Back to Blog

Proxy Providers 2026: Who Will Be Denied Access? KYC and AUP Comparison

IPRoyal updated its AUP on September 14, 2026, Bright Data has required a legal entity for new residential zones since July 7 and has closed mobile proxies for new clients. We compare what six major networks prohibit, what documents are requested upon entry, and which scenarios have ended up in the gray area.

📅September 17, 2026
Proxy Providers 2026: Who Will Be Denied Access? KYC and AUP Comparison

On September 14, 2026, IPRoyal released the sixth version of its Acceptable Use Policy. Two months prior, Bright Data restricted access to residential proxies for anyone unable to demonstrate a registered company. Even earlier, they quietly removed mobile proxies from sale and excluded the use of accounts on TikTok and Instagram from permitted scenarios. The proxy market in 2026 has changed the entry rules, and now "choosing a provider" is not about the price per gigabyte, but rather whether you will be allowed in at all and whether you will be cut off in a month.

Let's break it down: what exactly do six major networks prohibit, what documents do they require for entry, and which scenarios have fallen into the gray area.

Why Providers Suddenly Became Strict

The reason lies not in morality, but in law enforcement. The year 2026 was marked by high-profile seizures: after the IPIDEA case, the FBI targeted NetNut — domains netnut.io, proxyjet.io, and divinetworks.com were seized, which were part of the partner network supplying IP addresses. We discussed this story in detail in our article about the seizure of NetNut's infrastructure.

The conclusion drawn by the industry is simple: if a network does not have a documented answer to the question "who is your client and why do they need traffic," the next knock on the door will be at their address. Hence, KYC, scenario approvals, and the rewriting of acceptable use policies.

Criteria Worth Comparing

Price and pool size are what the provider shows themselves. However, everything usually breaks down on four other aspects:

  • Entry threshold. Is a registered company required, a corporate email domain, a compliance call, or a passport?
  • Scenario binding. Is a specific use case approved, and what happens if you go beyond its limits?
  • Prohibited categories of purposes. Banks, government sites, streaming, ticketing, app stores, email ports.
  • Attitude towards account management. The murkiest point — where "legal multi-accounting" ends and "fake profiles" begin.

Bright Data: The Highest Entry Threshold

Three changes occurred here, affecting different client groups.

Mobile Proxies Closed to New Clients

Since April 2026, it is impossible to purchase mobile proxies from Bright Data unless you had an active subscription before. The product page has been removed, and the pricing page returns a 404. There was no official announcement — neither a blog post nor a press release; all that is known has been gathered from support responses and observable changes on the site. Existing subscriptions continue to function, and new clients are offered residential and ISP proxies instead.

KYC for All New Residential Zones

As of July 7, 2026, every new residential zone requires verification. This rule applies to all subtypes: general rotating IPv4, Mega Pool (IPv4 and IPv6), IPv6, and dedicated residential proxies. What is required:

  1. Email on a corporate domain — free mailboxes are not accepted.
  2. Officially registered company.
  3. Funded balance — verification cannot be passed in trial mode.
  4. Description of the use case.
  5. Depending on the situation — a video call and an identity document.

Two consequences that are easy to overlook. First: zones created on or before July 7, 2026, continue to operate as before, and already verified clients retain access — meaning an old account has turned into an asset that cannot be reproduced. Second: personal projects are explicitly named — scraping "for hobby or pet project" is not included in the list of permitted uses.

Requests Outside Approved Scenarios Are Blocked

This is perhaps the most unpleasant aspect for practice. Government sites are closed across all networks without exception, and requests to domains and categories outside the approved use case are blocked. Expand parsing to a neighboring vertical — and you hit a wall that is repaired not by code, but by correspondence with compliance.

Additionally: in the updated policy from April 1, 2026, account management on social platforms, including TikTok and Instagram, is no longer listed as a supported scenario.

IPRoyal: The Freshest Policy and Most Specific Prohibitions

Version 6 has been in effect since September 14, 2026. Unlike the vague formulations of competitors, the scenarios are named explicitly here:

  • Social Networks. The creation and management of fake profiles and writing fake reviews are prohibited.
  • Multiple Accounts. Attempts to bypass verification and create multiple accounts for one person are prohibited.
  • Content Behind Barriers. Collecting data from behind a login, paywall, and DRM is not allowed.
  • Technical Restrictions of Platforms. Bypassing robots.txt and API limits is listed as a separate prohibition.
  • Advertising. Click-fraud — clicks on PPC ads by people, bots, or software.
  • Ports. Email ports — 110, 143, 993, 995 — are blocked.
  • Reselling. Reselling and sublicensing are prohibited.

Access to government sites and banks is granted only after identity verification. The wording regarding "multiple accounts for one person" refers to accounts with IPRoyal itself, but the point about fake profiles on social networks is written broadly — and it is this that turns part of SMM tasks into a risk zone, where the decision rests with the moderator.

