Alshorty is operated by Muqira. We take the security of our platform, our users, and the links our users create seriously. If you've found a security vulnerability, we want to hear about it — this page explains how to report it safely and what to expect from us.
Reporting a vulnerability
If you believe you've found a security issue in Alshorty, please email us at abuse@alshorty.com with:
- A clear description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce the issue
- Any proof-of-concept code, screenshots, or request/response captures that support the report
- The URL, endpoint, or feature affected
- Your contact information, so we can follow up with questions or credit you (optional)
A machine-readable version of this contact information is published at /.well-known/security.txt, per RFC 9116.
Our safe-harbor commitment
If you make a good-faith effort to comply with this policy during your security research, we will:
- Not pursue or support legal action against you for that research
- Work with you to understand and resolve the issue quickly
- Publicly acknowledge your contribution, if you'd like us to and once a fix has shipped
"Good faith" means you:
- Give us a reasonable amount of time to investigate and remediate before disclosing publicly
- Avoid privacy violations, data destruction, or service disruption during your testing
- Only interact with accounts you own or have explicit permission to test
- Do not access, download, or modify data belonging to other users
What's in scope
- alshorty.com and all subdomains (api.alshorty.com, dev3.alshorty.com)
- The Alshorty API
- SmartPages and Link-in-Bio hosting infrastructure
What's out of scope
The following are not eligible for review under this policy, though you're welcome to report them if you think they matter:
- Denial-of-service (DoS/DDoS) testing against our infrastructure
- Automated vulnerability scanning that generates significant traffic
- Social engineering of our staff or users
- Physical security of our offices or data centers
- Reports about the destination content of a shortened link — see our DMCA Policy or Report Abuse page for that instead
- Third-party services we integrate with (e.g. Razorpay, Google, Microsoft) — please report those directly to the respective provider
- Missing security headers or best-practice suggestions with no demonstrated exploit path
Response timeline
We aim to acknowledge every valid report within 3 business days, and to provide an initial assessment of severity and next steps within 10 business days. Complex issues may take longer to remediate; we'll keep you updated throughout.
Please don't
- Publicly disclose a vulnerability before we've had a chance to address it
- Access or attempt to access another user's account, links, or analytics data
- Submit a report through any channel other than the one above — reports sent via social media, public forums, or comment sections cannot be tracked or actioned reliably
For copyright or content concerns, see our DMCA Policy. To report a specific link as phishing, malware, or otherwise abusive, use our Report Abuse page. For anything else, visit our Contact page.