Security Page
URly / urly.tr
Authoritative English version • Effective date: [INSERT EFFECTIVE DATE]
This is suggested public-facing copy for https://urly.tr/security.
Security at URLy
Security is a core part of URLy’s infrastructure. We use encrypted transport, application controls, rate limiting, abuse prevention and security monitoring to protect the Service.
Transport security
URLy supports TLS 1.2 and TLS 1.3, disables legacy SSL/TLS, uses modern authenticated encryption cipher suites, supports forward secrecy and X25519MLKEM768, uses a trusted TLS certificate and supports HTTP/2.
Security testing
The primary urly.tr endpoint has received an A rating in Qualys SSL Labs testing, with common TLS vulnerabilities tested as clean or mitigated.
Link safety
URLy separates Global Slug Protection from Destination Safety. These systems help address phishing, malware, fraud, impersonation and other abusive activity.
Report a vulnerability
Send responsible vulnerability reports to abuse@urly.tr.
Related policies
See the Security Policy and Vulnerability Disclosure Policy for additional information.
Last reviewed
[INSERT DATE]
Application security
URLy uses authentication, authorization, input validation, rate limiting, CSRF protections where applicable and security logging.
Abuse protection
The platform maintains separate slug-protection and destination-safety concepts.
Responsible disclosure
Researchers should report security issues to abuse@urly.tr and follow the Vulnerability Disclosure Policy.
Limitations
No security system is perfect and no guarantee is made that every malicious URL or vulnerability will be detected.
Public claims
The security page intentionally does not claim controls that are not verified for production.