Security & Trust
Every security control we implement, explained in plain language. No marketing fluff — just the checklist we actually follow.
Data Protection
TLS 1.3 in transit
All API + web traffic over HTTPS via nginx + Let's Encrypt.
Encryption at rest
PostgreSQL Transparent Data Encryption + MinIO server-side encryption.
Password hashing
ASP.NET Identity PBKDF2 with SHA-256, 100k+ iterations.
Refresh token rotation
Old tokens revoked on login; single-use refresh tokens.
API keys hashed
SHA-256 hashed — never stored in plaintext.
Access Control
Multi-factor authentication (TOTP)
Time-based one-time passwords via authenticator apps.
Role-based authorization
Free / Starter / Pro / Business / Enterprise / Admin roles.
Workspace-level permissions
Owner / Admin / Editor / Viewer per workspace.
Active session management
View + revoke any logged-in device, with UA + device name.
SAML SSO (SCIM)
Enterprise single sign-on via WorkOS. Coming with enterprise tier.
Audit & Monitoring
Activity log per user
Every auth event, data change, and admin action logged with IP + UA.
Centralised log aggregation
Serilog → Seq with structured JSON events.
Health check endpoints
/health/live, /health/ready with PostgreSQL + Redis probes.
1-year log retention
Production retention policy; currently dev-default.
Anomaly detection
Auto-flag unusual scan spikes, login patterns.
Code + Dependency Security
Static code analysis
GitHub CodeQL on every PR.
Dependency scanning
Dependabot weekly + manual reviews.
Secret scanning
GitHub Secret Scanning blocks committed credentials.
Container scanning
Trivy for Docker image vulnerabilities.
Annual penetration test
Budgeted when enterprise pipeline justifies.
Data Handling
Soft delete + audit trail
Deleted records retained for audit; purged after policy window.
GDPR data export
Download all your data as JSON via /users/me/export.
Right to be forgotten
Account deletion purges personal data within 30 days.
Minimum data collection
We store only what's functionally needed. No third-party trackers.
Data residency options
EU / US / APAC regional deployments — when enterprise demand justifies.
Infrastructure
Per-tier rate limiting
Free 20/min, Starter 60, Pro 120, Business 300, Enterprise 600.
Anonymous endpoint protection
Public /generate + /barcodes/generate rate-limited by IP.
DDoS protection
Cloudflare proxy — production rollout.
Automated backups
PostgreSQL point-in-time recovery + daily snapshots.
Quarterly restore testing
Scheduled drill to verify recovery procedures.
Compliance Roadmap
We don\'t pay for certifications we don\'t yet need. Formal audits come when enterprise contracts justify the investment — in the meantime, every SOC 2-equivalent control is still implemented.
GDPR DPA Template
Target: Q2 2026
SOC 2 Type 1
Target: When enterprise demand justifies
SOC 2 Type 2
Target: Follows Type 1
HIPAA + BAA
Target: For healthcare contracts
ISO 27001
Target: For EU enterprise contracts
Found a vulnerability?
We respond to responsible disclosures within 72 hours. Please email us with reproduction steps and we\'ll acknowledge receipt promptly.
security@qrmax.io