Security at Kebo QR

A seamless experience is only possible when it is secure. We protect your data, your QR codes, and your audience with uncompromising security practices and modern infrastructure.

Security at Kebo QR

This Security overview was last updated on

The highlighted 'Summary' text is aimed to give a plain-English summary of our security posture. Please ensure you read the main text for technical specifics regarding how we protect your information.

1. Encryption in Transit and at Rest

We keep your account details, QR code routing data, and uploaded media strictly secure. In transit, all communications between your browser and Kebo QR are encrypted using industry-standard TLS/SSL. At rest, your data is encrypted using AES-256 encryption within our databases. Each QR code you create also receives a unique-to-it Initialization Vector (IV) to further enhance security. This means that even if two QR codes have the same content, their encrypted forms will look completely different and no two QR codes will be able to be decrypted using the other's IV.

2. Strict Data Security & Access Controls

We operate on a principle of least privilege. Our systems and authorized personnel can only access the specific data they need to perform their required duties (such as resolving a support ticket). Furthermore, we store your data with top-tier cloud providers who maintain rigorous, audited physical security controls at their data centers.

3. Monitored and Resilient Systems

We do not wait for users to report problems. Our automated threat detection, error logging, and system alerting tools constantly monitor the platform. If a potential incident or bottleneck arises, our engineering teams are immediately notified to investigate and resolve the issue proactively.

4. Secure Development and Staged Releases

Security is built into Kebo QR from the first line of code. We utilize secure development practices, requiring peer review and rigorous testing prior to any release. This includes both manual code reviews and automated vulnerability scanning.

Furthermore, we only release software to our live users after it has been fully qualified and tested in isolated development and staging environments.

5. Account Security and Permissions

We provide robust options to keep your account secure. This includes support for secure third-party single sign-on (such as Google OAuth) to reduce password fatigue.

For collaborative work, Kebo QR Teams allows you to assign specific in-app permissions and roles. This ensures team members only have the access they need to create, edit, and delete QR codes, manage subscriptions, or manage other user accounts within your Kebo QR Team.

6. Contact Us