Follow

ThreatSTOP Maintenance Notification: Saturday, September 5, 2026

Dear Valued Customer,
We are planning a major infrastructure upgrade that will migrate our production systems to Amazon Web Services (AWS). This migration will improve the scalability, reliability, and resilience of our services.

Maintenance Schedule
The customer-facing portion of the migration is scheduled for: Saturday, September 5, 2026

Maintenance window: 8:00 a.m. to 8:00 p.m. Pacific Time
Services may be unavailable or operate with limited functionality at various times during this window. The full maintenance window is reserved to complete the migration, validate the new environment, and address any issues that arise.

Our team will closely monitor the new infrastructure throughout the following week.

Expected Service Impact
During the maintenance window:

  • Customer portals and most APIs will be placed in maintenance mode and will be unavailable.
  • Log collection will remain operational. However, collected logs will not be processed until the migration is complete.
  • Policy services will remain available, but feeds, targets, and policies will not be updated during the maintenance window.
  • CTP (web-enabled automation) services will remain available.
  • CheckIOC API will remain available, except that new user registrations will be temporarily disabled.
  • PhishSTOP will remain available for most of the maintenance window. We anticipate less than 30 minutes of downtime, although the exact timing cannot be confirmed in advance.

Customer Action
Most customers will not need to make any changes because the affected services are accessed through hostnames and updated IP addresses will be propagated through DNS. If a customer has specific rules in their firewalls to access logging or CTP services, they will need to add rules to allow the relevant IP addresses below.
 

Customers who have explicitly allowlisted or whitelisted the existing IP addresses for the Log Collector or CTP (web-enabled automation) service should add the following new addresses before the migration:

Log Collection (Hostname: logs.threatstop.com)

  • 34.213.141.115
  • 44.236.151.182
  • 54.203.73.206

CTP (for devices using we-enabled automation, Hostname: ts-ctp.threatstop.com

  • 184.34.179.11
  • 35.165.163.81
  • 54.71.54.210

Note that these are the old IP address ranges that are being deprovisioned. 
Hostname: logs.threatstop.com
IP range: 204.68.99.208/28
Outbound TCP port 443

Hostname: ts-ctp.threatstop.com
IP Range: 204.68.97.208/28
Outbound TCP port 5353

Policy service IP addresses will not change.
 

The CTP service will continue to support SSLv3 temporarily following the migration. We currently expect to discontinue SSLv3 support approximately 60 to 90 days after the migration, once affected customers have had sufficient time to update their systems. Additional notice will be provided before this change is made.

Our team will monitor customer devices following the migration to identify any interruption in log uploads or other service issues.

We appreciate your patience while we complete this important infrastructure upgrade. Please contact Customer Support with any questions or concerns.
 

Sincerely,
 

The ThreatSTOP Team

Was this article helpful?
0 out of 0 found this helpful

Comments