urlcap

Security

Security & data handling

Last updated: 14 May 2026.

urlcap is operated by DATO CAPITAL LTD (UK company 09987396). This page is the canonical description of how the service handles your data — transport, secrets, captured request bodies, TOTP shared secrets, logs, retention, and how to disclose a vulnerability. For the legal commitments around all of this, see the Privacy Policy and Terms of Service.

Encryption in transit

Authentication & API keys

Captured request & response data

The /api/v1/capture endpoint dispatches an HTTP request to a target URL on your behalf and returns the response. Treat your captured data like you would treat the contents of your browser's network panel:

TOTP secrets

The /api/v1/totp endpoint takes an otpauth:// URI containing the shared secret, computes the current code, and returns it. Because the URI carries cryptographic material, it gets extra handling:

Logs & analytics

Datasets & scheduled tasks

Infrastructure & access

Payments (Stripe)

Reporting a vulnerability

If you believe you've found a security issue, please email info@urlcap.com with a clear reproduction. We acknowledge reports within two business days and aim to ship a fix or a clear mitigation plan within 30 days for high-severity issues.

Please:

In return we will not pursue legal action against good-faith researchers who follow these rules. We don't currently run a paid bug-bounty programme; we're happy to credit you publicly if you'd like.

Contact

DATO CAPITAL LTD · 71-75 Shelton Street, Covent Garden, London, England, WC2H 9JQ, United Kingdom · info@urlcap.com.