Infrastructure & Safety Standards

Security & Abuse Prevention

We take link integrity and user safety seriously. Here is an honest, technical explanation of the security systems safeguarding every redirect on ul0.

1. Mandatory TLS / HTTPS

All traffic to ul0 and customer custom domains is strictly encrypted with modern TLS 1.3 encryption. HTTP Strict Transport Security (HSTS) with a 1-year max-age is enforced across all endpoints.

2. SSRF & Private IP Blocking

Our backend server-side validation strictly prohibits shortening or inspecting private intranet IP ranges (127.0.0.1, 10.0.0.0/8, 192.168.0.0/16, AWS metadata 169.254.169.254, and IPv6 loopback addresses).

3. Brand Mimicry & Phishing Heuristics

Link submissions are checked in real-time against heuristics for brand spoofing (e.g. fake PayPal, Apple, Chase, or Google authentication forms on disposable TLDs). Suspicious URLs are automatically rejected.

4. Privacy-First Telemetry

Click analytics use anonymized telemetry (aggregate country codes and device categories). We never sell user data, record personal PII, or install third-party advertising tracking pixels on redirects.

Spam & Phishing Takedowns

Found a short link being used for malware, credential harvesting, or spam? We disable confirmed malicious slugs immediately.

Report Malicious Link