Summary

  • Galaxy Software LLC looks less like a commodity hosting seller than a small Russian telecom-software operator that can host, monitor and support its own platforms for customers that want responsibility attached to the software. Its public site points to anti-spam, anti-fraud and messaging-management software for mobile operators, optional PaaS deployment on Galaxy's infrastructure or inside the customer perimeter, two independent data centres and 24/7 monitoring.
  • The 2025 financial record is strong enough to say the current business can probably pay for its present infrastructure and labour base: public contractor databases report 251.045 million rubles of revenue and 51.326 million rubles of net profit. That is a profitable specialist-services run rate, not proof that Galaxy owns a scalable cloud platform.
  • The network evidence is real but modest. Galaxy is a RIPE NCC member and originates AS212299 with one visible IPv4 /22, two upstreams, no visible downstreams, no current IPv6 announcement in RIPEstat and no validating ROA for the current IPv4 route. This footprint supports a hosted-operations thesis, but it does not show broad wholesale demand, peering power or deep data-centre control.
  • The judgment is conditional: Galaxy can defend margin if customers value telecom-specific software operations more than raw compute. If customers can buy the same reliability from Yandex Cloud, Selectel, Cloud.ru, Rostelecom, mobile-operator anti-fraud clouds or in-house carrier systems, Galaxy's rented infrastructure becomes cost, not moat.

The payer is buying responsibility, not a server

The right starting point is the buyer. A mobile operator, enterprise messaging customer or regulated communications business does not wake up wanting "hosting" in the abstract. It wants a campaign-control system, a subscriber-protection workflow, a fraud-screening component, a monitoring bridge or an integration with its existing telecom stack to keep working after deployment. The vendor who takes that work is paid because someone must be answerable when delivery fails, false positives rise, spam leaks through, a database falls behind or a regulator asks why the operator's controls were not available.

That is the economic opening for Galaxy Software LLC. Its public site does not lead with low-cost virtual machines. It describes an accredited Russian IT company that develops software for the telecom industry. The stated specialism is software complexes for information and advertising mailings for mobile operators, plus tools that protect subscribers from spam and fraud. It offers analysis, architecture and design; software development, modification and adaptation; infrastructure deployment; and monitoring and support.

It says its platforms can be deployed either on Galaxy's own infrastructure under a PaaS model or inside the customer's own perimeter. It also says its infrastructure is located in two independent data centres, with additional redundancy for critical network nodes and communications channels, and that a unified monitoring centre operates 24/7/365.

Those claims make the unit of sale different from the unit of cost. The cost side is ordinary and difficult: compute, storage, traffic, data-centre space, upstream transit, monitoring tooling, engineers, first-line support and software maintenance. The revenue side must be less ordinary. Galaxy has to make a customer pay for a complete operating promise: design the system, adapt the software, deploy it in the right place, keep it monitored and carry enough incident responsibility that the customer does not have to run the whole stack alone.

If Galaxy only rents infrastructure and resells it, the payer can compare it with public cloud prices and ask for a discount. If Galaxy owns the software workload, understands operator messaging rules, provides hands-on support and can host the system when the customer does not want to operate it internally, the comparison changes. The buyer is no longer asking "How many vCPUs?" It is asking "Who will keep this telecom workflow alive, compliant and supportable?"

That distinction is the article's central test. Galaxy's economic future depends on whether the accountable software layer earns more than the rented infrastructure underneath it.

The legal company is small, controlled and recently repositioned

The public identity record is coherent. Contractor and registry mirrors identify the Russian legal entity as OOO "Galaxy Software", translated here as Galaxy Software LLC, registered in Moscow on 9 January 2019 with OGRN 1197746001815 and INN 9731021323. T-Bank's contractor page and RBC Companies list the current legal address at Bolshaya Ordynka Street 54, building 2, premises 1/P in Moscow. The registered main activity is software development. Additional activity codes include computer-game publishing, other software publishing, wired telecommunications activity and data transmission or Internet access services.

Control is concentrated. T-Bank lists Maria Davidovna Gorkova as director from 11 June 2024 and as the 100 percent founder or participant with a 200,000-ruble charter-capital contribution. RBC also identifies Gorkova as general director and founder. T-Bank records an address change in August 2025 from Gorbunova Street to Bolshaya Ordynka, and a management change in June 2024 from Alexander Vasilyevich Buyanov to Gorkova. Xfirm's mirror adds prior founder history, including Buyanov and other earlier participants, before Gorkova's current ownership period.

