Above Scale · custom pricing · no checkout

Short links your security review can actually sign off

You are not buying a link shortener; you are putting a redirect in front of your customers, a domain in front of your brand and a click log in front of your data protection officer. This page tells you exactly what the software does, which plan already includes it, and what it does not do — so the answer to your questionnaire is on the page rather than in a follow-up call.

Most of what follows ships on a self-serve plan. Scale is $140 a month and uncaps everything — an agreement is for contract terms, invoicing and a response target, not for a hidden feature set.

56links created on this installation
605clicks recorded
16domains connected
100%redirect availability measured over 1,081 self-checks since 2026-09-08

These four are counted from this installation's own database when you load the page. We do not publish a customer count or a logo wall, because we are not going to put a number or a brand on this page that you cannot check. The 99.9% availability figure elsewhere on this site is a committed target with service credits, not a measurement.

What a large buyer usually asks for

Answered below in the order a security questionnaire tends to arrive in. Every claim on this page is implemented in the product today; anything that is not is in what we do not do, named rather than omitted.

Connected operations

Build repeatable campaigns and support workflows with visible permissions and usage limits.

101 integration catalogue entries

Every plan, Free included

Browse direct connectors and 47 guided HTTP workflows. OAuth providers require administrator app credentials; key-based services use a token or webhook. Guides show which setup applies before you connect.

Connections follow your plan

Every plan, Free included

The server rechecks feature access and connection limits for requests and background deliveries. Revoking a connection also revokes its generated API key. Expired plans return to Free access.

Controlled AI support

Every plan, Free included

The administrator can configure provider routing, approved repair tools, confidence thresholds and human review. Ticket actions keep an audit trail. Provider credentials and automation settings must be configured before AI can run.

URL parameter controls

Every plan, Free included

Allow or block selected incoming parameters, choose how duplicates are handled and set a destination anchor. Preview the result before changing a campaign link.

Developer rollout guides

Every plan, Free included

Follow screenshot-led workflows for domains, links, targeting and reporting. The API reference includes 22 request example formats and a scoped-key request console.

Identity and access

Your directory stays the source of truth for who works here, and the audit trail answers who did what.

SAML 2.0 single sign-on

Scale — $140/mo and up

Each workspace gets its own ACS endpoint. Your identity provider posts the assertion there, we read the email and display name out of it, and the person lands in the dashboard. You set the entry point, entity ID and certificate from the workspace settings — there is no ticket to raise and nothing for us to configure at our end.

Just-in-time provisioning

Scale — $140/mo and up

A person who signs in through SSO for the first time and has no account gets one created, added to the organisation and added to the team the assertion arrived for. You do not pre-load a user list before a rollout.

Force SSO for a workspace

Scale — $140/mo and up

A workspace can be marked SSO-required, so a password is no longer a way in for anyone in it.

Four roles, enforced server-side

Every plan, Free included

Owner, admin, user and read-only. The check runs in the API layer rather than in the interface, so a role limit holds for an API key and a curl request exactly as it holds for a button that is greyed out.

Per-link permissions

Business — $44/mo and up

Name the people who may open and edit one specific link. Everyone else in the organisation gets a 404 on it, including through the API. This is what protects a URL that is already printed on packaging from being repointed by someone who did not know.

Multiple teams under one organisation

Business — $44/mo and up

Separate brands, regions or subsidiaries into teams, each with its own domains, members and SSO connection, all billed once.

Two-factor authentication and passkeys

Every plan, Free included

TOTP from any authenticator app, plus WebAuthn passkeys and hardware security keys. Every active session is listed and can be revoked one at a time or all at once.

Audit log, on every plan

Every plan, Free included

Sign-ins, link edits, domain changes, permission changes and billing events, each with the person, the entity, the IP and the timestamp. Filter by action, user or date range, and pull it out as CSV whenever your reviewers ask. It is not held back for a higher tier — the free plan has it.

Domains, certificates and the redirect path

The redirect is the part your audience touches. It is deliberately the simplest thing we run.

Automatic TLS on every domain you connect

Every plan, Free included

Point a DNS record at us and the certificate is issued and renewed for you, apex domains included. There is nothing to remember and nothing that expires at 2am on a bank holiday.

Upload your own certificate

Business — $44/mo and up

If your security policy says the private key for a company domain never leaves your CA, upload the certificate and key yourself instead of letting us issue one.

Signed redirects

Growth — $14/mo and up

An HMAC signature on the short URL, so a link cannot be forged or its parameters tampered with between your system and the visitor.

