# Fixedmark > Fixedmark (https://fixedmark.com) gives serverless and PaaS apps a dedicated, highly available pair of static outbound IPs in India, Asia, Europe, and the US. Apps route outbound traffic through one proxy URL (HTTP CONNECT over a TLS-wrapped endpoint, or SOCKS5) and partners allowlist the IP pair once. Fixedmark is a product of BitMask LLP (https://bitmask.in/). Key facts: - Status: in development, early access. Not generally available yet. No public uptime figures or certifications. - Protocols: HTTP CONNECT on a TLS-wrapped proxy endpoint, SOCKS5, and the `bm tunnel` CLI (port-forward and transparent mode, local config file, no startup API dependency). - Regions: Planned launch regions are Mumbai, Chennai, Bangalore, Singapore, Jakarta, Tokyo, Sydney, Frankfurt, New York, and Virginia. - Planned launch pricing (subject to change): free tier, paid plans from $9/month, dedicated IP pair on Pro at $29/month. - Zero-knowledge: TLS passes through end to end and is never decrypted. No content logging. - Not offered: rotating or residential proxies, scraping use. - Operator: BitMask LLP, India. Contact: hello@fixedmark.com. ## Product - [Home](https://fixedmark.com/): Fixedmark gives Vercel, Heroku, Railway, and Render apps a dedicated static outbound IP pair to allowlist once. HTTP and SOCKS5, India to the US. Early access. - [Use cases](https://fixedmark.com/use-cases): Where a fixed outbound IP is required: database allowlists, bank and partner APIs, and broker APIs for algo trading. - [Comparisons](https://fixedmark.com/compare): How Fixedmark compares with other static IP proxies and native PaaS static IP options. - [Features](https://fixedmark.com/features): Fixedmark features: dedicated static IP pairs, HTTP CONNECT and SOCKS5, the bm tunnel CLI, connection logs, and destination allowlists. Launch and roadmap. - [Pricing](https://fixedmark.com/pricing): Planned static IP pricing: a free tier, shared IP pairs from $9, and dedicated static IP pairs from $29 per month with SOCKS5 and HTTP. Subject to change. - [Static IP for algo trading (India)](https://fixedmark.com/india/algo-trading-static-ip): SEBI-ready static IP for algo trading: a dedicated Mumbai IPv4 pair for your broker's primary and secondary slots, planned from ₹399/month, from any cloud. - [Regions](https://fixedmark.com/regions): Static outbound IPs at launch in Mumbai, Chennai, Bangalore, Singapore, Jakarta, Tokyo, Sydney, Frankfurt, New York, and Virginia. Pick the region nearest your API. - [Security](https://fixedmark.com/security): How the Fixedmark static IP proxy protects traffic: zero-knowledge TLS passthrough, no content logging, a TLS-wrapped proxy endpoint, and per-token allowlists. - [About](https://fixedmark.com/about): Fixedmark is a static outbound IP proxy for serverless and PaaS apps, built in Rust and Go by BitMask LLP in India. Why we built it and who runs it. - [Early access](https://fixedmark.com/early-access): Join Fixedmark early access for dedicated static IPs in Mumbai, Singapore, Frankfurt, and the US. Get priority access, launch pricing, and IP pairs first. - [Privacy policy](https://fixedmark.com/privacy): The Fixedmark website sets no cookies and runs no analytics. What the IP tools read, how early-access emails work, and how to contact BitMask LLP about privacy. ## Docs - [Integrations](https://fixedmark.com/integrations): Static IP setup guides for Vercel, Railway, Render, Supabase, Fly.io, Heroku, Netlify, AWS Lambda, n8n, and more. - [Docs quickstart](https://fixedmark.com/docs): Static IP proxy quickstart: set FIXEDMARK_PROXY_URL, then copy snippets for cURL, Node, Python, Go, Ruby, PHP, Java, Deno, and Bun, plus SOCKS5 for databases. - [Concepts](https://fixedmark.com/docs/concepts): How the Fixedmark static IP proxy works: IP pairs and failover, regions, tokens, the TLS proxy endpoint, CONNECT tunnels, and socks5 versus socks5h DNS. - [Node.js](https://fixedmark.com/docs/node): Route Node.js requests through a static IP: undici ProxyAgent, EnvHttpProxyAgent, NODE_USE_ENV_PROXY, axios with an HTTPS proxy, and SOCKS5 agents. - [Python](https://fixedmark.com/docs/python): Send Python requests through a static IP with an HTTPS proxy URL: requests, httpx, and aiohttp snippets, version notes, SOCKS5, and environment variables. - [Go](https://fixedmark.com/docs/go): Route Go net/http requests through a static IP with http.Transport Proxy, an HTTPS proxy URL, or socks5h, plus a SOCKS5 dialer for database drivers. - [Ruby](https://fixedmark.com/docs/ruby): Send Ruby requests through a static IP: Typhoeus with an HTTPS proxy URL, why Net::HTTP and Faraday fail through a TLS proxy today, and planned