Security & Trust
Останнє оновлення: September 2026
LinkPreview lets anyone create a link with a custom preview card - that's a real surface for abuse if it isn't actively defended. Here's what actually runs on every link created through the service, and every visitor who clicks one.
Content moderation
Every link is scored by an automated content filter before it goes live - domain reputation, title and description text, and known spam/malware/phishing patterns. Links that fail are rejected outright; the destination itself is never fetched or rendered for a blocked submission. Prohibited categories:
- Adult and sexually explicit content
- Malware distribution and phishing/credential-theft domains
- Spam and bulk/automated link generation
- Illegal content and copyright-infringing material
If a link is later found to violate this policy, it's pulled and visitors are redirected to a plain notice explaining why, instead of the original destination.
Abuse and bot protection
- reCAPTCHA v3 verification on link creation and account sign-up
- IP-based rate limiting on anonymous (guest) link creation
- Server-Side Request Forgery (SSRF) protection - links can't target internal networks, localhost, or cloud metadata endpoints
- Bot traffic is filtered out of click analytics rather than counted as real visits
Infrastructure
- HTTPS everywhere, HSTS enforced
- Content-Security-Policy, X-Frame-Options, X-Content-Type-Options and a strict Referrer-Policy on every response
- The application runs as a non-root user in its container
- Dependencies are kept current against known CVEs
Reporting a problem
Found a link that shouldn't be here, or a security issue in the service itself? Email office@jspace.pl - reports are read by a human, not routed into a ticket queue.
This page describes current practice, not a compliance certification. See our Privacy Policy and Terms of Service for the legal terms these protections operate under.