Trust · sourcing
Where residential and mobile addresses come from
Each statement on this page is written so a reviewer can ask for the evidence behind it. Where we cannot yet supply evidence, we say so under the heading at the end.
Policy
- Informed consent. Participants opt in through partner applications, shown in plain language that their connection will carry other people’s traffic. Consent is a standalone choice, not a clause inside unrelated terms.
- Compensation. Participation is rewarded, and the participant is told how.
- Withdrawal. A participant can leave at any time, and their device leaves the pool.
- Partner control. Supply partners are bound by contract to these conditions. We ask partners for the consent text they show, and we may end a partnership that fails the policy.
- Static addresses. ISP and datacenter addresses are leased from registered providers and carry the provider name in public whois records, which anyone can check.
Prohibited channels
- Addresses obtained through malware or software that hides its network-sharing function.
- Compromised devices, including routers reached through default credentials.
- Botnet infrastructure, however it is described commercially.
- Bundled installers in which the user did not knowingly agree to share bandwidth.
- Pools bought from brokers who cannot show how the addresses were acquired.
- Addresses resold from another provider's network.
Evidence you can ask for
- The participant-facing consent text as displayed.
- The list of supply partners and the conduct clause in their contracts.
- Our acceptable-use policy and abuse-handling process.
What we do not yet have
- No third-party audit of sourcing has been completed and none is claimed.
- No SOC 2 or ISO 27001 report is claimed.
- We do not currently offer a public self-check tool for whether an address belongs to our network.
If any of these is a requirement for you, tell us. Write to [email protected]. See also the questions to ask any vendor.