Security throughout the link lifecycle
Security controls are applied when a link is created, reviewed and visited.
Destination protection
New destinations must use a valid public HTTP or HTTPS address. Private network addresses, malformed hosts and reserved aliases are rejected. Links may enter automated or manual safety review and can be blocked when risk is found.
Account protection
Passwords are securely hashed, email verification can be required, and sensitive actions are protected by authentication, validation and rate limits.
Report a vulnerability
Do not publicly disclose a suspected vulnerability. Send a concise report through the contact page with steps to reproduce it, without accessing or retaining other people’s data.