Security and trust

Trust must be designed, verified and auditable.

QR‑V’s security model protects issuer authority, record integrity, verification responses and the complete record lifecycle.

01

Transport

HTTPS on the production origin with same-origin handling for inquiry submissions.

02

Identity

Issuer administration remains unavailable to the public and requires an approved onboarding path.

03

Integrity

SHA-256 hashes and canonical serialization are active; Ed25519 signing and validation are disclosed as pending.

04

Application

Identifier validation, bounded inputs, prepared database statements, bot trapping and inquiry rate limits.

05

Operations

Live service checks, immutable deployments and platform-managed storage are active for the public launch.

06

Issuer authority

Organizational authority review precedes access; automated suspension and key rotation remain roadmap controls.

07

Audit

Verification result events are recorded; full issuer lifecycle audit capabilities remain access-controlled roadmap work.

08

Privacy

The launch registry returns public-mode fields only; restricted and private response modes are not yet publicly exposed.

Threat model

Designed against the ways verification can fail.

The production security review must consider both technical attacks and failures of organizational authority.

QR cloningMalicious URL substitutionForged certificate dataFake issuersReplay attacksStolen API keysUnauthorized revocationRecord tamperingScraping and enumerationDenial of service