Overview
Security is an important part of protecting your SPRL account, links, domains, integrations, and information. Following basic security practices can help reduce the risk of unauthorized access, credential theft, phishing, data exposure, and other security-related incidents.
SPRL applies security-focused practices across its platform and infrastructure, while customers are responsible for protecting their account credentials, user access, API credentials, and the information they manage through the platform.
Good to Know:
Most account security issues can be reduced by using strong passwords, enabling two-factor authentication where available, reviewing active login sessions, protecting API credentials, and staying alert to suspicious links or messages.
Protecting Your SPRL Account
Your SPRL account provides access to platform features and resources associated with your organization. Protecting your account credentials is therefore an important part of maintaining security.
- Use a strong and unique password.
- Do not share your password with other users.
- Enable two-factor authentication where available.
- Review active login sessions periodically.
- Sign out of devices that you no longer use.
- Do not enter your credentials on suspicious websites.
- Contact SPRL if you suspect unauthorized account activity.
Two-Factor Authentication
Two-factor authentication adds an additional layer of protection to your account by requiring an additional verification step when signing in.
When available for your SPRL account, enabling two-factor authentication can help protect your account even if your password is compromised.
Recommended:
Enable two-factor authentication for accounts that have administrative responsibilities or access to important organization resources.
Password Security
A strong password is one of the basic controls for protecting your account.
- Use a long and unique password.
- Do not reuse your SPRL password on other websites.
- Avoid easily guessed information such as names, birthdays, or common words.
- Never share your password through email, chat, or support requests.
- Change your password if you believe it may have been exposed.
For additional guidance, see Password Security Best Practices in the SPRL Help Center.
Managing Login Sessions
Reviewing active login sessions can help you identify devices or sessions that you do not recognize.
- Review your active sessions periodically.
- Sign out of devices you no longer use.
- Investigate unfamiliar login activity.
- Secure your account immediately if you suspect unauthorized access.
Security Reminder:
If you notice an unfamiliar session or suspect that someone else has accessed your account, secure your account and contact SPRL Support if assistance is required.
Recognizing Phishing Attempts
Phishing attacks attempt to trick users into revealing passwords, authentication codes, payment information, API credentials, or other sensitive information.
Be cautious when receiving unexpected messages that ask you to sign in, verify your account, make a payment, download a file, or provide confidential information.
| Warning Sign | What to Do |
|---|
| Unexpected Message | Verify the sender before clicking links or responding. |
| Suspicious URL | Check the destination carefully before entering credentials. |
| Urgent Request | Do not allow pressure or urgency to bypass normal security checks. |
| Credential Request | Never provide passwords, API keys, or authentication codes through an unsolicited request. |
Data Privacy & User Information
Protecting user and customer information requires both platform safeguards and responsible handling by customers.
Customers should only collect, upload, process, or share information that is necessary for their intended business purpose and should follow applicable privacy and data protection requirements.
- Protect personal and confidential information.
- Limit access to authorized users.
- Avoid sharing sensitive information unnecessarily.
- Review applicable privacy requirements.
- Follow SPRL's Privacy Policy and other applicable policies.
For more information, see Data Privacy & User Information in the SPRL Help Center.
API Security
API credentials provide access to automated platform functionality and should be treated as sensitive security information.
- Store API credentials securely.
- Never expose private credentials in frontend code.
- Do not commit API keys to public repositories.
- Limit access to authorized applications and personnel.
- Review integrations periodically.
- Replace exposed credentials where applicable.
Important:
Never include API keys, access tokens, passwords, or other private credentials in public documentation, screenshots, source code, or support requests.
Domain & SSL Security
Custom domains are an important part of branded link management. Proper DNS and SSL configuration helps ensure that users can securely access your branded links.
- Use domains that your organization controls.
- Configure DNS records according to SPRL requirements.
- Verify your domain before using it for production links.
- Ensure SSL activation has completed before sharing HTTPS links.
- Review domain configuration when DNS or hosting changes are made.
Infrastructure & Platform Security
SPRL applies security-focused practices across its application and infrastructure environments to help protect services and customer information.
