Summary

  • The subject is SW Internet Ltda - ME, CNPJ 18.605.214/0001-57, also recorded with the trade name SW Connect. Anatel's provider list and the published text of Ato 1765 identify that legal person as an SCM licensee, while Registro.br assigns the same CNPJ AS267217, 45.231.180.0/22 and 2804:4a14::/32.
  • A publication-date RIPE RIS snapshot found three IPv4 announcements and one IPv6 announcement. The covering 45.231.180.0/22 and lower 45.231.180.0/23 appeared through AS14840 BR.Digital and AS28186 ITS, but all 373 collected paths for 45.231.182.0/23 placed only ITS immediately before AS267217.
  • IX.br listed SWINTERNET at its Salvador exchange and exposed two established IPv4 and two established IPv6 route-server sessions. Multiple sessions confirm live logical participation, but they do not disclose the number of physical ports, delivery circuits, edge routers, sites or power domains.
  • SW Fibra and SW Tellecom are not treated as the subject. Public corporate data attaches the SW Fibra trade name to the separately numbered SW Tellecom, CNPJ 11.806.281/0001-90. Shared administrators and related-looking domains are signals of proximity, not evidence that SW Fibra's offers, locations, support operation, end-user links or access network belong to SW Internet or traverse AS267217.

The subject begins with a CNPJ and an ASN

Small-network research is especially vulnerable to an apparently harmless shortcut: matching a short brand name to a similar company name and then treating every nearby website, address and product as one operation. SW Internet demonstrates why that shortcut is unsafe. The strongest public evidence does not begin with a retail page. It begins with a telecom authorization, a legal registration number and Internet number resources.

Anatel's SCM authorized-provider list identifies SW Internet Ltda - ME under process 53500.022068/2014-89 and Ato 1765, with authorization dated 23 March 2015. A reproduced text of the relevant Diario Oficial da Uniao issue gives CNPJ 18.605.214/0001-57 and describes an indefinite, nationwide, non-exclusive authorization to provide Servico de Comunicacao Multimedia. The reproduction is hosted outside the regulator, so it is useful because its act, process and CNPJ align with Anatel's live list, not because the mirror alone is authoritative.

The number-registry evidence is more direct still. Registro.br's AS267217 record names SW Internet Ltda - ME and identifies the registrant handle as 18605214000157. The record dates registration to 20 February 2018. The linked 45.231.180.0/22 allocation covers 45.231.180.0 through 45.231.183.255 and names the same company and CNPJ. The 2804:4a14::/32 allocation does the same for IPv6. These three records establish a coherent technical identity: the legal person that holds the SCM authorization also holds the autonomous-system number and the address resources originated by that autonomous system.

A public mirror of corporate registration data for CNPJ 18.605.214/0001-57 records the active company as SW Internet Ltda, gives SW Connect as its trade name and places its head office in Lauro de Freitas, Bahia. The API is not the telecom regulator or the Internet registry, but it agrees with the identifiers in those primary systems. It also names Fabio Souza Rodrigues and Fabricio Souza Rodrigues as administrators. Those names matter for understanding why related-looking records exist, but they do not broaden the subject automatically.

The defensible starting proposition is therefore exact. SW Internet Ltda - ME, CNPJ 18.605.214/0001-57, is the licensed legal person and the registered holder of AS267217 and its directly allocated IPv4 and IPv6 space. Everything else has to be connected to that proposition with evidence of comparable specificity.

Similar names do not erase the corporate boundary

The boundary is not a technicality. A separate public corporate-data record for SW Tellecom Comercio de Informatica Ltda gives CNPJ 11.806.281/0001-90, an active registration in Salvador and the trade names Salvador Wireless, SW Fibra and SW Solar. It names the same two administrators reported for SW Internet. That is evidence of common human administration. It is not evidence that the two CNPJs are interchangeable, that one owns the other, that an authorization moved between them, or that services sold under one name are delivered by the other's autonomous system.

The domain records reinforce the need for restraint rather than resolving it. Registro.br records swinternet.net.br to SW Internet Ltda - ME under the subject CNPJ. By contrast, swfibra.com.br is registered to Fabricio Souza Rodrigues as an individual. The record for salvadorwireless.com.br uses CNPJ 11.806.371/0001-81, which differs by one digit group from SW Tellecom's number and is not the SW Internet CNPJ. A public corporate-data response for 11.806.371/0001-81 identifies a separately numbered sole-proprietor registration and reports it as inactive.

