Links for Financial Services
Recognisable domains, controlled access and an auditable record of every change.
In financial services a link is a trust signal. People have been trained to distrust unfamiliar short domains, and for good reason. Running links on a domain your customers already recognise, with access controls and a clear record of who changed what, turns a liability into infrastructure.
Your domain is the security feature
A generic shortener domain is indistinguishable from a phishing domain. A subdomain of your own registered domain is not. Connecting your domain with automatic SSL means every link you send is visibly yours before anyone clicks.
It also removes the third-party dependency in the URL itself. If the tooling changes later, the domain and the links on it remain yours to redirect.
- Custom domains and subdomains with automatic certificates
- Consistent domain across email, SMS, print and support
- A main-page redirect so the bare domain is never empty
- A custom 404 destination for mistyped or retired codes
Controlling who can reach a destination
Password protection, expiry by date or click count, and encrypted destinations cover the cases where a link is not meant to be public or not meant to be permanent. Referrer hiding prevents a destination from learning which internal system a visitor came from.
Every control has a defined fallback, so an expired or unmatched request lands on a page you chose rather than an error that invites a support call.
- Password gates styled to match your brand
- Expiry by date, click count or age, with a fallback
- Encrypted destinations decrypted in the browser
- Referrer hiding on outbound shares
Access, roles and single sign-on
Organisations split into teams, each with its own domains and folders. Roles run from owner and admin to standard user and read-only, and per-link permissions lock down the specific links that must not change — the one on a printed statement, or the one in an active campaign.
SAML 2.0 single sign-on works with the usual identity providers, so access follows your existing joiner and leaver process rather than a separate user list.
- SAML 2.0 SSO with standard identity providers
- Owner, admin, user and read-only roles
- Per-link permissions on high-risk links
- Separate teams for business lines or regions
Compliance and data handling
IP hiding and truncation keep full addresses out of the click log, retention is configurable so data ages out on your schedule, and a DPA is available. Everything exports, including the raw click stream, so evidence for a review does not depend on our reporting screens.
Because links are editable and expirable, a communication that has to be withdrawn can be redirected to a notice page immediately rather than remaining live until a page is taken down.
- IP hiding, configurable retention and a DPA
- Full export of aggregates and raw events
- Immediate redirect of withdrawn communications
- Stable link identifiers for records
Measuring campaigns without guesswork
UTM presets and folder defaults keep campaign tagging consistent across agencies and internal teams. Conversion tracking joins a click to an application or a completed action through a click identifier, so channels can be compared on outcomes rather than volume.
Automated traffic is separated from human traffic in every report, which matters for links distributed by email where scanners open messages before recipients do.
- Saved UTM presets and folder-level defaults
- Conversion tracking with an optional value
- Bot and human clicks counted separately
- Period-over-period comparison built in
Automation and integration
The REST API creates and updates links programmatically, which is how most regulated teams prefer to work: link creation as part of a reviewed process rather than an ad-hoc action. Webhooks stream click events into your own systems, signed so they can be verified and retried on failure.
Bulk creation, CSV import and Bitly migration cover consolidation when links are currently spread across several tools.
- REST API with tokens and rate limits
- Signed, retried webhooks per click
- CSV and XLSX import and export
- Bitly migration for existing short codes
Questions
Why not just use a generic short domain?
Because customers cannot tell it apart from a phishing domain. A subdomain of a domain they already know is the point of branded links in this sector.
Do you support single sign-on?
Yes, SAML 2.0 with the common identity providers, so access follows your existing joiner and leaver process.
Can we prevent a specific link from being edited?
Yes. Per-link permissions restrict who can change a link, which is how teams protect codes that are already printed or in active distribution.
Can we avoid storing IP addresses?
Yes. IP hiding or truncation can be enabled, and aggregate reporting continues to work without full addresses.
How quickly can a live link be withdrawn?
Immediately. Change the destination or expire the link and new requests follow the new rule; there is no cache to wait out.
Send links from a domain your customers already trust.
Start Free — no credit card
The free plan includes 1,000 links, 5 custom domains and 50,000 tracked clicks a month, free forever. Paid plans start at $4 a month when you outgrow it, and you keep everything you have built.

