Limits, quotas, and security model
What the proxy counts, what happens at your plan's limits, which traffic is blocked, and how your credentials and data are protected. All values are planned for launch and may change.
Docs preview: Fixedmark is not live yet. Endpoints are issued at launch, and these pages describe planned launch behavior. Anything marked planned may change. Join early access to get yours first.
Plan quotas
| Plan | Requests | Bandwidth | IPs |
|---|---|---|---|
| Free | 1,000 requests | 250 MB | Shared IP pair, 1 region |
| Starter | 50,000 requests | 20 GB | Shared IP pair |
| Pro | 500,000 requests | 200 GB | Dedicated IP pair, 1 region |
| Business | 2,000,000 requests | 1 TB | Dedicated IP pairs, 2 regions |
| Scale | 10M+ requests | 5 TB+ | Multi-region, BYOIP option |
Quotas are per month. Prices and the full feature list are on planned pricing.
How usage is counted
- Requests are new proxy sessions: one CONNECT tunnel, one SOCKS5 session, or one plain HTTP request. This matches how other static IP proxies count, so plans compare directly.
- Bandwidth is the payload sent and received through the proxy, in both directions.
- Keep-alive lowers request counts. One pooled tunnel can carry many HTTPS requests to the same host.
- A database connection is one request for as long as it stays open.
Soft limits
Planned behavior: usage alerts and webhooks fire before you reach your quota. Past 100%, traffic keeps flowing for a margin, planned at 10 to 20 percent. After that, the proxy rejects new connections with 429 or 407 and the header X-Proxy-Error: quota_exceeded.
Rate limits and timeouts
- Each app is planned to have a rate limit on requests per second and on concurrent connections. The values are not final.
- Idle connections close after 5 minutes by default. Database tunnels are planned to allow a longer idle timeout.
Blocked traffic
Allowlists only work if the IPs keep a clean reputation, so some traffic is blocked for everyone:
- SMTP ports 25, 465, and 587, unless enabled for your account after verification.
- Destinations on the Spamhaus DROP list and similar blocklists.
- Scraping and rotation. Fixedmark is not a scraping proxy. Apps that fan out to thousands of distinct hosts are suspended automatically.
Security model
- TLS to the proxy. The
https://proxy URL keeps your token encrypted between your app and the proxy. - No decryption. HTTPS and database TLS pass through the proxy untouched. The proxy holds no keys for your sessions.
- Hashed tokens. Fixedmark stores token hashes, not tokens. Each token can be revoked and rotated on its own.
- Destination allowlists. Restrict a token to the hosts and ports it needs, so a leaked token cannot reach anything else.
- Dedicated IPs. On Pro and higher plans, no other customer sends traffic from your IPs.
bm tunnel CLI wraps SOCKS5 in TLS.Read the full security overview for infrastructure and data handling details.
Connection logs
Each connection records the time, app, destination host and port, TLS SNI, bytes, duration, result, and egress IP. Payloads are never stored. Planned retention is 7 days on Pro and 30 days on Business.
Frequently asked questions
What counts as a request?
One new CONNECT tunnel, one new SOCKS5 session, or one plain HTTP request sent through the proxy. Many HTTPS requests over one kept-alive tunnel count once.
What happens when I go over my quota?
Planned soft limits: you get alerts first, and traffic continues for a margin past the limit. After that the proxy rejects new connections with X-Proxy-Error: quota_exceeded until you upgrade or the period resets.
Can I send email through Fixedmark?
Not by default. SMTP ports 25, 465, and 587 are blocked to protect IP reputation. Opt-in after account verification is planned.
Does Fixedmark log my request bodies?
No. Connection logs hold metadata only: time, app, destination host and port, SNI, bytes, duration, result, and egress IP. Payloads are never stored.
Make it fixed.
Fixedmark is in early access. Join the list to get dedicated static IPs when your region opens.