Taken together, the records show a cluster of names, people and domains. They do not supply the missing legal or network bridge. No directly authoritative record cited here states that SW Fibra is a trade name of SW Internet Ltda, CNPJ 18.605.214/0001-57. No cited record states that a connection contracted from SW Tellecom is originated by AS267217. No licence transfer, merger filing, network-services agreement, customer contract naming both entities, or regulator statement was found that would permit those propositions to be treated as facts.

That limitation controls the entire analysis. Prices, packages, installation claims, support channels, shop addresses, coverage language and repair promises published under SW Fibra or SW Tellecom cannot be used to describe SW Internet. The same is true of any access fibre, wireless link, optical terminal or end-user route associated only with those names. Even a shared administrator, shared email pattern or shared hosting address would show proximity, not which legal person owns an asset or owes a service obligation.

There are several ways a bridge could eventually be established. A regulator filing could identify a licence succession. A current legal notice could name SW Internet as the provider behind a branded contract. A signed service agreement could identify the contracting CNPJ and the autonomous system used for delivery. An authoritative corporate filing could document control or an incorporated branch. Measurements from an independently verified circuit could tie that circuit's traffic to AS267217. None of those is replaced by visual resemblance between websites or by a family of initials.

For that reason, SW Fibra and SW Tellecom appear here only as counterevidence against careless identity matching. They are not evidence for SW Internet's service area, product design, subscriber base, support labour, access technology or physical network.

The verified geography stops at two different kinds of place

The public record supports two geographic statements about SW Internet, and they describe different things. First, the Anatel list and the corporate-data response place the legal company in Lauro de Freitas. That is an administrative location. It may be associated with operations, but a registered address does not prove that a router, optical shelf, radio, warehouse or staffed network centre is installed there.

Second, IX.br's Salvador entity table lists 267217 SWINTERNET as a entity in the Bahia exchange locality. That is a logical interconnection location. It establishes that the autonomous system participates in the Salvador IX fabric under the conditions exposed by the exchange. It does not reveal which physical PIX or facility delivers the entity, whether the delivery is direct or transported, where SW's router is located, or whether the route to the exchange shares infrastructure with any external circuit.

The nationwide language in Ato 1765 is a third, easily misunderstood geography. It describes the legal scope of permission. It does not demonstrate nationwide plant, customers or active service. A company can hold authority to operate across Brazil while maintaining a much narrower network. Converting the authorization into a footprint would confuse what the operator may do with what it has built.

No authoritative, subject-specific evidence located for this analysis defines SW Internet's retail coverage, customer municipalities, access routes, tower sites, fibre paths, cabinets, aggregation sites or field-maintenance area. Those facts cannot be borrowed from SW Fibra's separate identity cluster. The result is a deliberately sparse map: a legal address in Lauro de Freitas and a logical IX presence in Salvador, with no line drawn between them and no service polygon around either.

This distinction matters to buyers and counterparties. A logical IX presence can improve reach to networks available at the exchange. It says nothing about whether SW owns a path from Lauro de Freitas to Salvador, leases transport from another carrier, reaches the IX through a reseller, or operates from a third-party colocation site. A corporate address can be important for notice and accountability while saying nothing about where packets enter the network. Until facility and circuit evidence appears, the physical distance between the two records is not a documented SW route.

Four announcements made AS267217 globally visible

At 08:00 UTC on 15 July 2026, RIPEstat's routing-status snapshot described a small but widely visible origin network. It counted three IPv4 announcements covering 1,024 unique IPv4 addresses and one IPv6 announcement covering an IPv6 /32. IPv4 routes were visible to 325 of 326 RIS full-feed peers, while IPv6 was visible to all 322 counted peers.

The announced-prefix set contained four entries: 45.231.180.0/22, 45.231.180.0/23, 45.231.182.0/23 and 2804:4a14::/32. The three IPv4 announcements do not represent three independent allocations. The /22 is the allocated block, and the two /23s divide that same block into lower and upper halves. Originating both the covering aggregate and its more-specific components is a routing-policy choice.

