Skip to content

Sourcing and compliance

Where our addresses come from, and how you can check

Every proxy provider says its network is ethically sourced. The claim is worth exactly as much as the evidence behind it, so this page is organised around what we can hand you rather than what we can assert. Each section below names the document that backs it and who can read it.

§ 01The record

What a chain of custody actually contains

This is the record we return when you name an address. Every field exists because a procurement reviewer, an auditor, or a regulator has a reason to ask for it. Nothing in it depends on trusting us — each line points at a document or a timestamp.

Provenance record
PF-CoC-2026-0714-EUW
pool
res-eu-west

The named pool the address serves, so audit scope is unambiguous.

exit_ip
185.xxx.xxx.42

Masked in samples. Unmasked in the record issued to you.

asn
AS12345 · residential ISP

The network operator, confirming the address is what we sold you.

acquisition
consented_sdk · partner-0114

How the address entered the network, and through which partner.

disclosure
in_app_notice + settings_toggle

What the peer was shown, and where they can change their mind.

consent
2026-04-02 · renewed 2026-07-02

When consent was given, and when it was last reaffirmed.

compensation
revenue_share · partner_paid

That the peer received something. Unpaid supply is a red flag.

attestation
PF-SRC-2026-Q2

The audit cycle in which this partner's records were reviewed.

withdrawal
removed in under 60s

How fast the address leaves rotation when consent is withdrawn.

9 of 9 fields tracedchain complete

Records are generated per address, on request, for any address active in your pools. Values above are illustrative; the schema is not.

§ 03Independent audit of sourcing

A third party reviews our acquisition records twice a year, and you can read the result.

Twice yearly an independent assessor samples addresses across every pool and traces each one back to its acquisition record, its partner, its disclosure, and its consent timestamp. They test whether withdrawal actually removes an address from rotation, and they report exceptions rather than a pass mark. The resulting attestation is available under NDA to any customer or prospect at evaluation stage. SOC 2 Type II is a separate track, currently in its observation window, with the report expected in Q1 2027.

Evidence

Sourcing attestation, current cycle. Available under NDA.

§ 04Published supply-chain policy

We say in writing where addresses may come from, and where they may not.

Our supply-chain policy is a public document, not a sales asset. It names the acquisition channels we permit — consented SDK partners, direct ISP leases, registered ranges we announce ourselves, and modems we operate — and it names what is prohibited: addresses obtained through malware, bundled software the user did not knowingly install, compromised devices, botnet infrastructure, or any resale chain we cannot trace to its origin. We do not buy pools from brokers. Where we cannot establish how an address was acquired, we do not sell access to it.

Evidence

Supply-chain policy, versioned and dated, published in full.

§ 05KYC and AML on both sides

We verify who is buying, not only where the addresses came from.

Provenance without customer diligence is half an answer. Every account is verified against a registered legal entity with a named signatory before traffic is enabled. We screen against sanctions and PEP lists at onboarding and continuously thereafter, and we decline sectors and use cases our acceptable use policy prohibits. Free trials do not exist; evaluations run under the same verification as paid accounts. This makes us slower to sign than some providers, which is the point.

Evidence

KYC procedure summary and sanctions-screening policy.

§ 06Data processing, on paper

A DPA with standard contractual clauses is available before you sign, not after.

We execute a data processing addendum incorporating the EU standard contractual clauses and the UK international data transfer addendum. It records what we process, for how long, where it sits, and which sub-processors are involved — that list is published and versioned, with 30 days' notice before anything changes. Traffic metadata is retained for 30 days to support abuse investigation and billing disputes, then deleted. We do not inspect, store, or sell request payloads.

Evidence

DPA, SCCs, sub-processor list, and retention schedule.

§ 07Abuse handling with a clock on it

Reports get a human, a case number, and a deadline.

Abuse reports reach a staffed queue, not a form that disappears. Each gets a case number and an acknowledgement within four hours. We can attribute traffic to an account and, where a report is substantiated, suspend it — most providers can do the first and are slow to do the second. Suspension decisions and their outcomes are logged, and the aggregate numbers appear in each audit cycle.

Evidence

Abuse-handling procedure and current-cycle case statistics.

§ 08Exclusions

What will never be in our network

A sourcing policy is only meaningful where it costs the provider something. These exclusions remove supply we could otherwise sell, and they are the reason our residential floor is not the cheapest on the market.

  • Addresses obtained through malware or unwanted software of any kind
  • Bundled installers where the user did not knowingly accept bandwidth sharing
  • Compromised devices, including routers reachable on default credentials
  • Botnet infrastructure, rented or owned, under any commercial framing
  • Pools bought from brokers who cannot evidence how the addresses were acquired
  • Addresses resold from another proxy network's supply
  • Devices belonging to minors, where a partner cannot enforce age gating

Where we cannot establish how an address was acquired, we do not sell access to it. That rule has no exception for volume, price, or urgency, and it is the one thing on this page we would not negotiate.

§ 09Register

Every document, and who can read it

Send this to your procurement or security team. The grid states where each credential stands today; the table below lists the artefacts behind them. If something they need is missing, say so and we will tell you whether it exists.

Sourcing attestation

Independent review of acquisition and consent records across every pool.

Current cycle · under NDA

GDPR

DPA incorporating the EU standard contractual clauses, available before signature.

Available now

UK IDTA

International data transfer addendum, executed alongside the SCCs.

Available now

PCI DSS

Card details never touch our systems. Payments run through a Level 1 service provider.

Handled by processor

SOC 2 Type II

Security, availability, and confidentiality. Observation window is open.

Report expected Q1 2027

ISO 27001

Scoping complete. Certification audit not yet booked.

Roadmap

Compliance documents, coverage, and availability
DocumentCoversAvailability
Supply-chain policyPermitted and prohibited acquisition channels, in fullPublic
Sourcing attestationIndependent review of acquisition and consent recordsUnder NDA
Chain-of-custody recordPer-address provenance, for addresses in your poolsOn request, any time
Data processing addendumEU SCCs, UK IDTA, retention scheduleBefore signature
Sub-processor listEvery third party in the processing chain, versionedPublic, 30 days' notice of change
Acceptable use policyProhibited uses and enforcement processPublic
KYC and sanctions procedureCustomer verification and continuous screeningUnder NDA
SOC 2 Type II reportSecurity, availability, confidentialityExpected Q1 2027
§ 10Diligence

Ask us the hard version

These are the four questions we think every proxy buyer should be asking, of us and of anyone else on the shortlist. We would rather you ran them across the whole market than took our word for the outcome.

  1. 01Name every channel through which an address can enter your network.
  2. 02Show me the disclosure a peer sees, and the control that reverses it.
  3. 03Who audited that, when, and may I read the exceptions they found?
  4. 04Trace one address I choose, at random, back to its acquisition record.

Compliance questions go straight to the team that owns the answers: [email protected].

Trace an address before you buy anything

Send us an address from a pool you already run, or ask us to pick one at random from ours. You will get the full record back, and you can judge the standard for yourself.

One business day, from a named engineer.