🔒 Transport & Infrastructure Security
URLy enforces modern encryption protocols and industry best practices:
- TLS 1.2 & TLS 1.3 enforcement; legacy ciphers disabled
- Modern AEAD cipher suites and Perfect Forward Secrecy (PFS)
- Quantum-resistant key exchange compatibility (X25519MLKEM768)
- Trusted CA certificate with HTTP/2 transport
- A-grade rating compliance on Qualys SSL Labs audits
🛡️ Destination Safety & Anti-Abuse
Separated layers of defense to mitigate phishing, malware, fraud, and impersonation:
- Global Slug Protection: System and brand keyword reservation
- SSRF Mitigation: Blocking private ranges, loopbacks, and reserved IPs
- Multi-tier Rate Limiting: Protection against brute-force and spam
- Referrer Minimization: Stripping sensitive query tokens from click logs
- CSRF protection and strict cookie security (HttpOnly, Secure, SameSite)
🎯 Vulnerability Disclosure Policy
We welcome reports from security researchers acting in good faith. If you believe you have discovered a vulnerability, please coordinate with us responsibly following these guidelines:
✓ Permitted & Good-Faith Testing
- Limit testing to the minimum necessary to demonstrate the issue.
- Provide clear reproduction steps and technical proof-of-concept.
- Redact personal data and live credentials before sending.
- Allow reasonable coordination time before any public disclosure.
✕ Strictly Prohibited Testing
- Accessing, modifying, deleting or exposing other users’ data.
- Denial of Service (DoS/DDoS) or destructive load attacks.
- Social engineering or phishing against staff or users.
- Installing malware, implants, or persistence backdoors.
⚖️ Safe Harbor Commitment
To the extent permitted by law, URLy commits not to initiate legal action against researchers conducting good-faith security research in compliance with this Policy.
📜 RFC 9116 security.txt Specification
Machine-readable security contact information located at /.well-known/security.txt:
Contact: mailto:security@urly.tr
Contact: mailto:abuse@urly.tr
Policy: https://urly.tr/security.php
Preferred-Languages: tr, en
Canonical: https://urly.tr/.well-known/security.txt
Expires: 2027-10-08T00:00:00.000Z