Trust Center

Security by Design

Your data security isn't just a feature—it's the foundation of our architecture. We use enterprise-grade encryption and serverless infrastructure to keep your links safe.

Serverless Infrastructure

Built entirely on AWS Serverless architecture (Lambda & App Runner). This means no dedicated servers to patch, zero OS vulnerabilities to exploit, and automatic scaling that absorbs DDoS attempts effortlessly.

Strict Encryption

ShortMe enforces HSTS (HTTP Strict Transport Security) with a pre-load grade policy. All data in transit is encrypted via TLS 1.2+, and sensitive secrets are managed in encrypted DynamoDB vaults, never in code.

Privacy First

We believe in data minimization. Your links are yours. We do not sell user data, and our infrastructure is designed to strip unnecessary metadata automatically. Metrics are aggregated and anonymized.

24/7 Monitoring

Our edge protection includes API Gateway Throttling to prevent abuse and bot protection via Google reCAPTCHA Enterprise. Anomalies are detected and blocked instantly at the network edge.

Safe Client Headers

We protect your browser with strict CSP (Content Security Policy) and Permissions-Policy headers, preventing XSS attacks and unauthorized access to your device's hardware (camera/mic).

99.9% Availability

Our distributed global CDN ensures your short links resolve instantly from anywhere in the world, backed by the reliability of Amazon CloudFront and DynamoDB Global Tables capabilities.

Official Verification

SecurityHeaders.io: A+ Grade
SSL Labs: A Grade
Google Safe Browsing: Clean
Infrastructure: AWS Serverless
HSTS Preload: Ready