Mysterium Network

Switzerland · mysterium.network · 11 vendors

NetSys Inc., operating as Mysterium Network, provides an open-source decentralized virtual private network (dVPN) and peer-to-peer infrastructure protocol. It enables censorship-resistant and privacy-focused internet access globally, allowing users to bypass geo-restrictions and surveillance. The network incentivizes individuals to share their spare bandwidth by running nodes, contributing to a distributed network for secure and anonymous online activity.

Resilience scores

Disruption prediction

Mysterium Network has an estimated 27% probability of disruption in the next 6 months.

4 of Mysterium Network's 11 vendors monitored for disruptions.

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 11 sub-vendors.

Insights

Last updated 2026-08-14 · revision 1

11 direct vendors, 118 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Mysterium Network exhibits high migration readiness due to its modern, distributed, and open-source technology stack. The use of contemporary languages and frameworks like Go, Kotlin, JavaScript, and the WireGuard protocol, combined with a multi-blockchain strategy (Ethereum, Polygon, Binance Smart Chain), indicates a flexible and adaptable architecture. The availability of an SDK/API for developers suggests modularity and ease of integration, which are beneficial for migration. Crucially, the stated 'Total Vendors: 0' implies very low direct vendor lock-in, significantly reducing the complexity, cost, and risk typically associated with migrating away from proprietary systems or services. The support for diverse platforms, including Raspberry Pi for node runners, also demonstrates inherent deployment flexibility. The primary challenges and unknowns for migration relate to missing data. There is no information regarding specific regulatory compliance requirements or data residency constraints, which can be critical factors in planning and executing a migration. Furthermore, the financial capacity to fund a significant migration is unknown due to the absence of financial data. While direct vendor lock-in is low, the reliance on '11 services' originating from diverse geographic locations (United States, India, Israel, United Kingdom, Spain) suggests underlying dependencies that, while not formal vendor contracts, would require careful consideration during any large-scale migration to ensure continuity and avoid unforeseen complexities.

Compliance

9 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO 27001 is the international standard for information security management systems (ISMS). As a cybersecurity company providing VPN and network infrastructure services, ISO 27001 certification would be highly relevant and expected by enterprise customers and partners. The absence of a publicly disclosed ISO 27001 certification is a notable gap for a company in the cybersecurity sector. Risk is MEDIUM because: (1) ISO 27001 is voluntary but commercially expected in the cybersecurity industry; (2) lack of certification may limit enterprise sales and partnership opportunities; (3) the company's own security posture (protecting node runner and user data) would benefit from a formal ISMS; (4) B2B partners building on Mysterium's infrastructure may require ISO 27001 as a supply chain security measure.

Evidence: https://www.mysterium.network, https://docs.mysterium.network/, https://www.iso.org/standard/27001

SOC 2 (source) — Assessment Required

Mysterium Network provides cloud-adjacent and digital infrastructure services (decentralised VPN, proxy network, B2B API/SDK integrations) to business customers. SOC 2 is a voluntary framework but is increasingly required by enterprise B2B customers as a condition of doing business. The company has a growing B2B client base (explicitly mentioned in their 2022 milestones) and provides infrastructure that B2B partners build products upon (PortalsVPN, GoProxies, MystNodes, etc.). Without a SOC 2 report, enterprise sales cycles may be impeded. Risk is MEDIUM because: (1) absence of SOC 2 is a commercial risk rather than a legal/regulatory risk; (2) B2B customers in regulated industries (finance, healthcare, government) will likely require SOC 2 Type II; (3) the decentralised architecture makes traditional SOC 2 scoping complex.

Evidence: https://www.mysterium.network/about, https://www.mysterium.network/developers, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services

FINMA — Assessment Required

Mysterium Network issues and operates the MYST utility token, which is an ERC-20 cryptocurrency. FINMA (Swiss Financial Market Supervisory Authority) regulates token issuances and cryptocurrency activities in Switzerland. In 2017, Mysterium conducted a token sale raising 14 million CHF. FINMA's ICO guidelines (2018) and the Swiss DLT Act (2021) classify tokens as payment tokens, utility tokens, or asset tokens, with different regulatory treatment. MYST is described as a 'utility token', but FINMA's analysis may differ. Risk is HIGH because: (1) the 14M CHF token sale may have required FINMA notification or approval; (2) ongoing MYST trading on exchanges (MEXC, HitBTC, Uniswap, PancakeSwap, QuickSwap) may trigger securities or payment services regulations; (3) the Hermes payment protocol and P2P payment infrastructure may require a payment services licence; (4) FINMA has been actively enforcing cryptocurrency regulations; (5) EU's MiCA (Markets in Crypto-Assets Regulation, applicable from December 2024) may also apply to MYST token activities targeting EU users.

Evidence: https://www.mysterium.network/token, https://www.mysterium.network/about, https://www.finma.ch/en/documentation/finma-guidance/, https://www.finma.ch/en/news/2018/02/20180216-mm-ico-wegleitung/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R1114

Financials

Three-year financials

Financial Resilience Score: 5/10

Mysterium Network, operated by BlockDev AG (Zug, Switzerland), presents a mixed financial resilience profile that is difficult to fully assess due to the absence of publicly disclosed financial statements. As a private Swiss AG, the company is not obligated to publish annual accounts, and no revenue, EBIT, or equity figures are available in the public domain. The only confirmed capital raise is the 2017 ICO which raised approximately USD 14 million. On the positive side, the project has demonstrated longevity since 2017, surviving multiple crypto down-cycles which suggests prudent treasury management. The network shows meaningful operational traction with approximately 22,000 active nodes, ~67,000 daily active sessions, ~1 PB monthly traffic, and coverage in 135+ countries. Recurring on-chain revenue flows through the MYST token, and the ecosystem is diversified across multiple partners (Avado, Dappnode, Nebra, GoProxies, Storj, Parsiq, Polygon, Kryptex, Crankk) and product lines (MysteriumVPN, PortalsVPN, B2B residential proxy). However, significant risks weigh on resilience: complete financial opacity prevents runway assessment; treasury is likely exposed to crypto market volatility given MYST's small market cap and thin trading; regulatory pressure on VPN/proxy services is increasing (EU DSA, national anti-circumvention laws); and competition is intense from both traditional VPN incumbents (Nord, Express, Proton) and other dVPNs (Sentinel, Orchid, Deeper). A midpoint score reflects operational continuity balanced against undisclosed financials and crypto-market dependency.

Key strengths: Operational since 2017, having survived multiple crypto downcycles, 2017 ICO raised approximately USD 14 million, Live network with ~22,000 active nodes and ~67,000 daily sessions, Coverage in 135+ countries with ~1 PB monthly traffic, Diversified partner ecosystem (Avado, Dappnode, Nebra, GoProxies, Storj, Polygon), Multiple revenue vectors: consumer dVPN, B2B residential proxy, node ecosystem fees

Risk factors: No published financial statements; cash runway and profitability unknown, Treasury denominated partly in MYST/ETH/stablecoins, exposing balance sheet to crypto volatility, MYST market cap in low tens of millions USD and thinly traded, Regulatory scrutiny on VPN and residential-proxy services (EU DSA, anti-circumvention laws), Intense competition from traditional VPN incumbents and other dVPNs, Revenue model concentrated on continued MYST token utility demand, No disclosed venture funding rounds since the 2017 ICO

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report