Destination allow-listing

Growth — $14/mo and up

Restrict which hostnames anyone in the organisation may point a link at. An open redirect on your own brand domain is an incident; this is the setting that prevents it.

Destination and domain monitoring

Every plan, Free included

A scheduled job visits monitored destinations, follows the hops by hand so a redirect loop is caught rather than exhausted, and checks DNS and certificate expiry on your connected domains. You hear about a broken destination before your audience does.

No third-party script on the redirect path

Every plan, Free included

Measurement tags are loaded on the marketing site only. The redirect and the dashboard never load someone else's JavaScript, which is one fewer supply-chain question for your reviewer to ask.

Data, retention and export

Your click data is yours. Getting it out again is a supported operation, not a support ticket.

Retention window by plan, enforced by a job

Every plan, Free included

Statistics queries are bounded by the retention window your plan carries — 730 days on Free and Starter, 1,095 on Growth, 1,825 on Business, unlimited on Scale. Separately, the operator sets a platform retention policy for clicks, click detail, aggregates, closed tickets, the audit log, the sign-in log and the error log, and a daily job enforces it. That job can be dry-run first, so nobody deletes a year of history by accident.

CSV and spreadsheet export of everything

Every plan, Free included

Links, the click stream, statistics, the audit log and the bulk sheet all export as CSV or XLSX from the dashboard and from the API. Nothing is trapped behind a screen.

Full account export as JSON

Every plan, Free included

One request returns the account, organisations, domains, links, folders, bundles, posts, conversions, invoices and the last 5,000 audit entries as a single JSON bundle. It exists for GDPR subject requests, and it is equally the answer to "what happens if we leave".

Scheduled statistics reports by email

Every plan, Free included

Weekly and monthly reports run on a schedule and are delivered to the addresses you nominate. Where the operator has not connected a mail provider, the job says so plainly rather than pretending to have sent them.

Click webhooks

Every plan, Free included

Every click can be posted to an endpoint you own, with delivery attempts recorded so a failure is visible rather than silent. Use it when you want each click as it happens; use the daily export when you want the whole day in one file.

Daily click export to object storage

Business — $44/mo and up

A daily job writes the previous UTC day's raw clicks as gzipped newline-delimited JSON — one file per domain you switch it on for — and uploads each file to an S3-compatible bucket with a signed PUT. The file is written to disk before it is uploaded, so a bucket that is misconfigured or unreachable loses the upload and not the data, and the run says which of the two happened. One thing to be clear about: the upload is signed with the credentials your operator connected, so a bucket you own needs a policy granting that principal write access. We do not assume the role ARN you save.

GDPR-shaped analytics controls

Starter — $4/mo and up

Visitor IP storage can be switched off per domain, in which case the country, region and city are still derived but the address itself is never written. Referrer hiding and a robots policy are separate switches.

Scale, limits and automation

The numbers a capacity planner asks for, taken from the plan table rather than from a brochure.

Published API rate limits

Every plan, Free included

The limit is per plan and printed on the pricing page: 50 requests a second on Free and Starter, 100 on Growth, 200 on Business, 500 on Scale. An individual API key can be given a lower limit than its plan if you want a script boxed in. It is enforced in the API middleware, so it is the same number in production as on the page.

Scoped, expiring API keys

Every plan, Free included

Keys are scoped to the whole organisation, one team or one domain, can carry an expiry date, are stored hashed, and can be revoked without touching the others. Last-used time is recorded so you can find the key nobody remembers issuing.

Bulk import, bulk edit and a bulk sheet

Every plan, Free included

Import from CSV or a spreadsheet with a preview before anything is written, edit thousands of links as a sheet and apply the diff in one pass, and download the errors from a failed row as their own CSV so you fix and re-run only what broke.

Unlimited on the top self-serve tier

Scale — $140/mo and up

Links, domains, team members, tracked clicks, conversions, folders, storage and retention are all uncapped on Scale. Enterprise exists for contract terms and support, not to unlock a number.

Per-organisation overrides

By arrangement

Any single limit or feature can be granted to one organisation without moving it to another plan, with an optional expiry date for a pilot. This is how a bespoke arrangement is honoured in the product instead of in a spreadsheet.

Coverage

Your audience, around the world

See where people discover your links. Markers show recorded click activity by country, sized by volume.

India: 48 clicks recorded Germany: 12 clicks recorded Brazil: 12 clicks recorded

3 countries plotted · 72 clicks behind the markers.

What the graphic shows

  • Measured. Marker position and size come from recorded clicks. A country with no marker is one this installation has not seen a click from yet.
  • Measured. Visitors are resolved to country, region and city from a geolocation database that runs on our own servers and sends nothing to anyone.
  • Country outlines. Natural Earth geography provides the basemap. Markers represent visitor activity; they do not indicate server locations.

