Summary
- AS210973 (DATAMATIX-AS) is registered to DATAMATIX Datensysteme GmbH in the RIPE region, allocated on 30 July 2021, with the company matching the Austrian Firmenbuch entry FN 240683x.
- Two RIPE-hosted ROAs authorise AS210973 to originate 212.236.9.0/24, 212.236.10.0/24, 149.62.35.0/24, 194.0.132.0/24 and 2a10:fd00::/32; the authorisations are valid, but an authorisation is not an announcement.
- Monitors disagree about what the network actually announces today: bgp.tools and RIPEstat/RIS list four IPv4 prefixes including 194.0.132.0/24, while CIDR Report and Qrator Radar show only three IPv4 prefixes (768 addresses), and one lookup service calls 194.0.132.0 not currently announced.
- The role of AS8218 (Zayo Europe), which appears in a route-server AS path but not in the RIPE aut-num's import/export statements, remains unresolved.
- Across the full evidence set, registration and cryptographic authorisation are provable; operated network or datacenter capacity is not, and the gap between the two is the finding.
DATAMATIX Datensysteme GmbH occupies a small but instructive corner of the public internet record. The Vienna data-systems company has held the autonomous system AS210973 since the RIPE NCC allocated the number on 30 July 2021, and the organisation object's registration number matches the Austrian commercial register entry FN 240683x, closing the chain from registry entry to identifiable business https://bgp.tools/as/210973 https://stat.ripe.net/resource/AS210973 https://btw.media/en/datamatix-as210973-evidence-chain-closed. The question this report asks goes one step beyond that closed chain: what does the network's current observable posture — live route originations, RPKI validity, upstream adjacencies — actually say about whether operated network capacity exists behind the registrations?
The short answer is that the record supports three separate conclusions, one per layer, and they do not converge.
The registration layer is solid. AS210973 is an Active/Allocated RIPE object registered to at.datamatix, allocated 30 July 2021, country AT. bgp.tools reports the network as a content-type network with four IPv4 and one IPv6 prefix originated: 149.62.35.0/24, 194.0.132.0/24, 212.236.9.0/24, 212.236.10.0/24 and 2a10:fd00::/32 https://bgp.tools/as/210973. RIPEstat independently records the allocation date and holder, and adds that the ASN is not seen in RIS as transiting https://stat.ripe.net/resource/AS210973.
The authorisation layer is complete and consistent. Two ROAs hosted in the RIPE NCC's certification repository authorise AS210973 for 212.236.9.0/24 and 212.236.10.0/24 with maximum length 24, and for 149.62.35.0/24 and 194.0.132.0/24 with maximum length 24 plus 2a10:fd00::/32 with maximum length 32 https://console.rpki-client.org/AS210973.html. A second, independent rpki-client validator instance in Amsterdam shows exactly the same two ROAs and the same rpki.ripe.net repository SIAs, corroborating that the cryptographic authorisations are not a single-snapshot artefact https://console-ams.rpki-client.org/AS210973.html. Hurricane Electric's monitor counts all four originated prefixes as RPKI-originated-valid with zero invalid https://bgp.he.net/AS210973. This is what a clean RPKI posture looks like: every announced prefix is covered by a valid authorisation naming exactly this origin AS.
But the same RIPE documentation is explicit about what a ROA certifies: an authorisation for an origin AS to announce a prefix with an optional maximum length. Route origin validation states — Not Found, Valid, Invalid — are computed from covering ROAs. A ROA's presence does not by itself prove that any announcement is live https://www.ripe.net/manage-ips-and-asns/resource-management/rpki/resource-certification-roa-management/. Authorisation, announcement and capacity are three different claims, and RPKI sits at the boundary between the first two, not across all three.
