Company
Reporting abuse, or a security problem
Three different problems arrive at this page: our traffic is bothering your site, you have found a hole in ours, or a key has gone missing. All three go to support@roamingproxy.com, with abuse@roamingproxy.com and legal@roamingproxy.com named in the Terms for the first and the formal ones. What follows is what each report needs to be actionable.
What we do not offer
There is no anonymous whistleblower portal, no report ID and access key to track a case with, no ethics hotline, and no bug bounty with a payout. The old version of this page promised all four, hosted supposedly outside our own infrastructure. What exists is an inbox that a person reads.
If our addresses are hitting your site
We run exactly three egress nodes, each with a stable Elastic IP in our own AWS account, so an address you saw is traceable to us rather than to an anonymous pool. Send the address, the timestamps with their timezone, the paths that were requested, the user-agent string, and what you want stopped.
One limitation, stated up front so you do not wait on something we cannot produce: our nodes do not log target URLs or response bodies. We cannot search our own records for your domain. What we can correlate is timing, volume and source, which is usually enough to identify the account behind sustained traffic and act on it under the acceptable-use section of the Terms.
If you have found a vulnerability
Email support@roamingproxy.com with the endpoint, the steps to reproduce, the timestamp with its timezone, the response status and the machine-readable code from any refusal involved. If the response you are describing was a successful fetch envelope, device_id and region_used name the node and region that served it; those are the handles we have. There is no request id on a proxy response to quote, so do not go looking for one.
Please do not test against other customers' accounts, do not run destructive or denial-of-service tests, and do not retain data you happen to reach.
We do not pay for reports and we will not pretend otherwise. We will read it, fix what needs fixing, and tell you what we did.
If it is your own account
A key you think has leaked should be revoked in the dashboard first. Keys are individually revocable and scoped, so revoking one does not disturb the rest, and rate limits are per account rather than per key. Tell us afterwards at support@roamingproxy.com. Under the Terms you are responsible for activity under your account and keys, including activity by anyone you shared a key with.
What happens next
The Terms state that we aim to respond to abuse reports within two business days. That is the commitment; there is no case-tracking portal behind it and no status page for reports. Where a report shows a material breach we may suspend or terminate the account immediately and without refund.
Questions
- Will you tell me which customer sent the traffic?
- No. We disclose customer information only where we are legally compelled to, as the Privacy Policy sets out, and we notify the customer unless we are prohibited from doing so.
- Can I report anonymously?
- You can write from any address you like, but we do not operate a system that guarantees anonymity and will not claim we do. If anonymity matters to you, assume the email headers are what they look like.
- Do you have a bug bounty?
- No. No payouts, no scope document, no hall of fame. Reports are still welcome and still read.
Get a key
Create an account and mint an API key in the dashboard. The full endpoint reference — request shapes, parameters and error codes — is published at https://api.roamingproxy.com/v2/docs.
