FAQ & quick answers
Answers from the published documentation — never guessed. Stuck? Ask the bot, bottom-right.
Frequently asked
What is Linktary?
Linktary is a signed-link shortener: every destination is checked before the link works — the full redirect chain is followed, host and content signals are scored, threat intel is corroborated — and the verdict with its evidence is published on a public trust report anyone can read. Safe links open instantly, risky ones warn first, dangerous ones never load.
What does a SAFE verdict mean?
SAFE means no issues were found during verification — it is not a guarantee the destination is benign. Every Linktary link is checked at creation (redirect chain, host signals, content signals, threat-intel corroboration) and the verdict, the evidence, and the check timestamp are published on the link's trust report. A verdict describes the destination as it was at check time, never as it is now.
How does verification work?
Three steps, on every link, before the first click: (1) the full redirect chain is followed — at most 5 hops, with an SSRF guard screening every target so our engine can never be turned into a probe for someone's internal network; (2) each hop is scored against a public signal taxonomy (chain, host, content, and domain-age signals) plus threat-intel corroboration; (3) the score becomes a verdict — SAFE (below 40), CAUTION (40–99), BLOCKED (100+) — published with all the evidence on the trust report. If the engine itself can't check a destination, the verdict is CAUTION, never a silent pass.
A Linktary link turned out to be malicious — what is the remedy?
Report it at /report-abuse (or email hello@linktary.com). Our incident path is: re-verify the destination immediately, block the host or revoke the link when the report checks out, and notify the reporter of the outcome. Abuse reports are reviewed within 24 hours. The full written remedy — including the commercial terms — is in the terms of service.
How do I take down one of my links immediately?
From your dashboard, or directly: POST /api/links/<code>/revoke while signed in. Revoke is instant and idempotent — the link stops resolving immediately (410), the trust report shows it as revoked, and its certificate is revoked with it. You can only revoke your own links; blocking a host for everyone stays with the Linktary team via /report-abuse.
How do I force a fresh check on a link?
Anyone can ask for a fresh verification: POST /v/<code>/recheck (the "Re-check this link now" button on caution pages does exactly this). An explicit recheck always runs a fresh verification — never a cached "still valid". It is rate-limited (10/hour per visitor) with a 5-minute per-link cooldown so one link can't burn fetch quota.
How do I report a suspicious link?
At /report-abuse — no account needed. You get a reference ID (r_…) to quote if you follow up. Reports are reviewed within 24 hours; confirmed malicious destinations are blocked and the offending links revoked. Reporting a link never reveals whether the code exists — every well-formed report is accepted.
How do I sign in? I forgot my password.
There are no passwords to forget. Enter your email on the sign-in page and we email you a single-use magic link (valid 15 minutes). Click it and you're in — the session lasts 30 days.
What does Linktary cost?
The full product is free: destination verification, public trust reports, and the dashboard — up to 60 links an hour, no credit card. The enterprise tier (SSO, audit logs, customer-held encryption keys, SLA, DPA) is planned; join the waitlist on the homepage if you need the paperwork to match the posture.
What happens when I delete a link?
It goes offline immediately (410 Gone) and is purged from active queries. The row is hard-deleted — encrypted destination, chain, signals, everything — 90 days after deletion. See the retention table on the security page.
How do I close my account?
Email hello@linktary.com and ask to close your account. Closing deletes your account email; your links go with the retention rules on the security page (offline immediately, hard-deleted after 90 days).
Do you track who clicks my links?
No. No visitor IPs, no user agents, no referrers, no per-visitor anything — click counts are aggregate numbers, and we cannot tell you who clicked your link because we never recorded it. The narrow exception is abuse prevention: IP addresses are processed transiently for rate-limiting and kept only as salted, non-reversible hashes inside short-lived counters. See /privacy.
How do I get Linktary allowlisted on my corporate network?
Send your IT team the one-pager at /allowlist: the single domain to allow, why it's safe, and a copy-paste justification for the ticket system. The pre-answered security questionnaire is linked from there.
What is the signed certificate on my link?
An Ed25519-signed document binding the verdict, score, destination hash, signal hashes, check time, and validity window to your short code. Anyone can verify it offline: the public keys are published at /.well-known/linktary-keys.json. Certificates expire (30 days) — an expired certificate means the verdict is stale, and the link stops redirecting silently until it's re-verified.
Can I check a link without an account?
Yes — /check runs the same verification engine on any URL, free, no account. Results are ephemeral: nothing is stored, and result pages are never indexed.
What if the bot can't answer my question?
Then it says so — it never guesses. Email hello@linktary.com and a human replies. Anything the bot answers comes verbatim from the FAQ or the quick-do guides below, with the source cited.
Quick-do guides
Create a verified link
- Go to /app and sign in with your email — we send a magic link, no password.
- Paste the destination URL and click Create.
- Verification runs before the link goes live: the chain is followed, scored, and verdicted.
- Copy your short link. Its public trust report lives at
linktary.com/v/<code>— no account needed to read it.
Read a trust report
- Open
linktary.com/v/<code>— no account, no permission needed. - Read the verdict badge: SAFE, CAUTION, or BLOCKED.
- Walk the redirect chain hop by hop — every hop shows its status code.
- Read the signals: each one is explained in plain language, with its weight.
- Check the timestamp. A verdict describes the destination as it was at check time.
Force a fresh check on a link
- Open the link's trust report.
- Click “Re-check this link now” — or
POST /v/<code>/recheckdirectly. - An explicit recheck always runs a fresh verification, never a cached result.
- Rate limit: 10 rechecks per hour per visitor.
Report a suspicious link
- Go to /report-abuse — no account needed.
- Enter the short-link code (the part after linktary.com/).
- Describe what looks wrong.
- Save the reference ID (r_…) for follow-ups. Reports are reviewed within 24 hours.
Allowlist Linktary on a corporate network
- Send your IT team the one-pager at /allowlist.
- They allowlist exactly one domain:
linktary.com. - That's it — short links, trust reports, and the docs all live on that domain.
Delete one of your links
- In your dashboard, find the link and click Delete — or
DELETE /api/links/<code>while signed in. - The link goes offline immediately (410 Gone).
- The row is hard-deleted — encrypted destination, chain, signals, everything — 90 days after deletion.
Close your account
- Email hello@linktary.com and ask to close your account.
- Your account email is deleted on closure.
- Your links follow the retention rules: offline immediately, hard-deleted after 90 days.
The bot answers only from the FAQ and guides on this page. It can't answer anything else — by design. When it doesn't know, it says so and points you to a human.