SOAX: Verification Does Not End with Registration

KYC/KYB policy as of June 1, 2026. They collect a set of information more typical for a bank: identity and contact details of the owner and authorized representatives, company registration data, tax identification number, information about beneficial owners, copies of documents. The specific volume depends on the level of verification, type of legal entity, and jurisdiction.

A key feature is that verification can be initiated at any time, not just during onboarding: upon change of ownership or control, change of representatives, change of business activity, or payment method. Additionally, work is limited to "pre-approved ethical scenarios," and some advanced targeting filters are only unlocked after KYC.

Oxylabs: Multi-Level KYC, Older Policy than Others

Clients are divided into stages based on automatic and manual risk assessment: depending on factors, verification of identity, a compliance call, and a risk questionnaire may be required. If the scenario appears unethical or suspicious, the service is simply denied.

The Acceptable Use Policy itself is dated June 25, 2024, and compared to IPRoyal, it sounds general: malicious software, hacking and bypassing protection, spam, providing false information, bots for ticket purchasing, generating invalid advertising traffic are prohibited. Additionally, one cannot violate the terms of use of target sites, collect non-public data without permission, and sensitive categories such as medical data and information about children are restricted. Categories of purposes are limited: email, banking, and government sites. There are no direct mentions of social networks and account management in the document — meaning the issue is resolved at the scenario assessment stage, not by the text of the policy.

Decodo: Entry Filter and Blocklist of Targets

Each new client undergoes automatic internal checks during registration, followed by third-party anti-fraud screening, assessing the declared intent of use. If necessary, KYC steps and document verification through an external provider are added. Metadata of connections is processed, including to identify requests to prohibited targets.

The list of closed categories at Decodo is broader than average: banking sites, government portals, streaming platforms, app stores, and ticketing services.

Summary: What Is Closed Where

  • Working with social media accounts: Bright Data — excluded from supported scenarios (since 01.04.2026); IPRoyal — prohibition on fake profiles and reviews (v6, 14.09.2026); Oxylabs and SOAX — not mentioned in policy texts, resolved during scenario approval; Decodo — social networks are not included in the blocklist.
  • Requirement for a legal entity: Bright Data — mandatory for new residential zones; SOAX — registration data and beneficiaries; Oxylabs — based on risk level; Decodo and IPRoyal — verification by trigger (documents for banks and government sites at IPRoyal).
  • Personal and small projects: explicitly excluded at Bright Data; at others, depend on passing screening.
  • Streaming and app stores: blocked at Decodo; absent in explicit lists at others.
  • Email ports: closed at IPRoyal; email sites — a restricted category at Oxylabs.
  • Government sites: completely closed at Bright Data, in restricted categories at Oxylabs and Decodo, access after ID verification at IPRoyal.
  • Mobile proxies: Bright Data no longer sells to new clients; the offer has shifted to Oxylabs, Decodo, SOAX, and IPRoyal.

What to Do About This in Practice

Three situations where the new rules disrupt the workflow, and what makes sense to do in advance.

You Manage Client Accounts on Social Media

This is the most vulnerable scenario. A formally legal task — an SMM agency with access from clients — is described in the policies using the same words as manipulation. Check not the marketing page "proxies for Instagram," but the AUP text, and if the scenario is not described in it, ask support in writing. A response in correspondence is the only thing to reference in case of a block. For selecting a network for the task, our proxy provider selection checklist will be useful: it discusses the source of IP, pool tests, and billing transparency.

You Scrape and Plan to Expand the List of Targets

The "approved scenario" model means that going beyond its limits is not a technical error, but a block on the provider's side. Before purchasing traffic, clarify whether the entire vertical is approved or specific domains, and how long re-approval takes. And keep in mind the prohibition on collecting from behind a login and bypassing API limits — this is now explicitly stated as a minimum by at least one major network.

You Work as an Individual or Small Team

The upper tier of the market is closing off to you: corporate email, legal entity, compliance call, minimum deposits. There remains a segment where entry does not require company registration and scenario approval — but even there, it is wise to read the policy before payment. For example, our residential proxies cost $2.7 per gigabyte, mobile — $3.8, datacenter — $1.5, payment is based on actual traffic, and purchase does not require use case approval from the compliance department.

Conclusion

The year 2026 has divided the market not by price, but by entry threshold. At the top are networks that sell traffic as a corporate service: legal entity, approved scenario, blocking everything outside of it. Below are providers where verification by trigger is sufficient. The practical takeaway is this: the date of the Acceptable Use Policy version now needs to be watched as closely as the price per gigabyte. For IPRoyal, it changed on September 14, for Bright Data, the entry rules were rewritten on July 7, and for SOAX — on June 1. Infrastructure that was legally purchased yesterday may be outside the policy the day after tomorrow — and it is better to find out about this before data collection stops.