Static IP proxy security
Fixedmark passes your TLS traffic through without decrypting it and never logs request content. The proxy endpoint itself uses TLS, so your proxy credentials stay encrypted, and per-token destination allowlists limit what a leaked token can reach.
Fixedmark is in development with an early-access list. This page describes the security design for launch. Fixedmark is operated by BitMask LLP.
Zero-knowledge passthrough
HTTP CONNECT and SOCKS5 relay your TLS connection byte for byte. The proxy never holds your destination's certificate keys and cannot read requests, responses, headers, or bodies.
No content logging
No request or response content is logged on any plan. Connection metadata (time, host, port, SNI, bytes, egress IP, result) is recorded only when connection logs are enabled.
TLS-wrapped proxy endpoint
Your app connects to the proxy over TLS on port 443. Proxy credentials are encrypted in transit, unlike plain-HTTP proxy endpoints on port 80. SOCKS5 has no TLS layer, so its token crosses the network in cleartext. Prefer the HTTPS endpoint or bm tunnel, and scope SOCKS5 tokens with destination allowlists.
Per-token destination allowlists
Limit each token to the hosts and ports it needs, such as api.razorpay.com:443 and db.example.com:5432. A leaked token cannot reach anything else.
Destination allowlists
Each token can carry its own list of allowed destinations. The proxy refuses connections to anything outside the list.
token: payouts-prod
allow:
- api.razorpay.com:443
- db.example.com:5432Illustrative. The final configuration format is set at launch.
Abuse policy
Static IPs only work if partners trust them. One abusive account can get a shared IP blocklisted for every customer on it, so these uses are not allowed:
- No web scraping or crawling.
- No rotating or residential proxy use. Fixedmark sells fixed IPs only.
- No outbound SMTP on the free plan.
- No spam, credential stuffing, or attacks on third parties.
Compliance roadmap
| Item | Status |
|---|---|
| Public security page | Now (this page) |
| Data processing agreement (DPA) | Now, on request at hello@fixedmark.com |
| SOC 2 Type I | Planned after launch |
| SOC 2 Type II | Planned after Type I |
Fixedmark does not hold a SOC 2 report today. We will update this table when that changes.
Who operates Fixedmark
Fixedmark is built and operated by BitMask LLP, based in India. Read more about Fixedmark and the website privacy policy.
Responsible disclosure
Found a vulnerability? Email hello@fixedmark.com with the details and steps to reproduce. Please give us reasonable time to fix the issue before you disclose it, and do not access other customers' data or disrupt the service while testing.
Frequently asked questions
Does Fixedmark decrypt or log my traffic?
No. HTTPS traffic passes through the proxy as an encrypted TLS tunnel and is never decrypted. Fixedmark does not log request or response content on any plan.
What does Fixedmark log?
Only connection metadata, and only when connection logs are enabled on your plan: time, destination host and port, TLS SNI, bytes sent and received, the egress IP used, and the result.
Why is the proxy endpoint TLS-wrapped?
A plain HTTP proxy sends your proxy credentials in a Basic auth header that anyone on the path can read. Fixedmark's proxy endpoint uses TLS, so the credentials are encrypted between your app and the proxy.
Is Fixedmark SOC 2 certified?
No. Fixedmark is in early access. A SOC 2 Type I report is planned after launch. Today we publish this security page and offer a data processing agreement on request.
How do I report a security issue?
Email hello@fixedmark.com with the details and steps to reproduce. We will acknowledge your report and keep you updated while we fix it.
Make it fixed.
Fixedmark is in early access. Join the list to get dedicated static IPs when your region opens.