Security

Last updated: October 10, 2026

Summary. WarpLink protects link configurations, attribution data, and analytics with encryption in transit, keyed hashing of IP addresses, role-based access, two-factor authentication, hashed keys, and automatic deletion of expired data. We store no raw IP addresses in click or install records. We notify customers of a personal data breach within 72 hours of becoming aware of it. Report vulnerabilities to security@warplink.app.

Data protection

  • The dashboard, the API, the MCP server, and the SDK endpoints use HTTPS (TLS).
  • We convert each link visitor's IP address to a keyed hash (HMAC-SHA256) before we queue or store the click. We do not store the raw IP address or the full user agent in click records.
  • Device fingerprints for install attribution are keyed hashes. We do not store their inputs.
  • Our SDKs collect no advertising identifiers. The Android SDK sends no device identifier.
  • Keyed hashes are still personal data under privacy law, and we treat them that way.
  • Our database and edge key-value storage are encrypted at rest by the providers.
  • Expired data is deleted by a daily automated process, on the retention period of each plan.

Access control

  • Sign-in with email and password, GitHub, or Google. Passwords are stored as salted hashes.
  • Two-factor authentication with an authenticator app (TOTP) and backup codes.
  • Organization owners can require two-factor authentication for every member, and set a session lifetime and an idle timeout.
  • Owner, admin, and member roles in each organization. Members can edit and delete only their own links.
  • An organization audit log records sign-ins, two-factor changes, key, link, app, domain, member, and billing changes, security policy changes, and data exports. It does not record every read.

API keys and SDK keys

  • We store keys only as SHA-256 hashes. We show a key once, when it is created.
  • API keys are secret. Keep them on your servers. They carry the scopes you choose, can expire, and are limited to 60 requests per minute per key.
  • SDK keys are not secret. They are built into your mobile app, so anyone who has the app can extract them. An SDK key works only on the three SDK endpoints: it resolves links, validates the key, and records install attribution. It cannot create, change, or delete anything, and it cannot read analytics. The SDK endpoints are limited to 60 requests per minute per key per client IP address.
  • Tie each SDK key to one app. A tied key acts only as its app, and a request for another app is refused. We recommend tying every SDK key to its app.
  • If a key leaks, revoke it in the dashboard and create a new one. Revocation takes effect at once.

Tenant isolation

Every customer record carries its organization identifier. Every request is checked against the organization of its session or key, and every database query is scoped by organization ID.

Secrets and recovery

  • Production secrets are stored encrypted and decrypted only at deployment.
  • Deleted data leaves our database provider's restore history within 6 hours. A restore loses changes made after the chosen restore point.
  • Click events that fail to process are retried and then held for review. Failures are logged and investigated, so they are not lost silently.

Incidents and status

We investigate every security report and incident. If a personal data breach affects your data, we email your organization owner without undue delay and in any case within 72 hours of becoming aware of it, as our Data Processing Agreement states. We do not offer a contractual uptime guarantee.

Reporting a vulnerability

Email security@warplink.app with a description of the issue, the steps to reproduce it, and its impact. Please:

  • test only against your own account and data;
  • do not access, change, or delete other customers' data, and stop and tell us if you reach any;
  • do not degrade the service, send spam, or use social engineering; and
  • give us reasonable time to fix the issue before you disclose it, and agree the disclosure date with us.

We confirm that we have received your report, keep you informed of our progress, and credit you when we publish a fix if you want us to. We will not take legal action against research done in good faith under these rules.

Certifications and testing

We have no SOC 2 report, no ISO 27001 certification, and no independent penetration test. We answer reasonable security questionnaires from customers: email legal@warplink.app. Our providers are listed on our Sub-processors page.