fallbacks. - [PHP](https://fixedmark.com/docs/php): Route PHP requests through a static IP with an HTTPS proxy URL in Guzzle or the cURL extension. Check libcurl HTTPS proxy support and set timeouts. - [Java](https://fixedmark.com/docs/java): Use a static IP proxy from Java: HttpClient with ProxySelector and Basic auth, why it cannot use an HTTPS proxy endpoint, and the planned workarounds. - [Deno and Bun](https://fixedmark.com/docs/deno-and-bun): Proxy fetch through a static IP in Deno with Deno.createHttpClient and in Bun with the fetch proxy option, including SOCKS5 and environment variables. - [Databases](https://fixedmark.com/docs/databases): Connect Postgres, MySQL, MongoDB, and Redis to IP allowlists through a static IP with SOCKS5 dialers or bm tunnel, with TLS and pooling notes per driver. - [bm tunnel CLI](https://fixedmark.com/docs/bm-tunnel): Planned reference for the bm tunnel CLI: port-forward syntax, transparent mode, the local config file, running it beside your app, and what is not final. - [Verify egress IP](https://fixedmark.com/docs/verify-egress-ip): Check which IP a destination sees by calling fixedmark.com/api/ip through your proxy with curl, Node, or Python, and confirm the database sees your IP pair. - [Troubleshooting](https://fixedmark.com/docs/troubleshooting): Fix static IP proxy errors: 407 auth failures, 403 destination not allowed, TLS errors to the proxy, timeouts, DNS leaks, connection resets, and quotas. - [Limits and security](https://fixedmark.com/docs/limits): Planned limits for the Fixedmark proxy: request and bandwidth quotas, soft limits, rate limits, idle timeouts, blocked ports, and how traffic is protected. ## Integrations - [Vercel Static IP for Functions: Setup and Cost](https://fixedmark.com/integrations/vercel): Get a static outbound IP for Vercel Functions. Compare Vercel Static IPs at $100 per project per month with a dedicated IP pair proxy for Node, Python, and Go. - [Railway Static IP: Dedicated Outbound IP Pair](https://fixedmark.com/integrations/railway): Railway's static outbound IPs are Pro only, may be shared, and change with region. Get a dedicated static IP for Railway through a proxy, with Node and Python. - [Render Static IP: Dedicated Outbound IP Pair](https://fixedmark.com/integrations/render): Render's outbound IPs are shared per region, and Dedicated IPs cost $100/mo per set on Pro and up. Get a Render static IP pair through a proxy for Node or Go. - [Supabase Edge Functions Static IP (Deno Proxy)](https://fixedmark.com/integrations/supabase-edge-functions): Supabase Edge Functions have no static egress IP, and the IPv4 add-on is inbound only. Route fetch through a dedicated static IP with Deno.createHttpClient. - [Fly.io Static Egress IP: Native vs Portable Pair](https://fixedmark.com/integrations/fly-io): Fly.io sells static egress IPs at $3.60/mo per IPv4, per app and region. Learn when Fly's native option fits and when a portable dedicated IP pair is better. - [Heroku Static IP: Fixed Outbound IPs for Dynos](https://fixedmark.com/integrations/heroku): Heroku Common Runtime dynos have no static outbound IP. Give dynos a dedicated static IP pair with a proxy URL config var, and keep it when you leave Heroku. - [Netlify Functions Static IP: Outbound IP Setup](https://fixedmark.com/integrations/netlify): Netlify Functions have no self-serve static outbound IP. Private Connectivity is Enterprise only. Route Netlify Function calls through a static IP pair instead. - [AWS Lambda Static IP Without a NAT Gateway](https://fixedmark.com/integrations/aws-lambda): Give AWS Lambda a static outbound IP without a VPC or NAT Gateway. Compare about $73/mo for two-AZ NAT with a dedicated IP pair proxy. Node and Python code. - [Cloudflare Workers Static IP: What Works](https://fixedmark.com/integrations/cloudflare-workers): Workers fetch has no proxy option, so a Cloudflare Worker cannot use a static IP proxy directly. Here is the relay pattern that works, and Cloudflare's options. - [Cloud Run Static Outbound IP Without Cloud NAT](https://fixedmark.com/integrations/google-cloud-run): Cloud Run needs Direct VPC egress, Cloud NAT, and a reserved IP for a static outbound IP. Or route calls through a dedicated static IP pair proxy with no VPC. - [n8n Static IP: HTTP Request Node Proxy Setup](https://fixedmark.com/integrations/n8n): Give n8n workflows a static outbound IP. Set a dedicated IP proxy in the HTTP Request node's Proxy option on n8n Cloud or self-hosted, and allowlist two IPs. - [GitHub Actions Static IP for Allowlisted Calls](https://fixedmark.com/integrations/github-actions): GitHub-hosted runners use large, shared, changing IP ranges. Set HTTPS_PROXY on the steps