Everything a security or procurement review asks about MostlyQR — where your data lives, how it is protected, who processes it and what we commit to — on one page. Where something isn't built yet, we say so.
Free to read and download. No email wall, no sales call.
Your codes, scan analytics and workspace records are stored in Google Cloud’s EU multi-region (Belgium and the Netherlands) and processed in London. Sign-in, your Mostly Tiny account and uploaded images are in the United States, and the scan map’s latest locations are kept on Cloudflare. Scans are served from a separate domain, mqr.sh, isolated from the app.
HTTPS everywhere — the app, mqr.sh and the API. Google Cloud encrypts stored data, and API keys are kept only as hashes.
Every destination is checked against Google Web Risk when it changes and re-scanned every 24 hours. A blocked code stops redirecting and its owner is emailed.
Cancel or downgrade and your printed codes keep redirecting to their last saved destination for as long as we operate MostlyQR — stopping payment never switches them off. From 2026-11-01, Enterprise and annual Business contracts add a commitment of at least two years after the contract ends.
Owner, admin, member and viewer roles in every workspace. Codes, rules and custom domains only ever serve their own workspace.
Scans, the app, the API and hosted pages are checked around the clock from two regions — scans every 60 seconds. A 99.9% monthly uptime target for scans, with service credits on Enterprise contracts.
Sign in with an email link or with your Mostly Tiny account. MostlyQR stores no passwords.
SAML 2.0 single sign-on through Mostly Tiny ID, tested with Okta, Microsoft Entra ID and Google. Link your organisation to your workspaces on Business or Enterprise: SCIM provisions and deprovisions MostlyQR seats, and your company sign-in can be required.
Owners and admins can require a second factor — a passkey or your company sign-in — for every seat. Members without one are sent to enrol at Mostly Tiny ID before they reach the workspace.
Code changes and seat, role and security-policy changes are logged for owners and admins, with CSV export and streaming to your SIEM.
Our UK GDPR / EU GDPR Article 28 DPA is part of the terms for every business customer — no separate signature, no request form.
No SOC 2 audit has been carried out yet. A Type I readiness programme is planned, and the report will be published here when one exists.
No independent penetration test has been run yet. When one is, its summary will be published on this page.
The third parties that process personal data for MostlyQR customers, and where. We give business customers 30 days' notice before adding or replacing one.
42 answers mapped to the CAIQ-Lite and SIG-Lite questionnaires, plus our sub-processors, SLA and continuity commitment in one PDF. Gaps are stated plainly: what is live and what is planned.
Found a vulnerability? Email security@mostlytiny.io · security.txt
No. This page, the security pack, the Data Processing Agreement and the sub-processor list are all public. Download them and share them with your security team.
Codes, scan analytics and workspace records are stored in Google Cloud’s EU multi-region eur3 (Belgium and the Netherlands), and our server functions run in London (europe-west2). Sign-in (Firebase Authentication) and your Mostly Tiny account are in the United States, uploaded logos and images are stored in the United States (us-east1), and the scan map’s latest locations and recent trail are kept on Cloudflare by Vekta, our map service. Scans are answered on a separate domain, mqr.sh, with Cloudflare in front for DNS and security.
Not yet. No SOC 2 audit has been carried out. A Type I readiness programme is planned, and we will publish the report here when one exists. Our questionnaire answers describe the controls we run today.
They keep redirecting to their last saved destination for as long as we operate MostlyQR — codes over your plan's limit are frozen, never switched off. Your account stays open on the free plan; deleting it is what removes your codes. From 2026-11-01, Enterprise and annual Business contracts also commit us to keep codes resolving for at least two years after the contract ends.
Send it to us through support and the people who build MostlyQR will answer it.