Latency — targets, not measurements

This platform runs from wherever it is deployed, in one place. There is no multi-region edge network, so the figures below are what we aim at from a single deployment. They have not been measured from the regions named, and we will not print them as though they had been.

Same region as the deploymentunder 50 ms target
Neighbouring continentunder 150 ms target
Furthest point from the deploymentunder 300 ms target

Measured availability of the redirect path is in the band at the top of this page, and the full record is on the status page.

Migration

Moving off your incumbent, without a dark weekend

The importer and the cut-over are product features, not a professional-services engagement. Bitly, Rebrandly, TinyURL, Cutt.ly and Short.io exports are recognised by their own column headings.

  1. 1

    Export from your incumbent

    Bitly, Rebrandly, TinyURL, Cutt.ly and Short.io exports are recognised by name, and any CSV with a destination and a slug column works. The importer maps the column headings each of those tools produces — a Bitly export's "Bitlink" column becomes the slug, tags split on commas, pipes or semicolons — so you upload the file you already have rather than reshaping it first.

  2. 2

    Preview before anything is written

    The preview pass parses the file, shows what each row would create and lists the rows it cannot read, before a single link exists. Errors from a real import come back as their own CSV, so you correct and re-run only the failures.

  3. 3

    Move DNS when you are ready

    Point the A record for your branded domain at the redirect IP the migration screen shows you. The certificate is issued automatically. Your old provider keeps serving until you are satisfied.

  4. 4

    Fallback resolution catches what you missed

    While the migration is switched on, a slug we do not know is looked up against your old domain, the visitor is redirected there, and the answer is cached. Nothing 404s during the cut-over, including links from a campaign nobody remembered to export.

  5. 5

    Turn fallback off when traffic to unknown slugs stops

    Usually about thirty days. At that point the old account can be closed. The importer, the migration screen and the fallback switch are all in the product — none of it needs us to run a script for you.

Bulk import, the bulk edit sheet and error CSVs are on every paid plan, from Starter. See what each plan carries.

Security and compliance

What the software does, and what the operator is responsible for

In the software

  • Passwords hashed with scrypt. A password is never stored or logged.
  • TOTP two-factor, WebAuthn passkeys and hardware keys; every session listed and individually revocable.
  • SAML 2.0 SSO per workspace, which a workspace can be required to use.
  • Roles enforced in the API layer, and per-link permissions that hold for an API key as well as a browser.
  • An audit log of who did what, with IP and timestamp, exportable as CSV — on every plan.
  • Third-party integration tokens encrypted at rest with a key derived from a server secret.
  • TLS everywhere; certificates for your domains issued and renewed automatically, or uploaded by you.
  • Visitor IP storage can be switched off per domain while still deriving country, region and city.
  • No third-party script on the redirect path or in the dashboard.
  • A public abuse report form on the main site, feeding a queue the operator works through and reviews within 24 hours.

The operator's responsibility

This platform is software that somebody runs. Several of the controls a reviewer cares about are set by whoever operates this installation, not shipped switched on, and it would be misleading to present them as ours:

  • Where it is hosted, and therefore where your data physically sits.
  • The retention policy for clicks, logs and closed tickets — the product enforces whatever is set, and can dry-run it first.
  • Whether backups run and are restored as a test, and where they are stored.
  • Which mail, payment and storage providers are connected — the sub-processor list should be edited to match.
  • Admin panel hardening: a secret path, an IP allowlist and forced two-factor for administrators are all available and all optional.

The security page, the data processing agreement, the sub-processor list and the service level are the documents your reviewer will want. They are public — you do not have to ask us for them under NDA.

Plainly

What we do not do

A sales page that lists only capabilities is a page you have to fact-check. These are the things a large buyer asks for that this product does not have. None of them is coming "soon" unless we tell you a date, and we will not.

SCIM user provisioning

There is no SCIM endpoint. Accounts are created just-in-time on first SSO sign-in, and de-provisioning is done by removing the member in the dashboard or through the API — an IdP that deactivates a user does not currently reach us on its own.

Assuming an IAM role inside your AWS account

The daily click export is built and runs — a gzipped NDJSON file per domain per day, written to disk and then uploaded with a signed S3 PUT. What it does not do is call STS and assume the role ARN you save. The upload is signed with the credentials your operator connected in the integrations hub, so writing to a bucket you own means granting that principal access through your bucket policy. The ARN field is kept because that is the identity most policies are written against, but nothing in this product assumes it yet.

