Security Policy

Responsible disclosure and vulnerability reporting

Last updated: July 28, 2026

Alshorty is operated by Muqira. We take the security of our platform, our users, and the links our users create seriously. If you've found a security vulnerability, we want to hear about it — this page explains how to report it safely and what to expect from us.

Reporting a vulnerability

If you believe you've found a security issue in Alshorty, please email us at abuse@alshorty.com with:

  1. A clear description of the vulnerability and its potential impact
  2. Step-by-step instructions to reproduce the issue
  3. Any proof-of-concept code, screenshots, or request/response captures that support the report
  4. The URL, endpoint, or feature affected
  5. Your contact information, so we can follow up with questions or credit you (optional)

A machine-readable version of this contact information is published at /.well-known/security.txt, per RFC 9116.

Our safe-harbor commitment

If you make a good-faith effort to comply with this policy during your security research, we will:

  • Not pursue or support legal action against you for that research
  • Work with you to understand and resolve the issue quickly
  • Publicly acknowledge your contribution, if you'd like us to and once a fix has shipped

"Good faith" means you:

  • Give us a reasonable amount of time to investigate and remediate before disclosing publicly
  • Avoid privacy violations, data destruction, or service disruption during your testing
  • Only interact with accounts you own or have explicit permission to test
  • Do not access, download, or modify data belonging to other users

What's in scope

  • alshorty.com and all subdomains (api.alshorty.com, dev3.alshorty.com)
  • The Alshorty API
  • SmartPages and Link-in-Bio hosting infrastructure

What's out of scope

The following are not eligible for review under this policy, though you're welcome to report them if you think they matter:

  • Denial-of-service (DoS/DDoS) testing against our infrastructure
  • Automated vulnerability scanning that generates significant traffic
  • Social engineering of our staff or users
  • Physical security of our offices or data centers
  • Reports about the destination content of a shortened link — see our DMCA Policy or Report Abuse page for that instead
  • Third-party services we integrate with (e.g. Razorpay, Google, Microsoft) — please report those directly to the respective provider
  • Missing security headers or best-practice suggestions with no demonstrated exploit path

Response timeline

We aim to acknowledge every valid report within 3 business days, and to provide an initial assessment of severity and next steps within 10 business days. Complex issues may take longer to remediate; we'll keep you updated throughout.

Please don't

  • Publicly disclose a vulnerability before we've had a chance to address it
  • Access or attempt to access another user's account, links, or analytics data
  • Submit a report through any channel other than the one above — reports sent via social media, public forums, or comment sections cannot be tracked or actioned reliably

For copyright or content concerns, see our DMCA Policy. To report a specific link as phishing, malware, or otherwise abusive, use our Report Abuse page. For anything else, visit our Contact page.