सुरक्षा

Security at 4ul.ink

Security is built into account access, link creation, redirects, analytics, APIs, and webhook delivery—not added as a badge after launch.

Defense in depth

Protection across the product

The controls below describe features currently implemented by 4ul.ink. They are not a claim that any online service is invulnerable.

01

Account protection

Strong password requirements, email verification, TOTP two-factor authentication, recovery codes, secure sessions, and security alerts protect access.

02

Application security

CSRF protection, prepared database queries, scoped API tokens, rate limits, permission checks, and audit events protect application actions.

03

Link and destination safety

Nova Shield validates destinations, blocks private and reserved networks, explains risk, monitors changes, and supports quarantine and appeals.

04

Integration integrity

Signed webhooks, replay-resistant delivery IDs, DNS pinning, strict HTTPS endpoints, and bounded responses reduce integration risk.

05

Privacy-conscious analytics

Product analytics are aggregated without exposing raw visitor IP addresses, full user agents, or persistent visitor identifiers to link owners.

06

Secret handling

Passwords and API tokens are hashed; sensitive provider, TOTP, and webhook secrets remain server-side and are encrypted where stored.

Responsible disclosure

Report a Security Vulnerability

Use the security topic in our contact form. Your report is stored securely and receives a reference number.

Include in your report

Submit a security report