BigQuery, Snowflake or Redshift connectors

Not built. The export routes and the click webhook are the supported ways into a warehouse today.

Data residency in a region you choose

The platform runs wherever the operator deploys it, in one place, on one database. There is no per-customer region selection and no multi-region replication. If your policy requires data to stay inside a specific jurisdiction, the honest answer is a dedicated installation in that jurisdiction, which is a conversation rather than a setting.

A SOC 2 or ISO 27001 report

We do not have one, and we will not imply otherwise. What exists is written down: the security page, the sub-processor list and the data processing agreement all describe what the software actually does and what the operator is responsible for.

FAQ

Frequently asked questions — common questions from enterprise buyers

20 of them, answered from the code rather than from a positioning document.

How is Enterprise priced, and why is there no price on this page?

Every self-serve tier has a public price, and Scale — the top one — is the ceiling of what you can buy with a card. Enterprise is not a bigger number on top of that; it is a contract. What it costs depends on committed volume, the term, the payment method and what support response you need, so it is quoted rather than listed. If you want a price today rather than a conversation, the pricing page has four of them.

Do we actually need an Enterprise agreement to get the features on this page?

Mostly no, and we would rather say so. Nearly everything described above ships on a self-serve plan: roles and teams from Growth, per-link permissions, multiple teams, custom certificates and priority support from Business, SSO and unlimited everything from Scale. The audit log, the API and automatic TLS are on every plan including Free; webhooks and exports start on Starter. An agreement buys contract terms, invoicing, a named response target and per-organisation limits — not a hidden feature set.

What contract length do you expect?

Annual is the normal term, and annual billing is a 17% saving on the published self-serve prices too. Monthly is possible on an agreement; it costs more per month for the same reason it does everywhere else. There is no multi-year lock-in requirement.

Can we pay by invoice, bank transfer or purchase order?

On an agreement, yes — that is arranged in the sales conversation. Be aware that the self-serve product has no PO workflow in it: card and UPI payments are taken by our payment provider and a numbered tax invoice is issued automatically for each one. Invoicing against a PO happens outside the checkout, not through it.

What is the uptime commitment, and what happens if you miss it?

The published service level is 99.9% monthly availability on the redirect path, with service credits of 10%, 25% or 50% of the monthly fee depending on how far below that a month falls, applied automatically to the next invoice. The dashboard and the API are best-effort and carry no credit — they are separate from the redirect path on purpose, so an incident in one cannot take the other down. Full terms are on the service level page.

Can we see your uptime history rather than your target?

Yes. The status page is computed from recorded self-checks and from nothing else, which is why it tells you how far back it has measured instead of asserting a figure it cannot support. The band at the top of this page shows the same measured number. If the installation is new, it will say so.

Who processes our data, and where does it go?

The sub-processor list names every third party and what each one sees: the hosting provider, the payment provider, the email provider and a local IP geolocation database that sends nothing back. None of them is an advertising network, and none receives data for its own purposes. We give 30 days' notice before adding one, so you have time to object.

Will you sign a DPA, and do you support the Standard Contractual Clauses?

There is a published data processing agreement that forms part of the terms: we act as your processor for click data, process only on your documented instructions, bind everyone with access to confidentiality, help with subject requests, notify you of a personal data breach within 72 hours of becoming aware, and delete or return data at the end. Transfers out of the EEA or UK rely on the Standard Contractual Clauses. We will also review your own paper.

Are you SOC 2 or ISO 27001 certified?

No. Nothing in this product has been through either audit, and we will not imply that it has. What we can give you is specific: the security page lists the technical measures, the sub-processor page lists who touches data, the DPA sets out the obligations, and the audit log lets you verify what happened in your own account rather than take our word for it.

Can we choose which country our data is stored in?

Not as a setting. The platform runs in one place, on one database, wherever it is deployed — there is no per-customer region selection and no multi-region replication. If a residency requirement is firm, the realistic answer is a dedicated installation in that jurisdiction, which is a conversation rather than a checkbox.

How much work is SSO to set up?

It is self-service and usually a single sitting. You enable SAML on the workspace, paste in your identity provider's entry point, entity ID and signing certificate, and copy the ACS URL the settings screen shows you into your provider. A person signing in for the first time is provisioned automatically. SSO is included from the Scale plan onwards, so you do not need to talk to us to switch it on.

Do you support SCIM for provisioning and de-provisioning?

No. There is no SCIM endpoint. Accounts are created just-in-time on first SSO sign-in; removing someone is done by removing the member in the dashboard or through the API, or by cutting them off at your identity provider so they can no longer authenticate. If SCIM is a hard requirement, it is not built and we will not pretend otherwise.

