Company
Acceptable use, and the certificates we do not have
Two things decide whether a fetch is acceptable: what you are entitled to request, and what our nodes will refuse regardless of what you ask. This page covers both, and then lists what we cannot attest to.
What we do not offer
We hold no SOC 2 report, no ISO 27001 certificate, no PCI DSS attestation and no CSA STAR listing. There is no Data Protection Officer, no HIPAA business associate agreement, no compliance department, no internal audit programme and no external auditor. A previous version of this page claimed every one of those. If a procurement process requires an attestation, we do not have one to send you.
You are responsible for what you fetch
We return the target's response. We do not review your target list, we do not read the pages you retrieve, and the nodes do not log target URLs or response bodies. That design means the judgement about whether a fetch is lawful and permitted sits with you, not with us.
Under the Terms, you may not use the Service to reach a system you are not authorised to reach, to bypass authentication, paywalls, rate limits or access controls you are not entitled to bypass, or to collect personal data in violation of applicable data-protection law. Scraping a site in breach of terms you have been put on notice of is on the same list.
What gets an account suspended
The acceptable-use section of the Terms is enforced strictly, because a proxy network that is not enforced becomes an attack tool. We may suspend or terminate access immediately and without refund for a material breach; where the breach is not causing ongoing harm we will normally contact you first.
Attack traffic
Credential stuffing, brute force, malware distribution, denial-of-service, unsolicited bulk messaging.
Unlawful targets
Child sexual abuse material, content inciting violence, and activity that is fraudulent or unlawful in your jurisdiction or ours.
Reselling raw access
Repackaging proxy egress as a competing proxy product, or sharing an account with unrelated third parties.
Evading metering
Circumventing quotas or billing, including running multiple accounts to collect repeated trial credit.
What the nodes refuse no matter who asks
Egress nodes resolve a hostname first and then check the resolved address, and they do it on every redirect hop rather than only the first. Private ranges and cloud metadata endpoints are refused at the point the connection would be made, which is the only point where the check is meaningful.
Nodes also require an HMAC signature from the caller and refuse unsigned requests, so a node cannot be used as an open proxy by anyone who finds its address. Size and timeout caps stop one very large or very slow target from occupying a node. Registered billing webhook URLs are validated the same way, at registration and again at every delivery.
What we keep, and for how long
The Privacy Policy is the authority here and is worth reading in full. In short: we log the API key prefix, source IP, user agent, endpoint, response status and timestamp for each call, never the full key and never the proxied body. Those logs are kept 13 months because that spans the card-network chargeback window. Usage records are kept 7 years because invoices and tax records depend on them.
Questions
- Can you complete our vendor security questionnaire?
- Send it to support@roamingproxy.com. We will answer what is true and leave blank what we cannot attest to. Expect the certification rows to come back empty.
- Will you sign a data processing agreement?
- We publish no DPA template. Ask at support@roamingproxy.com and we will tell you plainly what we can and cannot sign rather than returning a signed document we could not honour.
- Is web scraping legal?
- That depends on the site, the data, and where you and it are. We are not your lawyers and this page is not legal advice. What we can tell you is what the Terms require of you, which is above.
Get a key
Create an account and mint an API key in the dashboard. The full endpoint reference — request shapes, parameters and error codes — is published at https://api.roamingproxy.com/v2/docs.
