Original Research 8 min read

The Companies Behind Internet Censorship Technology

Sandvine, Netsweeper, Blue Coat, Allot and Geedge Networks: the firms whose deep packet inspection and filtering gear has been tied to internet censorship.

The Companies Behind Internet Censorship Technology

Key Findings

  • Citizen Lab found Netsweeper filtering installations on networks in 30 countries in 2018 and documented national-level censorship using the product in 10 of them.
  • The U.S. Commerce Department added Sandvine to its Entity List on February 27, 2024, over DPI sold to Egypt, then removed it on October 21, 2024 after the company pledged to leave dozens of countries.
  • A September 2025 leak of more than 100,000 internal documents showed Chinese firm Geedge Networks selling its Tiangou censorship platform to Kazakhstan, Ethiopia, Pakistan and Myanmar.
  • Amnesty International reported in 2025 that Pakistan's upgraded WMS 2.0 firewall can block two million active sessions at a time and combines Chinese, U.S. and French components.
  • Citizen Lab's 2013 scan found 61 Blue Coat devices on public or government networks in countries with records of censorship and surveillance concerns.

Most national internet censorship runs on commercial hardware and software. Deep packet inspection (DPI) boxes and URL-filtering systems, often sold for “traffic management” or “network security,” let governments block websites, throttle platforms, detect VPNs and sometimes inject spyware. Investigations by Citizen Lab, Amnesty International, Access Now and journalists have tied products from Canada’s Sandvine and Netsweeper, U.S.-based Blue Coat, Israel’s Allot and China’s Geedge Networks to censorship in more than a dozen countries. Governments have only rarely responded with export controls.

Documented censorship deployments by vendor

Vendor (HQ)TechnologyDocumented deployment or findingYear(s)Source
Sandvine (Canada)PacketLogic DPIUsed to redirect targeted users in Turkey and Syria to spyware, and to inject ads and crypto-mining scripts in Egypt2018Citizen Lab, 2018
SandvineDPIUsed by Belarus to block sites during the August 2020 election; Sandvine ended its license there2020Bloomberg via BHRRC, 2020
SandvinePacketLogicInjected Predator spyware toward an Egyptian presidential hopeful via Vodafone Egypt (high-confidence attribution)2023Citizen Lab, 2023
SandvineDPIOriginal basis of Pakistan’s Web Monitoring System (WMS), installed in 20182018-2025Dawn, 2025
Netsweeper (Canada)URL filteringInstallations found in 30 countries; national censorship in 10, including Bahrain, UAE, Pakistan and Yemen2018Citizen Lab, 2018
Blue Coat (U.S.)ProxySG, PacketShaper61 devices on public or government networks in countries of concern; products re-exported to Syria2011-2013Citizen Lab, 2013
Allot (Israel)DPI gatewayBought by Azerbaijan for about $2.8-3M; used to block independent media from March 20172015-2018Qurium, 2018
AllotNetEnforcer DPIReported to have reached Iran via a Danish distributor2011Haaretz, 2011
Geedge Networks (China)Tiangou Secure GatewayDeployed in Kazakhstan, Ethiopia, Pakistan and Myanmar; detects Tor, Psiphon and commercial VPNs2025 leakGeedge Report, 2025
Niagara Networks (U.S.), Thales (France), New H3C (China)Network and software componentsNamed by Amnesty as part of Pakistan’s WMS 2.0 setup2025Dawn, 2025

Sandvine and the U.S. Entity List

No vendor has been documented as thoroughly as Sandvine, which Citizen Lab’s 2018 research refers to as Sandvine/Procera Networks. Francisco Partners has owned the company since 2017.

In 2018, Citizen Lab’s Bad Traffic report found PacketLogic devices on Türk Telekom’s network silently redirecting targeted users to spyware-laced versions of legitimate software downloads. Some of those users were in Syria. In Egypt, the same type of device injected ads and cryptocurrency-mining scripts on a mass scale (Citizen Lab, 2018). Sandvine called the findings inaccurate, and Citizen Lab stood by them.

