Security at Linky

How Linky protects your account, links, and data - encryption, access control, and infrastructure practices.

Encryption

Traffic to Linky is encrypted in transit with HTTPS everywhere, including custom domains once verified. Sensitive secrets such as webhook and API credentials are stored using strong at-rest encryption.

Access control

Dashboard access requires authentication through Google, GitHub, or email sign-in. Organization roles (owner, admin, member, viewer) scope what each teammate can see and change.

  • Role-based access control for organizations
  • API keys with scoped permissions
  • Audit log of account and API activity

Infrastructure

Linky runs on managed cloud infrastructure with regular backups of the primary database and monitored uptime for the redirect and dashboard services.

Single sign-on (SSO)

SSO and SCIM provisioning are available for Enterprise customers on request. Contact us to discuss your organization's requirements.

Responsible disclosure

Found a security issue? Please report it via GitHub issues so we can investigate and respond promptly.

FAQ

Do you offer SSO?
SSO (SAML/OIDC) and SCIM are available on Enterprise plans by request. Contact us via GitHub issues to start a conversation.
How do you handle vulnerability reports?
Open a GitHub issue with details, or mark it confidential in the description. We prioritize security reports over regular support requests.

Get started free

Create your first smart link in under a minute. Free forever — no credit card required.