Security

Security is not a feature. It is the foundation.

When your business depends on proving products are genuine, the platform doing the proving must be uncompromising about security. Here is how we protect your data and your authentication infrastructure.

Encryption everywhere

All data encrypted in transit with TLS 1.3 and at rest with AES-256. API keys, passwords, and secrets are hashed and never stored in plaintext.

HMAC-SHA256 authentication

Every QR code is cryptographically signed with HMAC-SHA256. Verification happens server-side — counterfeiters cannot reverse-engineer the signing key.

AI fraud detection

Real-time scan analysis flags anomalies — geolocation mismatches, velocity attacks, cloned codes, and suspicious scan patterns — instantly.

Multi-tenant isolation

Row-Level Security at the database layer ensures complete tenant isolation. No company can ever reach another company’s data through any endpoint.

Access controls & audit logs

Role-based access control with least-privilege principles. Every administrative action is recorded in immutable audit trails.

Integrity hash chain

SHA-256 hash chains track every lifecycle event — generation, scans, dispatches, status changes. Any tampering is cryptographically detectable.

Audit-trail verification

Per-company hash-chained audit log sealed at INSERT via DB trigger; an on-demand verifier surfaces the exact tampered row. Maps to 21 CFR Part 11 / ALCOA+.

Per-unit decommissioning

Append-only ledger of every QR transition into a terminal state — dispensed, destroyed, returned, recalled — capturing actor, geo, IP, and reason.

Infrastructure

Built for enterprise scale

Qrynto runs on production-grade AWS infrastructure (Mumbai region) with encrypted storage, continuous monitoring, and automated recovery. Data is backed up daily to object storage with regularly tested restores.

Database-level partitioning handles very high QR volume. Connection pooling and Redis caching keep response times fast under load; the database moves to managed multi-AZ Postgres with automatic failover as enterprise volume grows.

All production deployments go through automated CI/CD with security scanning, dependency auditing, and staged rollouts. Infrastructure configuration is version-controlled and reproducible.

24/7

Continuous monitoring & alerting.

72h

Breach notification

AES-256

Encryption at rest

Security practices

  • Regular internal security audits and dependency vulnerability assessments
  • Automated dependency scanning on every deployment
  • Immutable audit logs for all administrative actions
  • Incident-response plan with defined escalation procedures
Compliance & assurance

Independently audited. Certifications in progress.

Independent security audits

Regular code-level security reviews. The most recent audit found zero critical or high-severity issues.

SOC 2 & ISO 27001 on the roadmap

Both are in progress. We don’t claim a certification we don’t yet hold — ask for our current status and timeline.

Data residency & privacy

Hosted in AWS Mumbai (ap-south-1). GDPR / DPDP-aligned with data export and deletion on request. Sub-processor list available.

Request our security package

Security questionnaire, DPA, and sub-processor list for your review.

Report a vulnerability

We value responsible disclosure. If you discover a security vulnerability, report it to our security team — we will not pursue legal action against good-faith reporters.