Most national internet censorship runs on commercial hardware and software. Deep packet inspection (DPI) boxes and URL-filtering systems, often sold for “traffic management” or “network security,” let governments block websites, throttle platforms, detect VPNs and sometimes inject spyware. Investigations by Citizen Lab, Amnesty International, Access Now and journalists have tied products from Canada’s Sandvine and Netsweeper, U.S.-based Blue Coat, Israel’s Allot and China’s Geedge Networks to censorship in more than a dozen countries. Governments have only rarely responded with export controls.
Documented censorship deployments by vendor
| Vendor (HQ) | Technology | Documented deployment or finding | Year(s) | Source |
|---|---|---|---|---|
| Sandvine (Canada) | PacketLogic DPI | Used to redirect targeted users in Turkey and Syria to spyware, and to inject ads and crypto-mining scripts in Egypt | 2018 | Citizen Lab, 2018 |
| Sandvine | DPI | Used by Belarus to block sites during the August 2020 election; Sandvine ended its license there | 2020 | Bloomberg via BHRRC, 2020 |
| Sandvine | PacketLogic | Injected Predator spyware toward an Egyptian presidential hopeful via Vodafone Egypt (high-confidence attribution) | 2023 | Citizen Lab, 2023 |
| Sandvine | DPI | Original basis of Pakistan’s Web Monitoring System (WMS), installed in 2018 | 2018-2025 | Dawn, 2025 |
| Netsweeper (Canada) | URL filtering | Installations found in 30 countries; national censorship in 10, including Bahrain, UAE, Pakistan and Yemen | 2018 | Citizen Lab, 2018 |
| Blue Coat (U.S.) | ProxySG, PacketShaper | 61 devices on public or government networks in countries of concern; products re-exported to Syria | 2011-2013 | Citizen Lab, 2013 |
| Allot (Israel) | DPI gateway | Bought by Azerbaijan for about $2.8-3M; used to block independent media from March 2017 | 2015-2018 | Qurium, 2018 |
| Allot | NetEnforcer DPI | Reported to have reached Iran via a Danish distributor | 2011 | Haaretz, 2011 |
| Geedge Networks (China) | Tiangou Secure Gateway | Deployed in Kazakhstan, Ethiopia, Pakistan and Myanmar; detects Tor, Psiphon and commercial VPNs | 2025 leak | Geedge Report, 2025 |
| Niagara Networks (U.S.), Thales (France), New H3C (China) | Network and software components | Named by Amnesty as part of Pakistan’s WMS 2.0 setup | 2025 | Dawn, 2025 |
Sandvine and the U.S. Entity List
No vendor has been documented as thoroughly as Sandvine, which Citizen Lab’s 2018 research refers to as Sandvine/Procera Networks. Francisco Partners has owned the company since 2017.
In 2018, Citizen Lab’s Bad Traffic report found PacketLogic devices on Türk Telekom’s network silently redirecting targeted users to spyware-laced versions of legitimate software downloads. Some of those users were in Syria. In Egypt, the same type of device injected ads and cryptocurrency-mining scripts on a mass scale (Citizen Lab, 2018). Sandvine called the findings inaccurate, and Citizen Lab stood by them.
Bloomberg reported in 2020 that Belarus used Sandvine equipment to block websites and services around the disputed August 2020 election. In September, Sandvine said custom code had been inserted into its products. It treated this as a human rights violation that automatically terminated its license, and it stopped selling in Belarus (BHRRC, 2020).
In 2023, Citizen Lab found that a middlebox on the link between Telecom Egypt and Vodafone Egypt was redirecting opposition politician Ahmed Eltantawy to an exploit that installs Predator spyware. It attributed the device to Sandvine’s PacketLogic with high confidence. Apple patched the exploited iOS flaws on September 21, 2023 (Citizen Lab, 2023).
On February 27, 2024, the U.S. Bureau of Industry and Security added Sandvine to the Entity List. It cited DPI supplied to Egypt’s government for mass web monitoring and censorship (JURIST, 2024). Sandvine then pledged to:
- leave 32 countries, with 24 more to follow by the end of 2025,
- end service for Egyptian customers by March 31, 2025, and
- operate only in democracies.
It was removed from the list on October 21, 2024. Access Now said delisting should depend on verified change rather than press releases (Access Now, 2024).
