Provenance page - what we require, and what we check

Where our IPs come from

Every proxy provider routes your traffic through someone else's IP address. The question that matters is whose, and how they got it. Our answer: we physically own and operate the modems our carrier IPs run on, and peer supply beyond that comes from partners who sign our agreement and pass checks we run on our own servers. Below is what we require, what we check, and what we do not yet verify.

Two supply sources. Owned hardware on real mobile carriers, plus peer supply from partners who must have the informed consent of device owners, sign an agreement in their legal name and declare where their supply comes from.

Source one: modems we physically own and operate

The core of our network is physical modems we own on real mobile carriers. We bought the hardware, we installed the SIM cards, we run the racks. When your request exits through one of these IPs, it exits through a device we control end to end - your traffic enters at gw.proxies.sx and leaves on a carrier connection we can point to on a shelf.

That means there is no mystery middle layer: no aggregator we license IPs from, no upstream reseller whose sourcing practices we have to take on faith. If you want to see how requests are routed across the fleet, thepool gatewaypage explains the mechanics.

Source two: peer supply - what we require, and what we check

Beyond our owned modems, partners can connect Android phones, Linux or Windows devices to the network. That supply is governed by a published contract (agents.proxies.sx/peer/skill.md).

What we require

  • Informed consent of the owner of every device that shares bandwidth.
  • A signed partner agreement in the supplier's own legal name, as an individual or a company.
  • An account-linked API key. Anonymous registration does not qualify a device for listed customer traffic.
  • A supply-source declaration: device owners or upstream suppliers, apps and installation channels, country and network mix, and how permission is obtained and withdrawn.

What we check

  • Server-side ASN classification of every IP as mobile carrier, residential or datacenter. The type a device reports about itself is ignored.
  • Datacenter IPs are rejected; only residential and mobile IPs can be listed.
  • Hourly re-verification of listed devices, and unlisting after an hour offline.

What we do not claim: submitted declarations are not independently verified KYC or proof of consent. Identity and business verification is being prepared separately. We do not publish the peer fleet's size or exit IPs.

To see exactly what the software does on a supplier's device, read what runs on my device. To supply bandwidth yourself, start at /earn.

The contrast: pools of unknown provenance

Much of the residential proxy market works differently. Large pools aggregate IPs they do not control - bought from third-party suppliers, harvested through bundled SDKs, or resold through chains of brokers. Some of those IPs were obtained cleanly; some were abused or enrolled without meaningful consent. The operator often cannot tell you which is which, and neither can you. That is not a performance problem - it is a provenance problem, and it lands on the customer whose traffic was routed through it.

Aggregated pool of unknown provenancePROXIES.SX supply
Who controls the exit deviceUnknown - often a broker chainUs (owned modems) or a supplier under a signed agreement
How the IP was obtainedBought / bundled / resold - varies per IPHardware we purchased, or a declared supply source
IP type checkOften self-reportedServer-side ASN classification; datacenter rejected
Whose consent backs the supplyOften unverifiableOurs (we own it), or device owners' informed consent required by contract
Independent KYC of suppliersVariesBeing prepared; declarations are not yet independently verified

Why this page exists: a note on July 2, 2026

In July 2026, the FBI seized the domains of a major residential proxy provider after its supply was tied to a ~2-million-device botnet, as reported by Krebs on Security and The Register. We take no pleasure in that - it was a bad week for a lot of teams who did nothing wrong except trust a supplier.

The lasting lesson is not about one company. It is that every customer of an opaque pool inherited a provenance question overnight: where was my traffic actually routed, and would I be able to prove it was clean? Verifiable sourcing is the only answer that survives that question, which is why we publish what we require and what we check.

Our honest limit: our owned modems do not cover every country, so peer supply extends coverage, and supplier declarations are not yet independently verified. On raw IP volume and enterprise compliance certifications, a giant like Bright Data or Oxylabs is still bigger - if that is what you need, they are the closer fit and we will say so. What we offer is owned hardware plus published supply requirements - and if a supplier outage broke your pipeline, our Data Works team can rebuild and run it for you while you regroup.

Simple pricing

The same IPs are available self-serve from $4/GB, down to $2.40/GB at volume. Endpoints, rotation and support are free - you pay only for the GB you use, and GB never expire. If you would rather have the pipeline built and run for you, scope a Data Works project instead.

Pricing verified July 2026.

Frequently asked questions

What is the difference between owned modems and a typical residential pool?

We physically own and operate the modems our carrier IPs run on, all on real mobile carriers. A typical residential pool aggregates IPs it does not control, often bought from third-party suppliers or SDK bundles, so the operator cannot see how each IP was obtained.

What do you require from peer suppliers?

Suppliers may share bandwidth only from devices whose owners have given informed consent. They sign the partner agreement in their own legal name, connect with their own account-linked API key, and declare where their supply comes from: device owners or upstream suppliers, apps and installation channels, country and network mix, and how permission is obtained and withdrawn.

What do you check?

IP type is classified on our servers by ASN; the type a device reports about itself is ignored. Datacenter IPs are rejected for listing. Listed devices are re-verified hourly and unlisted after an hour offline.

Are supplier declarations independently verified?

Not yet. Submitted declarations are not independently verified KYC or proof of consent. Identity and business verification is being prepared separately. We would rather say that plainly than overstate it.

Why does provenance matter now?

In July 2026, the FBI seized the domains of a major residential proxy provider after its supply was tied to a ~2-million-device botnet, as reported by Krebs on Security and The Register. Every customer of a pool with opaque sourcing inherits that kind of provenance and compliance question.

Ask us how our supply is sourced.

Owned modems on real carriers, plus peer supply under published requirements and server-side checks. If provenance matters to your compliance team, bring them to the call.