Security & Trust Infrastructure
We design our QR code redirects, shortlink databases, and developer APIs to meet strict compliance standards. Here is how we safeguard your traffic, data, and user privacy.
Encryption & Storage
All data in transit is protected using TLS 1.3 encryption. Shortlink directories and database columns are encrypted at rest using AES-256 with key rotation.
Privacy Compliance
We are 100% GDPR, CCPA, and ePrivacy compliant. Scan tracking analytics are anonymized, ensuring no personally identifiable information (PII) is compiled.
Edge Threat Mitigation
Redirection points run on Vercel's Edge network, which includes built-in DDoS protection, IP threat rating checks, and global firewalls.
Isolate Database Layers
Enterprise dynamic accounts utilize Row-Level Security (RLS) policies within Supabase to prevent cross-tenant queries and ensure complete data isolation.
Compliance Overview
| Framework / Requirement | Qodex Implementation | Status |
|---|---|---|
| GDPR & CCPA | No tracking cookies or raw IP recording; fully anonymized geo-referencing. | Compliant |
| Data Encryption | TLS 1.3 transit encryption & database-level AES-256 rest keys. | Active |
| DDoS & Firewall | Multi-region Edge network load-balancing and threat filter. | Active |
| SOC 2 Alignment | Continuous system logging, access reviews, and isolated server environments. | Aligned |