We run the sensors, so your team doesn't have to

sniche is an independent threat intelligence company. We collect malicious infrastructure data at source, validate it hard, and distribute it as clean, documented feeds.

Our story

Founded by people who were tired of bad feeds

sniche started in 2024 in a shared office, after our founders spent a decade inside SOCs and hosting providers watching the same problem repeat: threat data arrived late, in five different formats, with no way to tell a high-confidence detection from a guess — and no way to get a false positive retracted.

So we built the thing we wanted to buy. Our own sensor network instead of resold lists. One schema across every feed. A confidence score on every record, with the evidence behind it. And a support desk staffed by the engineers who run the collectors.

Today sniche processes several billion events a week across DNS, certificate transparency, mail flow and the open web, and delivers the distilled result to security teams, MSSPs and product companies in eleven countries.

The sniche office building, seen from the street on a clear day.
What we stand for

Four commitments we hold ourselves to

They sound simple. Keeping them is most of the work.

Evidence, not opinion

Every indicator carries the observation that produced it. If we cannot show why something is malicious, it does not ship.

Independence

We are self-funded and vendor-neutral. No feed is shaped by a partner's product roadmap or a reseller agreement.

Own our mistakes

False positives happen. We publish retractions in the feed itself, within hours, and tell you what went wrong.

Respect the clock

Intelligence has a half-life. Our slowest feed updates every six hours; most refresh in minutes.

Milestones

How we got here

A short history of the collectors, and the feeds.

  1. 2024

    First sensors online

    Three founders, a rack of passive DNS collectors and one customer who agreed to test the malicious-domains feed for free.

  2. Late 2024

    The API replaces the file drop

    We retired nightly CSV exports in favour of a cursor-based REST API — the same one documented on this site today.

  3. 2025

    Streaming and STIX 2.1

    NDJSON streaming shipped for Pro customers, alongside STIX output for teams standardising on structured threat exchange.

  4. Late 2025

    Twelve feeds, three regions

    Collector infrastructure expanded into North America and Singapore, cutting observation-to-publication time to under four minutes.

Trust & compliance

How we handle data and disclosure

We collect infrastructure data — domains, addresses, certificates, hosting metadata — not personal browsing activity. Where a record unavoidably contains personal data, such as a WHOIS contact, it is minimised and access-controlled.

  • Annual third-party penetration test
  • Coordinated disclosure programme for our own platform
  • Data processing agreement available for every plan
  • Sub-processor list published to customers

Found a vulnerability in our platform? Write to security@sniche.com — we acknowledge within one business day and never pursue good-faith researchers.

Panels from the sniche data set: IP address, ASN and ISP totals with global traffic maps, a single IP lookup showing its ASN, provider, location and first and last seen times, and the network path from a client through its ISP and transit provider to the destination host.
Work with us

Let's talk about what you need to block

Tell us the problem you are solving and we will tell you honestly whether our feeds help.