top of page

What a Free Key Can Run With Edge Shield, and What $99 Buys. That's the Business Model.

Writer: Patrick Duggan
Patrick Duggan
3 minutes ago
4 min read

Patrick put it in one line this morning: "that's the business model." So here it is, stated plainly, with the arithmetic shown. Edge Shield is free and open source. The feed it pulls from needs a key. A free key runs it on a small site. Running it fresh, every hour, across real traffic needs Pro. That is a cover charge, not a paywall on safety.



What Edge Shield is


Edge Shield is a Cloudflare Worker you run on your own Cloudflare account. The code is public at github.com/pduggusa/dugganusa-edge-shield, currently version 2.5.0, one file, no build step. It answers known scanners, rate-limits, and blocks requests from IPs and domains on our feed. You can read every line of it, fork it, and point it at whatever list you like. The software costs nothing and always will.


What it pulls is our blocklist: ips.csv and domains.csv from analytics.dugganusa.com. That is the part with a meter on it.



The meter


Every key gets a daily quota of feed calls, and quotas reset at midnight UTC.


  1. Free: 10 calls a day, $0.

  2. Pro: 2,000 calls a day, $99 a month or $948 a year.

  3. Enterprise: 50,000 calls a day, $995 a month.

Until today our own docs quoted the free quota four different ways (1, 10, 25 and 500 a day). The real number for a new key is 10, keys registered before the May cut kept the 25 they were issued, and we're fixing the pages.



The arithmetic


Every Edge Shield refresh pulls two files, so every refresh costs two calls. You set how often it refreshes with IOC_REFRESH_MINUTES, anywhere from 5 to 1440 minutes. The default is 60.


Since 2.5.0, the copies of the worker running inside one Cloudflare data center share a single cached download for ten minutes, so a data center pulls from us at most once every ten minutes instead of once per copy. That fixed a herd problem on our side. It does not make refreshes free. A freshly started copy refreshes on startup, and if the shared cache has expired, that is another two calls.




Now run the numbers.


Free key, hourly refresh. Ten calls is five refreshes. At one refresh an hour in a single data center, the key is spent around 5 a.m. UTC. For the next nineteen hours every refresh gets HTTP 429. A copy of the worker that already loaded a list keeps blocking on it, and that list gets older by the hour. A copy that starts fresh after the quota is gone has no list at all. Nothing crashes. The worker logs "IOC refresh FAILED" and keeps serving your site, but the IP and domain blocking is running on a stale or empty list.


Free key, daily refresh. Set IOC_REFRESH_MINUTES to 1440 and a free key has room for five refreshes a day. That fits a small site served from one or two data centers. It is not a guarantee, because fresh copies of the worker still pull on startup, so watch your Workers Logs for that failure line in the first week.


Pro, hourly refresh. 2,000 calls is 1,000 refreshes a day. One pull an hour costs 48 calls per data center per day, so Pro covers about 41 data centers refreshing hourly. If fresh copies start often and force extra pulls, it covers fewer. The ten-minute cache sets the worst case at six pulls an hour, which is about seven data centers.



Why freshness is the thing you pay for


Our ips.csv is a short-window list. By default Edge Shield loads the last seven days at confidence 80 and up, and the infrastructure on it moves. A list that stopped updating at 5 a.m. is blocking yesterday's addresses by evening. We don't claim it catches everything, and we don't claim we see threats first. We claim it is current, and current costs us compute to build and serve.


So the line falls there. Everyone gets the software and the same feed. Pro buys frequency and breadth. Nobody pays to be protected at all.



Setting it up


The repo ships a CLAUDE.md with a Claude-guided onboarding playbook. Open the repo in Claude Code and ask it to set up the shield. It walks you through one question at a time, checks your Cloudflare zones, and starts you in observe mode, where nothing is blocked and every request the shield would have blocked is logged. It recommends seven days of observing before you switch to blocking. It never asks you to paste a key into chat. Secrets go in through wrangler secret put.


Register a free key at https://analytics.dugganusa.com/stix/register. Pricing is at https://analytics.dugganusa.com/pricing. Start free, set the refresh to daily, read the logs. If you outgrow ten calls, that is what Pro is for.


Was this useful? Rate this post with the widget at the bottom of the page. We read every response.




Every indicator in this post is in the feed. Free.

1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.



Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=what-a-free-key-can-run-with-edge-shield-and-what-99-buys-that-s-the-business-model



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page