These practices may include access controls, secure communications, monitoring, system maintenance, application security measures, and operational safeguards.
- Controlled access to infrastructure resources.
- Secure communication between users and services.
- Application security controls.
- Infrastructure and service monitoring.
- Security-focused maintenance and operational practices.
Abuse Prevention
SPRL maintains processes to identify and respond to abusive, suspicious, or malicious activity involving its services.
Customers should not use SPRL services for activities that violate applicable laws, regulations, or SPRL policies.
- Follow the SPRL Acceptable Use Policy.
- Do not use SPRL to distribute malicious content.
- Do not use the platform for phishing or fraudulent activity.
- Report suspicious SPRL links through the abuse reporting process.
Reporting Security Issues
If you discover a potential security vulnerability affecting SPRL, report it through the appropriate security reporting channel rather than publicly disclosing the issue.
When reporting a security issue, provide enough information for the SPRL team to understand and investigate the issue while avoiding unnecessary disclosure of sensitive information.
- Describe the security issue clearly.
- Provide the affected URL, endpoint, or component where applicable.
- Include steps to reproduce the issue when possible.
- Explain the potential security impact.
- Do not include passwords or unnecessary personal information.
Security Contact:
Security vulnerabilities can be reported to reportspam[@]insprl.com.
Security Best Practices
| Security Area | Recommended Practice |
|---|
| Passwords | Use strong and unique passwords. |
| 2FA | Enable two-factor authentication where available. |
| Sessions | Review active login sessions periodically. |
| Phishing | Verify unexpected messages and suspicious links before interacting with them. |
| API | Protect API keys and keep them out of public code. |
| Domains | Maintain correct DNS and SSL configuration. |
| Data | Protect personal and confidential information. |
| Incidents | Report suspected security issues promptly. |
Security Checklist
| Practice | Status |
|---|
| Strong and unique password configured | Recommended |
| Two-factor authentication enabled where available | Recommended |
| Login sessions reviewed | Recommended |
| API credentials securely stored | Required if using API |
| Custom domain configuration reviewed | Recommended if applicable |
| Privacy requirements reviewed | Recommended |
| Security policies reviewed | Recommended |
| Security reporting process understood | Recommended |
Frequently Asked Questions
How can I protect my SPRL account?
Use a strong and unique password, enable two-factor authentication where available, review login sessions, and avoid sharing your credentials.
Does SPRL support two-factor authentication?
Two-factor authentication is available where enabled for your SPRL account. See the Enable Two-Factor Authentication (2FA) guide for the applicable setup instructions.
What should I do if I suspect my account has been compromised?
Secure your account immediately, change your password, review active login sessions, and contact SPRL Support if you need assistance investigating unauthorized activity.
How should I protect my API keys?
Store API credentials securely on your server or trusted application environment and never expose them in frontend code, public repositories, or publicly accessible documentation.
How can I recognize a phishing attempt?
Be cautious of unexpected messages, suspicious URLs, urgent requests, unusual login pages, and requests for passwords, authentication codes, payment information, or API credentials.
How do I report a security vulnerability?
Report potential security vulnerabilities to reportspam[@]insprl.com and provide sufficient information for the issue to be investigated.
Quick Reference
| Topic | Summary |
|---|
| Account Security | Use strong credentials and protect account access. |
| 2FA | Enable two-factor authentication where available. |
| Login Sessions | Review active sessions and investigate unfamiliar activity. |
| Phishing | Verify suspicious messages and links before interacting with them. |
| Data Privacy | Protect personal and confidential information. |
| API Security | Keep API credentials secure and confidential. |
| Domain Security | Maintain correct DNS and SSL configuration. |
| Security Reporting | Report suspected vulnerabilities through the appropriate security channel. |
Learn More:
Explore the SPRL Help Center for detailed guides on Two-Factor Authentication, Login Sessions, Password Security, Phishing Awareness, Data Privacy, API Security, Domain & SSL Security, Reporting Security Issues, and Security FAQs.
Tip: Security works best as an ongoing practice. Review your account access, credentials, integrations, and security settings regularly, and report anything suspicious as soon as possible.