Pricing

BGP Feed + API Subscriptions

Real-time threat intelligence delivered via API and BGP blackhole routing.

Community
$0 /mo

Free forever. No credit card.

  • Live threat dashboard
  • REST API (100 req/day)
  • 15-minute delayed feed
  • No SSE real-time streaming
  • No BGP peering
  • No WireGuard tunnel
  • Community support only
Get Started Free
Shield
$59 /mo

BGP blackholing for single-router networks.

  • Live BGP blackhole feed — real-time API (2,000 req/day)
  • GRE or WireGuard tunnel + your own BGP session
  • Peers on a private ASN you generate yourself, no LOA paperwork
  • Auto-approved — live in minutes, not days
  • 14-day free trial
  • Email support
Start Shield

or $590/yr — save $118

Enterprise
$999 /mo

Highest limits, priority support.

  • Unlimited API requests
  • SSE live streaming
  • Multiple GRE/WireGuard tunnels
  • Multiple BGP sessions
  • Custom threat feeds
  • Priority support
Start Enterprise

Just need the threat feed for your own SIEM or SOC tooling — no BGP router required? Feed — $14.99/mo, 5,000 req/day, STIX/TAXII & SIEM formats →

Feature Comparison

Feature Community Home Shield Professional Enterprise
Live Dashboard
REST API Access 100/day 1,000/day 2,000/day 10,000/day Unlimited
Feed Latency 15 min delay Real-time Real-time Real-time Real-time
SSE Streaming — — —
WireGuard Tunnels — — 1 1 Unlimited
BGP Sessions (RTBH) — — 1 1 Unlimited
Email Threat Feeds —
Custom Threat Feeds — — — —
Marketplace Access Browse free Browse free Browse free Subscribe + Publish Subscribe + Publish
Support Community Email Email Email Priority

How BGP Peering Works

Get threat blocks at the network edge via BGP RTBH.

You don't need to be multihomed. This is a private session just for receiving blackhole routes — it has nothing to do with how many upstream providers you have. A private ASN (free, no registry paperwork) and one router that speaks BGP are enough. That router does need to be something that actually runs a BGP daemon — OpenWrt, pfSense/OPNsense, VyOS, or Linux with BIRD/FRR all work. Most stock ISP routers and mesh Wi-Fi systems don't ship BGP, so Shield needs different hardware than what most home networks already have.
You don't need an existing BGP feed, either. SATIS can be your first BGP session, not an add-on to one you already have. If all you're running today is static routes, that's fine — the requirement is that your platform can run a BGP daemon (usually a package install, like BIRD or FRR), not that you're already using it for anything.
1
Request Peering

Submit a peering request from your portal with your ASN (private is fine) and peering IP.

2
GRE Tunnel Setup

We provision a GRE or WireGuard tunnel to your nearest PoP — LAX (Los Angeles, CA), DFW (Dallas, TX), or BUF (Buffalo, NY) — and generate a router config for your platform.

3
BGP Session Established

BIRD 2 establishes a BGP session over the tunnel, authenticated with TCP-MD5. You receive blackhole routes (community 64999:666).

4
Automatic Protection

Critical threats are announced in real time. Your edge routers null-route malicious IPs before they reach your network.

BGP RTBH Flow
  SATIS Blockchain
        |
        | threat published (action: blackhole)
        v
  ┌─ LAX  199.33.244.74   ─┐
  ├─ DFW  162.216.123.135 ─┤
  └─ BUF  107.174.35.183 ─┘
        |
        | BIRD 2 announces /32 or /128
        | community: 64999:666
        | next-hop: 192.0.2.1 (blackhole)
        v
  GRE/WireGuard Tunnel (encrypted)
        |
        v
  Your Edge Router
        |
        | RTBH: null-route 203.0.113.45/32
        v
  Malicious traffic dropped
  before reaching your network

Start Protecting Your Network

Sign up for free and upgrade when you're ready.