How we protect accounts, credentials and the network
A proxy account controls paid infrastructure and outgoing traffic, so we treat it like a hosting account: strong authentication, secrets that are never stored in clear, minimal logging and a published route for reporting problems.
Account protection
Controls available on every account, at no extra cost.
Passwords hashed with bcrypt
Passwords are salted and hashed with bcrypt (cost factor 11) before they are stored. Nobody at Proxuno can read your password, and login failures take the same time whether or not the address exists.
TOTP two-factor authentication
Enable two-factor authentication with any RFC 6238 authenticator app. Once enabled, every login asks for a 6-digit code after the password.
IP whitelist authentication
Authorise your servers' IP addresses or CIDR ranges and use the proxies without a password. Whitelisted addresses are managed per account in the dashboard and the API.
Hashed API keys
API keys are shown once at creation. We store only a SHA-256 hash and the last four characters, so a database leak would not expose usable keys. Revocation takes effect immediately.
Session control
The session identifier changes at every login. Settings list your active sessions with IP address and browser, and you can revoke any of them — or all others — in one click.
Rate limits and CSRF protection
Login, password reset and two-factor forms are rate-limited per IP address. Every form carries an anti-CSRF token, and the API uses its own keys instead of cookies.
Proxy credentials and rotation links
Each mobile and static proxy has its own random 16-character password, separate from your account password. Rotation links contain a 128-bit random token; regenerate the token from the dashboard if a link has been shared too widely. Credentials are never sent by email — order confirmations link to the dashboard instead.
Infrastructure practices
What we do on the systems that run the dashboard, the API and the gateways.
- TLS on the website, dashboard and API; HSTS in production
- A strict Content Security Policy: no third-party scripts, fonts or trackers are loaded on any page
- Dashboard and API run separately from the proxy gateways; a gateway incident cannot reach account data
- Staff access to production requires individual accounts with two-factor authentication; administrative actions are written to an audit log
- Encrypted backups, restored on a test system at least once per quarter
- Security updates for the operating system and dependencies applied on a weekly cycle, critical fixes within 72 hours
- Modems and gateways are monitored continuously; incidents are published on the status page
Abuse handling
Our IP addresses belong to carriers and residential ISPs. Keeping them clean is part of keeping the service usable, so every report is investigated.
Report
Send the source IP address, port, exact time with timezone, the target and log excerpts to [email protected].
Acknowledgement
A person acknowledges the report within 24 hours, 7 days a week.
Investigation
We match the IP address and time against gateway metadata to identify the proxy and the account behind it.
Action
Depending on severity: warning, suspension of the proxy, or termination of the account without refund, as set out in the acceptable use policy.
We do not disclose a customer's identity to the person reporting abuse. Information is disclosed to authorities only under valid legal process.
Responsible disclosure
If you believe you have found a security vulnerability in Proxuno, we want to hear about it and will work with you to fix it.
How to report
Email [email protected] with the subject line starting with [security]. Include the affected URL or component, the steps to reproduce, the impact you observed and, if possible, a proof of concept. Write in English.
In scope
- The website and dashboard on proxuno.com
- The REST API (v1) and its authentication
- Proxy gateway authentication on gw.proxuno.com
- Rotation links and credential exports
Out of scope
- Denial-of-service and volumetric tests against any system
- Social engineering, phishing and physical attacks
- Third-party services, including payment processors and email providers
- Reports from automated scanners without a demonstrated impact
- Missing best-practice headers or email (SPF/DMARC) settings without an exploitable consequence
- Using our proxies to attack third-party websites
Please
- Test only against your own account, and stop as soon as you reach other customers' data
- Do not modify or delete data, or degrade service for other customers
- Do not intercept or inspect traffic passing through our proxies
- Give us 90 days to fix the issue before any public disclosure
Our commitments
- Acknowledgement within 3 business days
- Initial assessment and severity within 10 business days
- Fix targets: critical within 7 days, high within 30 days, medium and low within 90 days
- Updates when the status of your report changes, and a note when the fix is deployed
Safe harbour
Research carried out in good faith and in line with this policy is considered authorised. We will not take legal action against you or ask authorities to do so, and if a third party initiates action, we will make it known that you acted in accordance with this policy. We do not run a paid bug bounty.