That choice matters because routers normally prefer the longest matching prefix. Traffic for an address inside 45.231.182.0/23 will ordinarily follow the /23 if it is available, even when the covering /22 is also present. The aggregate can still provide reachability for addresses in the allocation if a more-specific route disappears, but only if the aggregate remains propagated and the path carrying it is usable. A static table cannot prove that this fallback has been intentionally tested.

The four announcements establish operation at the BGP layer. They show that AS267217 was originating its registered resources and that those origins reached a broad sample of global collectors. They do not show traffic volume. A route with near-universal visibility may carry very little traffic, and a heavily used route may have the same visible prefix count. They also do not identify the applications, organisations or access links using addresses inside the block.

The routing record is nevertheless stronger than a network description. It is a dated observation of what the Internet saw. The useful question is not whether the ASN existed, but how each route reached the collectors and how the differences could affect resilience.

The upper /23 had a narrower observed path set

The covering 45.231.180.0/22 BGP snapshot contained 371 collected paths. In 201 of them, AS14840 appeared immediately before AS267217. In the other 170, AS28186 occupied that position. The lower 45.231.180.0/23 snapshot had the identical 201-to-170 split across 371 paths.

The upper half differed. The 45.231.182.0/23 snapshot contained 373 paths, and every one placed AS28186 immediately before AS267217. Registro.br identifies AS28186 as ITS Telecomunicacoes Ltda. It identifies AS14840 as BR.Digital Telecom. Those registry names let us label the adjacent autonomous systems without guessing their contractual roles.

The asymmetry is specific. For the aggregate and lower /23, the collectors saw routes with either BR.Digital or ITS adjacent to SW. For the upper /23, the more-specific route reached every collected path through ITS alone. That does not mean the addresses in the upper /23 had no possible path through BR.Digital. Because the covering /22 was also visible through BR.Digital, a router could fall back to that less-specific route if the upper /23 vanished.

Whether it would do so during a real failure depends on what remains reachable, how the routes are filtered, where the fault occurs and whether the BR.Digital-side path is physically and operationally independent.

Nor does immediate AS adjacency by itself prove "transit" in the commercial sense. BGP paths expose sequence, not invoices. AS14840 or AS28186 could be providing paid transit, partial transit, peering, transport to an exchange, a blended service or another arrangement. RIPEstat's ASN-neighbour observation is useful for identifying recurring path adjacency, but it does not reveal contract terms or circuit ownership.

The narrower path set could be intentional policy. SW may prefer ITS for the upper /23, advertise that more-specific only to ITS, apply communities that alter propagation, or use the route for traffic engineering. It could also reflect a temporary condition at the snapshot time. The data do not explain the reason. What they do show is that the upper /23's globally selected more-specific route did not exhibit the same adjacent-AS diversity as the aggregate and lower /23.

This is the most important operational distinction in the public record because a headline count of "two upstreams" would conceal it. Resilience belongs to a route under a failure condition, not to an ASN in the abstract. A network can have two adjacent autonomous systems while a particular more-specific route is visible through only one of them. It can also have two BGP sessions that ride the same transport, conduit, building entrance, router or power feed. The collector snapshot measures the first layer and says nothing about the second.

IPv6 was even more concentrated in the snapshot

The 2804:4a14::/32 BGP state contained 347 collected paths. AS14840 BR.Digital appeared immediately before AS267217 in 344 of them. Three other autonomous systems each appeared once in that position: AS28624, AS52873 and AS264479.

It would be a mistake to count those three single-path observations as three proven backup services. A one-path adjacency can arise from limited propagation, a route-server view, path-server behaviour, unusual policy or a transient state. Without repeated observations, contract evidence and failure testing, the robust conclusion is concentration: almost every collected IPv6 path reached SW through BR.Digital at the selected time.

The contrast with IPv4 is instructive. The IPv4 aggregate had substantial visibility through both BR.Digital and ITS, while the IPv6 /32 overwhelmingly presented BR.Digital immediately before SW. Dual-stack support therefore does not imply matched dual-stack resilience. A site or service can be reachable over both address families in normal conditions and still have different failure exposure in each.

There is also no reason to infer that the full /32 is actively used. Registro.br's allocation defines a very large address space, and RIPEstat's visibility confirms that the aggregate route was announced. Neither source reports how many /48s have been assigned, how many IPv6 endpoints are active, or how much traffic uses IPv6. Addressing scale and forwarding capacity are separate quantities.

