Proxy provider due diligence is the structured review a buyer runs before routing production traffic through a vendor's network: where the addresses come from, who else the vendor lets on, how it protects your data and credentials, and what happens to you if the vendor fails. The checklist below is grouped into seven areas and written to be pasted into a vendor review ticket. Each group opens with the reason it matters, because a checklist nobody understands becomes a checklist nobody enforces.
Why proxy vendors need their own checklist
Most vendor review templates were built for SaaS tools that store your data, and proxy provider due diligence needs more than they ask. A proxy provider is different in three ways. It carries your traffic rather than storing records. Its core supply, the addresses themselves, comes from a supply chain your standard questionnaire never asks about. And the legal risk in that supply chain can transfer to you: if the network is built on compromised devices, your requests were among the ones that used them.
This stopped being theoretical when a top-tier residential provider was seized by federal authorities in July 2026 after its network was found to be built on compromised devices. A seizure like that can end service overnight, freeze whatever balance a customer had prepaid, and leave every customer explaining to its own compliance team why vendor review did not catch it. The groups below are ordered by what that event exposed.
Two companion documents go deeper than a checklist can: the method for verifying a provider's IP sourcing and a ready-to-send proxy vendor security questionnaire.
Sourcing and supply chain
This is the group the seizure made mandatory. A proxy network is only as lawful as the least lawful way an address can enter it, and marketing copy is not evidence. The questions here are about records, not assurances.
- Public, versioned supply-chain policy naming every permitted acquisition channel
- Explicit prohibitions: malware, bundled installers without knowing consent, compromised devices, botnets, undocumented brokers, resold supply, minors' devices
- Independent sourcing attestation from the last 12 months, including scope, method and exceptions
- Attestation method includes sampling live addresses and tracing them to acquisition records
- Consent disclosure screenshots for each partner app category
- Documented peer withdrawal control and maximum time to removal from the pool
- Random-sample trace test run on addresses we selected, with results filed
- Datacenter ranges checked in RDAP and BGP; ISP ranges backed by lease or authorization letters
- Confirmation of whether any supply is bought from other networks, and evidence for each upstream source
Customer KYC, AML and acceptable use
A proxy network is shared infrastructure. Other customers' behavior determines whether the addresses you use are blocklisted, whether the vendor attracts regulatory attention, and whether the network survives. A vendor that lets anyone buy anonymously is also a vendor more likely to be used for fraud, which is exactly the traffic that gets networks investigated.
- Customer identity verification at signup, with stricter checks for invoiced or high-volume accounts
- Sanctions and PEP screening at signup and on a continuing basis, not only once
- Published acceptable use policy that names prohibited uses and the enforcement process
- Evidence of enforcement: how many accounts were suspended last year, and on what grounds, in aggregate
- Controls on high-risk targets (for example financial login pages, government services)
- Process for law-enforcement requests, and whether customers are notified where lawful
Security
A proxy vendor holds credentials that can spend your money and route traffic in your name, and it sees metadata about every request you make. The full question set is in the security questionnaire; the checklist items below are the minimum that should be answered before anything else.
- Current SOC 2 Type II report or ISO/IEC 27001 certificate, or a dated plan with the auditor named if in progress
- Multi-factor authentication and least-privilege access for vendor staff with production access
- Customer-side controls: separate credentials per team, scoped roles, per-credential revocation, IP allowlisting
- Credentials stored hashed or encrypted, never displayed in full after issue
- Encryption in transit for the dashboard, API and customer data at rest
- Penetration test within the last 12 months by an external party, with a summary available
- Documented vulnerability disclosure route
Data protection and the DPA
A proxy provider processes personal data on your behalf: at minimum the connection metadata about your requests, and possibly more depending on what you send through it. Under GDPR and similar laws you need processor terms in place before processing starts, not at renewal. The article on what a proxy provider DPA should cover walks through each clause.
- DPA available for review before signature, not only after
- Roles stated: which processing the vendor does as processor, and which as independent controller
- Categories of data listed, including whether request or response content is ever inspected or stored
- Traffic metadata retention period stated as a number of days
- Transfer mechanism for EU and UK data (SCCs, UK IDTA or addendum) incorporated
- Published sub-processor list with a notice period for changes and a right to object
- Breach notification commitment to you, with a stated maximum delay
- Deletion at termination, with written confirmation on request
Contract, SLA and exit terms
The seizure's most expensive lesson was about exit. Long notice periods, prepaid commitments and missing data export are all worth nothing once a vendor is gone, and they are hard to renegotiate once you depend on it. Negotiate exit before you need it, and read the proxy provider shutdown playbook for what to do in the first days if a vendor goes dark.
- No minimum term, or a term with termination for convenience on short notice
- Prepaid balances: refund terms on termination, and what happens to them if the vendor ceases trading
- Price change notice period, and whether promotional rates revert
- Data export: usage records, invoices and configuration available on request and at termination
- Termination rights on material breach, on sourcing misrepresentation, and on regulatory action against the vendor
- SLA definitions: what is measured, where, and what the credit is
- Right to suspend payment or terminate if the vendor cannot produce sourcing evidence it previously provided
Operational
These items decide what a bad day looks like. A vendor that takes days to acknowledge an abuse report will, eventually, have addresses you rely on blocked by the target. A vendor with no incident notification commitment will let you find out from your own error rates.
- Abuse reports acknowledged within a stated window, with a case number
- Security incident notification to customers within a stated window, with a named channel
- Status page or equivalent, with history
- Named technical contact, and the escalation path above them
- Change notification for gateway, authentication or targeting changes that could break integrations
- Support hours and languages that match where your team works
Financial and concentration risk
The last group of proxy provider due diligence is about you as much as the vendor. Ask what happens if this vendor disappears next week, and whether you could route around it in hours or in months. Concentration risk is not a reason to avoid a vendor; it is a reason to know your second source before you need it.
- Legal entity, jurisdiction, and ultimate ownership
- Years trading and, for large commitments, basic financial standing
- Share of our proxy traffic this vendor would carry; target maximum for a single vendor
- Second vendor identified and integration tested, even at low volume
- Our code reads proxy configuration from the environment, so switching is a configuration change
- Documented runbook for moving traffic, reviewed within the last year
The last three items are within your control, not the vendor's. Switching proxy providers without downtime covers how to keep that second path warm.
How ProxyForge fits this checklist
We built our compliance program so that each sourcing and data protection line in a proxy provider due diligence review has a document behind it. The supply-chain policy is public and versioned; the sourcing audit runs twice a year and the attestation is available under NDA; customers are screened against sanctions and PEP lists at signup and continuously; the DPA, with EU SCCs and the UK addendum, is available before you sign, alongside a published sub-processor list with 30 days' notice of change. Traffic metadata is kept for 30 days, and abuse reports are acknowledged within four hours with a case number. Our SOC 2 Type II observation window is open, with the report expected in Q1 2027.
The sourcing page lists each document and who can read it. If you are moving from an incumbent, the migration process lets you run both providers in parallel before you commit, which also leaves you with the tested second source this checklist asks for.