Security

The controls we actually run

We will not display SOC 2 or ISO badges we have not earned. This page is the honest list: encryption, account security, how little we log, and how to reach us when something is wrong.

Encryption

TLS 1.2+ on every public endpoint. Traffic between gateways is encrypted in transit. Logs and backups are encrypted at rest. We do not terminate customer TLS to destinations — we tunnel.

Account security

Passwords are hashed with Argon2id. TOTP two-factor is available to every plan and required for staff. API keys are shown once, hashed at rest, and can be scoped and rotated from the dashboard.

Infrastructure

Gateways run in UK and EU regions on providers named in the DPA. Production access is SSO + hardware key. There is no standing SSH from the public internet.

Logging and retention

Connection metadata only: timestamp, source, destination host, bytes, status. 30 days, then deletion. No request bodies, no response bodies, no full URLs. Staff access to logs is audited.

Access control

Dashboard roles (admin, developer, billing, viewer), per-proxy-user credentials, IP allowlists for the control plane, and an audit log on every plan — not an enterprise extra.

Monitoring and response

On-call for the gateway, authentication and billing. Abuse detection for stuffing, CSAM signatures and volumetric attacks. Security issues: security@wproxy.io. We aim to acknowledge within 24 hours.

Compliance

What we will sign, and what we will not claim

DPA, UK GDPR, EU SCCs where needed, Acceptable Use enforcement, and a law-enforcement desk that requires valid process. Vulnerability reports to security@wproxy.io. We do not currently hold SOC 2 or ISO 27001.

Get started

Security review for enterprise

Questionnaires, architecture calls, and a named counsel. Book it through sales — not a generic inbox.