As far as the crypto, right now it's just straight OTR (https://arlolra.github.io/otr/), but we have some cooler stuff in the works for non-intrusive non-ephemeral encryption.
I think the way we handle the URL mitigates a lot of potential issues (the design goal there was to make it as resistant to someone brute forcing the address space as possible, within reason):
* It expires after 10 minutes, at which point it's immediately recycled
* It's also immediately recycled the second the other guy connects to the cyph (meaning that, hypothetically, two unrelated pairs of people could be cyphing each other at the same URL)
That isn't perfect on its own, but it's good enough for almost any use case.
That said, in a few weeks we're also rolling out a two-factor auth feature to verify your friend via her phone number or email address, for when you really need to be sure. (We'll flesh this out a bit more later on, e.g. possibly integrating with Google Authenticator.)