Salvador IX participation is real but physically opaque

IX.br provides a second view of live operation. Its Salvador entity table lists AS267217 as SWINTERNET. More specifically, the exchange's neighbour lookup exposed four established sessions on 15 July: two IPv4 route-server sessions using 200.219.145.31 and two IPv6 route-server sessions using 2001:12f8:0:8::31. Each IPv4 session accepted four routes from AS267217; each IPv6 session accepted one.

That is strong evidence that SW was participating in the exchange's multilateral route-server environment and announcing the same four-prefix set visible to RIS. It also explains why the entity table is more useful than a stale interconnection profile. A live looking glass observes session state and accepted routes. It does not need to infer operation from a self-description.

But the two route servers should not be misread as two physical connections. Both IPv4 sessions used the same entity address, and both IPv6 sessions used the same entity address. A entity can establish sessions to two route servers over one exchange port and one router. The route servers improve control-plane continuity if one route-server process fails; they do not, by themselves, survive failure of the entity port, its transport circuit, its edge device, its rack, its facility or its power source.

The public records do not disclose SW's IX port speed. bgp.tools' AS267217 page identifies the Salvador exchange address but does not provide an available line rate. Hurricane Electric's PTT Salvador summary likewise lists SWINTERNET and 200.219.145.31 without a speed value. Absence from those displays is not evidence that no rate exists; it means a verifiable public number is not available from them.

PeeringDB's AS267217 profile creates a useful documentation conflict. The operator-maintained record describes a regional ISP, indicates IPv6 support and gives a broad self-reported traffic band of 1-5 Gbps, but it has no IX or facility rows and was last updated in 2022. Current IX.br evidence demonstrates an exchange presence that the older profile omits. The profile's traffic band should therefore be treated as dated, coarse self-reporting, not as a current port speed, external capacity figure or traffic measurement.

Even the term "Salvador presence" needs care. An IX locality can be reached through transport supplied by another network. IX.br documentation allows different delivery methods, and the entity table does not identify SW's chosen one. Without a subject-specific facility record, cross-connect order, port record or transport agreement, it is not possible to place SW equipment in any named Salvador building.

Adjacent networks' facilities are not SW facilities

PeeringDB's records for BR.Digital AS14840 and ITS AS28186 show their own Salvador interconnection and facility information. These records help establish that both adjacent networks operate in the metropolitan interconnection market. They do not locate SW.

If BR.Digital and ITS appear in separate facilities, that still does not prove that SW buys two independently delivered circuits into those sites. SW might meet them at one common location. One or both services might be transported over a third party. The paths could share ducts, poles, long-haul segments, building entrances, cross-connect frames, an edge chassis or a power system before they diverge. Conversely, SW could have more physical separation than the public record shows. The neighbouring networks' footprints cannot settle either possibility.

Secondary routing summaries provide corroboration at the logical layer. IPinfo's AS267217 summary identifies BR.Digital and ITS as principal upstreams, while CIDR Report shows the same two prominent adjacencies and no visible downstream customer ASN. Those labels are useful as cross-checks, but their methods and timing are less explicit than the dated RIS paths. They cannot transform a BGP neighbour into a known commercial supplier or a circuit into a physically diverse one.

An older manual policy can also outlive the network it describes. Registro.br's AS267217 record includes manual policy text that mentions AS52720. Registro.br identifies AS52720 as Webfoco Telecomunicacoes Ltda. AS52720 was not one of the two dominant immediate neighbours in the publication-date RIS path counts. The discrepancy is a reminder that registry policy fields may be historical declarations rather than live topology.

The evidence supports two recurring external adjacencies, one current IX locality and a specific per-prefix distribution. It does not support a physical diagram. Any diagram that placed SW, BR.Digital and ITS in named facilities with separate lines would add facts the sources do not contain.

Address space, traffic and capacity are different measurements

SW's IPv4 allocation contains 1,024 addresses. Its IPv6 /32 can be subdivided into 65,536 /48s. Those numbers are exact resource quantities, but neither is a throughput value. An address may identify an interface, server, router, translation pool or unused assignment. A /48 may be reserved without carrying traffic. Counting addresses does not reveal customers, ports, packets per second or gigabits per second.

