Security overview

Protection across
every campaign layer.

QRalto combines secure defaults, explicit authorization and operational controls across the website, API and redirect service.

IDENTITY

Account security

Email confirmation, strong password rules, lockout controls, short-lived access tokens, refresh-token rotation and optional TOTP multi-factor authentication.

ACCESS

Tenant isolation

Workspace membership and Owner, Admin, Editor and Viewer roles are revalidated by the API for protected operations.

ENTITLEMENTS

Subscription enforcement

Fail-closed authorization policies validate trial or paid status and plan capabilities at the protected API boundary.

INTEGRATIONS

API key controls

Scoped, expiring keys are displayed once, stored as hashes and rechecked against current membership and plan access on use.

PAYMENTS

Billing integrity

Stripe-hosted payment collection, signed webhook verification, event idempotency and return-URL allow-listing reduce payment-flow risk.

OBSERVABILITY

Audit evidence

Administrative actions retain actor, target and before-and-after evidence to support review and incident investigation.

RESPONSIBLE DISCLOSURE

Found a possible vulnerability?

Please email security@qralto.com with clear reproduction steps. Do not access other customers' data, disrupt the service or publish the issue before we have had a reasonable opportunity to investigate.