Overview
This article answers frequently asked questions about account and platform security when using SPRL. It covers account protection, passwords, two-factor authentication, login sessions, phishing, API security, domain security, privacy, and reporting security issues.
Following these security practices can help protect your SPRL account, integrations, branded domains, and business information from unauthorized access and misuse.
Good to Know:
Use a strong and unique password, enable two-factor authentication where available, review login sessions regularly, protect API credentials, and report suspicious activity promptly.
Account Security
How can I protect my SPRL account?
Use a strong and unique password, enable two-factor authentication where available, keep your credentials confidential, and regularly review your account security and login sessions.
Should I share my SPRL password with another person?
No. Your password should remain confidential. Avoid sharing account credentials with other users or employees.
What should I do if I believe someone accessed my account?
Change your password immediately, review your active login sessions, sign out of unfamiliar sessions where possible, review your security settings, and contact SPRL Support if you suspect unauthorized access.
Should I use the same password for SPRL and other services?
No. Your SPRL password should be unique and should not be reused on other websites or services.
Two-Factor Authentication
What is two-factor authentication?
Two-factor authentication (2FA) adds an additional verification step to your account login process. It provides an additional layer of protection beyond your password.
Should I enable 2FA?
Yes. Enabling two-factor authentication where available is recommended, particularly for accounts with administrative responsibilities or access to important business resources.
Can I share my authentication code?
No. Authentication codes should always remain confidential. Never provide an authentication code to another person or enter it into a suspicious website.
What should I do if I receive an unexpected authentication request?
Do not approve the request or provide any authentication information. Review your account security and contact SPRL Support if you suspect unauthorized access.
Login Sessions
What is a login session?
A login session is authenticated access established after you sign in to your SPRL account from a browser, device, or supported application.
Why should I review my login sessions?
Reviewing active sessions can help you identify old, unused, or unfamiliar access to your account.
What should I do if I see an unfamiliar session?
If you cannot identify the session, secure your account, review your credentials and security settings, and sign out of the session where possible. Contact SPRL Support if you suspect unauthorized access.
What should I do if my device is lost?
Secure your account as soon as possible, review your active sessions, sign out of the affected session where possible, and change your password if you believe your credentials may have been exposed.
Password Security
What makes a strong password?
A strong password should be long, unique, difficult to guess, and free from predictable personal information or commonly used patterns.
Should I use a password manager?
A reputable password manager can help generate, store, and manage unique passwords for different services.
When should I change my password?
Change your password when you believe it has been exposed or compromised, when you have entered it into a suspicious website, or when there is another reason to believe your credentials may no longer be secure.
Should I send my password to SPRL Support?
No. Never send your password or authentication codes through support requests, email, chat, screenshots, or other communication channels.
Phishing & Suspicious Activity
What is phishing?
Phishing is an attempt to deceive users into revealing sensitive information, visiting malicious websites, downloading harmful content, or performing an action that benefits an attacker.
How can I recognize a phishing attempt?
Be cautious of unexpected messages, urgent requests, suspicious website addresses, requests for passwords or authentication codes, unexpected attachments, and unusual payment or account-verification requests.
Does HTTPS mean a website is safe?
No. HTTPS encrypts communication between your browser and the website, but it does not guarantee that the website itself is legitimate or trustworthy. Always verify the domain and context.
What should I do if I clicked a suspicious link?
Close the page and avoid entering additional information. If you entered your SPRL credentials, change your password immediately and review your active login sessions.
What should I do if I submitted my password to a phishing website?
Change your SPRL password immediately, use a new unique password, review active login sessions, and check your account for unusual activity.
API Security
How should I protect my SPRL API credentials?
Treat API keys and other authentication credentials as confidential information. Store them securely and restrict access to authorized applications and users.
Can I put my API key in frontend JavaScript?
Private API credentials should not be exposed in browser-side code because users may be able to inspect the application and retrieve the credential.
Can I commit my API key to a public repository?
No. Never commit private API credentials to public repositories. If a credential has been exposed, treat it as compromised and replace or deactivate it where applicable.
Should API credentials be stored in application logs?