The public evidence provides no verified total for installed external capacity. It does not state the rate of a BR.Digital-facing circuit, an ITS-facing circuit or the IX delivery. It does not show committed information rates, burst limits, transit commits, peering-port speeds or traffic percentiles. It does not expose switch backplane, router forwarding capacity, interface utilization or spare optics. The dated PeeringDB traffic band is a traffic classification, not an engineering inventory.

Installed capacity would still not answer the resilience question on its own. A 10 Gbps interface can be rate-limited below 10 Gbps. Two nominally separate interfaces can feed one constrained transport service. A network with ample normal-condition headroom can congest when one path fails and all traffic moves to the survivor. Usable capacity is the lower of the capacities that remain across every necessary layer: edge forwarding, interface, transport, adjacent network, exchange and destination path.

Nor is there a verified sold or reserved capacity figure. No subject-specific public record identifies active connections, wholesale commitments, hosted systems or address utilisation. That prevents a defensible oversubscription calculation. The broad 1-5 Gbps PeeringDB band could be consistent with many network shapes, and its age makes it unsuitable as a publication-date load measurement.

The correct capacity statement is therefore modest. AS267217 had globally visible IPv4 and IPv6 routes, four accepted announcements at IX.br Salvador and two major external path adjacencies in RIS. Its current line rates, traffic load, reserve margin and failure-condition throughput were not publicly established.

Three failure tests expose what the tables cannot answer

The first test concerns the upper IPv4 /23. Suppose the ITS-side route for 45.231.182.0/23 disappears while the covering /22 through BR.Digital remains. In a simple policy case, remote routers would withdraw the more-specific and select the surviving /22, preserving reachability through BR.Digital. The snapshot makes that outcome plausible because the aggregate was visible through BR.Digital. It does not make it certain.

The fault could sit inside SW at a router or interface shared by both announcements. BR.Digital could receive the aggregate over infrastructure that also depends on the failed component. Filtering could differ by neighbour or region. Convergence could be delayed. Return traffic could follow a different path. A surviving route could have limited public evidence capacity for the shifted load. Only controlled withdrawal tests observed from multiple external vantage points, combined with circuit and topology records, would establish the fallback.

The second test concerns IPv6. If the BR.Digital-side IPv6 path failed, the publication-date snapshot offers only three isolated paths with other immediate ASes. Those observations are too sparse to promise broadly propagated backup reachability. A credible IPv6 resilience claim would require stable visibility through another contracted or deliberately selected adjacent network, repeated over time, and evidence that the alternative survives a BR.Digital-side fault with adequate capacity.

The third test concerns the Salvador IX connection. Loss of one IX.br route server may leave the other session operating, because SW had sessions to both BA route servers. Loss of the entity's exchange port or transport could remove all four sessions at once. Loss of a shared edge router or power domain could also affect both route servers and external circuits. The looking glass cannot distinguish those designs.

These tests show why route diversity, session diversity and physical diversity must be reported separately. Route diversity is visible when different AS paths reach a prefix. Session diversity is visible when multiple BGP sessions exist. Physical diversity requires evidence about circuits, entrances, devices, sites and power. SW has strong evidence at the first two layers for portions of its routing and almost none at the third.

There is a fourth boundary beyond the routed core: the access or delivery path to whoever uses the addresses. No directly verified subject record identifies that plant. It would be wrong to fill the gap with SW Fibra's separately associated products or field operation. As a result, this analysis cannot test a cut in a distribution cable, failure of an access radio, loss of a local optical node, depletion of repair stock or dispatch of a technician as SW Internet failure modes. They may be normal risks for some connectivity providers, but the necessary ownership and service bridge is absent here.

The same restraint applies to impact. A route withdrawal could affect systems using addresses in the withdrawn prefix, but the public record does not enumerate those systems or their operators. It cannot support a household count, business count, neighbourhood list or service-level claim. What can be measured is route visibility: whether the prefixes remain reachable from outside networks and through which adjacent autonomous systems.

Route-origin security was not validated

RIPEstat's RPKI validator returned unknown for the 45.231.180.0/22 aggregate, the 45.231.180.0/23 lower half, the 45.231.182.0/23 upper half and the 2804:4a14::/32 IPv6 route. Each response contained no validating ROA at the time checked.

Unknown is not the same as invalid. It means the validator did not find a route-origin authorization covering the prefix and origin combination. The routes were still widely propagated, as the RIS visibility counts demonstrate. RPKI status concerns cryptographic authorization of origin announcements; it does not measure uptime, latency, physical diversity or capacity.

