top of page

Spur Raises $200 Million to Expand Its Bot-Detection Platform

Jul 30
14 min read

Spur Intelligence raised $200 million from Insight Partners as techcrunch bot coverage highlighted an uncomfortable milestone: automated traffic is overtaking human activity online. The investment gives Spur substantial backing to identify traffic concealed behind residential proxies, VPNs, and other anonymizing services. It also raises the stakes for security vendors that still treat an IP address as a reliable identity signal.

The funding is not simply another large cybersecurity round. Spur is betting that understanding internet infrastructure has become essential to separating people, useful AI agents, and malicious automation. That task grows harder when all three can use the same browsers, networks, and residential connections.

Cloudflare has reported that bots became more active than humans online during 2026. That reversal creates the market Insight is funding. It also exposes the central challenge facing Spur, Cloudflare, HUMAN Security, DataDome, and other defenders: identifying automation is no longer enough. Security systems must infer its origin, purpose, and acceptable level of access without punishing legitimate users.

The $200 Million Bet Behind the TechCrunch Bot Story

Insight Partners is financing an infrastructure intelligence strategy, not a simple bot-blocking product.

Spur announced the investment on July 28, 2026. Insight led the round, while Spur said it would use the money across product development, intelligence coverage, integrations, customer operations, and broader company growth.

The Lake Mary, Florida company was founded in 2017 by Riley Kilmer and Ethan Smith. TechCrunch described both founders as former Defense Department engineers. Their early focus on anonymized infrastructure predates the public launch of ChatGPT and the current wave of autonomous web agents.

That history matters because the web’s identity problem did not begin with generative AI. Attackers have long used virtual private networks, hosting services, botnets, and compromised devices to disguise their locations. Residential proxy networks made the problem harder by routing activity through consumer internet connections that resemble normal household traffic.

Spur’s platform examines the infrastructure behind those connections. IP intelligence means contextual data about an internet address, including its network, location, observed behavior, and association with anonymizing services. Spur delivers that information through APIs, on-premises data feeds, integrations, and session enrichment.

The company says it continuously observes anonymizing infrastructure and maps addresses to particular services or behaviors. Its public platform describes coverage across more than 1,000 validated VPN and proxy services. It also says its systems identify about 60 million active suspect addresses daily.

Those figures are company claims, not independent benchmarks. They nevertheless show the intended scale of the product. Spur does not want customers to submit one suspicious address for investigation. It wants its intelligence embedded inside authentication, fraud scoring, threat hunting, and transaction decisions.

The original funding report framed Spur’s value around distinguishing legitimate humans from hidden bot traffic. Spur’s own announcement described a broader mission involving VPN attribution, residential proxy tracking, and AI-driven infrastructure.

That difference is important. “Bot detection” suggests a binary decision between human and machine. Modern traffic rarely offers such a clean split. A human can operate through a privacy service, an AI assistant can perform an authorized task, and a fraud ring can distribute requests across real residential devices.

Spur’s approach tries to add infrastructure context before a customer makes that decision. A suspicious connection does not automatically trigger a block. It can instead prompt another identity check, limit an action, raise a risk score, or send an alert to an analyst.

Insight managing director Thomas Krane described anonymized infrastructure as a blind spot. Security teams can often see the activity, he said, without understanding what sits behind it. That diagnosis explains why Insight committed such a large amount to a company operating beneath more visible fraud products.

The round gives Spur resources to expand, but no disclosed valuation accompanied the announcement. Spur also did not publish audited revenue, customer totals, or transaction terms. The investment therefore signals investor conviction without giving outsiders a complete view of the company’s commercial scale.

Why Bot Detection Became an Infrastructure Problem

Bots now imitate the network conditions of real users, so behavioral clues alone cannot explain where traffic originates.

Traditional bot defenses looked for obvious automation signals. A script might send requests too quickly, omit normal browser data, repeat an identical sequence, or operate from a known data-center address. Defenders could block it without creating much inconvenience for ordinary visitors.