Bloomberg reported in 2020 that Belarus used Sandvine equipment to block websites and services around the disputed August 2020 election. In September, Sandvine said custom code had been inserted into its products. It treated this as a human rights violation that automatically terminated its license, and it stopped selling in Belarus (BHRRC, 2020).

In 2023, Citizen Lab found that a middlebox on the link between Telecom Egypt and Vodafone Egypt was redirecting opposition politician Ahmed Eltantawy to an exploit that installs Predator spyware. It attributed the device to Sandvine’s PacketLogic with high confidence. Apple patched the exploited iOS flaws on September 21, 2023 (Citizen Lab, 2023).

On February 27, 2024, the U.S. Bureau of Industry and Security added Sandvine to the Entity List. It cited DPI supplied to Egypt’s government for mass web monitoring and censorship (JURIST, 2024). Sandvine then pledged to:

  • leave 32 countries, with 24 more to follow by the end of 2025,
  • end service for Egyptian customers by March 31, 2025, and
  • operate only in democracies.

It was removed from the list on October 21, 2024. Access Now said delisting should depend on verified change rather than press releases (Access Now, 2024).

National filtering with Netsweeper and Blue Coat

Citizen Lab’s 2018 Planet Netsweeper study found the Canadian company’s filters on networks in 30 countries. It documented national-level, consumer-facing censorship in 10 of them: Afghanistan, Bahrain, India, Kuwait, Pakistan, Qatar, Somalia, Sudan, the UAE and Yemen. The blocked material included religious content in Bahrain, political campaigns in the UAE, news sites in Yemen and non-pornographic LGBTQ resources that the product placed in an “Alternative Lifestyles” category (Citizen Lab, 2018).

Five years earlier, Planet Blue Coat identified 61 ProxySG and 316 PacketShaper appliances. Of these, 61 sat on public or government networks in countries with histories of censorship and surveillance concerns. In December 2011, U.S. authorities placed a UAE-based person and company on the Entity List for re-exporting Blue Coat filtering products to Syria (Citizen Lab, 2013).

Allot equipment in Azerbaijan and Iran

Qurium’s 2018 investigation traced a purchase of about $2.8 million to $3 million in Allot equipment by Azerbaijan’s security ministry. The deal was arranged through intermediaries and presented as social-media monitoring for the 2015 European Games. Azerbaijan enabled the DPI features on March 27, 2017, when major independent news sites were blocked (Qurium, 2018). Earlier, in 2011, Bloomberg reported that Allot gear had been repackaged in Denmark and sold on to Iran (Haaretz, 2011). The Haaretz article includes no response from Allot.

Geedge Networks and Great Firewall technology abroad

In September 2025, more than 100,000 internal documents from Geedge Networks leaked. They included source code, bug trackers and wikis. A consortium led by InterSecLab, with Amnesty International, Justice For Myanmar and media partners, analyzed them. The material describes the Tiangou Secure Gateway, a full-stack platform installed in telecom data centers. Its detection signatures cover Tor, Psiphon, Ultrasurf, Cloudflare WARP and commercial VPNs (Geedge Report, 2025).

The leak documents deployments in Kazakhstan, Ethiopia, Pakistan and Myanmar, and it shows code overlap with China’s own Great Firewall. Geedge is linked to Fang Binxing, often described as the architect of that system. In Myanmar, its rollout began in 2023 and helped block 55 apps, including VPNs, Tor, Signal and WhatsApp (Global Voices, 2025).

Vendors behind Pakistan’s firewall

Amnesty’s September 2025 report Shadows of Control found that Pakistan’s WMS firewall was first built on Sandvine technology in 2018. It was later upgraded to WMS 2.0 with Geedge Networks plus components from Niagara Networks (U.S.), Thales (France) and New H3C (China). According to the report, WMS 2.0 can block two million active sessions at once (Dawn, 2025; Amnesty International, 2025).

