Skip to content

Security

Security

People who scan our codes

  • Every web destination is checked against Google Web Risk when it is saved and re-checked daily, then weekly. One listed as phishing or malware is refused, or blocked if it turns bad later.
  • Anyone can report a code. We review every report, and a blocked code shows a notice instead of forwarding.
  • A code that would start a call, a text or an email asks first.
  • The redirect sets no cookie and does not store IP addresses.

Your account

  • There is no password to steal. You sign in with a link we email you, which works once and expires after 15 minutes.
  • Sign-in links and sessions are stored only as one-way hashes, so even a copy of our database would not let anyone sign in.
  • A session lasts 30 days on each device. "Sign out everywhere" in Settings ends all of them at once.
  • The sign-in form has a human check and rate limits.

The service

  • Payments go through Polar, our merchant of record. Card details never reach us.
  • Our pages are HTTPS-only, use a strict Content Security Policy and can't be embedded in other sites.
  • Admin screens sit behind an extra sign-in at the network edge, for named staff only.
  • Keys and tokens are kept in our host's encrypted secret storage, never in the code.

Report a vulnerability

Email security@guaranteedqr.com with what you found, how to reproduce it and what it affects. We'll confirm we got it and keep you posted while we fix it.

Please give us reasonable time to fix the problem before you publish it. While testing, don't access other people's data, change it, or slow the service down for others.