Attackers adapted. They rotate browser fingerprints, vary timing, solve challenges, and route sessions through residential networks. A residential proxy is an intermediary that sends traffic through an address assigned to a household or mobile device. To the destination, that request can appear to come from an ordinary customer.

Some proxy capacity comes from users who knowingly share bandwidth. Other capacity can involve compromised machines, deceptive software, or malware. The destination website sees an address with a plausible internet provider and location, regardless of how the sender acquired it.

This is where Spur’s infrastructure-first model enters. Instead of relying only on browser behavior, it attempts to identify the network service, proxy operator, or anonymization pattern associated with a session. That intelligence can reveal connections between activity that otherwise looks unrelated.

A retailer, for example, might see hundreds of accounts purchasing limited inventory from different household addresses. Each account can behave at a believable speed. If those addresses connect to one residential proxy network, the shared infrastructure becomes a stronger signal than any individual session.

The same logic applies to account creation. Fraud operators can automate registrations to exploit trials, referral credits, promotional offers, or platform incentives. Changing email addresses and device fingerprints is easier when the operator can also rotate through residential connections.

Spur says one unnamed technology customer blocked more than 90% of fraudulent registrations after adding its data. Another unnamed financial institution reportedly reduced successful account-takeover attempts by more than 40%. These outcomes come from customer case studies, so readers should treat them as vendor-presented evidence.

The underlying use cases are credible even when the exact performance needs independent validation. Authentication teams routinely combine multiple signals because no single attribute proves identity. IP context can contribute useful evidence alongside device history, account behavior, payment information, and user verification.

The rise of AI agents adds another layer. An agent can browse products, collect information, compare offers, schedule appointments, or complete approved work for a human. The same technical capabilities can support scraping, inventory hoarding, credential attacks, or mass account creation.

That overlap changes the defender’s objective. Blocking every machine would break useful services and frustrate customers who delegate tasks to assistants. Allowing every sophisticated agent would expose businesses to automated abuse at a scale human operators cannot match.

Spur acknowledges this tension on its own product pages. It warns that broad fraud and bot controls can interfere with desirable agentic automation. Its answer is more granular attribution, followed by targeted friction rather than universal blocking.

Targeted friction can include a verification request, a lower rate limit, a restricted action, or manual review. The goal is to reserve the strongest intervention for sessions with several concerning signals. That approach can protect conversion rates while increasing the cost of abuse.

The techcrunch bot framing captures the visible part of this shift. The deeper story concerns the loss of trustworthy network boundaries. A consumer address no longer guarantees a consumer, just as a convincing browser session no longer guarantees a person.

Bots Passed Humans, but Good Bots Complicate the Score

The market is expanding because automation dominates more traffic, while the boundary between helpful and harmful automation keeps weakening.

TechCrunch cited Cloudflare data indicating that automated activity passed human traffic online during mid-2026. Cloudflare CEO Matthew Prince said agentic traffic grew faster than he expected, moving the crossover ahead of his earlier forecast.

That finding deserves careful interpretation. Traffic measurements depend on which networks, requests, and classifications a provider observes. A request count also does not equal a count of users, decisions, or economic value. One automated process can generate many more requests than one person.

Still, the direction is clear. AI systems are becoming active participants on the web rather than tools waiting inside chat windows. They retrieve pages, call APIs, compare content, and take actions across services. Those activities add to the long-standing volume produced by search crawlers, monitoring services, fraud tools, scrapers, and malicious bots.

Cloudflare’s traffic analysis gives infrastructure providers an unusually broad view of this transition. However, no network operator can perfectly classify every request. Encrypted traffic, shared connections, changing agents, and incomplete behavioral histories all create uncertainty.

That uncertainty is commercially valuable for Spur. A company does not need bot detection because all bots are bad. It needs better context because some bots are welcome, some require limits, and others need immediate intervention.

A search crawler may improve discovery. A shopping assistant may bring a customer ready to buy. An accessibility tool may automate navigation for a legitimate user. Meanwhile, a scalping bot can purchase scarce inventory, and a credential-stuffing system can test stolen passwords against millions of accounts.