The public company site adds a separate operational identity. It gives the same Moscow address, the same OGRN, INN and KPP, states that the main OKVED is 62.01 software development, and says the company is included in the register of IT companies under number 10312 from 5 June 2019. It describes a comfortable Moscow office, tolerance for remote work, and employees living across Russia, from Kaliningrad to Sakhalin.

That labour statement is useful not because it proves scale, but because it fits the business model: a small specialist team can support software operations across time zones if the work is mostly remote engineering, monitoring and incident response.

The headcount evidence is inconsistent. RBC's company page reports average headcount of 9 employees, while Companium and Xfirm report 33 employees for 2025. That is not a trivial difference for a services business. At 9 employees, 2025 revenue would imply an unusually high revenue-per-employee figure for a small software operator. At 33, the company still looks lean but less anomalous. The safe conclusion is narrower: public mirrors agree Galaxy is a micro or small Russian company, not a large carrier, and its economics rely on a concentrated technical staff rather than a broad labour bench.

The governance risk follows from that. A customer that buys accountable operations from a small company is buying the judgment, availability and continuity of a few people. Concentrated ownership can make contracting faster and direction clearer, but it also raises key-person and succession risk. A 24/7 support promise is easier to write than to staff if incidents arrive at the same time as product work, regulatory changes and customer-specific integration requests.

The financial record supports a viable specialist operation

Galaxy's 2025 financial numbers are the strongest evidence that the current business is not merely aspirational. T-Bank reports 251.04 million rubles of 2025 revenue and 51.32 million rubles of profit. RBC gives the fuller rounded figures: 251.045 million rubles of revenue, 51.326 million rubles of net profit, 189.091 million rubles of assets and 110.950 million rubles of equity. RBC also lists 2025 cost of sales at 200.269 million rubles and says revenue rose from 40.501 million rubles at the beginning of the year to 251.045 million rubles by year end.

B2B House, Companium and Xfirm broadly mirror the same 2025 revenue and profit direction.

Those figures matter because they convert the assignment's question from theoretical to concrete. A company with roughly 251 million rubles of revenue and roughly 51 million rubles of net profit has enough reported operating room to pay for a modest network footprint, local data-centre capacity, monitoring, support and engineering labour. The public numbers do not show customer concentration, contract duration, gross margin by product or cash conversion, but they do show that the company did not need commodity-hosting margins alone to produce a profit in 2025.

The reported cost of sales is equally important. If one reads the RBC figure literally, cost of sales consumed about 200 million rubles against 251 million rubles of revenue. That leaves a gross spread that can support profit only if overheads are contained or if parts of the cost line include pass-through work tied to customer projects. This is consistent with a bespoke software and managed-operations model. Custom development, adaptation, support shifts, hosting inputs and integration work all create direct costs. They also justify customer-specific pricing.

Galaxy's own pricing statement supports that interpretation. The site says the company owns exclusive rights to its own software products, acts as an integrator and custom developer, and adapts or modifies software products and services to customer needs. It does not publish a commodity tariff. It says licence remuneration, development work, technical support and adaptation are calculated individually and fixed in contract. That is a useful commercial signal: Galaxy is not trying to win by posting the lowest virtual-server price. It is trying to price by customer problem, software rights, support scope and contract obligations.

The positive reading is that 2025 demonstrates demand for that bundle. The cautious reading is that a sudden jump from a lower revenue base could reflect one or several large projects rather than repeatable annual recurring revenue. Without named customers or contract tenors, one cannot know how much of the 251 million rubles is stable support and licensing, how much is non-recurring development, and how much is infrastructure pass-through. That distinction matters more than the revenue number itself. Recurring software and support revenue can cover ongoing monitoring and rented capacity.

One-off development revenue can make one year look strong while leaving the next year's support obligations underpriced.

Network resources show operational presence, not cloud depth

The public network evidence is real enough to separate Galaxy from a pure brochure company. RIPE NCC lists Galaxy Software LLC as a member in Russia, with the same Bolshaya Ordynka address, a contact phone number and a technical email at the Galaxy domain. RIPEstat identifies AS212299 as "Galaxysoft Galaxy Software LLC" and reports that it is announced. IPIP's WHOIS mirror shows the RIPE aut-num object created on 3 March 2025, with imports from AS29226 and AS12389 and exports to those same networks. Those upstreams are JSC Mastertel and PJSC Rostelecom, both sensible Russian connectivity suppliers for a Moscow-based operator.

