🛡️ Responsible Security & Disclosure

Security at URLy Platform

Encrypted transport, modern application controls, rate limiting, and safe harbor vulnerability disclosure policy.

🔒 Transport & Infrastructure Security

URLy enforces modern encryption protocols and industry best practices:

  • TLS 1.2 & TLS 1.3 enforcement; legacy ciphers disabled
  • Modern AEAD cipher suites and Perfect Forward Secrecy (PFS)
  • Quantum-resistant key exchange compatibility (X25519MLKEM768)
  • Trusted CA certificate with HTTP/2 transport
  • A-grade rating compliance on Qualys SSL Labs audits

🛡️ Destination Safety & Anti-Abuse

Separated layers of defense to mitigate phishing, malware, fraud, and impersonation:

  • Global Slug Protection: System and brand keyword reservation
  • SSRF Mitigation: Blocking private ranges, loopbacks, and reserved IPs
  • Multi-tier Rate Limiting: Protection against brute-force and spam
  • Referrer Minimization: Stripping sensitive query tokens from click logs
  • CSRF protection and strict cookie security (HttpOnly, Secure, SameSite)

🎯 Vulnerability Disclosure Policy

We welcome reports from security researchers acting in good faith. If you believe you have discovered a vulnerability, please coordinate with us responsibly following these guidelines:

✓ Permitted & Good-Faith Testing

  • Limit testing to the minimum necessary to demonstrate the issue.
  • Provide clear reproduction steps and technical proof-of-concept.
  • Redact personal data and live credentials before sending.
  • Allow reasonable coordination time before any public disclosure.

✕ Strictly Prohibited Testing

  • Accessing, modifying, deleting or exposing other users’ data.
  • Denial of Service (DoS/DDoS) or destructive load attacks.
  • Social engineering or phishing against staff or users.
  • Installing malware, implants, or persistence backdoors.

⚖️ Safe Harbor Commitment

To the extent permitted by law, URLy commits not to initiate legal action against researchers conducting good-faith security research in compliance with this Policy.

📜 RFC 9116 security.txt Specification

Machine-readable security contact information located at /.well-known/security.txt:

Contact: mailto:security@urly.tr Contact: mailto:abuse@urly.tr Policy: https://urly.tr/security.php Preferred-Languages: tr, en Canonical: https://urly.tr/.well-known/security.txt Expires: 2027-10-08T00:00:00.000Z
🔗 /.well-known/security.txt dosyasını görüntüle

Discovered a Security Issue?

Please report full reproduction steps directly to our dedicated security mailbox.

✉️ security@urly.tr 🛡️ Report Abuse