These agents can use similar tools and infrastructure. Their purpose often becomes visible only through repeated actions, account relationships, or transaction outcomes. Infrastructure intelligence can narrow the possibilities, but it cannot read intent directly.

This creates pressure for bot-management vendors and content delivery networks. Cloudflare already observes traffic at the network edge, while specialized companies analyze browser behavior, device fingerprints, interaction patterns, or fraud histories. Spur must show that its data adds information those existing layers cannot reliably produce.

The company argues that residential proxy attribution is that missing layer. Its IP intelligence platform says conventional edge tools struggle when malicious activity appears behind residential addresses. Spur claims its session-level data can connect those addresses to particular proxy services and campaigns.

That proposition turns Spur into both a supplier and a potential competitor. A fraud platform can consume Spur’s feeds to improve its own decisions. A large edge network can also develop comparable intelligence internally, combine it with first-party telemetry, or acquire another specialist.

Insight’s investment therefore does more than support customer growth. It gives Spur time and capital to widen its observation network before adjacent vendors close the gap. Coverage quality can improve as a provider sees more infrastructure, services, and changing addresses.

That dynamic resembles other intelligence markets. Threat-data providers gain value by observing more sources, validating more indicators, and integrating their findings into customer workflows. Buyers hesitate to replace them once detection rules and analyst processes depend on their data.

However, scale does not automatically produce accuracy. A large list of suspect addresses can create noise if labels remain stale or overly broad. The decisive metric is not how many addresses Spur catalogs. It is whether those labels improve decisions without blocking legitimate customers.

The techcrunch bot story is therefore about a new measurement layer. Automation’s growing share creates demand, but classification quality determines who captures the market. Investors are funding Spur to become a trusted source of that classification before bot traffic becomes even harder to interpret.

Spur’s Real Opponent Is the Binary Human-or-Bot Test

Spur is challenging a security model that treats human and automated traffic as opposing categories with one correct answer.

A binary test works when the policy is simple. A website may reject a basic scraper or allow a verified search crawler. Most valuable online services now face decisions that sit between those endpoints.

Consider a bank login from an address associated with a commercial VPN. A traveler might use that VPN for privacy. A criminal might use the same service to conceal an account takeover. The network signal should influence the decision, but it should not decide the case alone.

A retailer faces a similar problem during a product launch. Automated purchasing can remove inventory before ordinary customers reach checkout. Yet an approved shopping agent might be acting for a customer who expects the service to support delegated buying.

Security teams therefore need a policy engine, not merely a detector. The policy must combine infrastructure, account history, device behavior, transaction context, and the requested action. It should apply proportionate friction while preserving access for low-risk users.

Spur’s position is that infrastructure deserves more weight inside that process. Its data can reportedly identify whether a connection belongs to a VPN, residential proxy, mobile gateway, data-center service, or known automation network. Customers can then choose how each signal affects their systems.

This makes Spur different from a CAPTCHA vendor. A CAPTCHA asks a visitor to complete a challenge intended to separate people from automation. Modern models and human-solving services have reduced the reliability of that distinction, while repeated challenges impose costs on legitimate users.

Device fingerprinting offers another layer by combining browser and hardware attributes into a probabilistic identifier. It can identify recurring devices even when cookies change. Privacy controls, spoofed attributes, and shared devices can weaken those conclusions.

Behavioral detection evaluates actions such as typing rhythm, pointer movement, navigation order, and request timing. Those signals can reveal scripted behavior, but advanced agents can imitate variation. Legitimate automation can also look highly repetitive.

Infrastructure intelligence does not replace these methods. It supplies another dimension that can survive changes to an account, browser, or device fingerprint. A fraud operator rotating through addresses can still reveal a relationship to one proxy provider or anonymization network.

The strongest deployment combines these layers. A residential proxy label might increase risk slightly. A new account, unusual device, rapid checkout, and reused payment instrument might push the same session beyond an intervention threshold.

