Why Architecture Matters
Termination vs. Passthrough

All other public/private proxies decrypt your traffic at the proxy to know where to route your traffic.

Learn how Shield’s Passthrough architecture guarantees your data remains opaque from end-to-end.

Two green slider controls on a dark background, one with a pointer at the left and one with endpoints at both sides.

SSL and TLS

Secure Socket Layer (SSL), also known as TLS (Transport Layer Security), is the most common security protocol for HTTP traffic traversing on the Internet.

SSL/TLS encrypts the communications between a client and a server that allows for secure bi-directional message exchanges.

QG Static: SSL Termination / SSL Offloading

For outbound traffic, QuotaGuard Static routes your requests through a blind CONNECT tunnel, or SOCKS5 for raw TCP connections. The proxy reads only the CONNECT command and your proxy credentials to pick the right destination, then passes the encrypted bytes straight through without opening them. QuotaGuard never holds your keys and never decrypts your HTTPS payload. When your destination speaks HTTPS, as most do, the TLS session runs from your app all the way to the destination server, so your data stays encrypted end to end.

So where does SSL Termination come in? SSL Termination, also called SSL Offloading, is what Static does on inbound connections: you upload your certificate and the proxy terminates the TLS connection at your dedicated static IP before forwarding traffic to your origin. On outbound, the only thing that differs between Static and Shield is the single hop between your app and the proxy. Static sends that hop over the plain HTTP proxy protocol, so your proxy credentials travel unencrypted on that leg. Shield wraps the same hop in TLS, encrypting your credentials as well.

QG Shield: SSL Passthrough

QuotaGuard Shield uses SSL Passthrough for routing requests between endpoints.

SSL passthrough passes encrypted HTTPS traffic all the way to the backend server without decrypting the traffic on the proxy.

Therefore, traffic passes through the proxy encrypted and the destination server (web application server, database server, etc.) does the decryption process to read the data.

Flowchart illustrating QG Static Outbound Requests via HTTP, HTTPS, and TCP, showing service call, proxy server processing, trusted IP allow list, and security risks of HTTPS on QG Static.

FAQs

Common questions about encryption, compliance, and security specifics.

How do I get SSL Passthrough to work for my QuotaGuard Shield Static IP proxy?

To get SSL Passthrough to work with QuotaGuard Shield, do the following :

1. Sign up for QuotaGuard Shield either at Heroku, our Direct site, on AWS, or Azure.

2. Use the QuotaGuard wizard to configure your domain name and forwarding URL.

3. Change your DNS to point to the CNAME record we provide in your account.

4. Allow up to an hour for the DNS settings to propagate and you’re done.

Note that you do not have to upload your certificates to QuotaGuard when using QuotaGuard Shield.

What is the difference between Static and Shield for outbound traffic?

For outbound, neither product decrypts your HTTPS payload. The difference is the hop between your app and the proxy.

Static sends that hop over the plain HTTP proxy protocol, so your proxy credentials are not encrypted on the way to the proxy. Shield wraps that hop in TLS, using HTTPS and Secure SOCKS, so your credentials are encrypted too.

Choose Static for general outbound use, and Shield when the app-to-proxy hop must be encrypted, such as regulated or security-sensitive workloads.

Can I use QuotaGuard Shield for HIPAA and PCI workloads?

Yes.

Shield was explicitly developed for healthcare and FinTech customers who required a solution for routing HIPAA, Financial, and Personally Identifiable Information (PII).

Because Shield uses SSL passthrough, QuotaGuard never decrypts your traffic and functions as a blind conduit. For HTTPS destinations your data stays encrypted end-to-end, which makes Shield HIPAA-ready and helps keep regulated workloads in scope. A BAA is available on request.

Does Shield encrypt my proxy authentication credentials?

Yes.

With many standard HTTP/SOCKS proxies, your username, password, host, and port are sent "in the clear" between your source and the proxy.

Shield’s outbound service uses HTTPS and Secure SOCKS to encrypt your credentials as well, ensuring they are never exposed during the connection, unlike standard proxies where credentials can be vulnerable.

Do I need to share my private SSL keys with Shield?

No.

To maximize security, you are not permitted to share your SSL certificates or private keys with QuotaGuard when using QG Shield.

By using Server Name Indication (SNI) to route your traffic, we eliminate the need to store your keys.

This prevents your data from being exposed even if our network were compromised, as we simply do not possess the keys required to decrypt and steal your traffic.

Does Shield protect my infrastructure metadata?

Yes.

Beyond just encrypting your data, Shield protects your network topology. It ensures you never expose your source/destination hostnames, open ports, or running services to the public internet.

This prevents malicious actors from mapping out your corporate network to find vulnerabilities, safeguarding your "Sensitive Infrastructure Metadata" alongside your actual application data

Still have questions?

We don’t outsource Support to non-Engineers.

Reach out directly to the Engineers who built Shield to discuss your specific architecture, integration challenges, or compliance constraints here 👇

🚀 Ready to Get Started? Choose Your QuotaGuard Path

QuotaGuard STATIC

Why: You need a rock-solid, fixed IP for general API access, AI workflows, or standard third-party integrations.
Best For: Developers, startups, and general application connectivity.
Key Feature: SOCKS5 support for secure database access.
Sign Up for QG Static

QuotaGuard SHIELD

Why: You handle HIPAA, PCI, or sensitive PII data and require End-to-End Encryption (E2EE) for full compliance.
Best For: Regulated industries, financial services, and healthcare.
Key Feature: SSL Passthrough and key isolation.
Sign Up for QG Shield

Quotaguard has amazing customer service. Some of the best I've interacted with for B2B companies.

Whenever there are snags or setup issues, their support answers emails quickly and hops on zooms to debug with us.

Even with very little notice, they'll hop on zooms to debug. That is absolutely incredible.

Gary L.
CEO
Saas Ai Webflow Website Datalog TemplateSaas Ai Webflow Website Datalog Template

Before I found QuotaGuard, I had tried to use Fixie Socks.

However, I couldn't get it to work even after downloading a separate library that they recommend (fixie-wrench). So I was relieved to find QuotaGuard.

The QuotaGuard team clearly cares about their product and their customers. I enjoyed my interactions with them, and their product seems reliable so far.

Overall a solid choice for Heroku/MongoDB Atlas builds.

Gayle M.
Software Engineer- Health, Wellness and Fitness
Saas Ai Webflow Website Datalog TemplateSaas Ai Webflow Website Datalog Template

Reliability Engineered for the Modern Cloud

For over a decade, QuotaGuard has provided reliable, high-performance static IP and proxy solutions for cloud environments like Heroku, Kubernetes, and AWS.

Get the fixed identity and security your application needs today.