Trust · sourcing

Where residential and mobile addresses come from

Each statement on this page is written so a reviewer can ask for the evidence behind it. Where we cannot yet supply evidence, we say so under the heading at the end.

Policy

  1. Informed consent. Participants opt in through partner applications, shown in plain language that their connection will carry other people’s traffic. Consent is a standalone choice, not a clause inside unrelated terms.
  2. Compensation. Participation is rewarded, and the participant is told how.
  3. Withdrawal. A participant can leave at any time, and their device leaves the pool.
  4. Partner control. Supply partners are bound by contract to these conditions. We ask partners for the consent text they show, and we may end a partnership that fails the policy.
  5. Static addresses. ISP and datacenter addresses are leased from registered providers and carry the provider name in public whois records, which anyone can check.

Prohibited channels

  • Addresses obtained through malware or software that hides its network-sharing function.
  • Compromised devices, including routers reached through default credentials.
  • Botnet infrastructure, however it is described commercially.
  • Bundled installers in which the user did not knowingly agree to share bandwidth.
  • Pools bought from brokers who cannot show how the addresses were acquired.
  • Addresses resold from another provider's network.

Evidence you can ask for

  • The participant-facing consent text as displayed.
  • The list of supply partners and the conduct clause in their contracts.
  • Our acceptable-use policy and abuse-handling process.

What we do not yet have

  • No third-party audit of sourcing has been completed and none is claimed.
  • No SOC 2 or ISO 27001 report is claimed.
  • We do not currently offer a public self-check tool for whether an address belongs to our network.

If any of these is a requirement for you, tell us. Write to [email protected]. See also the questions to ask any vendor.