No. Passwords, API keys, access tokens, and authorization headers should not be stored in application logs.
What should I do if an API credential is exposed?
Secure or replace the affected credential where applicable, review API activity, investigate unexpected requests, and contact SPRL Support if assistance is required.
Domain & SSL Security
Does SPRL provide SSL for custom domains?
Yes. SSL activation is part of the custom domain setup process after successful domain verification.
Do I need to install an SSL certificate manually?
No. Manual certificate installation is not normally required for SPRL-managed custom domain SSL activation.
Why is my custom domain still pending?
DNS changes may still be propagating, or SPRL may not yet be able to detect the required DNS configuration.
Does HTTPS make my destination URL safe?
No. HTTPS secures the connection to the branded domain but does not guarantee that the destination website is safe or legitimate.
Can I use a subdomain for branded links?
Yes. Dedicated subdomains such as go.example.com or links.example.com can be used for branded links.
Data Privacy
What is personal information?
Personal information generally refers to information that can identify, relate to, describe, or reasonably be associated with an individual.
What information can be processed through SPRL?
The information processed through SPRL depends on how the platform is used. It may include account information, contact information, campaign data, form submissions, link-related information, and other information provided through supported services.
Should I collect all available customer information?
No. Collect only information that is necessary for your intended business purpose and follow applicable privacy and data protection requirements.
Can I put personal information in a short URL?
It is strongly recommended to avoid placing unnecessary personal or confidential information in URLs. URLs may appear in browser history, analytics, logs, referrer information, screenshots, emails, and other systems.
Who is responsible for the personal information I upload?
Customers are responsible for ensuring that their collection and processing of personal information complies with applicable privacy and data protection requirements.
Reporting Security Issues
Where can I report an abusive SPRL link?
You can report suspicious or abusive SPRL links through the SPRL Report Abuse page.
What should I report?
You can report phishing, fraudulent content, malicious activity, spam, suspicious SPRL links, potential security vulnerabilities, or other activity that may violate SPRL policies.
What information should I include in a report?
Include the affected URL, a clear description of the issue, relevant evidence, steps to reproduce a technical issue where applicable, and information about the potential impact.
Can I include an API key or password in my report?
No. Never include passwords, API keys, access tokens, authentication codes, or other confidential credentials in a security or abuse report.
Security Incident Response
What should I do if I believe my account has been compromised?
Secure the account immediately by changing your password, reviewing active login sessions, checking two-factor authentication settings, and investigating unusual activity.
What if an API credential has been compromised?
Secure or replace the affected credential where applicable and review recent API activity for unexpected requests or changes.
What if my domain or DNS account has been compromised?
Secure your domain or DNS provider account immediately, review recent DNS changes, enable available security controls such as two-factor authentication, and verify that your SPRL DNS configuration remains correct.
Security Best Practices
| Security Area | Recommended Practice |
|---|
| Password | Use a strong and unique password. |
| 2FA | Enable two-factor authentication where available. |
| Sessions | Review active login sessions periodically. |
| Phishing | Verify suspicious messages and website addresses before taking action. |
| API | Keep API credentials private and securely stored. |
| SSL | Use HTTPS for branded links. |
| Privacy | Collect and process only necessary personal information. |
| Reporting | Report suspicious or abusive activity promptly. |
Quick Security Checklist
| Security Practice | Status |
|---|
| Strong and unique password configured | Recommended |
| Two-factor authentication enabled where available | Recommended |
| Login sessions reviewed periodically | Recommended |
| API credentials protected | Required if using API |
| Branded domains configured with HTTPS | Recommended |
| Personal information collected appropriately | Required if applicable |
| Suspicious activity reported | Required if applicable |
Learn More:
Explore the SPRL Help Center for detailed guides on Security Overview, Two-Factor Authentication, Managing Login Sessions, Password Security Best Practices, Recognizing Phishing Attempts, Data Privacy & User Information, API Security, Domain & SSL Security, Reporting Security Issues, and other security resources.
Tip: Security works best as a combination of good practices. Protect your credentials, use additional authentication controls, review access regularly, keep integrations secure, and report suspicious activity when you encounter it.