Sourcing and compliance
Where our addresses come from, and how you can check
Every proxy provider says its network is ethically sourced. The claim is worth exactly as much as the evidence behind it, so this page is organised around what we can hand you rather than what we can assert. Each section below names the document that backs it and who can read it.
What a chain of custody actually contains
This is the record we return when you name an address. Every field exists because a procurement reviewer, an auditor, or a regulator has a reason to ask for it. Nothing in it depends on trusting us — each line points at a document or a timestamp.
- pool
- res-eu-west
- exit_ip
- 185.xxx.xxx.42
- asn
- AS12345 · residential ISP
- acquisition
- consented_sdk · partner-0114
- disclosure
- in_app_notice + settings_toggle
- consent
- 2026-04-02 · renewed 2026-07-02
- compensation
- revenue_share · partner_paid
- attestation
- PF-SRC-2026-Q2
- withdrawal
- removed in under 60s
The named pool the address serves, so audit scope is unambiguous.
Masked in samples. Unmasked in the record issued to you.
The network operator, confirming the address is what we sold you.
How the address entered the network, and through which partner.
What the peer was shown, and where they can change their mind.
When consent was given, and when it was last reaffirmed.
That the peer received something. Unpaid supply is a red flag.
The audit cycle in which this partner's records were reviewed.
How fast the address leaves rotation when consent is withdrawn.
Records are generated per address, on request, for any address active in your pools. Values above are illustrative; the schema is not.
Every peer address enters the network through a disclosed, compensated opt-in.
Residential and mobile peers reach us through partner applications. Before a device joins, the person using it is shown a plain-language notice explaining that their connection will be used to route traffic, and they must act to accept it. The choice is reversible from the application's own settings, not buried in a support flow. Partners compensate peers, in cash, in credit, or by removing advertising. We review each partner's disclosure text and consent flow before onboarding and again at every audit cycle, and we test the withdrawal path ourselves.
Evidence
Partner disclosure texts and consent-flow screenshots, per pool.
A third party reviews our acquisition records twice a year, and you can read the result.
Twice yearly an independent assessor samples addresses across every pool and traces each one back to its acquisition record, its partner, its disclosure, and its consent timestamp. They test whether withdrawal actually removes an address from rotation, and they report exceptions rather than a pass mark. The resulting attestation is available under NDA to any customer or prospect at evaluation stage. SOC 2 Type II is a separate track, currently in its observation window, with the report expected in Q1 2027.
Evidence
Sourcing attestation, current cycle. Available under NDA.
We say in writing where addresses may come from, and where they may not.
Our supply-chain policy is a public document, not a sales asset. It names the acquisition channels we permit — consented SDK partners, direct ISP leases, registered ranges we announce ourselves, and modems we operate — and it names what is prohibited: addresses obtained through malware, bundled software the user did not knowingly install, compromised devices, botnet infrastructure, or any resale chain we cannot trace to its origin. We do not buy pools from brokers. Where we cannot establish how an address was acquired, we do not sell access to it.
Evidence
Supply-chain policy, versioned and dated, published in full.
We verify who is buying, not only where the addresses came from.
Provenance without customer diligence is half an answer. Every account is verified against a registered legal entity with a named signatory before traffic is enabled. We screen against sanctions and PEP lists at onboarding and continuously thereafter, and we decline sectors and use cases our acceptable use policy prohibits. Free trials do not exist; evaluations run under the same verification as paid accounts. This makes us slower to sign than some providers, which is the point.
Evidence
KYC procedure summary and sanctions-screening policy.
A DPA with standard contractual clauses is available before you sign, not after.
We execute a data processing addendum incorporating the EU standard contractual clauses and the UK international data transfer addendum. It records what we process, for how long, where it sits, and which sub-processors are involved — that list is published and versioned, with 30 days' notice before anything changes. Traffic metadata is retained for 30 days to support abuse investigation and billing disputes, then deleted. We do not inspect, store, or sell request payloads.
Evidence
DPA, SCCs, sub-processor list, and retention schedule.
Reports get a human, a case number, and a deadline.
Abuse reports reach a staffed queue, not a form that disappears. Each gets a case number and an acknowledgement within four hours. We can attribute traffic to an account and, where a report is substantiated, suspend it — most providers can do the first and are slow to do the second. Suspension decisions and their outcomes are logged, and the aggregate numbers appear in each audit cycle.
Evidence
Abuse-handling procedure and current-cycle case statistics.
What will never be in our network
A sourcing policy is only meaningful where it costs the provider something. These exclusions remove supply we could otherwise sell, and they are the reason our residential floor is not the cheapest on the market.
- Addresses obtained through malware or unwanted software of any kind
- Bundled installers where the user did not knowingly accept bandwidth sharing
- Compromised devices, including routers reachable on default credentials
- Botnet infrastructure, rented or owned, under any commercial framing
- Pools bought from brokers who cannot evidence how the addresses were acquired
- Addresses resold from another proxy network's supply
- Devices belonging to minors, where a partner cannot enforce age gating
Where we cannot establish how an address was acquired, we do not sell access to it. That rule has no exception for volume, price, or urgency, and it is the one thing on this page we would not negotiate.
Every document, and who can read it
Send this to your procurement or security team. The grid states where each credential stands today; the table below lists the artefacts behind them. If something they need is missing, say so and we will tell you whether it exists.
Sourcing attestation
Independent review of acquisition and consent records across every pool.
Current cycle · under NDA
GDPR
DPA incorporating the EU standard contractual clauses, available before signature.
Available now
UK IDTA
International data transfer addendum, executed alongside the SCCs.
Available now
PCI DSS
Card details never touch our systems. Payments run through a Level 1 service provider.
Handled by processor
SOC 2 Type II
Security, availability, and confidentiality. Observation window is open.
Report expected Q1 2027
ISO 27001
Scoping complete. Certification audit not yet booked.
Roadmap
| Document | Covers | Availability |
|---|---|---|
| Supply-chain policy | Permitted and prohibited acquisition channels, in full | Public |
| Sourcing attestation | Independent review of acquisition and consent records | Under NDA |
| Chain-of-custody record | Per-address provenance, for addresses in your pools | On request, any time |
| Data processing addendum | EU SCCs, UK IDTA, retention schedule | Before signature |
| Sub-processor list | Every third party in the processing chain, versioned | Public, 30 days' notice of change |
| Acceptable use policy | Prohibited uses and enforcement process | Public |
| KYC and sanctions procedure | Customer verification and continuous screening | Under NDA |
| SOC 2 Type II report | Security, availability, confidentiality | Expected Q1 2027 |
Ask us the hard version
These are the four questions we think every proxy buyer should be asking, of us and of anyone else on the shortlist. We would rather you ran them across the whole market than took our word for the outcome.
- 01Name every channel through which an address can enter your network.
- 02Show me the disclosure a peer sees, and the control that reverses it.
- 03Who audited that, when, and may I read the exceptions they found?
- 04Trace one address I choose, at random, back to its acquisition record.
Compliance questions go straight to the team that owns the answers: [email protected].
Trace an address before you buy anything
Send us an address from a pool you already run, or ask us to pick one at random from ours. You will get the full record back, and you can judge the standard for yourself.
One business day, from a named engineer.