Behavioural network-integrity detection

You see an IP.We see who's behind it.

VPNs, proxies, residential-proxy exit nodes, proxyware, bots and tampered connections — caught by how they behave, not by a list of addresses that's stale the day it ships.

Free live check for anyone: whatami.me

● live verdict feedbehaviour · not IP list
Visitor · residential IP
tls·rtt·timing consistent — no tunnel
CLEAN
!
Visitor · mobile carrier
datacenter hop · RTT gap on fresh connect
SUSPICIOUS
Device · me.***.exit
relays to a known gateway · out ≫ in
EXIT NODE
verdict = server-sideclient never scores
IP reputation lists

Always one step behind

A new residential-proxy provider or exit range is clean on every list until it's been abused enough to be reported. Behaviour is visible on the first connection.

EDR / antivirus

Blind to proxyware

A bandwidth-selling SDK isn't malware by signature — it's an app the user "agreed" to. EDR waves it through; its traffic shape gives it away.

Port / protocol rules

Everything hides on 443

Blocking ports and matching signatures misses tunnels that look like normal HTTPS. We judge the flow, not the port.

One engine · three surfaces

Detect it in the browser, on the device, or across the fleet

The same behavioural core, delivered where you need it — a tag for your website, an app for a device, or an on-prem deployment for a network you run.

Web · SaaS tag

Visitor verdict

A lightweight script returns a real-time risk verdict per visitor — VPN/proxy, automation, multi-accounting, connection tampering — before they act.

  • Drop-in JavaScript, verdict via API
  • Scoring stays server-side — the client can't be spoofed
  • Behaviour + network, not a shared blocklist
Live in production
Device · mobile / desktop / TV

On-device monitor

An app that inspects a device's own traffic behaviour to find proxyware, residential-proxy SDKs and VPN/relay apps running on it — often without the owner's knowledge.

  • Per-app attribution: which package is relaying
  • All analysis bound to that one device
  • Verdict only kept locally — never the traffic
Android ready · more platforms coming
Enterprise · on-prem + intel

Fleet & network

Run the engine on your own infrastructure — data never leaves — with a central, self-learning feed of known relay gateways and proxy infrastructure.

  • On-premises: you are the controller
  • Intel feed: exit → package → networks, behaviour-earned
  • Built to sit beside EDR, catching what it can't
Early access
Coverage

What SecIn catches

All from behaviour and network signals — no client-supplied trust, no third-party API.

01

Residential proxies

Traffic routed through someone else's home IP to look local.

02

Proxyware SDKs

Bandwidth-selling clients (honeygain-class) relaying on a device.

03

Exit nodes

A device used AS a proxy — out ≫ in, pulling from many hosts.

04

VPN & tunnels

Tunnelled clients, including ones hidden on standard ports.

05

Bots & automation

Headless browsers, anti-detect stacks, non-human interaction shape.

06

Multi-accounting

One device behind many accounts, linked by hardware fingerprint.

07

Connection tampering

Mismatched TLS/TCP, RTT gaps, spoofed network characteristics.

08

Malware beaconing

DGA / NXDOMAIN patterns and persistent phone-home channels.

The difference

Behaviour-first, by design

Lists tell you where abuse has already happened. Behaviour tells you what's happening now.

list / signature based

Clean until an address has been reported enough times
Misses proxyware the user "installed" willingly
Evaded by rotating IPs and standard ports
One shared blocklist everyone can probe around

SecIn · behaviour based

+Flags on the first connection from how it moves
+Reads traffic shape — a relay looks like a relay
+Port-agnostic; judges the flow, not the number
+Verdict computed server-side, never trusted from the client
The moat

A self-learning intel base, earned by behaviour

Every confirmed relay teaches the system its gateways — exit IP, port and the owning app package — and how many independent networks have seen it. Not a static list we buy; one that compounds from what we actually observe.

gateway → package → networks ───────────────────────────── 80.96.x.x:9001 me.***.exit n=1 13.140.x.x:9443 · n=4 185.60.x.x:5222 (messenger) ok ───────────────────────────── seen on ≥2 networks = known relay
Get started

See what your traffic is really doing

Try the free live check, or talk to us about the tag, the device monitor, or an on-prem deployment.