The operational implication is limited but real. Networks that use RPKI-based policy can distinguish valid and invalid origins, while an unknown route lacks that positive validation. Publishing correctly scoped ROAs could reduce ambiguity about which ASN is authorised to originate these resources. It would not solve the upper-/23 path concentration or prove a second physical circuit.

The subject's own domain adds a narrow caution

The domain record for swinternet.net.br is one of the few online identifiers directly tied to the subject CNPJ. It names ns1.swinternet.net.br at 45.231.180.13 and ns2.swinternet.net.br at 45.231.180.14, both inside SW's allocated /22. This is evidence that the domain's authoritative DNS design uses addresses from the registered network.

The same Registro.br response records an automated delegation check on 15 July 2026 with an ns timeout status for both nameservers, and gives 30 August 2025 as the last correct delegation check. That result must be interpreted narrowly. A registry probe can fail because of DNS configuration, filtering, packet loss, maintenance or the probe's path. It does not prove that AS267217 was unreachable, that all queries failed globally, or that any unrelated service was down. The strong BGP visibility at 08:00 UTC shows that the prefixes themselves were broadly routed.

The co-location of both listed nameservers inside one /22 also does not establish whether they run on separate hardware, sites or power. Different IP addresses can terminate on one machine, and one prefix can span multiple locations. The public record supplies addresses and a probe result, not the underlying architecture.

This is a useful example of evidence layers working together. The domain record is strong for legal identity and configured DNS addresses. It is a limited operational signal for one registry check. It is not a substitute for multi-vantage DNS monitoring or facility evidence.

The economics are those of maintaining reachability, not a verified retail offer

Without a defensible link to a retail brand, the economic analysis must stay at the autonomous-system layer. A small origin network has several recurring cost centres: Internet number administration, edge routing, external connectivity, exchange access or transport, equipment, colocation or site costs, power, monitoring and skilled network operations. The relative weight of each item depends on contracts and topology that SW does not publish.

The route pattern suggests an operator balancing reachability across at least two important external adjacencies and a local exchange. Announcing the aggregate and two more-specifics creates policy options. Participation at IX.br can provide direct or multilateral paths to exchange members, potentially reducing dependence on paid external carriage for eligible traffic. None of that proves a saving. Exchange participation can require port, transport, cross-connect, equipment and operational expenditure, while the value depends on traffic mix.

The upper-/23 asymmetry illustrates a trade-off. Steering one more-specific predominantly or exclusively through one adjacent network can support traffic engineering, but it makes the visible path set for that route narrower than the aggregate's. The covering /22 may offer fallback, yet fallback capacity and convergence remain unknown. The economic decision is therefore not simply "buy two upstreams." It is to decide which prefixes are advertised where, how much capacity is committed on each path, what failure load each survivor must carry and what redundancy is worth paying for.

The stale PeeringDB traffic band cannot answer those questions. Even if the network once carried between 1 and 5 Gbps, the figure would not state peak utilization, 95th-percentile billing, contract commits, traffic direction, or the load after a failure. A financially efficient design can still be operationally fragile if both apparent paths share one transport or if the survivor has little headroom.

The absence of verified access and product evidence also means there is no responsible way to estimate revenue, average revenue per connection, acquisition cost, support staffing or local repair economics for SW Internet. Those calculations would require a subject-specific customer and contract base. Borrowing figures from SW Tellecom or SW Fibra would create a precise-looking calculation for the wrong legal person.

What remains is a network-economics question with a clear evidence request: how much independent usable external capacity does AS267217 retain after loss of each adjacent network, IX delivery, edge device and power domain? That figure, paired with normal and busy-hour load, would reveal far more than a plan price or address count.

Who depends on AS267217 remains only partly visible

The first affected party is SW Internet itself. The company is responsible for the lawful use and operation of the registered autonomous system and address resources. A prolonged routing failure could disrupt systems using its prefixes, reduce reachability to counterparties and complicate operation of its own domain infrastructure.

The second group consists of organisations or systems assigned addresses inside 45.231.180.0/22 or 2804:4a14::/32. The public routing data do not identify them. CIDR Report did not show a visible downstream customer ASN, but that does not exclude end systems, private networks, address translation, hosted services or users reached without their own ASN. Their number and function are unknown.

