LinkTimerExpiring link generator
Home/Guides/trustlock

LINKTIMER GUIDE

The short link whose destination cannot change silently

TrustLock creates a SHA-256 fingerprint of the destination, expiry policy, fallback and routing rules. Any protected change pauses the redirect, runs a safety scan, records a new revision and can require a second workspace administrator.

What this option gives you

Fail-closed changes

Pending, suspended or mismatched fingerprints cannot redirect through the gate, direct redirect service, API or scheduler.

Signed receipts

Owners can export HMAC-SHA256 JSON and PDF receipts with a canonical public verification URL.

Public privacy-safe ledger

Visitors see approved hosts, fingerprints, revisions and decisions without exposing full destination paths or approver identities.

Practical use cases

Campaign handoff

Prove that a reviewed campaign destination did not change after approval.

Regulated communications

Require a second administrator before a Business workspace destination can change.

Incident response

Pause a redirect automatically while a proposed destination is rescanned.

Vendor assurance

Share a durable receipt and public verification record with reviewers.

How it works

  1. Enable TrustLock

    Choose owner approval or two-person workspace approval.

  2. Propose a protected change

    LinkTimer pauses the redirect before the new destination can go live.

  3. Verify and approve

    Safety checks and the configured approval policy must both succeed.

  4. Share the new receipt

    A new fingerprint, signature and ledger event document the approved revision.

Important limitation

TrustLock proves LinkTimer change integrity and approval history. It does not endorse a destination, guarantee its content, or replace independent security review.

Frequently asked questions

What fields are protected?

The primary destination, activation and expiry controls, fallback, routing rules and deep-link destinations.

Do normal opens change the fingerprint?

No. Operational counters are deliberately excluded.

Can TrustLock be silently removed?

No. The current implementation does not expose a silent unlock path; deletion remains separately auditable.

What happens to a blocked proposal?

The link stays suspended and the blocked decision is written to the public ledger.

Authoritative external resources

These links provide additional context from the destination provider or recognized security resources. External sites are responsible for their own content and policies.

Related LinkTimer guides

Ready to make the destination temporary?

Choose the expiration rule, confirm the destination, and share the generated LinkTimer URL or QR code.

Open the LinkTimer creator