Security
Last updated September 11, 2026
Client-side processing reduces what there is to secure
The single biggest security property of this site is that most tools never receive your file in the first place — it's processed in your own browser and never transmitted anywhere. There's no server-side copy of your document, image, or PDF to secure, back up, or accidentally leak, because it was never sent to us.
Account data and authentication
Accounts are handled by Supabase Auth — we don't write our own password storage or session logic. Passwords are never stored in plain text or visible to us. All traffic to and from this site is served over HTTPS.
Row Level Security on every table
Every database table that stores user data — short links, link-in-bio pages, saved email templates, favourites, recently-used tools — has row-level security enabled, with policies that restrict reads and writes to the row's own owner. This is enforced by the database itself: even if application code had a bug, the database would still refuse a request for someone else's data. The handful of intentionally public reads (resolving a short link, viewing a public link-in-bio page) are scoped narrowly at the database's column-privilege level, not just in application code, to exactly the fields needed for that purpose — an internal account id, for example, is never among them, even to a request made directly against the database API rather than through the site.
URL and redirect safety
Anywhere this site stores a URL you provide — a short link's destination, a link-in-bio button — it's validated against an allow-list of the http and https schemes only, both when you create it and independently at the database level, so a javascript:, data:, or other script-bearing scheme can never be saved, redirected to, or rendered as a clickable link, regardless of how the request reaches the database.
Connected AI assistants
If you connect an AI assistant to your account (see the Privacy page), it authenticates the same way signing into the site does — OAuth through Supabase Auth — and every action it takes is subject to the exact same row-level security policies as the website itself. It cannot read or act on anyone else's data, and it cannot do anything your account itself isn't authorized to do.
Abuse and rate-limit protection
The anonymous usage check (see the Privacy page) is itself rate-limited — a maximum number of requests per IP per minute — to prevent it from being hammered or used to enumerate data. Once an anonymous visitor's daily free-action limit is reached, continuing requires passing a bot challenge (Cloudflare Turnstile) rather than simply being blocked outright, so real people aren't locked out by an overly blunt limit.
Dependencies
Tools that do real processing use well-established, widely-used open-source libraries (pdf-lib, pdf.js, and similar) rather than custom-written file-format parsing, to avoid reinventing security-sensitive code where a mature library already exists.
Reporting a security issue
If you believe you've found a security vulnerability, please email hello@ziptest.app directly rather than filing a public issue, so we have a chance to address it before it's disclosed publicly.
Questions about this page? hello@ziptest.app. See also: Privacy, Security, and Terms.