RIPEstat's current announced-prefixes data shows one visible IPv4 announcement, 185.225.152.0/22. RIPEstat's routing-status data reports one IPv4 prefix, 1,024 IPv4 addresses, full visibility among measured IPv4 RIS peers at the query time, two observed neighbours and no visible IPv6 announcement. Its as-routing-consistency data shows the /22 in BGP and WHOIS, plus more-specific WHOIS route objects that were not visible as separate BGP announcements at query time. Its ASN-neighbours data identifies two left-side neighbours, AS12389 and AS29226. The prefix-overview endpoint ties the /22 to AS212299.

CIDR Report likewise sees the autonomous system originating 1,024 IPv4 addresses and no transit address space.

The network also has weaknesses. RIPEstat's RPKI validation endpoint reports the current 185.225.152.0/22 origin status as unknown, with no validating ROAs. That is not evidence of abuse, but it is a route-security gap for a company selling accountable hosted operations. RPKI does not make an application good or a customer safe; it reduces one class of routing assurance problem. For a vendor that asks customers to trust its platform availability, unsigned origin authorization is a fixable omission.

The IPv6 picture is also mixed. Third-party allocation summaries show Galaxy-associated IPv6 space in RIPE-region allocation tables, while RIPEstat's current routing-status output shows no IPv6 prefix announced at the measured time. That suggests number-resource possession or historical allocation is not the same as active dual-stack service. For many telecom and enterprise workloads in Russia, IPv4 may still carry the practical load. But if Galaxy wants to be judged as an infrastructure operator rather than a project host, the lack of visible IPv6 routing weakens the story.

There is no public evidence of downstream networks or large wholesale customers behind AS212299. IPLocate and IP2Location describe one IPv4 range or a small number of ranges, two upstreams and no downstreams. BigDataCloud's lookup for a more-specific /24 shows Galaxy as the organization and AS212299 as announcer, with traffic received via Mastertel and Rostelecom. CleanTalk reports zero spam-active IPs in its detected slice of AS212299 at the time its page was crawled. Cloudflare Radar has overview, routing and traffic pages for AS212299, but those pages are better treated as public telemetry surfaces than as proof of business scale.

The inference is straightforward. Galaxy has enough routing evidence to support a claim that it operates or controls a modest public network footprint. It does not have enough public network evidence to support a claim that it is a broad cloud platform. The infrastructure looks like support for hosted telecom software, internal platforms, customer-specific services and maybe a small number of hosted domains. That is adequate if the product is accountable software operations. It is inadequate if the business is meant to compete as a general-purpose cloud.

The PaaS claim must absorb the hidden costs of reliability

Galaxy's site says its software platforms can run on its own infrastructure by PaaS model or in the customer's perimeter. That optionality is economically valuable. Some telecom customers will want a vendor-operated platform because they lack the internal team, want faster deployment or prefer contract accountability. Others will insist on in-perimeter deployment because of data, security, network integration or procurement rules. Galaxy can serve both only if its software is portable enough and its support model is disciplined enough.

The cost problem begins with that same flexibility. Running a vendor-hosted platform means Galaxy pays for or rents data-centre space, compute, storage, backup, network, DDoS protection and monitoring. Running in the customer's perimeter reduces some hosting cost, but increases integration, documentation, upgrade and support complexity. Each customer variation creates a maintenance surface. Each version, data path and deployment topology can become a support obligation.

Galaxy's claim of two independent data centres is useful but incomplete. It tells the buyer that the company understands redundancy, not who owns the facilities, which availability tier applies, how failover is tested or whether customers receive service-level credits. In practical economic terms, two data centres mean duplicated capacity, duplicated network arrangements, monitoring across sites and a support team that can act when one side fails. Those are fixed or semi-fixed costs. They only improve margins if enough customers or enough high-value workloads share the architecture.