National filtering with Netsweeper and Blue Coat
Citizen Lab’s 2018 Planet Netsweeper study found the Canadian company’s filters on networks in 30 countries. It documented national-level, consumer-facing censorship in 10 of them: Afghanistan, Bahrain, India, Kuwait, Pakistan, Qatar, Somalia, Sudan, the UAE and Yemen. The blocked material included religious content in Bahrain, political campaigns in the UAE, news sites in Yemen and non-pornographic LGBTQ resources that the product placed in an “Alternative Lifestyles” category (Citizen Lab, 2018).
Five years earlier, Planet Blue Coat identified 61 ProxySG and 316 PacketShaper appliances. Of these, 61 sat on public or government networks in countries with histories of censorship and surveillance concerns. In December 2011, U.S. authorities placed a UAE-based person and company on the Entity List for re-exporting Blue Coat filtering products to Syria (Citizen Lab, 2013).
Allot equipment in Azerbaijan and Iran
Qurium’s 2018 investigation traced a purchase of about $2.8 million to $3 million in Allot equipment by Azerbaijan’s security ministry. The deal was arranged through intermediaries and presented as social-media monitoring for the 2015 European Games. Azerbaijan enabled the DPI features on March 27, 2017, when major independent news sites were blocked (Qurium, 2018). Earlier, in 2011, Bloomberg reported that Allot gear had been repackaged in Denmark and sold on to Iran (Haaretz, 2011). The Haaretz article includes no response from Allot.
Geedge Networks and Great Firewall technology abroad
In September 2025, more than 100,000 internal documents from Geedge Networks leaked. They included source code, bug trackers and wikis. A consortium led by InterSecLab, with Amnesty International, Justice For Myanmar and media partners, analyzed them. The material describes the Tiangou Secure Gateway, a full-stack platform installed in telecom data centers. Its detection signatures cover Tor, Psiphon, Ultrasurf, Cloudflare WARP and commercial VPNs (Geedge Report, 2025).
The leak documents deployments in Kazakhstan, Ethiopia, Pakistan and Myanmar, and it shows code overlap with China’s own Great Firewall. Geedge is linked to Fang Binxing, often described as the architect of that system. In Myanmar, its rollout began in 2023 and helped block 55 apps, including VPNs, Tor, Signal and WhatsApp (Global Voices, 2025).
Vendors behind Pakistan’s firewall
Amnesty’s September 2025 report Shadows of Control found that Pakistan’s WMS firewall was first built on Sandvine technology in 2018. It was later upgraded to WMS 2.0 with Geedge Networks plus components from Niagara Networks (U.S.), Thales (France) and New H3C (China). According to the report, WMS 2.0 can block two million active sessions at once (Dawn, 2025; Amnesty International, 2025).
State-built systems
Not every censorship system has a known commercial vendor. Russia’s TSPU DPI boxes, mandated by the 2019 “sovereign internet” law, inspect the type of traffic as well as its destination. Mediazona reports plans to expand their capacity to 954 terabits per second by 2030 (Mediazona, 2026). None of the sources cited here names the supplier.
Practical consequences
- DPI systems like these classify protocols and apps as well as destinations, which is how they can single out VPN traffic even when they can’t read its contents.
- The Turkey and Egypt injection cases both exploited HTTP downloads or plain-HTTP pages. Using HTTPS everywhere and getting software only from verified sources reduces the risk of such injection.
- In heavily filtered countries, platforms such as Tiangou are built to fingerprint standard VPN protocols, and tools designed to resist that fingerprinting tend to last longer.
- Western origin is no sign of safety: several documented deployments involve North American or European technology, often sold through intermediaries.
Methodology and limitations
A vendor appears here only when a named investigation by an NGO, an academic lab, a regulator or an established news outlet tied its product to a specific censorship or network-manipulation deployment. Each entry rests on the original report or a reliable summary of it. Export-control facts come from official actions as reported by JURIST and Access Now.
Vendors often dispute attribution, as Sandvine did in 2018. Equipment can be resold or reconfigured without the maker’s knowledge. Most deployments become public only through leaks or forensic research, so the list is certainly incomplete. Companies whose role in a specific censorship deployment could not be confirmed from primary documentation, including Huawei, are left out, so a missing entry is not a clean record.