Security-first, transparency-always

Security & Trust

Every security control we implement, explained in plain language. No marketing fluff — just the checklist we actually follow.

Data Protection

TLS 1.3 in transit

All API + web traffic over HTTPS via nginx + Let's Encrypt.

✓ Live

Encryption at rest

PostgreSQL Transparent Data Encryption + MinIO server-side encryption.

✓ Live

Password hashing

ASP.NET Identity PBKDF2 with SHA-256, 100k+ iterations.

✓ Live

Refresh token rotation

Old tokens revoked on login; single-use refresh tokens.

✓ Live

API keys hashed

SHA-256 hashed — never stored in plaintext.

✓ Live

Access Control

Multi-factor authentication (TOTP)

Time-based one-time passwords via authenticator apps.

✓ Live

Role-based authorization

Free / Starter / Pro / Business / Enterprise / Admin roles.

✓ Live

Workspace-level permissions

Owner / Admin / Editor / Viewer per workspace.

✓ Live

Active session management

View + revoke any logged-in device, with UA + device name.

✓ Live

SAML SSO (SCIM)

Enterprise single sign-on via WorkOS. Coming with enterprise tier.

○ Planned

Audit & Monitoring

Activity log per user

Every auth event, data change, and admin action logged with IP + UA.

✓ Live

Centralised log aggregation

Serilog → Seq with structured JSON events.

✓ Live

Health check endpoints

/health/live, /health/ready with PostgreSQL + Redis probes.

✓ Live

1-year log retention

Production retention policy; currently dev-default.

○ Planned

Anomaly detection

Auto-flag unusual scan spikes, login patterns.

○ Planned

Code + Dependency Security

Static code analysis

GitHub CodeQL on every PR.

✓ Live

Dependency scanning

Dependabot weekly + manual reviews.

✓ Live

Secret scanning

GitHub Secret Scanning blocks committed credentials.

✓ Live

Container scanning

Trivy for Docker image vulnerabilities.

○ Planned

Annual penetration test

Budgeted when enterprise pipeline justifies.

○ Planned

Data Handling

Soft delete + audit trail

Deleted records retained for audit; purged after policy window.

✓ Live

GDPR data export

Download all your data as JSON via /users/me/export.

✓ Live

Right to be forgotten

Account deletion purges personal data within 30 days.

✓ Live

Minimum data collection

We store only what's functionally needed. No third-party trackers.

✓ Live

Data residency options

EU / US / APAC regional deployments — when enterprise demand justifies.

○ Planned

Infrastructure

Per-tier rate limiting

Free 20/min, Starter 60, Pro 120, Business 300, Enterprise 600.

✓ Live

Anonymous endpoint protection

Public /generate + /barcodes/generate rate-limited by IP.

✓ Live

DDoS protection

Cloudflare proxy — production rollout.

○ Planned

Automated backups

PostgreSQL point-in-time recovery + daily snapshots.

✓ Live

Quarterly restore testing

Scheduled drill to verify recovery procedures.

○ Planned

Compliance Roadmap

We don\'t pay for certifications we don\'t yet need. Formal audits come when enterprise contracts justify the investment — in the meantime, every SOC 2-equivalent control is still implemented.

GDPR DPA Template

Target: Q2 2026

⏳ In progress

SOC 2 Type 1

Target: When enterprise demand justifies

○ Planned

SOC 2 Type 2

Target: Follows Type 1

○ Planned

HIPAA + BAA

Target: For healthcare contracts

○ Planned

ISO 27001

Target: For EU enterprise contracts

○ Planned

Found a vulnerability?

We respond to responsible disclosures within 72 hours. Please email us with reproduction steps and we\'ll acknowledge receipt promptly.

security@qrmax.io