The network suppliers are visible where the facilities are not. Mastertel and Rostelecom are present as upstreams in the routing record. RIPE membership itself has recurring institutional cost: the 2026 RIPE NCC charging scheme keeps the annual contribution per LIR account at 1,800 euros, plus relevant resource charges, and the membership page says organisations needing IPv6, AS numbers or assignments to end users may become members. For a company with 251 million rubles of revenue, the RIPE fee is not material. It is still a reminder that the infrastructure business carries ongoing obligations before a single customer incident is handled.

The larger cost is labour. Galaxy's page describes a first-line duty shift that can resolve most incidents and escalate to engineers or developers when needed. That is exactly the model customers pay for, and exactly where underpricing becomes dangerous. If a customer buys hosted telecom software because it is critical, incidents are not just tickets. They become business interruptions, fraud leakage, failed messaging traffic or regulatory exposure. A support contract that prices only server uptime but absorbs application accountability will lose money at the first difficult customer.

The company's individual-pricing language is therefore not evasive; it is rational. Public tariffs would push Galaxy into commodity comparison. Individual contracts let it price licence rights, adaptation work, support hours, platform hosting, monitoring, incident response and customer-specific risk. The danger is that customers also prefer individual pricing when they can push more responsibility into the vendor without paying a proportional premium. Galaxy's discipline will be tested less by its ability to deploy infrastructure than by its refusal to sell open-ended support at project-service prices.

Direct cloud alternatives set the floor for what Galaxy cannot charge

The Russian market gives Galaxy both shelter and pressure. Shelter comes from locality, language, sanctions-driven substitution, data-sovereignty requirements and a regulatory environment that rewards domestic infrastructure and operator-specific compliance. Pressure comes from the fact that Russian customers have several direct cloud and hosting alternatives with transparent pricing, larger capacity pools and established operations.

Yandex Cloud publishes Compute Cloud pricing rules that charge for vCPU, RAM, storage, outgoing traffic and public IP addresses, with Russian-region ruble pricing available for customers contracting with the Russian legal entity. Its compute service page presents ready configurations from small development instances to larger standard setups. Selectel publishes cloud-server payment rules based on pay-as-you-go hourly charging, external traffic limits and a broader price list that includes cloud servers, managed Kubernetes, colocation and related services.

Cloud.ru publishes virtual-machine pricing rules, including pay-as-you-go charging for compute, boot disks, additional disks and public IP addresses, and gives calculation examples for different VM shapes.

Those providers are not perfect substitutes for Galaxy. A cloud VM does not by itself give a telecom operator a subscriber anti-fraud platform, a campaign-management system or a vendor who knows the operator's integration constraints. But they are excellent substitutes for the infrastructure layer. If a customer can deploy Galaxy's software inside its own cloud account, or if a larger integrator can combine generic cloud capacity with a comparable application, Galaxy cannot earn a large markup for raw compute alone.

The same is true of colocation and direct hosting. Selectel's public price list includes colocation and network-related services. A customer with enough internal capability can rent rack space, buy cloud instances or contract with a larger managed provider. The more standardized the workload, the easier it is to bypass Galaxy's hosted option. The more operator-specific the workflow, the more valuable Galaxy becomes.

This is why Galaxy's own wording matters. It says architecture is selected according to reasonable sufficiency and the price, quality and fault-tolerance ratio. That is the language of a services integrator, not a hyperscale cloud. The promise is not infinite capacity; it is fit-for-purpose architecture. In a procurement contest, that can win when the buyer values lower integration burden and named accountability. It loses when the buyer wants a commodity bill, abundant self-service tooling and a provider with national-scale platform depth.

The direct-cloud alternatives also create a negotiating anchor. A customer can use Yandex, Selectel or Cloud.ru pricing to challenge the infrastructure portion of Galaxy's bill. Galaxy then has to defend the rest of the price with software rights, adaptation work, monitoring, incident response and telecom expertise. If those items are visible in the contract, the margin can survive. If they are bundled into a vague hosted-service price, the customer will treat them as free.

Telecom anti-fraud creates demand, but also powerful rivals

Galaxy's stated focus on subscriber protection from spam and fraud is timely. Russian public institutions have made telephone and internet fraud a policy priority. The Bank of Russia's 2025 fraud review says it forwarded information on 69,091 phone numbers used by fraudsters to communications providers for response measures. The Russian government has described a broad anti-fraud effort involving banks, mobile operators, digital platforms and law enforcement, including an integrated state information system.

