Abstract Massive-branded illustration of a consent checkbox connecting to a distributed global device network, dark background with orange accent lines.
All Posts

Transparency Report: Massive's Opt-In Device Network

Franklin Uche
Franklin Uche · Community Lead
Open markdown

Every device on Massive's network is there because someone opted in, not because a device was compromised, bundled without disclosure, or swept up by a script. That's the single fact this report exists to back up with specifics rather than assert as a slogan.

Key Takeaways
  • Massive's network started as an app-monetization SDK: users traded idle device compute for premium features inside apps they already used, with the exchange disclosed up front.
  • The network now runs on real consumer devices in 195+ countries, measured in daily active devices (~1.3M DAU) rather than a static IP count, because residential IPs rotate constantly.
  • The network carries SOC 2 audit, GDPR compliance, and AppEsteem certification, with a full audit trail from source device to individual request.
  • Sourcing integrity, not privacy, is the honest differentiator: the audit logging behind Massive's SOC 2 program is what lets a device's opt-in actually be traced and verified, not a claim that no records exist at all.

Where the network actually came from

Massive didn't start as a proxy company that went looking for IP supply after the fact. It started as a monetization SDK: an app could offer users something (premium features, an ad-free tier, extra in-app currency) in exchange for the user's device contributing idle bandwidth to the network. The user saw the offer, agreed to it, and kept using their app. That's the origin point for every device currently in the residential proxy network.

That origin story is also what makes the compliance record behind it meaningful. Every device traces back through a disclosed SDK exchange, not an anonymous IP pool assembled after the fact. The audit logging that makes that traceability possible is part of Massive's SOC 2-audited security program, listed on its public Trust Center. What matters is that those controls connect a real device to a real consent event, not a blanket claim that no records exist.

What "opted in" actually means, mechanically

Consent here isn't a checkbox buried in a terms-of-service document nobody reads. It's structural to how a device joins the network at all: the app integrating the SDK discloses the exchange, the user accepts it to unlock whatever the app is offering, and the device only participates in the network for as long as that app remains installed and the user keeps that setting active. Uninstall the app, and the device leaves the network. There's no separate step where a user has to have known they were part of a residential proxy network by that name; they knew they were trading device resources for something the app offered, and that's the actual transaction being audited.

This is also why Massive doesn't sell on a device count. The unit Massive actually tracks and reports on is daily active devices, currently around 1.3 million, because that number reflects real, distinct participants rather than an address count that inflates or deflates based on network behavior that has nothing to do with supply.

The compliance record behind the sourcing claim

A consent-based origin story is only as good as the audit trail that can prove it, so here's what backs it:

  • SOC 2 audit. Massive's infrastructure and data handling practices are independently audited against the SOC 2 framework, the standard third-party attestation for how a service provider manages customer data and system security. The certification and the audit-logging controls behind it are listed on Massive's public Trust Center.
  • GDPR compliance. The network's data handling meets GDPR's requirements, which matters directly for any customer serving EU users or operating in the EU market themselves.
  • AppEsteem certification. AppEsteem is an independent certification body focused specifically on whether software behaves the way it discloses to end users. Certification here is a direct, third-party check on the consent claim, not a self-reported one.
  • Full audit trail from source to request. Every request that moves through the network traces back to a specific opted-in device, not an anonymous, unaccountable IP pool.

None of these are marketing badges collected after the fact. They're the specific mechanisms that let Massive say a device is opted-in and mean something falsifiable by it. We cover the full mechanics of that consent chain in rendering the web through consent, and the certification specifics in what compliance teams should ask a proxy vendor.

Why this is a recurring report, not a one-time claim

A sourcing claim made once and never revisited is worth less over time, not more. Networks grow, SDK integrations change, and compliance certifications get renewed on their own schedules. This transparency report format exists so that the sourcing claim keeps getting re-stated with current numbers rather than left to age as a static "About" page line that nobody checks again.

What this means if you're evaluating a web access vendor

If you're a compliance-sensitive buyer, an enterprise team, or anyone in finance or threat intelligence evaluating a proxy or web-access vendor, "ethically sourced" should be a question you can actually get an answer to, not a phrase you take on faith. Origin mechanism, certification, and traceability are the three things worth asking any vendor about directly: what the origin mechanism actually is (an SDK-based opt-in is a different model from an undisclosed bundling arrangement), which third-party audits and certifications back it up, and whether the vendor can trace a specific request back to a specific consenting device. A vendor that can answer all three has an "ethically sourced" claim you can actually verify. Our companion piece, what "ethically sourced" actually means for a web access network, walks through that evaluation in more depth.

The bottom line

Ethical sourcing, at Massive, isn't a phrase on a homepage. It's an SDK-based opt-in mechanism, a ~1.3M-device daily active network, and a compliance stack (SOC 2, GDPR, AppEsteem) built specifically to make that sourcing claim checkable rather than assumed. This report exists to keep restating that with current numbers, on a recurring basis, rather than once and done.

Frequently Asked Questions

Does Massive log what customers fetch through the network?+

Massive isn't a no-logs service, and it doesn't pretend to be. Proving a device opted in means keeping real records, not fewer of them. Audit logging and access-log management are active, SOC 2-audited controls on Massive's public Trust Center, the same records that trace a request back to the device that handled it. Massive's own FAQ draws the actual line: no browsing history, no file contents, no personal communications. The differentiator was never an absence of records. It's a trail you can verify.

What happens to a device if a user uninstalls the app that carries the SDK?+

The device leaves the network. Participation only continues while the app that carries the SDK integration remains installed and the user's setting stays active; there's no separate mechanism keeping a device in the pool after that.

Why does Massive report device counts instead of IP counts?+

Because IPs rotate as real users move across networks throughout the day, a static IP number is a poor measure of actual supply and is easy to inflate. Daily active devices is the unit that reflects real, distinct participants; one device typically produces multiple IPs per day depending on usage.