That is also why claims about identifying “legit human traffic” require caution. Spur can provide evidence about a connection’s infrastructure. It cannot guarantee that a person sits behind every unflagged address or that every proxied session is malicious.

Even the company’s statement that AI models cannot replicate its real-world infrastructure observations is a competitive claim. Models cannot invent reliable current network attribution from nothing. However, rivals can collect telemetry, license data, and use machine learning to interpret similar signals.

Large platforms possess an additional advantage: direct visibility into accounts, transactions, and historical behavior. Spur needs to prove that specialized observation produces better attribution than the intelligence those platforms can assemble themselves.

Its role may ultimately resemble a credit bureau for network provenance. The bureau supplies a risk signal, while the customer makes the final decision. That position can be valuable, but it requires consistency, transparency, and rapid correction when labels are wrong.

False positives create real costs. A mislabeled address can block a customer, interrupt a worker, or force unnecessary verification. False negatives allow abuse to continue. Both errors become more consequential when customers automate decisions using real-time APIs.

Spur says its data is explainable and based on observed infrastructure. Buyers should still ask how classifications are validated, how quickly records expire, and how disputes are handled. They should also measure outcomes against a control group before allowing any single signal to block users.

The $200 million round gives Spur the resources to improve those processes. It does not settle the question of whether infrastructure attribution becomes the dominant bot-detection layer. That result depends on measurable performance inside customer workflows.

What the Funding Announcement Does Not Show

The investment validates the size of the problem, but it does not independently validate Spur’s accuracy, valuation, or defensibility.

Spur’s announcement contains several promising indicators. The company says more than 95% of customers renew subscriptions each year. It also cites improvements in fraudulent-registration detection, account-takeover prevention, and proxy identification across unnamed customer cases.

Those figures remain difficult to assess without denominators and evaluation methods. A percentage reduction can depend on the original fraud rate, rule configuration, observation period, and definition of a successful incident. An unnamed customer also prevents outsiders from checking the result.

The company’s 2026 study found that 94% of surveyed organizations encountered anonymizing VPNs or residential proxies during security incidents. Nearly half reportedly planned to add, replace, or upgrade a commercial IP intelligence product within the following year.

That research supports the demand argument. Yet vendor-sponsored studies can reflect respondent selection, question wording, and the sponsor’s market framing. Buyers should examine the study’s methodology before treating its findings as market-wide measurements.

There is also a privacy tradeoff. More detailed network and session attribution can help stop fraud, but broad collection can reveal patterns about legitimate users. Companies need clear retention policies, access controls, and lawful purposes for combining IP intelligence with account data.

An IP address is not a person. Households share connections, mobile addresses change, corporate gateways aggregate employees, and privacy tools serve legitimate needs. Security teams that forget those limits can turn a useful risk indicator into an unfair identity judgment.

Geolocation introduces another risk. IP-based location can be imprecise or misleading, especially across mobile networks and VPNs. Using it for sanctions screening, regional access, or compliance decisions requires escalation paths when the signal conflicts with other evidence.

Competition creates a separate uncertainty. Edge networks see enormous request volumes and can build detection from traffic they already process. Fraud platforms can connect network observations with payment, identity, and account histories. Browser-security vendors can observe interaction details that IP data misses.

Spur’s defensibility therefore rests on the quality and freshness of its attribution. It must discover proxy infrastructure before attackers rotate away from it. It must distinguish commercial privacy services from criminal networks. It must update labels quickly enough for real-time decisions.

Attackers will respond. If customers block known proxy pools, operators can recruit new residential devices, distribute traffic more slowly, or mix automated and human labor. Better attribution raises the attacker’s cost, but it rarely ends the contest.

Agentic AI further complicates the economics. Businesses increasingly want automated customers, partners, and assistants to interact with their services. A detection system that rejects them all will protect the website by making it less useful.