Interfax reported that a 2026 legislative package would tighten operator requirements around the GIS "Anti-Fraud" system and SIM-card controls, citing more than 113.4 million calls passed without verification in 2025 because verification nodes operated by telecom providers were unavailable.

That environment creates demand for telecom software, monitoring, integration and support. It also raises the standard. Anti-fraud systems are not static web applications. They ingest signals, coordinate with operator networks, interact with banks or state systems, and must avoid both missed fraud and damaging false positives. Galaxy's website claim that it builds subscriber-protection software is therefore economically significant. If true in deployed systems, it gives Galaxy access to urgent regulated demand.

But the same market has strong incumbents. ComNews Research's 2025 review of mobile-operator subscriber security discusses anti-fraud systems at the big four operators, connection to the state anti-fraud system, cloud verification services and the role of operator-owned platforms. It describes Beeline's own import-independent anti-fraud platform and notes that operators have developed cloud verification services for smaller operators that lack the equipment or expertise to connect directly.

That is exactly the type of adjacent service Galaxy might want to provide or integrate with, but it also means large carriers and their technology partners are already monetizing the need.

Galaxy's likely opening is not to displace the big four. It is to serve specialized, customer-specific or smaller-operator workflows where a large carrier platform is too rigid, where bespoke development is needed, or where the buyer wants a vendor that can adapt software and host it if necessary. That is a narrower market, but it can be profitable if contracts are priced for complexity.

The risk is liability mismatch. Anti-fraud and anti-spam systems create binary customer expectations: if the system works, it becomes invisible; if it fails, the vendor is blamed. A small company can be pulled into emergency support, regulator-facing explanation or customer compensation long after the original development work was paid. Galaxy's individual pricing must account for that tail. A recurring support fee that only covers first-line monitoring will not pay for deep forensic engineering after a fraud wave or messaging failure.

Data locality helps, but it is not a private moat

Russian data-locality requirements strengthen the case for domestic hosting and in-country operations. The personal data law, as amended, restricts the collection and handling of Russian citizens' personal data using databases located outside Russia, subject to defined exceptions. For telecom-related systems, subscriber data, campaign records and fraud signals are sensitive enough that customers will naturally prefer local deployment or Russian-controlled hosting.

That helps Galaxy in two ways. First, it reduces the attractiveness of foreign hyperscale defaults for Russian customer data, especially after geopolitical separation and sanctions pressure. Second, it makes customer-perimeter deployment more valuable, because some buyers will want the software inside their own controlled environment rather than in a foreign or opaque cloud.

Locality, however, is shared by many competitors. Yandex Cloud, Selectel, Cloud.ru, Rostelecom and mobile-operator platforms can all sell Russian locality in some form. Galaxy cannot win merely by being Russian or by using Russian data centres. It has to win by combining locality with software specificity and operational accountability.

Sanctions and cross-border risk also cut both ways. RIPE's membership page notes that entities subject to EU sanctions cannot become members. Galaxy is listed as a RIPE member, which is positive in that narrow institutional sense. But Russian infrastructure businesses still face a procurement world shaped by foreign supplier exits, hardware constraints, software substitution, payment friction and customer concern about long-term supply chains. A local provider may become more attractive when foreign vendors leave, but its own equipment, security tooling and route ecosystem may also become harder to maintain.

The data-locality point is therefore a support to the thesis, not the thesis itself. It can push customers toward domestic providers. It does not explain why Galaxy rather than a larger domestic cloud should capture the recurring value.

The unofficial signals are quiet rather than expansive

Unofficial and market-signal sources do not show a broad public footprint. CleanTalk's blacklist page reports no spam-active IPs in the detected AS212299 slice. Cloudflare Radar exposes overview, routing and traffic pages, which confirms the ASN is visible enough for telemetry surfaces, but does not by itself demonstrate scale. PeeringDB's API returned no network entity for AS212299 when queried by ASN, which is consistent with a customer network buying transit rather than an interconnection-heavy operator seeking public peering relationships.

Search results did not surface a strong body of customer reviews, forum complaints, named telecom deployments or social proof. T-Bank's contractor page says there are no reviews or ratings in its interface. That absence is not a defect by itself. Many B2B telecom-software vendors have private customer relationships and little public marketing. But it does affect confidence. A public article cannot infer customer satisfaction from silence.

