Security
Safe to trust with your codes.
Last updated 6 October 2026
What we do with your files, your keys and your customers’ scans, and how to tell us if we got something wrong. Written and reviewed by the AriaQR Team.
On this page
How we protect your data
These are the controls that are in place today. The same points, with more detail, are in our privacy policy.
- Encryption in transit. Every page, scan and API call travels over TLS 1.2 or 1.3. Plain HTTP is redirected, and browsers are told for two years never to use it.
- Private, encrypted storage. Images, codes and account data sit in a private store with no public addresses, encrypted at rest with AES-256. Every read goes through our servers.
- No passwords to leak. You sign in with Google or a one-time email code. API keys are shown once and kept only as salted hashes, so a stored key can be revoked but never read back.
- Private links stay private. Manage and download links carry long random secrets, checked in constant time. Landing-page previews use signed links that stop working after an hour.
- Scans without tracking. Scans, short-link clicks and landing-page visits set no cookies, and we never store the visitor’s IP address. Locations come from the network; unique visitors are a one-way hash with a secret that changes every day.
- Links checked for abuse. Destinations are checked against Google Safe Browsing when a link is made or changed, and short links and free codes again every day. Flagged links stop redirecting. You can report a link.
- No card data on our side. Payments run through Razorpay and PayPal. Card, UPI and bank details are entered with them and never reach us.
- Access is limited. Production systems are reachable only by the people who run AriaQR.
Certifications
Realityrift Innovations Private Limited is certified to ISO/IEC 20000-1 (IT service management) and ISO 9001 (quality management).
- ISO/IEC 20000-1:2018, IT service management, certified 23 June 2026. Valid until 22 June 2029.
- ISO 9001:2015, quality management. Valid until 10 November 2027.
Both cover how the company runs its services and its quality. Neither is a security or privacy certification, and we do not present them as one. The controls above stand on their own.
Data handling
The full detail lives in two documents. Read these for what we collect, why, how long we keep it and who processes it.
- Privacy policy: what we keep, why, for how long, and your rights to export, correct, object and delete.
- Data processing terms: the terms that apply when a business uses AriaQR for its customers’ scans. They apply on every plan and include notice of a breach within 72 hours.
You can delete a code, and its scan history goes with it, or delete your whole account yourself from the account page. Precise locations a scanner chose to share are deleted after 90 days.
Report a vulnerability
If you think you have found a security problem in AriaQR, email info@realityrift.co with the subject “Security report”. Please write in English.
To help us reproduce it quickly, include:
- what you found and why you think it matters;
- the address or API call where it happens, and the steps to reproduce it;
- what you saw, with screenshots or a short recording if that helps;
- the account or code you used for testing, so we can tell your activity from anyone else’s;
- how to reach you, and whether you want credit once it is fixed.
Please do not put sensitive data you came across in the report. Describe it instead.
What we promise researchers
- We will read every report, reply, and keep you updated while we investigate and fix it.
- We do not pursue legal action against good-faith research that follows these rules, and we will say so if anyone asks.
- We will credit you when the fix ships, if you want that.
We do not run a bug bounty and cannot pay for reports. We would still rather hear about a problem than not.
Good faith means:
- test only against accounts and codes you own, or that you have permission to use;
- stop as soon as you reach someone else’s data, do not keep or share it, and tell us;
- no denial-of-service, spam, brute-forcing or load testing, and no social engineering of our team or customers;
- give us reasonable time to fix the problem before you make it public.
The scope is ariaqr.com and the aqr.li short links. A landing page or link that a customer made to mislead people is abuse, not a vulnerability: please use Report a link for that.
Our security.txt carries the same contact and policy in the standard machine-readable form.
Realityrift Innovations Private Limited
Governed by the laws of India; courts of Hyderabad, Telangana have exclusive jurisdiction.
Privacy · Terms · Acceptable use · Data processing · Refunds · Report a link · Contact