How it's run
Security
A printed QR code cannot be recalled, so the things protecting it have to keep working long after the print run. Here is what those are.
Last updated Aug 9, 2026 · Hostelastic Technologies LLP
The thing we protect first
A QR code on packaging, a menu or a banner cannot be reissued. Whatever is printed is printed, and it has to keep resolving for years. That shapes every decision below, and it means the risk we treat most seriously is not the one most vendors lead with.
Short links are shared infrastructure. Every customer's printed codes resolve through the same short domain, so a single destination serving malware could get that domain flagged by browsers — and a browser warning would appear in front of every printed code, for every customer, at once. One person's mistake is everybody's outage. Guarding against that is the work described in the next section.
Destinations are checked, and re-checked
Every destination is checked against Google Safe Browsing — the same reputation service behind the warnings in Chrome, Safari and Android — at three separate moments:
- When a code is created. A destination already known for malware, phishing or unwanted software is refused, with an explanation rather than a generic error.
- Whenever it is repointed. Changing a printed code's destination is the whole point of a dynamic QR code — and it means a code checked once is not the code that is live tomorrow. Every repoint is checked afresh.
- Every night, across every live code. The check that matters most, because it is the only one that sees the estate as it actually is rather than as it was when someone last touched it. A destination that turns malicious weeks after printing is found here.
A code found pointing at something harmful is switched off within minutes, worldwide, and its owner is emailed the reason and what to do about it. The most common cause is not abuse — it is a small business whose own website has been compromised, and who often learns it from that email.
The printed code itself is never harmed. It keeps its short link, its design and its scan history; scanning it shows a brief “this code is paused” page instead of opening the destination. Once the site is cleaned up, it is turned back on and works exactly as before — no reprint.
Taking one code down, not a business
When a code has to be switched off, only that code is switched off. A customer with one bad link and two hundred good printed codes keeps the two hundred working. Every takedown is recorded with a reason, a timestamp and the person who made it.
Nothing comes back on by itself. Reinstating a code is a decision a person makes and signs their name to, because a code that quietly restored itself overnight would give a harmful page a second run at an audience that has already been handed the paper.
If you find a code on our short domain pointing somewhere it should not, tell us at our contact page and we will act on it. Our acceptable use policy sets out what codes may point at; every account agrees to it before it can create anything.
What a scan records, and what it never does
Scan analytics answer how many people scanned a code, roughly where from, and on what kind of device. They are not built to identify anybody, and two decisions enforce that rather than merely promising it:
- No IP address is ever stored. Not hashed, not truncated, not kept briefly — the database has no column to put one in. Country and city are resolved at the network edge, and the address itself never reaches our application.
- Repeat visitors are counted without being identified. Telling one phone from another uses a one-way digest that changes every day and cannot be reversed to a person or a device.
- Scan detail is deleted on a schedule. Each plan states how long per-scan detail is kept. When that window passes, the day is summarised to totals and the underlying rows are deleted, so older history answers how many without retaining who or where.
Access, accounts and payment
- We never see your password. Sign-in is handled by a managed authentication service; passwords are hashed there and never reach our code. Google sign-in means there is no password at all.
- Sign-in, sign-up and password reset are rate limited per address and overall, so a credential cannot be guessed at speed from one machine or from many.
- Passcode-protected codes hold only a slow one-way hash of the passcode, and guesses against a printed code are counted and throttled at the edge.
- Card details never touch us. Checkout runs end to end on a PCI-DSS compliant processor acting as merchant of record. We receive a confirmation, never a card number.
- Support access is logged. If our staff open your workspace to help with a ticket, it is recorded, it expires by itself, and a banner says so on every screen while it is happening.
Staying up, and getting back
Printed codes are served by a small, separate deployment that does not depend on the dashboard, the marketing site or the main database. An outage in any of those does not stop a poster from working, and shipping a change to the website does not touch the system answering printed codes.
A full copy of the database is taken every night and stored with a second, independent provider. Each copy is restored into a clean database and checked table by table before it is kept — an untested backup is a hope rather than a backup, and this is the difference stated plainly. Older copies are kept for a year.
Scale, Business and Enterprise carry a 99.9% uptime commitment with service credits.
What we do not claim
A security page with no limits is not one to trust, so here are ours, stated before you have to ask:
- We do not hold SOC 2 or ISO 27001. Cloudflare and AWS, who run the infrastructure underneath us, hold both. Hostelastic Technologies LLP does not, and we will not imply otherwise.
- No reputation service catches everything. Safe Browsing finds what is already known to be harmful. A brand-new malicious page can be unlisted for a time, which is precisely why we re-check every night instead of trusting a single check.
- We have not had an external penetration test. When that changes, this page will say so and give the date.
- A workspace is one login today. Separate team seats with individual accounts are not built yet, and we would rather say that here than let a security questionnaire discover it.
Buying for an organisation with its own review process? Write to us through the contact page and we will complete your security questionnaire in full, in your own format, and answer follow-up questions from an engineer rather than a form.
Questions about this page? Email support@pixelqode.com.