Account security
Email confirmation, strong password rules, lockout controls, short-lived access tokens, refresh-token rotation and optional TOTP multi-factor authentication.
QRalto combines secure defaults, explicit authorization and operational controls across the website, API and redirect service.
Email confirmation, strong password rules, lockout controls, short-lived access tokens, refresh-token rotation and optional TOTP multi-factor authentication.
Workspace membership and Owner, Admin, Editor and Viewer roles are revalidated by the API for protected operations.
Fail-closed authorization policies validate trial or paid status and plan capabilities at the protected API boundary.
Scoped, expiring keys are displayed once, stored as hashes and rechecked against current membership and plan access on use.
Stripe-hosted payment collection, signed webhook verification, event idempotency and return-URL allow-listing reduce payment-flow risk.
Administrative actions retain actor, target and before-and-after evidence to support review and incident investigation.
Please email security@qralto.com with clear reproduction steps. Do not access other customers' data, disrupt the service or publish the issue before we have had a reasonable opportunity to investigate.