Security
Last updated:
How we protect the service
We take reasonable precautions to protect the service and its users:
- All traffic is served over HTTPS.
- Passwords are stored as one-way hashes (never in plaintext).
- Login/session tokens are signed and stored in httpOnly cookies.
- The administrative area is password-protected and separate from user accounts.
- Short links and report input are treated as untrusted data; URLs are escaped when displayed.
Responsible disclosure
If you believe you have found a security issue, we ask you to report it responsibly:
- Do not publicly disclose the issue until we have had a reasonable opportunity to address it.
- Avoid disrupting the service or accessing other users’ data beyond what is necessary to demonstrate the issue.
- Send a clear description to [email protected], including affected URLs/endpoints and reproduction steps.
What we will not expose
Internal infrastructure details, database contents, stack traces, keys, and the identities of actors behind abuse reports are not published. We take care not to leak sensitive configuration through public pages.
Report abuse
For non-security abuse (phishing, malware, scams), please use our Report Abuse form instead.