Skip to content
qrflex.

QRFLEX / SECURITY

Built around trust.

Your printed links are long-lived. Their identity, access and operation deserve the same care.

A printed identity that stays put

Public SmartLink IDs are immutable, high-entropy and non-sequential. Previously owned IDs are never silently assigned to someone else. Archiving preserves identity, and restoration is available for 60 days.

Permissions enforced by the server

Roles determine access to workspace resources. The API checks authorization, including for service accounts. Hiding a control in the interface is not the security boundary.

Redirects designed to keep moving

Published routing configuration is served at the edge. Redirects do not synchronously wait on PostgreSQL, and analytics never block the redirect path. Free and paid links share the same reliability principles.

Separate credentials for integrations

API credential plaintext is never stored or logged. Integrations use service accounts governed by the same authorization model as people.