Skip to content
Fixedmark
Security

Static IP proxy security

Fixedmark passes your TLS traffic through without decrypting it and never logs request content. The proxy endpoint itself uses TLS, so your proxy credentials stay encrypted, and per-token destination allowlists limit what a leaked token can reach.

Fixedmark is in development with an early-access list. This page describes the security design for launch. Fixedmark is operated by BitMask LLP.

Zero-knowledge passthrough

HTTP CONNECT and SOCKS5 relay your TLS connection byte for byte. The proxy never holds your destination's certificate keys and cannot read requests, responses, headers, or bodies.

No content logging

No request or response content is logged on any plan. Connection metadata (time, host, port, SNI, bytes, egress IP, result) is recorded only when connection logs are enabled.

TLS-wrapped proxy endpoint

Your app connects to the proxy over TLS on port 443. Proxy credentials are encrypted in transit, unlike plain-HTTP proxy endpoints on port 80. SOCKS5 has no TLS layer, so its token crosses the network in cleartext. Prefer the HTTPS endpoint or bm tunnel, and scope SOCKS5 tokens with destination allowlists.

Per-token destination allowlists

Limit each token to the hosts and ports it needs, such as api.razorpay.com:443 and db.example.com:5432. A leaked token cannot reach anything else.

Destination allowlists

Each token can carry its own list of allowed destinations. The proxy refuses connections to anything outside the list.

token: payouts-prod
allow:
  - api.razorpay.com:443
  - db.example.com:5432

Illustrative. The final configuration format is set at launch.

Abuse policy

Static IPs only work if partners trust them. One abusive account can get a shared IP blocklisted for every customer on it, so these uses are not allowed:

  • No web scraping or crawling.
  • No rotating or residential proxy use. Fixedmark sells fixed IPs only.
  • No outbound SMTP on the free plan.
  • No spam, credential stuffing, or attacks on third parties.

Compliance roadmap

ItemStatus
Public security pageNow (this page)
Data processing agreement (DPA)Now, on request at hello@fixedmark.com
SOC 2 Type IPlanned after launch
SOC 2 Type IIPlanned after Type I

Fixedmark does not hold a SOC 2 report today. We will update this table when that changes.

Who operates Fixedmark

Fixedmark is built and operated by BitMask LLP, based in India. Read more about Fixedmark and the website privacy policy.

Responsible disclosure

Found a vulnerability? Email hello@fixedmark.com with the details and steps to reproduce. Please give us reasonable time to fix the issue before you disclose it, and do not access other customers' data or disrupt the service while testing.

Frequently asked questions

Does Fixedmark decrypt or log my traffic?

No. HTTPS traffic passes through the proxy as an encrypted TLS tunnel and is never decrypted. Fixedmark does not log request or response content on any plan.

What does Fixedmark log?

Only connection metadata, and only when connection logs are enabled on your plan: time, destination host and port, TLS SNI, bytes sent and received, the egress IP used, and the result.

Why is the proxy endpoint TLS-wrapped?

A plain HTTP proxy sends your proxy credentials in a Basic auth header that anyone on the path can read. Fixedmark's proxy endpoint uses TLS, so the credentials are encrypted between your app and the proxy.

Is Fixedmark SOC 2 certified?

No. Fixedmark is in early access. A SOC 2 Type I report is planned after launch. Today we publish this security page and offer a data processing agreement on request.

How do I report a security issue?

Email hello@fixedmark.com with the details and steps to reproduce. We will acknowledge your report and keep you updated while we fix it.

Make it fixed.

Fixedmark is in early access. Join the list to get dedicated static IPs when your region opens.