Legal
Security
What we do to keep your data safe and your links working. Security questionnaire? We're happy to fill it in.
Effective 3 October 2026 · Last updated 3 October 2026
1. Architecture and availability
- Redirects are served from Cloudflare's global edge network out of a cache, independent of our servers and databases.
- Link records are versioned so an older copy can never overwrite a newer one, and failed cache updates are retried automatically.
- Billing state never affects redirects: an expired card or empty balance can't break a live link.
- Click events are queued and retried, with a dead-letter queue, so analytics outages don't lose clicks.
2. Data protection
- All traffic uses TLS (HTTPS), including on customers' custom domains, with certificates managed automatically.
- IP addresses of people who click links are stored only as hashes with a secret salt that rotates daily.
- Passwords are hashed with bcrypt. API keys and invite and reset tokens are stored only as SHA-256 hashes and shown once.
- Every database query for customer data goes through a single data-access layer scoped to the customer's organization.
- We collect no advertising identifiers and set no tracking cookies.
3. Accounts and access
- Owner, admin, member and viewer roles, enforced on the server for every action and API call.
- Email verification is required before accepting team invites; invites are bound to the invited address.
- An audit log records changes to links, domains, keys, members and billing.
- Sign-in, signup, password reset and API requests are rate-limited.
- API keys are scoped to a single project and can be revoked at any time; SDK keys can be rotated.
4. Application security
- Strict security headers: Content Security Policy, HSTS, frame protection and MIME sniffing protection.
- All input is validated; link destinations that could run scripts (such as javascript: URLs) are rejected.
- Webhook and internal service calls are authenticated with secrets compared in constant time.
- Payment webhooks are signature-verified and processed exactly once.
5. Payments
Card, UPI and bank details are entered on Razorpay's PCI DSS-compliant checkout and never reach ivlink's servers. We store only payment references, amounts and invoices.
6. Operations
- Infrastructure runs on Cloudflare and Railway; see our Subprocessors page.
- Secrets are kept in environment variables and the platforms' secret stores, never in source code.
- Changes are tested before deployment, and deployments can be rolled back.
- Database migrations are backward compatible, so a rollback never strands data.
7. Reporting a vulnerability
Found a security issue? Email help@ivrs.app with details and steps to reproduce. Please give us a reasonable time to fix it before disclosing it, and don't access other customers' data or disrupt the service while testing. We don't take legal action against good-faith research that follows these rules.