A precision inspection gauge and a stamped quality-control checklist on a matte charcoal workbench with orange edge lighting, representing a quarterly network audit.
All Posts

Q3 2026 Network Integrity Update: SOC 2, GDPR, and Customer Controls

Franklin Uche
Franklin Uche · Community Lead
Open markdown

This is Massive's first quarterly network integrity update. Our earlier transparency report on how the opt-in network works explained the model. This series tracks it over time.

Each edition answers the same three questions: which attestations Massive holds and where you can check them, how big the network is and how we count it, and which traffic controls customers have. We link to a public, third-party page wherever one exists. Where a claim is ours alone, we say so, and where something is still in progress, we say that too.

Key Takeaways
  • Massive has completed a SOC 2 Type I audit, with a Type II audit listed as in progress on the public Massive Trust Center. Its AppEsteem certification is on AppEsteem's certified-apps list, and Massive is a listed AMTSO member.
  • The Monetization SDK privacy policy lists GDPR and CCPA among the compliance standards the SDK meets.
  • The network counts devices, not IPs: over 1,000,000 verified residential devices per the public docs, in 195+ countries.
  • Documented controls include per-sub-account session limits and 90-day daily usage reporting for resellers, plus a 1,000-domain blocklist on each Residential account.

Why publish a quarterly network integrity update?

Buyers have more reason to ask where residential traffic comes from than they did a year ago. In January 2026, Google's Threat Intelligence Group said it had disrupted one of the largest residential proxy networks in the world. It reported that the network's SDKs had been used to add devices to botnets, and that it saw over 550 threat groups using the network's exit nodes in a single seven-day period (Google Cloud Blog, 2026). That moved device sourcing from a niche question to a procurement question.

"Trust us" doesn't answer procurement questions.

A dated report with links does, because it gives a security reviewer something to check and gives us a record to be held to next quarter.

What can you verify about Massive today?

As of this update, Massive has four items on public pages, plus a SOC 2 Type II audit in progress. The Massive Trust Center lists a completed SOC 2 Type I audit by Zero Day CPA, with a SOC 2 Type II audit marked as in progress. AppEsteem certification is listed on AppEsteem's certified-apps directory. GDPR and CCPA compliance is our own statement, made in our Monetization SDK privacy policy, and Massive Computing appears on the AMTSO members list.

Item What it covers Where to check
SOC 2 Type I (completed) An independent auditor's report on whether security controls are designed correctly at a point in time trust.joinmassive.com
SOC 2 Type II (in progress) Tests whether those controls actually operated over a review window Listed as in progress on trust.joinmassive.com
AppEsteem certification Checks against AppEsteem's published requirements on disclosure, consent, and uninstall AppEsteem certified list
GDPR + CCPA compliance EU and California privacy law: consent, data minimization, and user rights over personal data Stated in our Monetization SDK privacy policy
AMTSO membership Membership in the Anti-Malware Testing Standards Organization, the industry body working on fair, transparent security-product testing AMTSO members list

What's the difference? SOC 2 is an attestation framework defined by the AICPA, and it comes in two report types. A Type I report checks that controls are designed correctly on one date. A Type II report checks that they actually worked across a review window, which is the stronger evidence for a vendor that routes your traffic every day. That's why we list ours as in progress rather than rounding it up. We'll update this table in the edition after the Type II period completes.

What does "GDPR compliant" mean for Massive?

GDPR has no single pass-or-fail certificate that a vendor can hang on the wall. It's part of the EU's legal framework for data protection, a set of obligations: a lawful basis for processing, data minimization, and user rights like access and deletion. When any vendor, including us, says "GDPR compliant," treat it as a claim to test, not a badge.

So here is what ours rests on. Massive's Monetization SDK privacy policy lists GDPR and CCPA, along with Brazil's LGPD and India's ITA-2000, as compliance standards the SDK meets. It also spells out what the SDK does not collect: no names, email addresses, location data, browsing history, or files. IP addresses are used for network routing only and are not stored.

For the supply side of our network, the relevant obligation is consent. The Massive SDK documentation makes app partners responsible for making sure users "are prompted with clear terms before opting in," and that they can then pause, opt out, and see how much of their device's resources the SDK uses.

That enrollment step is also what AppEsteem's certification requirements focus on: what an app discloses before it installs, how it asks for consent, and whether users can easily disable or uninstall it. We describe the step in more detail in what "ethically sourced" actually means for a web access network.

