Security is not a feature. It is the foundation.
When your business depends on proving products are genuine, the platform doing the proving must be uncompromising about security. Here is how we protect your data and your authentication infrastructure.
Encryption everywhere
All data encrypted in transit with TLS 1.3 and at rest with AES-256. API keys, passwords, and secrets are hashed and never stored in plaintext.
HMAC-SHA256 authentication
Every QR code is cryptographically signed with HMAC-SHA256. Verification happens server-side — counterfeiters cannot reverse-engineer the signing key.
AI fraud detection
Real-time scan analysis flags anomalies — geolocation mismatches, velocity attacks, cloned codes, and suspicious scan patterns — instantly.
Multi-tenant isolation
Row-Level Security at the database layer ensures complete tenant isolation. No company can ever reach another company’s data through any endpoint.
Access controls & audit logs
Role-based access control with least-privilege principles. Every administrative action is recorded in immutable audit trails.
Integrity hash chain
SHA-256 hash chains track every lifecycle event — generation, scans, dispatches, status changes. Any tampering is cryptographically detectable.
Audit-trail verification
Per-company hash-chained audit log sealed at INSERT via DB trigger; an on-demand verifier surfaces the exact tampered row. Maps to 21 CFR Part 11 / ALCOA+.
Per-unit decommissioning
Append-only ledger of every QR transition into a terminal state — dispensed, destroyed, returned, recalled — capturing actor, geo, IP, and reason.
Built for enterprise scale
Qrynto runs on production-grade AWS infrastructure (Mumbai region) with encrypted storage, continuous monitoring, and automated recovery. Data is backed up daily to object storage with regularly tested restores.
Database-level partitioning handles very high QR volume. Connection pooling and Redis caching keep response times fast under load; the database moves to managed multi-AZ Postgres with automatic failover as enterprise volume grows.
All production deployments go through automated CI/CD with security scanning, dependency auditing, and staged rollouts. Infrastructure configuration is version-controlled and reproducible.
24/7
Continuous monitoring & alerting.
72h
Breach notification
AES-256
Encryption at rest
Security practices
- Regular internal security audits and dependency vulnerability assessments
- Automated dependency scanning on every deployment
- Immutable audit logs for all administrative actions
- Incident-response plan with defined escalation procedures
Independently audited. Certifications in progress.
Independent security audits
Regular code-level security reviews. The most recent audit found zero critical or high-severity issues.
SOC 2 & ISO 27001 on the roadmap
Both are in progress. We don’t claim a certification we don’t yet hold — ask for our current status and timeline.
Data residency & privacy
Hosted in AWS Mumbai (ap-south-1). GDPR / DPDP-aligned with data export and deletion on request. Sub-processor list available.
Security questionnaire, DPA, and sub-processor list for your review.
Report a vulnerability
We value responsible disclosure. If you discover a security vulnerability, report it to our security team — we will not pursue legal action against good-faith reporters.