Trust
Security controls for link infrastructure
Omni Links is built around workspace-scoped access, privacy-conscious analytics, auditable administration, and abuse controls for public redirects.
Authentication
Supabase Auth manages user sessions, protected dashboard routes, server-side session checks, and TOTP MFA enrollment.
Authorization
Workspace roles are enforced in server actions, route handlers, and Supabase Row Level Security policies.
Data protection
Raw IP addresses are not stored for analytics. Click events use hashed identifiers and configurable retention controls.
Developer security
API keys are stored as hashes, webhooks use signing secrets, and export files redact developer secrets.
Abuse prevention
Destination URLs block local/private hosts, public abuse reports are rate-limited, and admins can review reports.
Auditability
Security-sensitive workspace, team, billing, API, webhook, link, QR, bio page, UTM, abuse, and data-control changes are audited.
MFA enforcement
Workspace owners and admins can require AAL2 sessions before members access the dashboard.
SSO
The sign-in flow supports Supabase SSO domains, and workspace admins can register SAML provider IDs for tracking and exports.
Security review requests
Enterprise security reviews, vendor questionnaires, and DPA requests are handled through the compliance request workflow.
Request reviewReview SLA