Platform

Built on AWS. Engineered for the redirect tier.

Providing an enterprise-grade redirect surface has always been the goal. This page lists the platform components, capacity targets, and operational commitments customers have told us they need to evaluate URL shortener vendors.

100/sec
API burst — Business plan
300/sec
API burst — Scale plan
1,000/sec
API burst — Enterprise plan
99.99%
Monthly uptime SLA

Core stack

  • AWS multi-AZ deployment
  • AWS API Gateway in front of the public API
  • Server-less compute on the redirect tier
  • Open Graph and meta-tag injection at redirect time
  • Click capture pipeline writes to durable storage
  • Free, auto-renewed SSL via the platform CA

Operational posture

Shorten.REST is operated by Api Lads Inc., a small focused team. The marketing site is a static Astro build; the dashboard, API, and redirect tier are independently deployed.

The redirect tier and management API both run on AWS multi-AZ. Billing is processed via Chargebee with Stripe as the payment processor — payment instruments never touch our servers.

We have not yet pursued a third-party SOC 2 or ISO 27001 audit. Our intent is to pursue formal attestation as the customer base scales; in the meantime our infrastructure choices already align with the controls those programs require.

What we do not store

Privacy by architecture, not by promise.

The redirect tier captures technical click metadata only. The platform is designed not to require end-user PII to operate.

End-user PII

The redirect tier does not require user identifiers to operate. Click events captured are technical (referrer, user-agent, country) — not personal.

Payment data

Card details are tokenized by Stripe via Chargebee. We never see, store, or transmit raw card numbers or CVCs.

Customer destinations

Destinations and aliases you create remain editable for the lifetime of your account. You can repoint or delete a link at any time.

Procurement

Need detailed answers for your security review?

Send us your vendor questionnaire. We answer infrastructure, privacy and operational questions directly — no NDA dance required for the standard ones.

Contact us Read the SLA