Summary

  • Plus Analytics says it offers VPN products for business travellers and corporate offices; RIPE records separately identify it as a US local internet registry with IPv4 and IPv6 resources.
  • At the recorded RIPEstat observation time, its listed IPv4 /22 had no current origin visible to RIPE RIS collectors. That narrows what public routing evidence can prove; it does not prove that every Plus Analytics service was offline.

The word “VPN” compresses several promises into one label. A customer may hear confidentiality, private browsing, a US exit point, dependable access and a party that will respond when something fails. Plus Analytics’ own pages make versions of those promises. They describe Easy Tunnel for business travellers using hotel and airport networks and Total Tunnel for companies seeking to obscure corporate source addresses during online research. The company also says its team focuses on networking, security and IP attribution.

Those claims describe intended product outcomes. The public number-resource evidence describes something else. RIPE NCC lists Plus Analytics Inc. as a member serving the United States. Its organisation object, ORG-PAI2-RIPE, classifies the company as an LIR in the United States and gives a San Diego address. The company page, by contrast, describes a privately held business headquartered in San Antonio. The difference may be as ordinary as a move, an administrative address or old web copy. It is a question to resolve, not a basis for alleging misconduct.

The same distinction applies to network geography. RIPE links the IPv4 block 185.69.156.0/22 and the IPv6 block 2a05:2300::/29 to the organisation. Both resource objects carry a Netherlands country attribute, while the organisation is recorded in the United States. A registry country field is not a verified map of tunnel endpoints, customer traffic, staff or physical equipment. It can describe an administrative convention or intended network context. Treating it as proof of where a user’s traffic terminates would be a category error.

Routing adds another boundary. RIPEstat’s observation for 3 September 2026 at 16:00 UTC found no current origin for 185.69.156.0/22 and visibility at zero of 327 RIS IPv4 peers. It recorded the last observation of that block with origin AS201665 on 11 June 2026. The IPv6 /29 likewise had no current origin or observed route history in the returned data. This is meaningful evidence about those prefixes at that observation time.

It is not evidence that every possible Plus Analytics endpoint was unreachable: a service might use other address space, a hosting partner, a smaller assignment, a changed origin or an entirely different delivery arrangement.

The historical origin requires similar care. RIPE’s aut-num object calls AS201665 KSTNETWORKS and links it to ORG-KNI1-RIPE, not the Plus Analytics organisation object. RIPEstat returned no validating ROA and an “unknown” RPKI status for the queried historical pairing. None of this, alone, establishes who operated a tunnel, held a commercial contract or authorised a route at a particular moment. It shows why the join between allocation holder and delivery operator cannot be assumed.

For a VPN buyer, the practical task is to request that join. The seller should identify the legal contracting entity, current tunnel endpoints, the address holder, the announcing ASN, any hosting or transit operator, logging and key-management responsibility, abuse and incident contacts, and the party accountable for recovery. Evidence should be dated because routes, leases, subcontractors and endpoint locations can change faster than a product page.

Sources

Plus Analytics home; company page; services page; mission page; RIPE NCC member record; RIPE organisation object; RIPE linked resource objects; RIPEstat IPv4 routing status; RIPEstat IPv6 routing status; RIPE AS201665 object; RIPEstat RPKI validation.