Account protection
Strong password requirements, email verification, TOTP two-factor authentication, recovery codes, secure sessions, and security alerts protect access.
セキュリティ
Security is built into account access, link creation, redirects, analytics, APIs, and webhook delivery—not added as a badge after launch.
Defense in depth
The controls below describe features currently implemented by 4ul.ink. They are not a claim that any online service is invulnerable.
Strong password requirements, email verification, TOTP two-factor authentication, recovery codes, secure sessions, and security alerts protect access.
CSRF protection, prepared database queries, scoped API tokens, rate limits, permission checks, and audit events protect application actions.
Nova Shield validates destinations, blocks private and reserved networks, explains risk, monitors changes, and supports quarantine and appeals.
Signed webhooks, replay-resistant delivery IDs, DNS pinning, strict HTTPS endpoints, and bounded responses reduce integration risk.
Product analytics are aggregated without exposing raw visitor IP addresses, full user agents, or persistent visitor identifiers to link owners.
Passwords and API tokens are hashed; sensitive provider, TOTP, and webhook secrets remain server-side and are encrypted where stored.
Responsible disclosure
Use the security topic in our contact form. Your report is stored securely and receives a reference number.