This is the core tradeoff behind techcrunch bot coverage of Spur. The company benefits from fear about automated traffic, but its long-term value depends on supporting acceptable automation. Detection without policy could become a bottleneck rather than a solution.

Insight’s involvement can help Spur expand sales and integrations. The firm manages more than $90 billion in regulatory assets and has backed hundreds of software companies, according to the investment announcement. Its participation offers operational support, not independent proof of product performance.

The absence of disclosed valuation and revenue also limits comparisons. A $200 million investment can include different securities, ownership terms, or secondary components. Neither Spur nor Insight provided those details publicly.

Customers should evaluate the product through controlled testing. They can compare fraud detection, false-positive rates, manual-review volume, customer abandonment, and response latency before and after introducing Spur’s data.

That evidence will matter more than the round itself. Funding lets Spur collect more intelligence and enter more workflows. Customer results will determine whether it becomes infrastructure or remains one useful signal among many.

Three Signals That Will Decide Spur’s Next Chapter

Spur now has to turn investor confidence into broader coverage, verifiable customer outcomes, and policies that accommodate legitimate AI agents.

The first signal is independently measurable detection performance. Spur publishes customer stories, but the market needs comparable tests across residential proxies, VPNs, bot networks, and ordinary users. Useful evaluations should report both detection rates and false positives.

A strong result would show that Spur improves fraud outcomes beyond browser, device, and behavioral controls already deployed by customers. It would also demonstrate that labels remain accurate as proxy providers rotate addresses. Weak or opaque evidence would reduce the significance of the funding.

The second signal is integration depth. Spur plans to invest in product coverage and integrations, which should place its data inside authentication systems, fraud platforms, security analytics, and edge controls. Adoption inside real-time workflows would indicate that customers consider infrastructure context operationally useful.

Integration can also reveal whether Spur becomes a neutral data layer or competes directly with platforms consuming its intelligence. A neutral supplier can reach many customers through partners. A broader application vendor can capture more value but risks alienating those partners.

The third signal is how Spur classifies legitimate agents. The company already distinguishes harmful automation from desirable agentic activity in its messaging. Buyers should watch for documented categories, verification mechanisms, and policy controls designed for authorized AI systems.

A useful system might recognize verified agents, declared purposes, approved accounts, or limited actions. It could assign different permissions to research, purchasing, support, and administrative agents. That model would move the market beyond an outdated human-or-bot gate.

The challenge is trust. Attackers can falsely claim legitimate purposes, copy agent identifiers, or compromise approved services. Verification must therefore connect an agent to an accountable operator and defined permissions, not simply accept a label in a request.

Industry coordination will matter. Edge providers, publishers, marketplaces, security vendors, and AI developers need shared ways to express agent identity and access policies. A fragmented system would force every website to maintain separate rules for every agent.

Spur can influence that transition if its intelligence becomes widely embedded. Its view of proxy networks and automation infrastructure gives it useful evidence about how agents reach services. However, identity standards and customer policy will extend beyond IP attribution.

For enterprise buyers, the immediate action is practical. Map where automated traffic affects registrations, logins, payments, scraping, inventory, or support. Then identify which decisions lack reliable infrastructure context and measure the cost of both missed abuse and unnecessary friction.

Do not treat every VPN user as an attacker. Do not treat every unflagged residential address as human. Use infrastructure intelligence as one input, require additional evidence for high-impact decisions, and maintain a path for legitimate users to recover access.

Developers should also prepare for a web where machine traffic is ordinary. Rate limits, scoped credentials, audit logs, and explicit automation policies will become as important as detection. A service that only blocks suspicious requests will struggle when valuable customers arrive through agents.

The techcrunch bot headline made Spur’s financing the event. The more consequential story is the erosion of the human-versus-machine boundary. Insight has backed Spur to map the infrastructure beneath that ambiguity.

Now the company must show that its map improves decisions in the real world. Watch for published performance evidence, major workflow integrations, and credible support for authorized agents. Those signals will reveal whether Spur becomes a core internet intelligence layer or an expensive addition to an already crowded security stack.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page