Your Payments. Our Protection.
QrX is built from the ground up with security at every layer — from encrypted API requests to verified driver terminals. Your data, your customers' data, and every transaction are protected by design, not as an afterthought.
Security at Every Layer
Six layers of protection work together to secure every transaction, every API call, and every piece of data in the QrX platform.
End-to-End Encryption
All data is encrypted in transit with TLS 1.3 and at rest with AES-256 encryption. Payment data never touches our servers in plaintext.
HMAC Request Signing
Every API request is authenticated with HMAC-SHA256 signatures, timestamps, and nonces — preventing replay attacks and ensuring request integrity.
Token-Based Authentication
JWT access tokens with short expiry windows and automatic refresh. Sessions are isolated and can be revoked instantly from any device.
Secure Database Layer
PostgreSQL with encrypted connections, parameterized queries to prevent SQL injection, and automated daily backups with geographic redundancy.
Fraud Monitoring
Real-time transaction monitoring with anomaly detection. Suspicious payment patterns are flagged automatically before they complete.
Infrastructure Security
Hosted on EU-based infrastructure with DDoS protection, automated failover, and 99.9% uptime SLA. No data leaves European borders.
How We Protect Your Data
Every piece of data in QrX is protected by multiple overlapping controls. Here's exactly what we do.
All payment processing happens through PCI-compliant payment providers — QrX never stores card numbers or sensitive payment credentials
Role-based access control with granular permissions — team members only see what they need to see
Complete audit trails for every data access, modification, and administrative action
Automated encrypted backups with geographic redundancy and tested restore procedures
Data retention policies aligned with GDPR requirements, with secure deletion when data is no longer needed
Origin enforcement, User-Agent verification, and Accept-Type validation on all API endpoints
Compliance & Standards
QrX follows industry best practices and regulatory requirements to keep your business compliant and your customers protected.
GDPR Compliant
Full compliance with the EU General Data Protection Regulation. Data minimization, consent management, right to erasure, and data portability are built into the platform.
PCI-Compliant Payments
All payment processing is handled through PCI DSS certified providers (Stripe, MultiSafepay). QrX never stores, processes, or transmits raw card data.
Privacy by Design
Security and privacy are embedded into every feature from the design phase. We collect only the minimum data needed and protect it at every step.
Regular Security Reviews
Ongoing code reviews, dependency auditing, and security testing to identify and address vulnerabilities before they become risks.
Incident Response
In the unlikely event of a security incident, we have documented procedures for rapid response, transparent communication, and thorough remediation.
Detection
Automated monitoring and alerting
Response
Documented escalation procedures
Communication
Transparent customer notification
Security You Can Trust
Protect your customers and your reputation with a payment platform that takes security as seriously as you do.