Methodology
How we collect signals and turn them into connectivity and censorship scores.
Net Surveil is an observatory, not a courtroom. Two independent scores summarize different questions. Prefer reading labels as signals consistent with disruption or filtering, then open the country pulse before treating a claim as decisive.
Dual scores
Connectivity (0–100%)
Can people actually reach the internet? Higher is healthier. User-plane signals are primary. This score alone sets disruption level and can open connectivity incidents when evidence is strong enough.
Censorship (0–100%)
How blocked or filtered is the network? 0% = none, 100% = full. Levels rise with the score: low, elevated, high, severe. Score-only — chronic blocking does not flood the incident ledger.
What we measure
Connectivity — traffic and quality
Cloudflare netflow, IQI, and speed; M-Lab NDT; ArvanCloud (IR); probe loss, latency, jitter, foreign speed, DNS reachability.
Connectivity — reachability
IODA ping and darknet telescope falling below diurnal-adjusted baselines.
Connectivity — routing (secondary)
RIPE BGP v4, IODA BGP, RIS Live withdrawals, nationwide outage flags. Routing-only anomalies cannot open major/blackout incidents alone.
Censorship — blocking and filtering
OONI IM and circumvention blockage; Censored Planet unexpected rates; probe DNS poisoning and SNI blocking; Tor censorship events; government-directed outage flags.
Advisory
RIPE BGP v6 is collected for inspection but not scored (uneven IPv6 deployment).
How collection works
A separate Tracker service polls providers on a fixed interval (default about 15 minutes), stores time series, and scores countries. Volunteer probes register once and submit encrypted pulses. This website reads Tracker website_* views via DATABASE_URL (website_readonly). Partners use the Tracker HTTP API — this site does not scrape providers or handle probe crypto.
Ranking
Comparative ranks come from monthly website_country_ranks rows. Browse the ranking board.
Trailing 12 months (default)
Average each country’s monthly connectivity and censorship means over the last 12 calendar months, then RANK. MoM/YoY compare shifted 12-month windows (not a single calendar month).
Latest month
Tracker-authored calendar-month cohort with stored MoM/YoY deltas (previous month / same month a year earlier).
Polarity
Rank 1 = worst connectivity (lowest mean) or highest censorship (highest mean). Rank delta positive = improved. Connectivity mean up = healthier; censorship mean up = more censorship.
Disruption days
On usable connectivity observation days only: disrupted days are scores < 65; blackout days are scores < 30. Trailing boards sum these across the window.
Anomaly detection
Continuous healthier-is-higher series use MAD modified Z-scores against rolling baselines (soft Z > 2.5 with ≥5% drop; hard Z > 3.5 with ≥15% drop), plus absolute floors where configured. High-frequency sources use ~24h history; slower feeds look back farther. Cloudflare netflow, IODA, and RIPE visibility subtract hour-of-week medians before MAD so routine night/weekend dips look less like outages.
Blockage-style metrics (OONI, Censored Planet, probe poisoning/SNI) use absolute soft/hard thresholds instead of MAD.
Corroboration and bands
Penalties dampen single-source noise and scale with multi-source confidence. Connectivity keeps a routing secondary cap so BGP cannot dominate. Coverage and confidence appear on country views so thin telemetry is visible next to the scores.
Connectivity disruption bands (map and incidents):
Blackout
< 30
Major disruption
30–64.9
Degraded
65–84.9
Normal
≥ 85
When a monitored country has no usable signals in the lookback window, Tracker reports insufficient data instead of normal. That band is not a healthy reading and does not auto-clear open incidents. GeoJSON territories without a Tracker row stay unmonitored on the map (distinct from normal).
What becomes an incident
Only connectivity collapses open incidents. Major disruption and blackout require at least one primary user-plane hard signal; routing-only anomalies stay at degraded and do not open the ledger. Soft single-source degraded states stay on the country view. Likely cause labels are interpretive and never set either score. Browse the incidents ledger.
Sources
Traffic volume (netflow), Internet Quality Index, download speed, and outage feeds that can add countries mid-event.
Ping probing, darknet telescope, and BGP routing signals. Outage alerts help discover countries in disruption.
BGP routing visibility for IPv4 and IPv6 plus neighbour counts from RIS peers.
Live BGP announcement and withdrawal sampling for short-window routing stress.
Application measurement outcomes for instant-messaging and circumvention tool blockage.
Remote scanner unexpected-response rates consistent with interference or filtering.
Crowdsourced NDT download throughput and minimum RTT.
Relay, bridge, and snowflake user counts plus Tor Project censorship events.
Iranian ISP disruption signals when Iran is in scope.
Encrypted in-country pulses: packet loss, latency, jitter, DNS poisoning, SNI blocking, foreign-path download speed.
Probe privacy
Volunteer probes use Ed25519 identities and encrypted envelopes. The Tracker stores network-local HMAC pseudonyms; this site shows aggregates only. Full retention, rights, and data-handling details are in the Privacy Policy. To run a node, see Probes.