How does seat counting work?

A seat is a member of the organisation. Free is one, Starter two, Growth five, Business fifteen, and Scale is unlimited. Read-only members count as members. A single organisation can be given a higher seat count than its plan without moving plan, which is how a bespoke number is honoured.

What are the rate limits, and can they be raised?

The API limit is per plan — 50 requests a second on Free and Starter, 100 on Growth, 200 on Business, 500 on Scale — and it is enforced in the API middleware, not merely documented. An individual key can be given a lower ceiling than its plan. A higher ceiling than the plan is a per-organisation override, which is part of an agreement.

How hard is it to migrate off our current provider?

The importer recognises Bitly, Rebrandly, TinyURL, Cutt.ly and Short.io exports by their own column headings, previews every row before anything is written, and returns failed rows as a CSV you can fix and re-run. During the DNS cut-over, fallback resolution forwards any slug we do not know yet to your old domain and caches the answer, so nothing breaks while you switch. Every step of that is in the product.

Can we use our own SSL certificate on our domain?

Yes, from the Business plan. Certificates are normally issued and renewed automatically, apex domains included, but if your policy requires your own CA you can upload the certificate and key instead.

Can we run this ourselves, on our own infrastructure?

The software is a single Node process with a SQLite database and no third-party runtime dependencies, so it is genuinely deployable on your own machines — there is a Dockerfile and a deployment guide in the repository. Whether that is offered to you, and on what licence and support terms, is a conversation. It is not something you can buy from the pricing page.

What support do we get, and how do we escalate?

Every message becomes a tracked ticket with a reference, whether it comes from this page, the contact form or the dashboard, and it is answered by email against that reference. Priority support puts a ticket higher in the queue from the Business plan onwards. A named response target and an escalation path to a person are part of an agreement rather than a plan.

Can we influence what gets built?

You can put a request in front of the people who decide, and a large customer is heard sooner than a small one — that is honest rather than special. What we will not do is put a date on a feature in a sales conversation. If something on the roadmap section of this page is a condition of your purchase, say so now and we will tell you plainly whether it is being worked on.

What happens to our data if we leave?

You export it: the whole account as a JSON bundle, the links and click stream as CSV, the audit log as CSV, all from the product without asking us. Your branded domains are yours — you point the DNS somewhere else and the links keep working at whatever you point them at. After the agreement ends, the data is deleted or returned in line with the DPA.

Request a quote

Tell us what you are trying to do

This opens a tracked ticket with a reference, not an email into a void. If your requirement is something on the "what we do not do" list above, say so — we will tell you straight away rather than after two calls.

Estimated usage

Prefer to start without talking to anyone? Create a free account — the audit log, the API and automatic TLS are all on the free plan; exports and webhooks start on Starter.

Links, campaigns and support in one place

Choose the tools you need and see exactly which plan includes them. 72 available integrations, 45 guided workflows and 9 planned listings; planned listings are not working connectors.

Starter · $4/month

Google & Meta tracking

Google Ads Data Manager, GA4 Measurement Protocol and Meta Conversions API. Connect accounts and inspect delivery results.

Explore setup →
Starter · $4/month

More advertising platforms

Snapchat, TikTok, X, LinkedIn, Pinterest and Reddit event connectors. Provider permissions and configuration are required.

Explore setup →
Growth · $14/month

Email marketing drafts

Mailchimp, Brevo and supported email providers: select a list and create a campaign draft from a short link. Review and send in the provider.

Explore setup →
Starter · $4/month

Core apps & plugins

Zapier, Make, Slack, Segment and WordPress. Browser extensions, REST API and SDKs use the same workspace quotas.

Explore setup →
Starter · $4/month

Additional workflows

Other app connections and guided HTTP workflows with Make, Zapier or n8n. Follow the full illustrated setup guide.

Explore setup →
Starter · $4/month

Direct account imports

Import selected URLs from supported task, form, document and scheduling accounts. API creation allowances apply.

Explore setup →
Starter · $4/month

Multiple accounts

Connect multiple accounts for the same provider within the plan connection allowance; manage and disconnect each independently.

Explore setup →
Free · included

Android & developer tools

Use current dashboard features on Android; download WordPress, SDKs and CLI installation guides. Purchases and API limits remain server-enforced.

Explore setup →
Free · included

Ask with AI

Ask questions about current guides, API setup and plans; follow cited instructions and escalate account-specific problems to Support.

Explore setup →

USD monthly prices. Provider subscriptions may cost extra. API-created links consume the plan's automation allowance; website links and automation are separate. Compare full plans.