We run the sensors, so your team doesn't have to
sniche is an independent threat intelligence company. We collect malicious infrastructure data at source, validate it hard, and distribute it as clean, documented feeds.
Founded by people who were tired of bad feeds
sniche started in 2024 in a shared office, after our founders spent a decade inside SOCs and hosting providers watching the same problem repeat: threat data arrived late, in five different formats, with no way to tell a high-confidence detection from a guess — and no way to get a false positive retracted.
So we built the thing we wanted to buy. Our own sensor network instead of resold lists. One schema across every feed. A confidence score on every record, with the evidence behind it. And a support desk staffed by the engineers who run the collectors.
Today sniche processes several billion events a week across DNS, certificate transparency, mail flow and the open web, and delivers the distilled result to security teams, MSSPs and product companies in eleven countries.
Four commitments we hold ourselves to
They sound simple. Keeping them is most of the work.
Evidence, not opinion
Every indicator carries the observation that produced it. If we cannot show why something is malicious, it does not ship.
Independence
We are self-funded and vendor-neutral. No feed is shaped by a partner's product roadmap or a reseller agreement.
Own our mistakes
False positives happen. We publish retractions in the feed itself, within hours, and tell you what went wrong.
Respect the clock
Intelligence has a half-life. Our slowest feed updates every six hours; most refresh in minutes.
How we got here
A short history of the collectors, and the feeds.
-
2024
First sensors online
Three founders, a rack of passive DNS collectors and one customer who agreed to test the malicious-domains feed for free.
-
Late 2024
The API replaces the file drop
We retired nightly CSV exports in favour of a cursor-based REST API — the same one documented on this site today.
-
2025
Streaming and STIX 2.1
NDJSON streaming shipped for Pro customers, alongside STIX output for teams standardising on structured threat exchange.
-
Late 2025
Twelve feeds, three regions
Collector infrastructure expanded into North America and Singapore, cutting observation-to-publication time to under four minutes.
How we handle data and disclosure
We collect infrastructure data — domains, addresses, certificates, hosting metadata — not personal browsing activity. Where a record unavoidably contains personal data, such as a WHOIS contact, it is minimised and access-controlled.
- Annual third-party penetration test
- Coordinated disclosure programme for our own platform
- Data processing agreement available for every plan
- Sub-processor list published to customers
Found a vulnerability in our platform? Write to security@sniche.com — we acknowledge within one business day and never pursue good-faith researchers.
Let's talk about what you need to block
Tell us the problem you are solving and we will tell you honestly whether our feeds help.