Spur: Interview With Co-Founder And Chief Strategy Officer Ethan Smith About IP Intelligence And Anonymized Traffic

By Amit Chowdhry ● Today at 10:32 AM

Spur is an IP intelligence company that helps security, fraud, and threat intelligence teams identify intentionally obscured internet traffic and understand the infrastructure behind it. Its technology provides context around VPNs, residential proxies, mobile proxies, botnets, and other anonymization services through APIs, data feeds, and session enrichment. Pulse 2.0 interviewed Spur Co-Founder and Chief Strategy Officer Ethan Smith to learn more.

Ethan Smith’s Background

When asked about his background, Smith shared:

I co-founded Spur in 2017 and today serve as chief strategy officer, helping guide the company’s strategic vision, product direction, and long-term market positioning.

Before Spur, I was a senior engineer at Redacted and an engineer with the U.S. Department of Defense, where I focused on computer network operations and cyber capability development. Those roles gave me a firsthand understanding of how threat actors operate, and the challenges security teams face when malicious activity is hidden behind proxies, VPNs, and other anonymizing infrastructure. That experience helped shape the idea behind Spur.

How Spur Started

When asked how the idea for the company came together, Smith explained:

Spur was built on a simple thesis: threat actors often obscure the origin of their traffic to avoid detection and attribution. In our own investigations, we kept running into the same dead ends. Traditional IP data could tell us where an address was registered or which network owned it, but not whether the traffic was moving through a VPN or residential proxy, or why that mattered.

We initially built the technology for our own investigations. We soon realized that fraud, security, and threat intelligence teams across many industries faced the same visibility gap. Spur grew from an internal capability into a platform that helps organizations identify obscured traffic and make faster, more confident decisions.

The Growing IP Intelligence Problem

When asked what problem Spur is solving and why it has become more urgent, Smith noted:

IP addresses were once more reliable signals for detecting malicious activity. VPNs, residential proxies, mobile proxies, and other anonymization technologies have made them less reliable by allowing threat actors to disguise where their traffic comes from.

As a result, malicious activity can appear to come from a normal residential connection, while legitimate users may be blocked because organizations lack enough context to distinguish between the two.

The problem is becoming more urgent as account takeover, automated fraud, bot activity, and AI-driven abuse scale. In Spur’s 2026 IP Intelligence Study, 94% of organizations said VPNs or residential proxies appear in security incidents at least sometimes, yet many still rely on reactive investigations and fragmented data.

AI adds another layer of complexity by accelerating both legitimate automation and malicious activity. Our challenge is to help customers evaluate the full context of each interaction rather than relying on simplistic labels or treating every automated interaction the same way.

Core Products And Features

When asked about Spur’s core products and features, Smith detailed:

Spur provides IP intelligence that helps organizations identify intentionally obscured traffic and understand the infrastructure behind it. We classify IP addresses using technical, behavioral, and attribution signals, including whether an address is associated with a VPN, a residential proxy, a mobile proxy, a botnet, or other anonymization technology.

Customers access that intelligence through APIs, data feeds, and session enrichment that integrate with existing security, fraud, authentication, and edge infrastructure. It can support investigations such as threat hunting and incident response, as well as real-time decisions during account creation, login, and other sensitive user interactions.

The goal is not simply to label an IP address as risky. It is to give customers enough transparent context to detect account takeover, fraudulent account creation, bots, geo-evasion, and other abuse without creating unnecessary friction for legitimate users.

Competitive Differentiation

When asked what differentiates Spur from its competition, Smith emphasized:

What differentiates Spur is the accuracy, depth, and transparency of our intelligence. Our assessments must be reliable enough to support operational decisions.

Because Spur conducts its own research and maintains ownership and auditability of its dataset, we can explain why an IP address has been classified and continually validate those findings as infrastructure changes. We also focus on areas where traditional IP intelligence often falls short, including residential proxies, mobile proxies, botnets, and other technologies designed to evade detection.

That combination gives customers the confidence to use Spur’s intelligence in high-stakes, real-time workflows without automatically penalizing every user connecting from a VPN or residential network.

How The Technology Has Evolved

When asked how Spur’s technology has evolved since launching, Smith explained:

Fraud and security are always a cat-and-mouse game, so Spur’s technology has evolved alongside the infrastructure attackers use. One of the most important areas of expansion has been residential proxy detection, where malicious activity is routed through consumer internet connections, making it look like ordinary household traffic.

The platform now covers more than 1,000 VPNs and provides context spanning infrastructure type, geography, network ownership, tunnel information, and behavioral patterns.

We have also evolved how customers can use the data. What began primarily as investigative intelligence can now be incorporated into real-time sessions and enforcement workflows, rather than only investigating afterward.

Key Company Milestones

When asked about some of Spur’s most significant milestones, Smith highlighted:

One significant milestone was seeing Spur’s expertise contribute to the broader industry understanding of IPIDEA, one of the world’s largest residential proxy networks.

The work demonstrated that high-fidelity IP intelligence can have an impact beyond an individual customer. It can help the wider security community better understand the infrastructure supporting cybercrime, espionage and online abuse.

Gopuff Customer Success

When asked to share a specific customer success story, Smith said:

One example is our work with Gopuff. The company was dealing with sophisticated bot traffic that closely resembled legitimate customer activity. At times, bots accounted for as much as 80% of its traffic, increasing infrastructure costs, triggering false alerts, and making conversion data less reliable.

Gopuff integrated Spur Monocle into its Cloudflare environment to identify traffic associated with residential proxies, VPNs, and other anonymizing infrastructure. After deployment, activity from previously unidentified scrapers declined significantly. The company also reduced hosting and Cloudflare costs, experienced fewer crawler-related errors, and gained greater confidence in its conversion data, without creating additional friction for legitimate customers.

That example captures the broader value of Spur. The objective is not to block more traffic indiscriminately, but to help companies distinguish legitimate users from deceptive or automated activity.

Funding

When asked about funding, Smith shared:

In July 2026, Spur announced a $200 million investment from Insight Partners. The investment gives us additional resources to expand the platform, accelerate growth, and continue building the next generation of IP intelligence while maintaining the accuracy and research depth our customers rely on.

Future Goals

When discussing Spur’s future goals, Smith concluded:

Our goal is to move IP intelligence earlier in the process, so it can shape fraud, security, and authentication decisions as activity is happening, not only help teams investigate afterward.

We want organizations to understand what infrastructure is behind a connection, how it is behaving, and whether it should influence the decision being made in that moment.

We will continue expanding our visibility into emerging anonymization and automation technologies and making that intelligence easier for customers to use. The tradecraft attackers use is never static, so there is always more to observe, understand, and address.

Exit mobile version