Legal
Data security
Last updated
How the data behind your links is protected, and what you can do that we cannot do for you.
Our commitment to security
Trizlink holds the addresses you publish and the traffic they attract. Losing either would be worse than losing the product, so security decisions are made before feature decisions rather than after them.
Key security features
Encryption in transit and at rest, sign-in through an established identity provider rather than passwords we store, per-workspace access rules enforced on the server, an audit log of administrative actions, and optional password protection or expiry on individual links.
Infrastructure and network security
The service runs on managed infrastructure with isolated environments, restricted administrative access and automated patching. Backups are encrypted and restored regularly to prove they work.
Data protection practices
Access to production data is limited to the people who need it, granted for a reason and logged. Analytics are aggregated where a raw record would add nothing, and click records are stored without retaining the IP address they were derived from.
How you can stay secure
Protect the account you sign in with, turn on its two-factor authentication, invite teammates into a workspace instead of sharing a login, review who has access when someone leaves, and use link passwords or expiry dates for anything sensitive.
Compliance and standards
We follow GDPR obligations for the personal data we hold and build against the OWASP Top Ten. Trizlink does not hold a SOC 2 or ISO 27001 certification, and we will not imply one until it exists.
Report a security issue
Email support@trizlink.com with the subject "SECURITY". Tell us what you found and how to reproduce it. We will acknowledge within two working days, and we will not pursue anyone who reports a genuine issue in good faith.
Questions about this document? Email support@trizlink.com or use the contact form.