Acceptable Use Policy & Anti-Abuse Standards
Last Updated: September 11, 2026
This Acceptable Use Policy ("AUP") defines the rules, restrictions, and operational boundaries governing the use of links.ceo ("we," "our," "us," or the
"Service"). This policy applies to all registered account holders, client applications (web, desktop, and Flutter WebAssembly implementations), custom
branded domains, and all shortlinks routed through our serverless redirection infrastructure. By registering an account, generating shortlinks or dynamic
QR codes, or routing traffic through our edge network, you agree to comply with this policy. Violations will result in immediate corrective action,
including link disabling, domain delisting, account termination, and potential reporting to public threat repositories and law enforcement.
1. Automated Real-Time Threat Screening
links.ceo operates a zero-tolerance policy against cyber threats, fraudulent campaigns, and abusive traffic routing. To ensure platform-wide safety,
preserve our global edge IP reputation, and prevent domain blacklisting:
-
Pre-Creation Verification: Every destination URL submitted through our dashboard or API is subjected to automated, real-time threat
screening before shortlink generation or custom slug binding is authorized.
-
Integrated Threat Engines: Destination endpoints are checked against enterprise threat intelligence systems, including Google Cloud Web
Risk API and abuse.ch URLhaus, alongside our internal heuristic security rules.
-
Continuous and Post-Creation Auditing: We periodically re-evaluate existing, active shortlinks. If a previously safe destination URL is
compromised, altered, or flagged by our security providers post-creation, the corresponding shortlink is disabled immediately at the edge.
2. Strictly Prohibited Link Destinations
Shortlinks, dynamic QR codes, or custom domain mappings that point to, redirect toward, or facilitate the following categories of content are strictly
prohibited:
-
Malware and Hostile Payloads: Websites hosting, distributing, executing, or propagating malicious executables, viruses, trojans, worms,
spyware, ransomware, keyloggers, rootkits, cryptojackers, or malicious browser extensions.
-
Phishing and Credential Harvesting: Deceptive pages designed to mimic legitimate services, financial institutions, cryptocurrency
platforms, e-commerce storefronts, or authentication portals to steal passwords, session tokens, personal identity details, or credit card numbers.
-
Botnet Infrastructure: URLs associated with command-and-control (C2) servers, automated exploit kits, distributed brute-force nodes, or
compromised server assets listed in databases such as URLhaus.
-
Deceptive Social Engineering: Sites utilizing fake system update prompts, scareware warnings, fraudulent lottery/prize notifications,
unauthorized device locking scripts, or forced browser push-notification permission traps.
-
Child Sexual Abuse Material (CSAM): Any link directly hosting, linking to, or facilitating the dissemination of CSAM or child sexual
exploitation and abuse. Such violations result in instantaneous account destruction, permanent IP blacklisting, and mandatory reporting to the National
Center for Missing & Exploited Children (NCMEC) and relevant legal authorities.
-
Terrorism and Violent Extremism: Content that promotes, incites, plans, or glorifies acts of terrorism, violent extremist ideologies,
illegal firearms trafficking, or organized criminal activity.
-
Illegal Drugs and Contraband: Marketplaces or landing pages facilitating the sale of illicit narcotics, prescription drugs without
verification, counterfeit pharmaceuticals, or contraband goods.
-
Intellectual Property Theft and Piracy: Links directly distributing pirated media, unauthorized software cracks, torrent indexers, or
counterfeit merchandise violating copyright or trademark laws.
3. Spam, Messaging, and Platform Abuse
The Service must not be used to conduct, amplify, or disguise abusive outbound communication campaigns. Prohibited practices include:
-
Unsolicited Bulk Communications (Spam): Deploying shortlinks within unsolicited bulk emails (CAN-SPAM / CASL / GDPR violations), mass
cold SMS campaigns, unsolicited direct messages on social networks, or automated messaging bots.
-
Automated Web Spam: Placing shortlinks within automated blog comment spam, forum spam, guestbook spam, wiki defacement, or link farms
designed solely to manipulate search engine rankings.
-
Evasion and Layered Nesting: Creating multi-tiered redirect chains, URL loops, or nesting links.ceo shortlinks inside other shortening
or cloaking services to deliberately obfuscate a malicious or banned destination from our automated screening mechanisms.
-
Slugs Imputing Impersonation: Registering custom slugs, UTF-16 Unicode sequences, or emoji combinations designed to deceive users by
impersonating registered trademarks, financial entities, or government agencies.
4. Platform Infrastructure Integrity
You agree not to engage in activities that degrade, compromise, or overload our platform infrastructure:
-
DDoS and Flood Attacks: Generating synthetic, coordinated, or malicious traffic floods designed to degrade edge routing, disrupt
serverless function cold starts, or exhaust database connections.
-
API Abuse: Attempting to bypass subscription link thresholds, run unauthorized automated scraping bots against client dashboards, or
submit rapid programmatic URL creations outside established rate limits.
-
Reverse Engineering: Decompiling, reverse engineering, or extracting source code from our Flutter WebAssembly binaries or desktop
application runtimes.
5. Enforcement and Account Suspension
We enforce this Acceptable Use Policy through automated scanning systems, real-time edge monitoring, and human review:
-
Immediate Link Disabling: If a destination link fails a Google Web Risk scan, triggers a URLhaus detection, or violates this policy,
the shortlink is terminated at the DNS/edge routing layer. Requests will return an error or security warning page.
-
Account Revocation: We reserve the right to suspend or permanently delete the associated links.ceo account without prior notice.
Accounts terminated due to AUP violations are ineligible for subscription refunds.
- Database Purging: Abusive links and mapped domains will be wiped from active routing records.
-
Legal and Regulatory Disclosure: In cases involving malware deployment, phishing operations, or illegal activities, we cooperate with
hosting providers, threat intelligence partners, domain registrars, and law enforcement agencies.
6. Reporting Abuse
We actively investigate abuse reports submitted by security researchers, network administrators, ad platforms, and the public. To report a links.ceo
shortlink that violates this policy: contact@links.ceo