The intellectual-property record adds a different signal. RBC Companies lists the FUNBOX FUNBOX FUN BOX trademark as owned by Galaxy Software, with registration in 2016 and rights shown through 2034. Garant's publication of a Rospatent decision shows Galaxy as applicant in a patent dispute concerning a method of learning a foreign language. Those records show that the legal entity or its predecessor asset base has dealt with software or digital-product IP beyond the current telecom-hosting page. They do not prove current telecom revenue, but they fit the pattern of a software-rights company rather than a shell host.

The occupational-safety declaration listed by Rostrud in 2022 is minor but useful. It places the company at an earlier Moscow address, identifies one general-director workplace in a labour-safety declaration and gives the same INN and OGRN. It supports operational continuity of a small office employer, not platform scale.

The quiet signal set points to a private, project-led company. That can be economically healthy. It also means public investors, suppliers and customers cannot verify much beyond registry, finance, website claims and routing.

The control boundary is the important diligence question

Galaxy's control boundary should be the first question in any serious customer diligence. Which parts of the stack does Galaxy own? Which parts does it rent? Which parts are customer-controlled? Which incidents are Galaxy's responsibility? Which are upstream, data-centre, cloud, operator or customer perimeter problems?

The public evidence gives only a partial map. Galaxy owns or controls its software products, according to its site. It controls AS212299 and a visible IPv4 /22 route, according to RIPE and routing sources. It uses Mastertel and Rostelecom as upstreams. It says it has infrastructure in two independent data centres. It uses Tilda and DDoS-Guard for its public marketing website, based on the page's technology and response headers, but that is not evidence about production customer infrastructure. It does not publicly name data-centre facilities, hardware suppliers, monitoring stack, customer list, backup design or service-level terms.

For a buyer, this matters because accountability without control is expensive. If Galaxy sells hosted operations on rented facilities and upstream connectivity, it can monitor and escalate, but it cannot directly repair every failure. If it sells in-perimeter deployments, it may control software but not customer firewalls, databases or identity systems. If it adapts software for operator-specific anti-fraud workflows, it may depend on external state systems, bank signals or operator routing that are outside its power.

Good contracts can price that boundary. Bad contracts hide it. Galaxy's individual contract model gives it a chance to define support tiers, escalation windows, hosting responsibility, change management, maintenance windows and liability caps. The economic risk is that a customer hears "24/7/365 monitoring" and interprets it as total operational insurance.

The public evidence does not show whether Galaxy has solved this contract problem. Its 2025 profit suggests it has not obviously failed. But a single profitable year is not a stress test for support liability.

What would reverse the judgment

The current judgment is positive but narrow. Galaxy appears capable of supporting a profitable specialist software-and-hosted-operations business at its present scale. The business is attractive only when the customer pays for accountable telecom software operations, not when the customer prices it as rented infrastructure.

Several facts would reverse or weaken that judgment. The first would be customer concentration. If most of 2025 revenue came from one non-recurring development project or one customer with weak renewal probability, the reported profit would not prove recurring infrastructure coverage. The second would be margin deterioration. If hosting obligations, first-line support, data-centre costs or anti-fraud incident work grow faster than support fees, the apparent software margin can disappear.

The third would be evidence that customers mostly deploy inside their own perimeter and pay Galaxy only for one-off development. That would make the PaaS claim less important and reduce the recurring-hosting thesis. The fourth would be direct evidence that large Russian clouds or mobile operators offer equivalent anti-spam, anti-fraud or messaging-control services at lower total cost, including support. In that case Galaxy would have to survive as a custom integrator, not as a platform owner.

The fifth would be network-quality stagnation. A growing hosted-operations provider should eventually show stronger routing hygiene, clearer IPv6 posture, RPKI coverage, better public abuse-contact practice and perhaps broader interconnection evidence. A small single-/22, two-upstream topology can serve present workloads, but it does not support a large cloud story.

The sixth would be regulatory capture by larger platforms. If GIS Anti-Fraud integration, call-marking requirements or telecom-security controls become easier to buy through major operators, smaller specialist vendors may be pushed into subcontracting positions with lower margin and less customer ownership.

Judgment

Galaxy Software LLC has a plausible economic position because it sells, or at least publicly presents, a bundle that customers cannot buy from a commodity VM page: telecom-sector software, adaptation, hosted deployment, monitoring and support. The 2025 financial record shows enough revenue and profit to cover a modest infrastructure footprint and a small technical team. The RIPE and routing records show real network control, though not a large cloud platform. The regulatory environment creates demand for anti-spam, anti-fraud and localized telecom software, while also raising the cost of failure.