The observation layer is genuinely split, and the split has a pattern. RIPEstat's RIS-based view lists four IPv4 prefixes for AS210973, each at 25% visibility, including 194.0.132.0/24 https://stat.ripe.net/resource/AS210973. bgp.tools agrees on the four-prefix IPv4 footprint https://bgp.tools/as/210973. Hurricane Electric likewise counts 194.0.132.0/24 among the announcements and reports 768 IPv4 addresses originated across three IPv4 prefixes plus the IPv6 block 2a10:fd00::/32 https://bgp.he.net/AS210973 — a count where the arithmetic (three /24s at 256 addresses each) quietly excludes the fourth prefix from the address tally even as it lists the announcement.
CIDR Report tells a different story. Its AS report shows three announced prefixes totalling 768 IPv4 addresses, upstream adjacencies limited to AS24953 (NETPLANET GmbH) and AS8245 (Video-Broadcast GmbH), and it describes 212.236.9.0/24 and 212.236.10.0/24 as more-specifics of 212.236.0.0/16. Its view omits 194.0.132.0/24 entirely https://www.cidr-report.org/cgi-bin/as-report?as=AS210973&view=2.0. Qrator Radar's prefix view matches that three-IPv4-prefix picture: it lists 2a10:fd00::/32, 149.62.35.0/24, 212.236.9.0/24 and 212.236.10.0/24 as RPKI Valid and Route Object Valid with 100% propagation in its sample — and does not list 194.0.132.0/24 at all https://radar.qrator.net/as/210973/connectivity/prefixes.
A third voice complicates the split in the other direction. The lookup service checkip.com labels 194.0.132.0 as "not currently announced", assigns it a historical ASN of AS210973, and attributes the netblock to DATAMATIX Datensysteme GmbH — a position that conflicts with both the RIS-visible evidence and the valid ROA covering the prefix https://checkip.com/ip/194.0.132.0/. Prior BTW reporting has already mapped this divergence in detail: a RIPE route object for 194.0.132.0/24 with origin AS210973 was created on 13 November 2025 with maximum length 24; the prefix appeared as an RPKI Valid Best Route at an AMS-IX route server with AS path 8218 210973, but as received-not-exported at a Netnod route server, and it is absent from CIDR Report's view. Monitor default filters can exclude low-visibility announcements, which is the mechanism RIPEstat's inclusion and CIDR Report's exclusion are both consistent with https://btw.media/en/datamatix-as210973-route-visibility-divergence.
The upstream question has no closure in the registry. The RIPE aut-num object for AS210973 declares import and export policies only toward AS8245 and AS24953, and was last modified on 5 June 2023 https://bgp.tools/as/210973. Yet bgp.tools and Hurricane Electric both list AS8218 (Zayo Europe) among the network's upstreams or peers https://bgp.tools/as/210973 https://bgp.he.net/AS210973. The 8218 210973 AS path observed at the AMS-IX route server is the only place AS8218 connects to this network in the observable record. Whether AS8218 is an active transit provider, a historical adjacency, or a backup path cannot be determined from the public record, and the aut-num's static policy list does not resolve it.
Netblock attribution is a fourth, weaker layer. IPinfo attributes all four /24 netblocks to DATAMATIX Datensysteme GmbH and reports 1,024 IPv4 addresses for the ASN — allocated 30 July 2021, last updated 5 June 2023. Netblock attribution is a registry-derived view distinct from observed announcements, and IPinfo's own announcement views have in other coverage been reported as omitting 194.0.132.0/24 https://ipinfo.io/AS210973. Attribution answers "whose addresses are these in the commercial database?", not "are they routed right now?"
Read as a whole, the current posture yields a precise verdict. What is proven: the registry identity, the allocation date, the firm registry match, two complete and independently corroborated ROA sets, and a monitor-divergent but real origination footprint of three IPv4 prefixes plus one IPv6 prefix. What is contested in observation: the live announcement of 194.0.132.0/24. What is unresolved: AS8218's role. What is not addressed by any public source in the evidence set: whether any physical network, datacenter or service capacity operates behind the registrations.
A ROA authorises, a route object declares, a monitor observes with filters and vantage-point bias — none of these measures forwarded packets, housed hardware, or served a customer. On the current record, DATAMATIX's network is fully registered and fully authorised, and its operational substance remains an open measurement question.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
