Security at Blinkhop.
How we protect the service and the people who use it, and how to tell us about a vulnerability.
Vulnerability disclosure
- In scope
- blinkhop.com, api., mcp., zou.sh
- How to report
- Private form on this page
- Safe harbor
- For good-faith research
- Bug bounty
- Not offered at this time
Protection
How we keep Blinkhop safe.
Simple by design: the less we collect and run, the less can go wrong.
-
Encrypted everywhere
HTTPS on every domain, TLS 1.2 or newer only, and HSTS so browsers never fall back to plain HTTP.
-
Hardened responses
Security headers on every page, and a strict content security policy on zou.sh preview pages.
-
Least privilege
The link service runs as its own system user and can only write to its own data folder.
-
Little to steal
No cookies, no passwords and no visitor IP addresses stored. Data we don’t keep can’t leak.
-
Abuse-resistant links
Known phishing and malware domains, embedded credentials and private addresses are refused.
-
Protected edge
Cloudflare sits in front of all our domains for TLS and DDoS protection, with bot challenges switched off.
Disclosure policy
Found a vulnerability? Thank you.
In scope
blinkhop.comand its pagesapi.blinkhop.com, the REST APImcp.blinkhop.com, the MCP serverzou.shshort links, previews and QR codes
Out of scope
- Denial of service and load testing
- Spam, phishing or social engineering of our team
- Third-party services, including Cloudflare
- Findings from automated scanners without a working proof
- Missing headers or best practices with no real impact
Please
- Act in good faith and test only against your own links
- Don’t access, change or delete other people’s data
- Don’t degrade the service for others
- Keep the issue private until it’s fixed
Our promise
- We read every report and confirm we received it
- We keep you informed until the issue is fixed
- We won’t take legal action over good-faith research that follows these rules
- We’ll credit you if you’d like
We don’t run a paid bug bounty program at this time.
Report
Send a report privately.
Describe the issue, the affected URL, steps to reproduce and the impact. Reports go straight to the people who can fix them.
Reporting a malicious short link rather than a flaw in Blinkhop? Use the abuse form instead.
Thanks for writing. We’ll answer by email.