← Back to the directory

Flagged companies

22 Mac cloud brands removed from our comparisons pending operator and affiliation verification.

Investigation dated September 22, 2026. Publication review: September 23, 2026 UTC (September 22 in Los Angeles). Scope: the 22 brands below, plus vmzen.com as a related site.

Our listing decision

We found repeated payment-platform configuration, cross-brand references and shared mail infrastructure. We do not consider these brands sufficiently verified to present them as independent alternatives. Their listings and offers are excluded from the directory, comparisons, API and MCP. The underlying research records are retained for review.

This is an editorial exclusion, not a finding of fraud. Shared software, a reseller platform or a common service provider can produce overlapping infrastructure. Common legal ownership, the Stripe merchant identity and the actual contractual counterparty for every brand remain unverified.

GitHub report · Download reviewed evidence (CSV). GitHub access currently requires repository permission; this page and the CSV are public.

The affected brands

These names identify websites and trade brands, not independently verified registered companies. vmzen.com is included in the investigation but was not a separate listing in our catalog.

What we independently reproduced

1. Matching payment configuration, after domain normalization

On 22 of the 23 investigated domains, the public guest gateway endpoint returned the same configuration after replacing each brand's domain in logo URLs: gateway 4, EpayUsdt / USDT-TRC20, one-time payments; gateway 3, Stripe / Credit Cards, one-time and recurring payments; USD only. runamac.com returned HTTP 502, so no gateway result was obtained there. Examples: ArmMini and kvmrun.

The original report called these responses “byte-identical.” The raw responses actually differ in their brand-specific logo URLs; the reviewed CSV records both raw and normalized SHA-256 hashes. The public frontend supplies an anonymous x-client-ssaid header and language header. No account login or payment was used. Gateway IDs describe software configuration, not a Stripe merchant account.

2. A mail-infrastructure link across the proposed families

We reproduced MX records pointing to each domain's mail host, A records resolving those mail hosts to the same address (178.95.79.18), and SPF records including that address for armmini.com, jexmac.com and kvmrun.com. This connects the previously proposed DNS families at the mail layer; a shared mail service is also a possible explanation. Public DNS sources: ArmMini, JexMac, kvmrun. The CSV links the corresponding A and TXT records.

3. Two direct cross-brand references

kvmrun.com's sitemap listed sitemap URLs on vmzen.com. SpinMac's privacy policy named the local-storage identifier macxcode_ssaid. These are concrete cross-brand references. They support a shared-template or platform relationship, but do not establish a parent company or the direction of copying.

4. A self-described operator, not a registry match

vmzen.com's Terms of Service name “vmzen Inc.” as a party to the agreement. The governing-law clause refers to its place of registration without identifying the jurisdiction. We have not verified that name in a corporate registry or established that it is the legal counterparty for the other 22 brands.

What the evidence does not establish

Evidence scope and review

The supplied investigation described 404 research rows. Our downloadable file is a smaller, independently reproduced publication subset, not a claim that every original row was verified. It contains dated observations, source URLs and the gateway comparison hashes. No customer accounts, private personal data, credentials or raw provider dumps are published.

Remaining questions include legal registration, the counterparty for each brand, the Stripe merchant identity and whether the relationships are common ownership, reselling or shared platform services. No purchases, account creation, paid WHOIS searches or provider contact were made during this publication review.

Corrections and reinstatement

We will reconsider a listing when verifiable operator information and an explanation of these relationships are available. Corrections should identify the domain, disputed claim and primary evidence, such as a registry record or first-party affiliation disclosure. A lack of response is not evidence of wrongdoing.

Repository collaborators can submit a correction on GitHub. Because the repository is currently private, external readers without access will need to request a review through their existing contact with Mac Cloud Index; we do not yet have a public submission form.