Security at QR12345
We design around data minimization, isolated secrets, and validation of inputs and destinations.
Last updated: September 12, 2026
Files
Processing runs in the browser, then one output copy is sent over HTTPS to a private, non-public bucket. Database policies restrict reading and downloading to the site owner, and the admin dashboard uses short-lived signed download links.
Links and secrets
Unsafe protocols and destinations are rejected. QR management secrets are kept out of query strings and analytics and remain in the browser session.
Service protection
External API keys remain on the server, and paid functions have usage limits. Dependencies and errors are reviewed without sending personal information by default.
Reporting
If you find a vulnerability, use the contact form with a clear description and reproduction steps. Avoid accessing other people’s data or publishing details before remediation.