that call allowlisted servers to send them through a static IP pair. ## Use cases - [Static IP for Bank, UPI, and GSP APIs in India](https://fixedmark.com/use-cases/bank-and-upi-apis): Static IP for Indian bank payout APIs, UPI partner banks, and GSP e-invoicing. Whitelist one dedicated IP pair once and deploy on any cloud. Early access. - [MongoDB Atlas IP Whitelist for Serverless Apps](https://fixedmark.com/use-cases/mongodb-atlas): Add a static IP to your MongoDB Atlas IP access list instead of 0.0.0.0/0. Connect from Vercel, Netlify, or Lambda through a dedicated SOCKS5 IP pair. - [Static IP for Postgres and MySQL Allowlists](https://fixedmark.com/use-cases/postgres-and-mysql): Static IP for Postgres and MySQL allowlists on AWS RDS, Cloud SQL, and self-hosted servers. Connect serverless apps via SOCKS5 or the bm tunnel CLI. - [Static IP for Partner API Allowlisting](https://fixedmark.com/use-cases/partner-api-allowlisting): Static IP for partner API allowlisting: Salesforce trusted IP ranges, legacy SOAP vendors, and payment gateways. One dedicated IP pair for every partner. - [Static IP for AI Agents and n8n Automations](https://fixedmark.com/use-cases/ai-agents-and-automations): Static IP for AI agents and automations in n8n, Make, and Lovable. Send tool calls to allowlisted APIs from one dedicated IP pair. Early access. - [Keep Your Static IP When Leaving Heroku](https://fixedmark.com/use-cases/heroku-migration): Leaving Heroku but need a static IP? Keep partner allowlists working by moving outbound traffic to a dedicated IP pair before you switch platforms. - [Static IP for Payout APIs: Razorpay, Cashfree, Stripe](https://fixedmark.com/use-cases/payment-gateway-apis): RazorpayX and Cashfree Payouts reject live API calls from IPs you have not whitelisted. Give your app a static IP pair on Vercel, Railway, or Lambda. - [Static IP for SFTP Allowlisting From Serverless Apps](https://fixedmark.com/use-cases/sftp-allowlisting): Connect to IP-allowlisted SFTP servers from Lambda, Vercel, Railway, or Render. Use SOCKS5 in your SFTP library or a local tunnel, with host key checks intact. ## Comparisons - [Fixie Alternative: Dedicated IP Pair, HTTP + SOCKS5](https://fixedmark.com/compare/fixie-alternative): Looking for a Fixie alternative? Compare Fixie's published plans with Fixedmark's planned dedicated IP pairs, Mumbai and Singapore regions, and HTTP + SOCKS5. - [QuotaGuard Alternative: Dedicated IPs From $29](https://fixedmark.com/compare/quotaguard-alternative): A QuotaGuard alternative for Vercel, Railway, and Supabase: compare QuotaGuard's published plans with Fixedmark's planned $29 dedicated IP pair in Mumbai. - [QuotaGuard vs Fixie: Static IP Pricing and Features](https://fixedmark.com/compare/quotaguard-vs-fixie): QuotaGuard vs Fixie, from their published pages: prices, SOCKS5, dedicated IPs, inbound proxy, regions, and SOC 2 or HIPAA. Plus where Fixedmark's plan fits. - [QGTunnel Alternative: Static IP Database Tunnels](https://fixedmark.com/compare/qgtunnel-alternative): A QGTunnel alternative for database, Redis, and SFTP connections through a static IP: compare QGTunnel with SOCKS5 drivers, fixie-wrench, and the bm tunnel CLI. - [Proximo Alternative: Static IP Pair On and Off Heroku](https://fixedmark.com/compare/proximo-alternative): Need a Proximo alternative? Compare Proximo's Heroku add-on plans and single static IP with Fixedmark's planned dedicated IP pair, SOCKS5, and direct sign-up. - [Vercel Static IPs vs Fixedmark: Cost, Limits, Regions](https://fixedmark.com/compare/vercel-static-ips): Vercel Static IPs cost $100 per project per month on Pro or Enterprise. Compare Vercel's native static egress with Fixedmark's planned $29 dedicated pair. - [AWS NAT Gateway vs Static IP Proxy: Cost](https://fixedmark.com/compare/aws-nat-gateway): An AWS NAT Gateway with Elastic IPs costs about $73/mo for two AZs before traffic. Compare NAT Gateway pricing and limits with a Fixedmark static IP proxy. - [Google Cloud NAT Static IP: Cost vs a Proxy](https://fixedmark.com/compare/google-cloud-nat): Google Cloud NAT gives VMs, GKE, and Cloud Run a static outbound IP. Compare its hourly, per-GiB, and IP charges with a Fixedmark static IP pair from $29/mo. ## Tools - [What's my IP](https://fixedmark.com/tools/whats-my-ip): See your public IP address and whether it is IPv4 or IPv6. Learn why serverless egress IPs change and how to check the egress IP of your app with curl. - [NAT Gateway cost calculator](https://fixedmark.com/tools/nat-gateway-cost-calculator): Estimate the monthly cost of an AWS NAT Gateway static IP: hourly charges, data processing, and public IPv4, per AZ, next to planned Fixedmark static IP plans.