Security at Blinkhop.

How we protect the service and the people who use it, and how to tell us about a vulnerability.

Vulnerability disclosure

In scope
blinkhop.com, api., mcp., zou.sh
How to report
Private form on this page
Safe harbor
For good-faith research
Bug bounty
Not offered at this time
Read the rules

Protection

How we keep Blinkhop safe.

Simple by design: the less we collect and run, the less can go wrong.

  • Encrypted everywhere

    HTTPS on every domain, TLS 1.2 or newer only, and HSTS so browsers never fall back to plain HTTP.

  • Hardened responses

    Security headers on every page, and a strict content security policy on zou.sh preview pages.

  • Least privilege

    The link service runs as its own system user and can only write to its own data folder.

  • Little to steal

    No cookies, no passwords and no visitor IP addresses stored. Data we don’t keep can’t leak.

  • Abuse-resistant links

    Known phishing and malware domains, embedded credentials and private addresses are refused.

  • Protected edge

    Cloudflare sits in front of all our domains for TLS and DDoS protection, with bot challenges switched off.

Disclosure policy

Found a vulnerability? Thank you.

In scope

  • blinkhop.com and its pages
  • api.blinkhop.com, the REST API
  • mcp.blinkhop.com, the MCP server
  • zou.sh short links, previews and QR codes

Out of scope

  • Denial of service and load testing
  • Spam, phishing or social engineering of our team
  • Third-party services, including Cloudflare
  • Findings from automated scanners without a working proof
  • Missing headers or best practices with no real impact

Please

  • Act in good faith and test only against your own links
  • Don’t access, change or delete other people’s data
  • Don’t degrade the service for others
  • Keep the issue private until it’s fixed

Our promise

  • We read every report and confirm we received it
  • We keep you informed until the issue is fixed
  • We won’t take legal action over good-faith research that follows these rules
  • We’ll credit you if you’d like

We don’t run a paid bug bounty program at this time.

Report

Send a report privately.

Describe the issue, the affected URL, steps to reproduce and the impact. Reports go straight to the people who can fix them.

Reporting a malicious short link rather than a flaw in Blinkhop? Use the abuse form instead.

0 / 5,000

We reply by email. See our privacy policy.