Choose Static or Shield
Static is the normal choice for standard HTTPS traffic. Shield is for architectures requiring SSL passthrough or where traffic must not be decrypted at the proxy.
Inbound Static IPs
When a customer's firewall permits connections only to approved destination IPs, QuotaGuard puts a stable, fault-tolerant IP pair in front of the cloud application you already operate. Keep your hosting platform, application code, and deployment process. QuotaGuard manages the proxy infrastructure, routing, availability, monitoring, failover, and maintenance.
Need stable source IPs for your application to connect to another API, database, or firewall? See Outbound Static IPs →
Commercial Proof
Keygen documents that it uses QuotaGuard to provide static destination IPs to eligible Keygen Cloud customers. Keygen owns the customer experience while QuotaGuard operates the managed network layer underneath.
See How Keygen Uses QuotaGuard →Static is the normal choice for standard HTTPS traffic. Shield is for architectures requiring SSL passthrough or where traffic must not be decrypted at the proxy.
Enter the reachable application URL that should receive forwarded traffic.
Use the QuotaGuard-generated hostname or configure your own approved domain. DNS and certificate requirements depend on whether you select Static or Shield.
Provide the hostname, both static IPs, port, protocol, expected path, authentication method, and support contact. Test the complete connection from the customer's restricted network.
Dashboard setup is self-service. New inbound configurations can take up to 10 minutes to propagate.
Standard SaaS APIs, customer portals, callbacks, and ordinary HTTPS traffic
TLS terminates at the QuotaGuard inbound proxy
Stable IP pair on managed shared infrastructure
$19/month
Start Static TrialSensitive or regulated traffic requiring SSL passthrough
Traffic remains encrypted through the QuotaGuard proxy
Stable IP pair on managed shared infrastructure
$29/month
Start Shield TrialContracts, security reviews, or architectures requiring customer-only IPs and proxy resources
Dedicated static IPs and dedicated proxy resources
Static Enterprise from $219/month
Shield Enterprise from $269/month
QuotaGuard typically adds only a few milliseconds of latency.
Choose from 12 global regions to place the proxy close to your application and expected customers.
Test representative production traffic before launch.
The application origin must be reachable by the selected proxy architecture.
Customers connect through the configured hostname.
Both assigned IPs should be allowlisted for availability.
Standard plan addresses are stable but shared.
Customer-only addresses require Enterprise.
Static terminates inbound TLS at QuotaGuard.
Shield is the appropriate path when proxy-level TLS termination is unacceptable.
Static IP allowlisting does not replace authentication, authorization, request validation, rate limits, or logging.
Keep your application on the platform you already use. Give customers two stable addresses they can approve, and let QuotaGuard operate the network infrastructure behind them.
Real answers from the engineers who operate QuotaGuard. No chatbot and no scripted support.
A static inbound IP gives customers, partners, and webhook providers a fixed, allowlistable destination for reaching your application. They connect through your configured hostname, which resolves to your QuotaGuard IP pair, and QuotaGuard forwards the request to your application. Your application's underlying cloud IP can change without disrupting the integration.
Inbound and outbound describe the direction of the connection, not separate sets of addresses. Outbound traffic leaves your application through your static IPs, while inbound traffic reaches your application through them. With QuotaGuard, the same stable pair supports both directions, so you do not need to manage two different IP lists.
Every subscription includes a load-balanced pair on separate proxy nodes for availability. If one node has a problem, new connections can continue through its partner without introducing an unexpected third address. Allowlist both IPs so your integration receives the full benefit of the redundant design.
On standard shared plans, customers connect through the QuotaGuard hostname or your custom domain rather than entering a raw IP. The hostname identifies which application should receive the request on the shared proxy, just as it does with other managed web infrastructure. Callers still use an ordinary HTTPS URL, so there is no special client software or unusual integration process. Direct HTTP access by raw IP is available with an Enterprise dedicated proxy when a specific integration requires it.
Yes. You can use a customer-friendly domain such as api.example.com instead of displaying the QuotaGuard-generated hostname. Setup is handled with a DNS CNAME and the appropriate certificate configuration: Static terminates TLS at the inbound proxy using your uploaded certificate, while Shield uses SSL passthrough so TLS remains encrypted through QuotaGuard and terminates at your application.
No. Your customer simply connects to the hostname you provide using its normal HTTP or HTTPS client. There is no QuotaGuard account to create, software to install, or QuotaGuard credential to manage on their side. You control the subscription and present the static endpoint as part of your own service.
Standard plans use managed shared IP addresses and shared proxy resources, but your assigned pair remains stable and suitable for allowlisting. Each subscription has its own credentials, and customer traffic remains logically separated. If a partner requires customer-only addresses and dedicated proxy resources, Enterprise provides both.
Static is the simpler, lower-cost choice for most general HTTPS, webhook, and allowlisting use cases. It terminates inbound TLS at the QuotaGuard proxy and forwards the request to your application. Choose Shield when you handle regulated data or require SSL passthrough, which keeps the connection encrypted through QuotaGuard and lets your application terminate TLS using certificates you control.
Yes, but typically only a few milliseconds. QuotaGuard operates across 12 global regions, so you can place the proxy close to your application and keep the additional network distance minimal. As with any production network change, test the complete route with representative traffic before launch.
No. A static destination solves the network allowlisting requirement by giving trusted systems a predictable endpoint, but it does not identify or authorize individual requests. Keep your application's existing authentication, authorization, request validation, rate limits, and logging in place. The static IP becomes an additional network control within that layered security model.
For over a decade, QuotaGuard has provided reliable, high-performance static IP and proxy solutions for cloud environments like Heroku, Kubernetes, and AWS.
Get the fixed identity and security your application needs today.