✓IXP route server peering
✓WireGuard tunnel sessions
✓Valid IRR & RPKI required
✗Drop / unroutable ASNs
✓Valid RPKI ROA mandatory
✓IRR route object required
✓Abuse handled within 24h
✗No default route leaks
✗DDoS / amplification attacks
✗Spam & malware distribution
✗Tor exit nodes
✗Illegal content