Trust Center

Security and reliability, answered up front

Everything a security or procurement review asks about MostlyQR — where your data lives, how it is protected, who processes it and what we commit to — on one page. Where something isn't built yet, we say so.

Free to read and download. No email wall, no sales call.

Database in the EU

Your codes, scan analytics and workspace records are stored in Google Cloud’s EU multi-region (Belgium and the Netherlands) and processed in London. Sign-in, your Mostly Tiny account and uploaded images are in the United States, and the scan map’s latest locations are kept on Cloudflare. Scans are served from a separate domain, mqr.sh, isolated from the app.

Encrypted in transit and at rest

HTTPS everywhere — the app, mqr.sh and the API. Google Cloud encrypts stored data, and API keys are kept only as hashes.

Malware and phishing scanning

Every destination is checked against Google Web Risk when it changes and re-scanned every 24 hours. A blocked code stops redirecting and its owner is emailed.

Codes outlive your plan

Cancel or downgrade and your printed codes keep redirecting to their last saved destination for as long as we operate MostlyQR — stopping payment never switches them off. From 2026-11-01, Enterprise and annual Business contracts add a commitment of at least two years after the contract ends.

Roles and tenant isolation

Owner, admin, member and viewer roles in every workspace. Codes, rules and custom domains only ever serve their own workspace.

Public status and a written SLA

Scans, the app, the API and hosted pages are checked around the clock from two regions — scans every 60 seconds. A 99.9% monthly uptime target for scans, with service credits on Enterprise contracts.

Identity & access

Sign-in, SSO and two-factor — where each one stands

Live

Passwordless sign-in

Sign in with an email link or with your Mostly Tiny account. MostlyQR stores no passwords.

Live

SAML single sign-on and SCIM

SAML 2.0 single sign-on through Mostly Tiny ID, tested with Okta, Microsoft Entra ID and Google. Link your organisation to your workspaces on Business or Enterprise: SCIM provisions and deprovisions MostlyQR seats, and your company sign-in can be required.

Live

Enforced two-factor authentication

Owners and admins can require a second factor — a passkey or your company sign-in — for every seat. Members without one are sent to enrol at Mostly Tiny ID before they reach the workspace.

Live

Audit log

Code changes and seat, role and security-policy changes are logged for owners and admins, with CSV export and streaming to your SIEM.

Compliance

What exists today, and what doesn't yet

Live

Data Processing Agreement

Our UK GDPR / EU GDPR Article 28 DPA is part of the terms for every business customer — no separate signature, no request form.

Planned

SOC 2

No SOC 2 audit has been carried out yet. A Type I readiness programme is planned, and the report will be published here when one exists.

Planned

Penetration test

No independent penetration test has been run yet. When one is, its summary will be published on this page.

Sub-processors

Who processes data for us

The third parties that process personal data for MostlyQR customers, and where. We give business customers 30 days' notice before adding or replacing one.

  • Google Cloud and Firebase (Google)EU, UK and US
  • Firebase Authentication (Google)United States
  • Firebase Hosting (Google)global network
  • StripeUnited States and EU
  • ResendUnited States
  • Cloudflareglobal edge network
  • PostHog (EU Cloud)EU (Germany)
  • Fathom AnalyticsCanada (UK and EU adequacy decisions)
  • AnthropicUnited States
  • Google Web Risk and Safe BrowsingUnited States
Security pack

Questionnaire answers, ready to paste

42 answers mapped to the CAIQ-Lite and SIG-Lite questionnaires, plus our sub-processors, SLA and continuity commitment in one PDF. Gaps are stated plainly: what is live and what is planned.

FAQ

Security questions buyers ask us

Do I need to talk to sales to see your security documents?

No. This page, the security pack, the Data Processing Agreement and the sub-processor list are all public. Download them and share them with your security team.

Where is MostlyQR data hosted?

Codes, scan analytics and workspace records are stored in Google Cloud’s EU multi-region eur3 (Belgium and the Netherlands), and our server functions run in London (europe-west2). Sign-in (Firebase Authentication) and your Mostly Tiny account are in the United States, uploaded logos and images are stored in the United States (us-east1), and the scan map’s latest locations and recent trail are kept on Cloudflare by Vekta, our map service. Scans are answered on a separate domain, mqr.sh, with Cloudflare in front for DNS and security.

Is MostlyQR SOC 2 certified?

Not yet. No SOC 2 audit has been carried out. A Type I readiness programme is planned, and we will publish the report here when one exists. Our questionnaire answers describe the controls we run today.

What happens to our printed codes if we stop paying?

They keep redirecting to their last saved destination for as long as we operate MostlyQR — codes over your plan's limit are frozen, never switched off. Your account stays open on the free plan; deleting it is what removes your codes. From 2026-11-01, Enterprise and annual Business contracts also commit us to keep codes resolving for at least two years after the contract ends.

A question the pack doesn't answer?

Send it to us through support and the people who build MostlyQR will answer it.