QR Inspector

Security

Security is part of keeping printed codes dependable

These are the protections currently built into QR Inspector.

Accounts

Passwords are stored as one-way salted hashes. Production sessions use secure, HTTP-only cookies, and sensitive form submissions use CSRF protection.

Payments

Card details are collected and processed by Stripe. QR Inspector does not store full card numbers, and paid QR creation is bound to a verified payment amount and account.

Web traffic

The production service uses HTTPS and strict transport security, restrictive browser security headers, request-size limits, and validated redirect destinations.

Scan data

Location analytics are approximate and IP-derived. They do not identify a scanner's street address. Analytics are available to the code owner and service administrators.

Responsible reporting

If you believe you found a vulnerability, please avoid accessing other users' data and report it privately to qrinspector.contact@gmail.com.

Service scope

No online service can promise zero risk. We publish concrete controls rather than unsupported certification or compliance claims.