Compliance · 6 min read · 2026-10-05

Questions to ask any proxy vendor about IP sourcing

A checklist for procurement and security reviewers: consent, compensation, withdrawal, customer vetting, and what evidence to request.

Residential and mobile proxies route traffic through devices owned by other people. Whether those people knew, agreed and were paid is a supply-chain question, and increasingly it is a procurement one. Vendors answer it with marketing. The questions below are meant to elicit answers that can be checked.

Consent

  • Who is the participant, and what exactly are they shown before their device joins the network?
  • Is consent a standalone screen, or a clause in terms of service for an unrelated app?
  • Can a participant see when and how their bandwidth is used?

Compensation and exit

  • How is a participant rewarded, and is that disclosed to them?
  • How does a participant leave, and how quickly does their device leave the pool?

Supply-chain control

  • Does the vendor source directly, or through resellers and SDK partners? If partners, which ones, and under what audit rights?
  • Does the vendor publish a way for anyone to check whether an address belongs to its network?

Customer vetting

The other half of a clean supply chain is who buys. Ask what a new customer is asked before access is granted, who can refuse an account, and what happens when traffic is reported as abusive.

Evidence to request

  • The participant-facing consent text, as shown.
  • The partner list and the audit clause in partner contracts, redacted as needed.
  • The acceptable-use policy and the abuse-handling process.
  • Any third-party attestation, with its scope and date.

We publish our own answers to these on the sourcing and KYC pages, and we describe what we do not yet have as plainly as what we do.

Test it on your own targets.

Create an account, run the measurement harness against your real workload, and read the numbers before you commit to anything.