All other public/private proxies decrypt your traffic at the proxy to know where to route your traffic.
Learn how Shield’s Passthrough architecture guarantees your data remains opaque from end-to-end.

Secure Socket Layer (SSL), also known as TLS (Transport Layer Security), is the most common security protocol for HTTP traffic traversing on the Internet.
SSL/TLS encrypts the communications between a client and a server that allows for secure bi-directional message exchanges.
For outbound traffic, QuotaGuard Static routes your requests through a blind CONNECT tunnel, or SOCKS5 for raw TCP connections. The proxy reads only the CONNECT command and your proxy credentials to pick the right destination, then passes the encrypted bytes straight through without opening them. QuotaGuard never holds your keys and never decrypts your HTTPS payload. When your destination speaks HTTPS, as most do, the TLS session runs from your app all the way to the destination server, so your data stays encrypted end to end.
So where does SSL Termination come in? SSL Termination, also called SSL Offloading, is what Static does on inbound connections: you upload your certificate and the proxy terminates the TLS connection at your dedicated static IP before forwarding traffic to your origin. On outbound, the only thing that differs between Static and Shield is the single hop between your app and the proxy. Static sends that hop over the plain HTTP proxy protocol, so your proxy credentials travel unencrypted on that leg. Shield wraps the same hop in TLS, encrypting your credentials as well.
QuotaGuard Shield uses SSL Passthrough for routing requests between endpoints.
SSL passthrough passes encrypted HTTPS traffic all the way to the backend server without decrypting the traffic on the proxy.
Therefore, traffic passes through the proxy encrypted and the destination server (web application server, database server, etc.) does the decryption process to read the data.

Common questions about encryption, compliance, and security specifics.
To get SSL Passthrough to work with QuotaGuard Shield, do the following :
1. Sign up for QuotaGuard Shield either at Heroku, our Direct site, on AWS, or Azure.
2. Use the QuotaGuard wizard to configure your domain name and forwarding URL.
3. Change your DNS to point to the CNAME record we provide in your account.
4. Allow up to an hour for the DNS settings to propagate and you’re done.
Note that you do not have to upload your certificates to QuotaGuard when using QuotaGuard Shield.
For outbound, neither product decrypts your HTTPS payload. The difference is the hop between your app and the proxy.
Static sends that hop over the plain HTTP proxy protocol, so your proxy credentials are not encrypted on the way to the proxy. Shield wraps that hop in TLS, using HTTPS and Secure SOCKS, so your credentials are encrypted too.
Choose Static for general outbound use, and Shield when the app-to-proxy hop must be encrypted, such as regulated or security-sensitive workloads.
Yes.
Shield was explicitly developed for healthcare and FinTech customers who required a solution for routing HIPAA, Financial, and Personally Identifiable Information (PII).
Because Shield uses SSL passthrough, QuotaGuard never decrypts your traffic and functions as a blind conduit. For HTTPS destinations your data stays encrypted end-to-end, which makes Shield HIPAA-ready and helps keep regulated workloads in scope. A BAA is available on request.
Yes.
With many standard HTTP/SOCKS proxies, your username, password, host, and port are sent "in the clear" between your source and the proxy.
Shield’s outbound service uses HTTPS and Secure SOCKS to encrypt your credentials as well, ensuring they are never exposed during the connection, unlike standard proxies where credentials can be vulnerable.
No.
To maximize security, you are not permitted to share your SSL certificates or private keys with QuotaGuard when using QG Shield.
By using Server Name Indication (SNI) to route your traffic, we eliminate the need to store your keys.
This prevents your data from being exposed even if our network were compromised, as we simply do not possess the keys required to decrypt and steal your traffic.
Yes.
Beyond just encrypting your data, Shield protects your network topology. It ensures you never expose your source/destination hostnames, open ports, or running services to the public internet.
This prevents malicious actors from mapping out your corporate network to find vulnerabilities, safeguarding your "Sensitive Infrastructure Metadata" alongside your actual application data
We don’t outsource Support to non-Engineers.
Reach out directly to the Engineers who built Shield to discuss your specific architecture, integration challenges, or compliance constraints here 👇
For over a decade, QuotaGuard has provided reliable, high-performance static IP and proxy solutions for cloud environments like Heroku, Kubernetes, and AWS.
Get the fixed identity and security your application needs today.