LinkSheild
    Platform Security & Compliance

    Security Architecture

    How LinkSheild safeguards creator profiles, monetized links, and follower data.

    1. Dual-Layer Bio Protection & Turnstile Gating

    Traditional link-in-bio services leave all destination URLs completely exposed to automated scrapers and web crawlers operated by TikTok, Meta, Instagram, and AI models. When scrapers detect sensitive subscription links or unmasked affiliate parameters, algorithmic reach is throttled and accounts are shadowbanned.

    Default SFW Bio Rendering

    Platform crawlers and initial visitors view a 100% compliant Safe-For-Work bio page populated with your clean links (portfolio, YouTube, stores).

    Turnstile-Gated Reveal

    Monetized and sensitive links are placed behind a "Reveal All Links" button gated by Cloudflare Turnstile. Bots cannot solve the challenge, while human followers verify in 1 second.

    2. Cryptography, Authentication & Tokens

    • Salted Bcrypt Password Hashing: Passwords are never stored in plaintext. We utilize bcrypt with high work factors to protect against rainbow table and brute force attacks.
    • HMAC-SHA256 Signed Tokens: Session and recovery tokens are signed using a server-side cryptographic secret. Signature verification utilizes timing-safe comparisons to prevent timing side-channel attacks.
    • Strict Expiration: Password reset tokens automatically expire in 1 hour; session tokens rotate every 7 days.

    3. Network Security & Data in Transit

    • Mandatory TLS 1.3 Encryption: All traffic between creators, visitors, and LinkSheild is encrypted in transit using TLS 1.3 with automated HTTP-to-HTTPS redirects and strict HSTS headers.
    • Security Headers: We enforce Content Security Policy (CSP), X-Frame-Options (DENY), X-Content-Type-Options (nosniff), and Referrer-Policy headers to prevent cross-site scripting (XSS) and clickjacking.
    • Edge Rate Limiting: In-memory and edge rate limiting protect all sensitive endpoints (login, register, forgot-password, link analytics) from brute-force and denial-of-service attempts.

    4. Payment Security & PCI-DSS Compliance

    LinkSheild outsources all cardholder data processing to Stripe, Inc., a certified PCI-DSS Level 1 Service Provider. We never receive, process, or store credit card numbers, CVVs, or cardholder banking credentials on our infrastructure. All checkout sessions and Tip Jar donations take place over Stripe Checkout and Stripe Connect.

    5. Independent Bot Audit & Link Simulation

    Creators can verify their links against automated crawlers at any time using our dedicated scanner:

    Bot's-Eye-View Link Safety Scanner

    Simulates the exact 40+ bots, crawlers, and spiders we protect against with a side-by-side bot view vs. human view comparison.

    6. Vulnerability Reporting & Disclosure

    We take security reports seriously and value the contributions of ethical security researchers. If you discover a potential vulnerability within LinkSheild, please report it responsibly to:

    Security Operations Center
    Email: [email protected]
    PGP Key available upon request

    We kindly ask that you provide reasonable time for remediation prior to public disclosure.

    © 2026 LinkSheild. All rights reserved.