0BLA / TRUST AND INFORMATION

Security & Architecture

0bla is designed with a radical approach: reduce the attack surface, limit data collection and maintain total control over the infrastructure.

On this page6 sections

1. Zero-Trace by Design

Clicks are associated with the relevant link so its owner can view statistics. Stored data includes approximate location, device and browser type and a daily digest, without the visitor's name or email address. This data is pseudonymised and presented in aggregate form.

2. IP Address Management

The IP address is used in memory for approximate location lookup and is not recorded in click statistics. Abuse prevention uses separate HMAC digests for different purposes. Daily rotation of some digests limits their correlation period; it does not guarantee that a person cannot be reidentified by combining information.

3. Security Stack

HTTPS (TLS) across the entire service, HSTS to force secure connections, CSP with nonce to limit injections, XSS and CSRF protection, secure hashing of sensitive data (Argon2ID).

4. Technical Architecture

Server-side PHP sessions, no JWT (no token exposed client-side), centralized and controlled logic, limited external dependencies. This approach reduces attack vectors.

5. Hosting

The service's primary hosting is operated by Koperateur Consulting within the European Union. Exchanges required for payments, Google sign-in, forms, email and webhooks are separate from this hosting and are described in the privacy policy.

6. Reduced Attack Surface

0bla limits external integrations to the features described in the privacy policy. The site's interfaces do not include advertising trackers. Limiting dependencies complements access controls and data validation.