedicated low-latency infrastructure
- Custom rate limits
- Dedicated support
- Custom SLAs available
- Volume discounts
- Invoiced billing
Prices exclude applicable taxes. Tax is calculated at checkout based on your location.
What Makes Reput.io Different
Purpose-built for reducing false positives in SOC environments
Two Types of Intelligence
Whitelist: Verified safe sources (FAANG, banks, governments) - auto-allow
Enrichment: Contextual data (CDNs, VPNs, cloud) - analyst review
Confidence Scoring
Every indicator gets a 0-100 confidence score based on source trust tier, corroboration, and institutional recognition. Not just "good" or "bad".
Risk Context
Human-readable explanations: "Verified Google infrastructure - safe to allow" or "Dynamic DNS provider - commonly abused for C2".
180+ Authoritative Sources
MISP warninglists, Cisco Umbrella, Tranco, AWS/GCP/Azure ranges, government registries, ASN providers, and curated institutional data.