The company should not be valued as a cloud infrastructure competitor in the usual sense. Its visible network footprint is too small, its upstream posture too dependent and its public platform evidence too thin. It should be understood as a specialist software operator with optional hosting. That is a better business if priced correctly. It can earn margin when the customer pays for responsibility. It loses that margin when the customer sees only rented compute.

The explicit answer to the core question is therefore: yes, recurring software, support and hosted-operations revenue can cover Galaxy's rented compute, network cost, engineering labour, customer support and security risk at the current scale, but only if the recurring part is real and the support liability is contractually bounded. The public numbers show present viability, not durable scale. Galaxy's moat is not the /22, the ASN or the data-centre claim. It is the customer's willingness to pay for a small team to understand a telecom problem well enough to operate it better than a generic cloud account.

Sources

  1. https://galaxysoft.group/
  2. https://www.ripe.net/membership/member-support/list-of-members/ru/galaxysoft/
  3. https://stat.ripe.net/data/as-overview/data.json?resource=AS212299
  4. https://stat.ripe.net/data/announced-prefixes/data.json?resource=AS212299
  5. https://stat.ripe.net/data/routing-status/data.json?resource=AS212299
  6. https://stat.ripe.net/data/as-routing-consistency/data.json?resource=AS212299
  7. https://stat.ripe.net/data/asn-neighbours/data.json?resource=AS212299
  8. https://stat.ripe.net/data/rpki-validation/data.json?resource=AS212299&prefix=185.225.152.0/22
  9. https://stat.ripe.net/data/prefix-overview/data.json?resource=185.225.152.0/22
  10. https://whois.ipip.net/AS212299
  11. https://www.ip2location.com/as212299
  12. https://www.iplocate.io/AS212299
  13. https://www.bigdatacloud.com/network-lookup/185.225.153.0/24
  14. https://www.ipaddress.com/ipv4/185.225.153.12
  15. https://cleantalk.org/blacklists/as212299
  16. https://radar.cloudflare.com/as212299/
  17. https://radar.cloudflare.com/routing/as212299
  18. https://radar.cloudflare.com/traffic/as212299
  19. https://www.cidr-report.org/cgi-bin/as-report?as=AS212299&view=2.0
  20. https://www-public.telecom-sudparis.eu/~maigron/rir-stats/ripe-allocations/allocations/ru-ip-allocations.html
  21. https://www.tbank.ru/business/contractor/legal/1197746001815/
  22. https://companies.rbc.ru/id/1197746001815-obschestvo-s-ogranichennoj-otvetstvennostyu-gelaksi-softver/
  23. https://b2b.house/company/OOO-GELAKSI-SOFTVER_33885659-a44b-48ca-bbe2-d25a904cb579/
  24. https://companium.ru/id/1197746001815-gehlaksi-softver
  25. https://xfirm.ru/company/9731021323
  26. https://companies.rbc.ru/trademark/570900/funbox-funbox-fun-box/
  27. https://base.garant.ru/480205657/
  28. https://declaration.rostrud.gov.ru/declaration/index?DeclarationSearchinn=7714109038&DeclarationSearchregion_id=&DeclarationSearchtele=&DeclarationSearchverify=0&page=9464&per-page=50
  29. https://www.ripe.net/publications/docs/ripe-848/
  30. https://www.ripe.net/languages/en/membership/
  31. https://yandex.cloud/en/docs/compute/pricing
  32. https://yandex.cloud/ru/services/compute
  33. https://docs.selectel.ru/cloud-servers/about/payment/
  34. https://selectel.ru/prices/
  35. https://cloud.ru/docs/virtual-machines/ug/topics/pricing
  36. https://government.ru/docs/all/98196/?page=4
  37. https://www.cbr.ru/eng/analytics/ib/operations_survey/2025/
  38. https://government.ru/news/57324/
  39. https://www.interfax.ru/russia/1068002
  40. https://www.comnews.ru/content/241963/2025-10-28/2025-w44/1180/bilayn-priznan-samym-bezopasnym-operatorom-2025-godu-kompleksu-mekhanizmov-zaschity-abonentov-sotovoy-svyazi