Skip to content

How Rebrandly strengthened security and SOC 2 compliance with NordLayer

Summary: See how Rebrandly secures remote access to internal resources, meets SOC 2 compliance, and saves time on IP management.

Results at a glance Rebrandly case study

Rebrandly is a global link management platform that helps businesses create and track branded short URLs. With over 1.3 million users and 3 billion clicks tracked monthly, the company helps businesses manage their links more efficiently, giving them better performance, control, and visibility online.

As the company handles large volumes of customer data, strict compliance and data protection are part of its foundation. They meet the highest security standards, including SOC 2 Type II (Service Organization Control 2), GDPR and HIPAA compliance, giving businesses peace of mind about data protection.

Rebrandly profile

Before NordLayer, Rebrandly managed access through manual IP allowlisting, which was a time-consuming process. They needed a security solution that offered automated access control, AWS cloud integration, and support for SOC 2 Type II compliance. NordLayer’s Site-to-Site, a dedicated IP, and custom DNS streamlined their security and eliminated manual overhead.

The challenge: manual IP allowlisting was a headache

We spoke with Antonio Romano, VP of Engineering at Rebrandly, about the company’s shift to a more scalable, secure access management approach.

Before NordLayer, Rebrandly relied on manual IP allowlisting to protect access to internal resources. However, with a globally distributed team and no dedicated IP, this process became frustrating, especially for a company handling confidential data across billions of links.

“With everyone remote, we were constantly updating the IP allowlist. It just wasn’t scalable.”

The manual process made it more challenging to manage SOC 2 Type II compliance, which requires strict access control and consistent security enforcement.

Rebrandly also needed a solution that integrated easily with their AWS cloud environment and simplified permission management.

How NordLayer helped Rebrandly

Rebrandly’s previous setup lacked the automation and centralized control to maintain secure, compliant operations. As Antonio Romano puts it:

“We needed something more consistent to meet SOC 2 compliance requirements. Manual IP management just wasn’t reliable enough.”

With NordLayer, Rebrandly transitioned from manual IP allowlisting to a dedicated IP setup, enabling secure, policy-based access control. The solution integrated seamlessly with their AWS cloud environment, helping protect internal tools and customer data while supporting SOC 2 Type II compliance.

Benefit 1: Secure access with a Dedicated IP

With NordLayer’s Site-to-Site feature, it was easy to configure a server with a dedicated IP in Rebrandly’s AWS cloud environment for secure access.

The Site-to-Site feature uses encryption to securely route each user’s traffic directly to the right company resource based on their needs without affecting connection speed.

“Now we can restrict access to our hardware resources. It’s helping us a lot.”

How Site-to-Site works

Benefit 2: Tools that help achieve SOC 2 Type II compliance

As a SOC 2 certified company, Rebrandly must meet strict security and audit requirements. NordLayer makes it easy by providing Site-to-Site connections and custom DNS settings that ensure consistent, secure access across their team.

“NordLayer helps us meet the security standards required for SOC 2 compliance.”

Benefit 3: Time saved through automation

Manual IP management was time-consuming and unscalable. NordLayer replaced it with a streamlined, automated solution, saving valuable engineering hours.

“Automating our IP setup saves a couple of hours every week. It’s no longer a constant headache to manage access manually.”

NordLayer control panel screenshot with Servers

Results: simplified SOC 2 compliance and streamlined IP management

By switching to NordLayer, Rebrandly strengthened its security posture while reducing the time and effort spent managing access.

  • Faster workflows
    Automated IP management saves several hours per week.

“The real benefit is not having to manage IP manually—it’s just not scalable when your team grows”

  • Increased network security
    Encrypted data transfers between Rebrandly’s employees using NordLayer’s Site-to-Site, whether in the office or remote, help protect the company’s data. This not only protects sensitive customer data but also allows Rebrandly to meet SOC 2 Type II requirements for secure access and data handling.

Why NordLayer works for Rebrandly

Rebrandly uses NordLayer’s Site-to-Site feature to securely connect its internal network to the AWS cloud infrastructure. The setup includes a Virtual Private Gateway and a Dedicated IP, allowing the team to protect sensitive data without compromising performance.

NordLayer also helped Rebrandly save time by eliminating manual IP management. It also supports the company’s SOC 2 Type II compliance efforts, helping them build client trust.

“From a security point of view, NordLayer’s helping us a lot. And we don’t have to deal with manual processes anymore.”

Cybersecurity tips from Rebrandly

Cybersecurity tips by Antonio Romano

Conclusion

Rebrandly’s experience with NordLayer proves you don’t need a large team to have strong, reliable security. By automating access control and making SOC 2 compliance easier, NordLayer helped Rebrandly maintain its strong security posture, save time, and keep things running smoothly.

