Web data collection runs on other people's connections. That fact deserves a straight answer rather than a marketing page, so here is ours: what cloro operates, what it buys, and what we look at before routing traffic through someone else's network. It's written to be forwarded to a security or procurement review as-is.
We run our own scraping stack. The API, the browser fleet, rendering, fingerprint matching, captcha handling, retries, and parsing are all ours. When you call the cloro SERP API or any of our AI-engine endpoints, that pipeline is what answers you.
We don't source our own IPs. We don't recruit peers, we don't operate a peer network, and we don't ship an SDK into consumer apps to acquire connections. This capacity comes from a vetted set of upstream providers.
That makes provider selection the whole question for us, not a footnote to it. The rest of this page is the work behind it: what we look for, what evidence we ask to see, and what we're willing to put in front of your procurement team.
Six things we work through before routing traffic through a network, and keep coming back to afterwards. They're the difference between a provider that has thought about where its supply comes from and one that would rather not be asked.
The person whose connection carries the traffic should have been told, in plain language, what they were signing up to.
Participation should buy something concrete — cash, credit, an ad-free tier, a paid app feature someone would otherwise pay for.
Leaving should be possible at any time, from the app or device someone joined through, without penalty and without having to email anyone.
Nothing sourced from botnets, malware, cracked apps, or devices enrolled without their owner's knowledge.
A sales rep's assurance is where the conversation starts, not where it ends.
Where a provider doesn't recruit peers itself, we want to know how the same obligations reach whoever does.
Every proxy vendor says its IPs are ethically sourced. What separates them is what they'll show you. These are the four kinds of evidence we ask for, in rough order of how much weight we give them. The linked documents are public examples of each type — they show the standard we're describing, not a list of who supplies cloro.
The EWDCI (Ethical Web Data Collection Initiative), run under the i2Coalition, certifies networks against a published code of conduct and lists its members publicly. Certification is the strongest single signal a provider can offer.
ethicalwebdata.comA written, public document setting out how peers are recruited, what they're shown at opt-in, how they're compensated, and how they leave. It's the difference between a claim and a commitment: once it's published, anyone can check it.
Example: Infatica's sourcing handbook (PDF)Where a provider recruits peers directly, we look for the SDK published under its own name and brand, with its own site and documentation — so someone who wants to find out what they joined actually can.
Example: ByteConnectSome networks publish a methodology document covering the same ground — network composition, consent flow, compensation model, and the compliance posture behind collection at scale. We read it, and we ask about whatever it leaves out.
None of this is a one-time gate. Certifications lapse, sourcing models change, and networks get acquired — so we go back to it rather than assuming that what was true when we onboarded a provider is still true now.
Sourcing is half the question. The other half is what a network gets used for once you have access to it, and that half is what a customer inherits.
No, and we're direct about it. We build and run the scraping infrastructure — the API, the browser fleet, rendering, fingerprinting, retries, and parsing — but we don't recruit peers, we don't operate our own residential or mobile peer network, and we don't bundle an SDK into consumer apps to acquire IPs. Residential and mobile capacity is bought from a vetted set of upstream providers, picked on how they source it and what they're able to show us.
No. EWDCI certification applies to the networks that actually recruit peers and operate pools, which isn't what cloro does. What we do is look for that certification — or documented equivalent evidence — from the providers we buy capacity from. If your review needs the certification status of a specific provider in our mix, ask us and we'll share it under NDA.
Our traffic is portable across providers by design, and no single one is load-bearing, so the practical answer is that traffic moves. That means we're never in the position of defending a supplier we've stopped believing because unwinding would break the product.
No. cloro isn't a proxy reseller — customers get an API endpoint and a credit balance, not credentials to a pool. That's a control as much as a product decision: it means the IPs behind cloro only ever reach the search engines and AI engines our endpoints support, under the acceptable use terms, rather than anything a credential holder chooses to point them at.