The third group is the network's interconnection counterparties. IX.br route servers accepted SW's four routes, making them available within the multilateral environment according to exchange policy. BR.Digital and ITS appeared repeatedly next to SW in global paths. Route changes, leaks or withdrawals can therefore affect how other networks reach the prefixes even when no physical failure occurs.

Regulators and resource registries form another accountability layer. Anatel's authorization identifies the licensed person. Registro.br identifies the resource holder and contacts. Those records matter precisely because similar commercial names do not determine responsibility. Anyone evaluating a contract or incident should begin with the CNPJ on the relevant document rather than assume that all SW-labelled activity belongs to AS267217.

No verified evidence supports a count of SW Internet retail subscribers, served homes, business circuits or municipalities. The impact surface can be described at prefix level, not converted into a population figure.

The evidence needed for a stronger resilience claim is concrete

The highest-value disclosure would be a current logical-and-physical interconnection inventory. For each BR.Digital, ITS and IX connection, it should identify service type, committed and physical rate, handoff facility, delivery provider, edge router, port, route policy and whether any component is shared. Sensitive details could be disclosed under controlled conditions to enterprise buyers or auditors while public summaries state the independence level.

A second useful record would be per-prefix policy. It should explain why the aggregate and lower /23 were visible through both major adjacent ASes while the upper /23 was visible only through ITS. The answer could be intentional engineering. Publishing communities, routing objectives or a redacted policy summary would distinguish design from drift.

Third, controlled failure evidence would turn plausible fallback into demonstrated recovery. SW could withdraw the upper /23 from ITS and observe whether external vantage points converge to the BR.Digital-carried /22. It could test loss of each IPv6 adjacency, one route server, the IX delivery and each edge device. The result should include convergence time, packet loss and throughput under shifted load.

Fourth, capacity evidence should separate design, installed, operational and usable values. Interface rates alone are not enough. A useful statement would provide current traffic percentiles, contractual commits, rate limits and the minimum capacity remaining after each single failure. It should say whether IX and external services share transport.

Fifth, facility and power evidence should identify the number of active edge sites, independent building entrances, router redundancy, power feeds, battery autonomy and generator coverage. This is the layer completely absent from routing collectors. A route can look diverse while terminating on one device in one room.

Sixth, route-origin security can be improved and verified through published ROAs for the aggregate, permitted more-specifics and IPv6 /32. Monitoring should confirm that intended announcements are valid and unintended origins are rejected or alerted.

Seventh, any claim connecting SW Internet to SW Fibra or SW Tellecom should be supported with a direct authoritative bridge. The decisive document would identify both CNPJs and state the relevant legal, contractual or network relationship. Until then, separate labels must remain separate in service, geography, support, capacity and outage analysis.

Finally, the operator's own domain would benefit from independently tested authoritative DNS, with servers demonstrably separated across failure domains if that is the design. A single registry timeout is not an outage history, but a current multi-vantage result could resolve the uncertainty it creates.

An active network with a sharply bounded public case

SW Internet is not a paper-only registration. On 15 July 2026, AS267217 originated its registered IPv4 and IPv6 resources with broad RIS visibility. IX.br exposed established dual-stack sessions in Salvador. The routing layer is active, measurable and specific enough to reveal that the two IPv4 /23s did not have the same path distribution.

The most consequential finding is the upper half's concentration. Every collected path for 45.231.182.0/23 placed ITS immediately before SW, while the covering /22 and lower /23 also appeared through BR.Digital. The aggregate could provide an alternative route if the more-specific disappears, but the public record does not show whether that recovery has been tested, whether the surviving path is independent, or whether it has sufficient headroom.

IPv6 showed a different concentration, with BR.Digital immediately before SW in 344 of 347 paths. Salvador IX participation added live logical reach but not proven physical redundancy. RPKI validation was unknown for all four announcements. Port rates, circuit rates, traffic load, facilities, equipment, power and failure-condition capacity remained undisclosed.

The evidence grade is therefore Medium for the network as a logical operating system and Weak for its physical resilience and capacity. That conclusion belongs only to SW Internet Ltda - ME, CNPJ 18.605.214/0001-57, and AS267217. It does not absorb the offers, locations, support operation, access assets or users of the separately numbered SW Tellecom or the SW Fibra name. The boundary is not a footnote to the research. It is what keeps a precise routing analysis attached to the correct company.