If your business needs simple, scalable security that works, NordLayer is a good place to start. Contact our sales team to book a demo and find out more.

About NordLayer
NordLayer is an adaptive network access security solution for modern businesses – from the world’s most trusted cybersecurity brand, Nord Security.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

加密是最後一道防線

超越合規:為何加密是現代網絡安全的終極答案 

近期 SK Telecom 的安全事件,嚴肅地提醒了我們網絡安全領域的一個基本真理:合規不等於安全。正如 Penta Security 的執行董事 Taejun Jung 所解釋,真正的資料保護需要一種主動積極的心態,將加密視為最終的防線,而非監管負擔。

在 SKT 的案例中,外洩的 USIM 資料並未被法律要求加密。然而,Jung 指出,當這些資料與其他資訊結合時,便能輕易地用於個人身份識別。這凸顯了「清單打勾式」安全方法的嚴重危險,以及為何企業必須主動擴大其加密範圍,超越最低的法律要求。

許多機構因擔心效能下降而對廣泛加密猶豫不決,但 Jung 認為這是一種誤解。他表示:「透過適當的系統優化,效能往往可以維持甚至提升。」並將加密重新定義為「一種保險,而非成本。」

展望未來,安全格局將由「連接性」所定義,這得益於人工智慧、自動駕駛、物聯網和雲端的推動。Jung 預測:「因此,透過加密來安全保護互聯數據的重要性只會日益增長。」這就是為何 Penta Security 積極研究同態加密和後量子密碼學等新一代技術的原因。

教訓很明確。在一個威脅不斷演變的世界裡,邊界防禦終將被攻破。Jung 的最終訊息呼籲一次典範轉移:「終究,加密是最後一道防線……加密就是答案。」

關於 Penta Security

Penta Security 採取全方位的策略來涵蓋資訊安全的每個面向。本公司持續努力,透過廣泛的 IT 安全產品,在幕後確保客戶的安全。因此,Penta Security 總部位於韓國,並已在全球擴展,成為亞太地區的市佔領導者。

作為韓國最早進入資訊安全領域的公司之一,Penta Security 已經開發出廣泛的基礎技術。我們將科學、工程與管理相結合,擴展自身的技術能力,並以此技術視角做出關鍵決策。

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

Penta Security 將適用於 AWS WAF 的 Cloudbric 受管規則擴展至兩個新地區

Penta Security 於 GISEC 2025 展示領先數據安全解決方案,進軍蓬勃發展的中東市場 

Penta Security 已成功結束其在 GISEC 2025 的參展活動,該展覽是中東及非洲地區規模最大的網路安全展覽會,此舉突顯了公司對此快速增長地區的策略性重視。在杜拜舉行的這次活動,隨著市場對先進安全解決方案的需求急增,為我們提供了一個與合作夥伴和客戶交流的寶貴機會。

中東的安全市場正經歷強勁增長,預計年增長率為 9.6%。這得益於廣泛的數碼轉型、智慧城市計畫,以及如阿拉伯聯合大公國《個人資料保護法》(PDPL)等日益嚴格的資料保護法規所推動。

展覽期間,Penta Security 與超過 25,000 名安全專家交流,展示了其為應對區域挑戰而設計的企業級解決方案組合:

  • D.AMO:用於資料加密的全方位密碼學平台。
  • WAPPLES:一款智慧型網站應用程式與 API 保護(WAAP)解決方案。
  • Cloudbric WAF+:韓國首個用於網站保護的安全即服務(SECaaS)產品。

本次活動的一個主要收穫是,區內的銀行、政府機構和企業對 Penta Security 的 D.AMO 加密平台表現出濃厚興趣。此需求與該地區各國實施 GDPR 級別的資料保護法規直接相關,使得資料安全成為首要任務。

在與具潛力的合作夥伴及客戶進行了成功的會談後,Penta Security 已準備好迅速擴大其在中東和非洲網絡安全市場的業務版圖,繼續其在全球範圍內提供值得信賴的安全解決方案的使命。

關於 Penta Security

Penta Security 採取全方位的策略來涵蓋資訊安全的每個面向。本公司持續努力,透過廣泛的 IT 安全產品,在幕後確保客戶的安全。因此,Penta Security 總部位於韓國,並已在全球擴展,成為亞太地區的市佔領導者。

作為韓國最早進入資訊安全領域的公司之一,Penta Security 已經開發出廣泛的基礎技術。我們將科學、工程與管理相結合,擴展自身的技術能力,並以此技術視角做出關鍵決策。

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

×

Hello!

Click one of our contacts below to chat on WhatsApp

×