---
title: "Abuse reports and destination takedown"
description: "How to report an abusive destination on rrte.link. We review reports. We do not promise a response time. Printed QR codes are not paused."
canonical: https://reroutehq.com/security/takedown
---

# Abuse reports and destination takedown

Last updated: August 23, 2026

This page describes how to report an abusive destination behind an rrte.link shortlink, and what we do with that report. We describe only what is in place today.

HTML: [/security/takedown](/security/takedown).

## How to report

Send the shortlink URL (for example https://rrte.link/abc123) and a short description of the problem to abuse@reroutehq.com. You do not need an account.

If you found a software vulnerability — XSS, an auth bypass, a data leak — do not use the abuse mailbox. Report it privately to security@reroutehq.com before any public disclosure.

## What we do

A person on our team reviews each report. We do not auto-block a link because someone reported it.

We do not promise a response time. There is no SLA for abuse reports.

## What a takedown looks like

If staff agree the destination must come down, they remove that destination for that link only. A later scan of the printed QR code still opens a page. The page is an HTTP 200 that says the destination was removed. It does not include a Continue button to the old URL.

The link is not paused. Printed codes keep resolving to a page so they do not look dead.

## What we will not do

These limits are the product, not a temporary gap.

- We will not disable every link on rrte.link because one back-half was abused. Takedown is per destination row, not per host.
- We will not take a printed QR code offline. The printed square still opens a page.
- Cancelling a subscription does not disable existing QR codes or pause their links. Existing links keep redirecting.
- We do not offer a contractual SLA.

## Scope

Takedown applies to one dynamic link destination. A second link with a different destination is not affected. We do not block the rrte.link hostname as a whole unless a vendor lists rrte.link itself.

## Related

- [Security & Trust](/security)
- [Customer Trust Pack](/security/trust-pack)
- [security.txt](/.well-known/security.txt)