State-built systems

Not every censorship system has a known commercial vendor. Russia’s TSPU DPI boxes, mandated by the 2019 “sovereign internet” law, inspect the type of traffic as well as its destination. Mediazona reports plans to expand their capacity to 954 terabits per second by 2030 (Mediazona, 2026). None of the sources cited here names the supplier.

Practical consequences

  • DPI systems like these classify protocols and apps as well as destinations, which is how they can single out VPN traffic even when they can’t read its contents.
  • The Turkey and Egypt injection cases both exploited HTTP downloads or plain-HTTP pages. Using HTTPS everywhere and getting software only from verified sources reduces the risk of such injection.
  • In heavily filtered countries, platforms such as Tiangou are built to fingerprint standard VPN protocols, and tools designed to resist that fingerprinting tend to last longer.
  • Western origin is no sign of safety: several documented deployments involve North American or European technology, often sold through intermediaries.

Methodology and limitations

A vendor appears here only when a named investigation by an NGO, an academic lab, a regulator or an established news outlet tied its product to a specific censorship or network-manipulation deployment. Each entry rests on the original report or a reliable summary of it. Export-control facts come from official actions as reported by JURIST and Access Now.

Vendors often dispute attribution, as Sandvine did in 2018. Equipment can be resold or reconfigured without the maker’s knowledge. Most deployments become public only through leaks or forensic research, so the list is certainly incomplete. Companies whose role in a specific censorship deployment could not be confirmed from primary documentation, including Huawei, are left out, so a missing entry is not a clean record.

Sources

  1. Bad Traffic: Sandvine's PacketLogic Devices Used to Deploy Government Spyware in Turkey and Redirect Egyptian Users to Affiliate Ads? — Citizen Lab, University of Toronto, 2018-03
  2. Predator in the Wires: Ahmed Eltantawy Targeted with Predator Spyware After Announcing Presidential Ambitions — Citizen Lab, 2023-09-22
  3. Belarusian Officials Shut Down Internet With Technology Made by U.S. Firm (Bloomberg, summarized) — Business & Human Rights Resource Centre / Bloomberg, 2020-08-28
  4. Sandvine's response to allegations regarding the Belarus internet shutdown — Business & Human Rights Resource Centre, 2020-09-15
  5. US introduces restrictions against Canada-based company after accusations of Egypt censorship — JURIST, 2024-02-27
  6. Sandvine removed from U.S. Entity List: Access Now urges continued scrutiny — Access Now, 2024-10
  7. Planet Netsweeper: Executive Summary — Citizen Lab, 2018-04-25
  8. Planet Blue Coat: Mapping Global Censorship and Surveillance Tools — Citizen Lab, 2013-01-15
  9. Corruption, Censorship and a Deep Packet Inspection Vendor — Qurium Media Foundation, 2018-04-10
  10. Report: Israeli Company Sold Surveillance Equipment to Iran — Haaretz, 2011-12-23
  11. Geedge Report: Investigating the Geedge Networks data leak — InterSecLab and partners, 2025-09
  12. How a Chinese company exports the Great Firewall to autocratic regimes — Global Voices Advox, 2025-09-18
  13. Two Major Leaks Illuminate Censorship and Surveillance Sales Into and From China — China Digital Times, 2025-09
  14. Shadows of Control: Censorship and Mass Surveillance in Pakistan — Amnesty International, 2025-09-09
  15. Pakistani authorities allegedly spying on millions through mass surveillance systems: Amnesty report — Dawn, 2025-09-09
  16. Egypt: Freedom on the Net 2021 — Freedom House, 2021
  17. Russia's internet censorship in 2026 — Mediazona, 2026-04-07
Cite this research: PhantomGuide Research Team, “The Companies Behind Internet Censorship Technology”, PhantomGuide, 2026-10-01, https://phantomguide.com/research/censorship-tech-vendors/

More Research