Built for trust. Engineered for scale.
The same infrastructure that powers fiscalization, payments and public services across the Intelectsoft ecosystem.
In short
QRL.md runs on the Intelectsoft infrastructure used for fiscalization, payments and public services: traffic encrypted in transit, anti-abuse protection with bot mitigation and rate limiting on every endpoint, and GDPR-aligned data processing with minimization by design. Every access and change is recorded in exportable audit logs; data retention is configurable, and Enterprise adds SLA commitments, SSO/OIDC, role-based access and multi-tenant scoping.
Why security matters even for a "simple" link
A short link is an entry point: if the platform behind it can be abused, your printed code can end up serving something else. QRL treats every code as infrastructure: anti-abuse and bot mitigation on redirects, rate limiting on every endpoint, scoped API keys and HMAC-signed webhooks — nobody can forge events or burn through your quota.
Data: minimal, controlled, auditable
Processing is GDPR-aligned with minimization by design: only what analytics needs is collected (country, device, browser, source), retention is configurable, and inactive links are cleaned up automatically. Audit logs record every access and change and can be exported for compliance.
Enterprise: full control
The Enterprise plan adds uptime commitments (SLA), SSO/OIDC, role-based access, multi-tenant scoping, custom domains, white-label and dedicated support — for organizations making QRL part of their own product.
QRL at a glance
The verifiable summary of this page — product, operator, capabilities and cost, in one look.
- Transport
- Encrypted in transit; anti-abuse, bot mitigation, per-endpoint rate limiting
- GDPR
- EU-aligned processing, data minimization by design
- Audit
- Every access and change — logged and exportable
- Retention
- Configurable; automatic cleanup of inactive links
- API
- Scoped keys, HMAC-signed webhooks, per-client quotas
- Enterprise
- SLA, SSO/OIDC, role-based access, multi-tenant, dedicated support
Frequently asked questions
Is scan data GDPR-compliant?
Yes — EU-aligned processing with data minimization by design, configurable retention and automatic cleanup of inactive links.
Can I export the audit logs?
Yes — every access and change is recorded and the logs are exportable.
Who can use my API key?
Keys are scoped with per-client quotas and per-endpoint rate limiting; webhooks are HMAC-signed, so events can't be forged.
Is there an SLA?
Yes, on Enterprise: uptime commitments and dedicated support, plus SSO/OIDC and role-based access.
Related pages
Create your first Smart QR — free
QR codes and short links are free forever, no account needed. Upgrade only when you need management, routing and the API.
+373 22 835 312 · sales@edi.md · Mon–Fri 09:00–18:00Published: 2026-08-14 · Updated: 2026-08-15 · Author: Intelectsoft team · Technical review: Intelectsoft SRL