The controls we actually run
We will not display SOC 2 or ISO badges we have not earned. This page is the honest list: encryption, account security, how little we log, and how to reach us when something is wrong.
Encryption
TLS 1.2+ on every public endpoint. Traffic between gateways is encrypted in transit. Logs and backups are encrypted at rest. We do not terminate customer TLS to destinations — we tunnel.
Account security
Passwords are hashed with Argon2id. TOTP two-factor is available to every plan and required for staff. API keys are shown once, hashed at rest, and can be scoped and rotated from the dashboard.
Infrastructure
Gateways run in UK and EU regions on providers named in the DPA. Production access is SSO + hardware key. There is no standing SSH from the public internet.
Logging and retention
Connection metadata only: timestamp, source, destination host, bytes, status. 30 days, then deletion. No request bodies, no response bodies, no full URLs. Staff access to logs is audited.
Access control
Dashboard roles (admin, developer, billing, viewer), per-proxy-user credentials, IP allowlists for the control plane, and an audit log on every plan — not an enterprise extra.
Monitoring and response
On-call for the gateway, authentication and billing. Abuse detection for stuffing, CSAM signatures and volumetric attacks. Security issues: security@wproxy.io. We aim to acknowledge within 24 hours.
What we will sign, and what we will not claim
DPA, UK GDPR, EU SCCs where needed, Acceptable Use enforcement, and a law-enforcement desk that requires valid process. Vulnerability reports to security@wproxy.io. We do not currently hold SOC 2 or ISO 27001.
Security review for enterprise
Questionnaires, architecture calls, and a named counsel. Book it through sales — not a generic inbox.