Here's the useful test for any vendor: ask which third party has looked at the moment a device joins the network. For Massive, that third party is AppEsteem. Security audits cover how a company runs its systems. They usually don't cover whether the person whose phone carries your request agreed to it.

AMTSO membership is a different kind of signal. It places Massive in the industry body working on fair, transparent testing of security products. It's a membership, not an audit of our network.

How big is the network, and how do we count it?

Massive's public docs describe the residential network as "over 1,000,000 verified residential devices" across 195+ countries (Residential Proxies introduction).

We report devices, not IPs, on purpose. One residential device can show up as anywhere from 1 to 15 IP addresses in a day, depending on the device type and how its owner uses it. An IP count over any window mostly measures how long you counted. We explained this in more depth in why more IPs doesn't mean a better proxy network.

Which traffic controls protect network integrity?

The controls below let customers cap and audit their own traffic. Each is live in the public documentation as of this edition, with a link to the exact behavior.

Reseller controls: session limits and daily usage

Resellers get two documented levers for each sub-account. The first is a session ceiling. A reseller can set a traffic limit, a duration limit, or both on a sub-account's sessions, and the proxy disconnects once either limit is hit. Traffic limits start at 1,000 bytes, and duration limits start at one second (Update session limit).

The second is daily usage reporting. One API call returns per-day traffic, total requests, and successful requests for a single sub-account, over up to 90 days. The data comes from hourly rollups and runs from April 10, 2026 onward (Get daily account usage). Together, the two let a reseller set a limit, then confirm from the usage record that each sub-account stayed inside it.

Domain blocklists on Residential Proxies

Each Residential account can block up to 1,000 domains in the dashboard, with wildcard support. (Reseller sub-account blocklists set through the API are a separate control, capped at 100 domains.) Blocked requests return error 452 (Disallowed Content). Admins can apply global blocklists that override personal settings. These sit on top of content categories Massive blocks for every account at the network layer (Domain blocking).

Why does a transparency report spend this much space on limits? Network integrity depends on customers being able to see and cap their own usage. Session ceilings and per-day reporting let a reseller prove what its sub-accounts did, not just what they paid for.

What comes next

This edition covers what we can link to today. Future editions will update the SOC 2 Type II status and add any new controls as they reach the public docs.

For the background on how opt-in enrollment works end to end, read how Massive's opt-in network works. For a vendor-evaluation checklist, see proxy vendor compliance: SOC 2 and GDPR.

The bottom line

  • SOC 2 Type I is complete and Type II is in progress; both statuses, and AppEsteem, are checkable on public pages.
  • GDPR and CCPA compliance is stated in our Monetization SDK privacy policy, and Massive is a listed AMTSO member.
  • GDPR is an obligation, not a badge. Ask any vendor how consent gets captured.
  • The network is counted in devices: over 1M verified, per the docs.
  • Network integrity also rests on customer controls: session ceilings, 90-day daily usage for resellers, and 1,000-domain blocklists on Residential.

Sources

Frequently Asked Questions

Is Massive SOC 2 certified?+

Massive has completed a SOC 2 Type I audit by Zero Day CPA, and a Type II audit is listed as in progress on trust.joinmassive.com. Strictly, SOC 2 isn't a certification. It's an independent auditor's report, and the Type II version adds evidence that controls worked over time.

Is Massive GDPR compliant?+

Massive states that it is. Our Monetization SDK privacy policy lists GDPR and CCPA among the compliance standards the SDK meets. Because GDPR has no certificate, the testable parts are what the SDK collects and how consent is captured. The policy states that the SDK collects no names, emails, location data, or browsing history, that participation is "100% opt-in," and that users can opt out, pause, or uninstall at any time.

How can I verify Massive's AppEsteem certification?+

AppEsteem lists certified vendors publicly. Massive appears on AppEsteem's certified-apps directory under vendor code MSSIV. AppEsteem's published requirements cover what an app discloses before install, how it asks for consent, and whether users can uninstall it, which is the step that matters for how residential devices join a network.

How many devices are in the Massive network?+

Massive's public documentation describes over 1,000,000 verified residential devices across 195+ countries. Massive reports devices rather than IPs because each device can show up as 1 to 15 IPs a day.

Can I stop my traffic from reaching specific sites?+

Yes. Each Residential account can block up to 1,000 domains, including wildcards, and blocked requests return error 452. Resellers get two more levers through the API: a sub-account blocklist of up to 100 domains, and caps on each sub-account's session traffic and duration.