QCut

Security model

Server-side URL validation blocks unsafe schemes, localhost, private IP ranges, and internal hostnames.
Guest management tokens are hashed before storage and are never shown in analytics or Sentry events.
Sentry beforeSend removes original URLs, raw IPs, cookies, Authorization headers, tokens, and secrets.
Public stats expose aggregates only: no raw IP, full user-agent, detailed referrer URL, reports, or admin notes.
Cloudflare Turnstile protects guest creation and abuse reports.