No open redirects
Fallback destinations must match app-owned allowlists. Cloud activation also requires exact hostname ownership verification; revocation removes the web fallback without disabling an otherwise active native link.
Deep links sit on a public trust boundary. LinksetGo keeps private configuration authenticated, exposes narrow public projections and refuses arbitrary redirect targets.
Fallback destinations must match app-owned allowlists. Cloud activation also requires exact hostname ownership verification; revocation removes the web fallback without disabling an otherwise active native link.
Apple and Android association files expose only public app identifiers. Signing keys, keystores, passwords and store credentials do not belong in LinksetGo.
Report suspected vulnerabilities privately through the repository security policy. Do not include customer secrets or production personal data.
Start with the self-hosting guide or inspect the plan and domain model.