Security

    Last reviewed: 2026-08-22

    Security is a core part of how we build and operate QRcodium. This page describes the technical and organizational measures we apply. It supplements our Privacy Policy.

    1. Application Security

    • All traffic to the Service is encrypted in transit using TLS.
    • Passwords are stored as salted, iterated hashes and are never stored in plain text.
    • Access to production systems requires multi-factor authentication and is granted on a least-privilege basis.
    • We conduct code reviews and automated dependency and vulnerability scanning as part of our development process.

    2. Infrastructure

    Our infrastructure provider maintains physical and network security controls, including data-at-rest encryption, redundant availability zones, and 24/7 monitoring. We deploy changes through a reviewable pipeline with staged rollouts.

    3. Data Handling

    • Personal information is processed in accordance with our Privacy Policy and applicable law.
    • Payment card data is handled exclusively by PCI DSS-compliant payment providers; we do not store card numbers or authentication data.
    • Access to stored user content is restricted to personnel who require it for support and operations, and is logged.

    4. Incident Response

    We maintain an incident response plan covering detection, containment, eradication, recovery, and notification. If a data breach affects your personal information and notification is required by law, we will notify you and the relevant authorities without undue delay.

    5. Vulnerability Reporting

    If you believe you have found a security vulnerability in the Service, please report it via the Contact page. Please do not test the Service in ways that affect other users or production data. We respond to reports in a timely manner and acknowledge researchers who follow responsible disclosure.

    6. Your Responsibilities

    You can help protect your account by using a strong, unique password, enabling multi-factor authentication where offered, and keeping your contact email up to date so we can reach you about security matters.

    7. Contact

    For security inquiries, see the Contact page.