For enterprise
Link infrastructure with terms, isolation and an audit trail
Large organisations do not buy a link shortener, they buy the guarantees around it: contractual availability, a data processing agreement, controlled retention, isolation from other tenants and a record of who changed what. All of it runs on domains you own.
Contract terms rather than a self-serve checkbox
Enterprise agreements are negotiated: a service level agreement covering redirect availability, a data processing agreement with a current list of sub-processors, a security review before signature, and a platform fee negotiated from five per cent rather than taken from a published grid. Domains, workspaces and tracked clicks are uncapped.
Single sign-on is on the roadmap after launch, and it is listed that way rather than implied. If identity federation is a hard requirement for your rollout, it should be part of the conversation and the timeline before anything is signed — a vendor that answers that question vaguely will answer the harder ones the same way.
- Service level agreement on redirect availability
- Data processing agreement and published sub-processor list
- Negotiated platform fee from five per cent
- Unlimited domains, workspaces, links and tracked clicks
- Analytics retention up to twenty-four months
- Single sign-on after launch, stated as a roadmap item
Dedicated ingress and predictable routing
From the Scale plan upward you get a dedicated ingress IP for your domains, which matters in three concrete ways: apex domains work at registrars that cannot flatten a CNAME, corporate networks and partners can allow-list a stable address, and your traffic is not sharing an entry point with unrelated tenants.
Every domain is provisioned with ownership verification, and one hostname belongs to exactly one tenant globally, so nobody else can claim a hostname that resolves to your brand. Certificate renewal is delegated at connection time and then runs unattended, which removes the classic expiry incident from your calendar. Domain lifecycle changes are emitted as webhooks, so they can be routed into your own monitoring instead of discovered by a customer.
Redirects are answered at the edge from a cache rather than a database, with negative caching and rate limiting on the miss path, and the redirect path is deliberately kept independent of the dashboard: a control-plane outage does not stop links from resolving.
Data handling stated precisely
Click events store no IP addresses. Unique visitors are derived from a hash with a salt that rotates daily, which cannot be reversed into an address or used to follow a person across weeks, and the metric is labelled as unique visitors per day rather than dressed up as identity resolution. The redirector sets no tracking cookie; the only cookie it issues is the short-lived one that unlocks a password-protected link.
Detailed events are retained for the window your contract sets, up to twenty-four months, and are deleted automatically after it. Daily rollups per link are kept permanently, so lifetime counts survive the deletion of the underlying events. Reports are unsampled: every non-bot click is a stored event, and bot traffic is excluded from reports by default but never silently discarded.
Tenant isolation is enforced in the data layer, with every tenant-scoped query filtered by workspace and partner and a dedicated test suite covering it, rather than being a property of careful interface design.
Governance across business units
Structure follows the organisation: a workspace per brand, region, product line or agency, each with its own domains, links, analytics and members. Four roles — owner, admin, member and viewer — cover the difference between the team that publishes links, the stakeholders who only read results, and the person who controls the plan. API keys are scoped per workspace with explicit permission lists, can carry an expiry, and are revocable instantly, with last-used timestamps to find integrations nobody remembers.
Every meaningful change writes an audit entry — destination edits, member and role changes, domain connections, key revocations — readable in the dashboard and available through the API for export into your own log platform. Combined with signed webhooks for domain and subscription events, that is enough for a security review to answer its own questions instead of filing tickets.
Frequently asked questions
Do you offer single sign-on?
Not yet. It is planned after launch and is listed as an Enterprise commitment rather than a current feature. Until it ships, access is controlled with per-workspace roles, scoped API keys and the audit log, and we will give you a timeline rather than a maybe.
Can we run the platform under our own brand internally?
Yes. Enterprise includes the same white-label surface as every partner plan: your dashboard domain, your branding, your email sender, and the branded pages the edge renders for expired, protected and unknown links. Nothing carries our name.
How is data separated from other customers?
Every tenant-scoped query carries a workspace and partner filter enforced in the data layer, and analytics queries require the tenant identifier as a parameter rather than adding it as an afterthought. A dedicated ingress IP adds network-level separation at the entry point for your domains.
Launch your branded link shortener
Connect a domain, publish your prices and invite your first customer — most partners go live in an evening.
No card required for the trial.