Transparency about how we protect your data. No marketing fluff, just facts about our security practices.
security@elkqr.comFull implementation of EU data protection requirements
Implemented in CodeSecurity controls following SOC 2 Trust Service Criteria
Controls ImplementedAll data stored in Amsterdam, Netherlands (EU)
DigitalOcean AMS3Note: We have implemented SOC 2 security controls but have not yet undergone formal SOC 2 Type 2 audit. Enterprise Plus customers receive full compliance documentation.
These are the actual security measures implemented in our codebase, not marketing promises.
All sensitive data encrypted at rest
All connections use HTTPS
Each workspace has unique encryption key
30-day retention with AES encryption
DDoS protection and edge caching
Isolated storage with daily backups
TOTP-based 2FA for all accounts
Industry-standard password security
24-hour expiration, secure cookies
Owner, Editor, Viewer permissions
Scoped permissions per API key
60-240 req/min based on plan
Full JSON export of all your data
Complete account deletion
Clear opt-in for marketing
Automated user notification system
GDPR-compliant cookie banner
Only collect what's necessary
Tamper-proof logging with SHA-256
Full audit trail for compliance
Who did what, when, from where
URLhaus threat intelligence integration
Failed login detection
Old/new value logging for edits
Third-party services that process data on our behalf
Cloud VPS Servers, Spaces (Backups)
CDN, DDoS Protection, R2 File Storage
Transactional Email Delivery
Payment Processing & Billing
Malware URL Detection
QR Scan Location Analytics
Custom Domain SSL Certificates
Error Tracking & Analytics Infrastructure
We have implemented security controls aligned with SOC 2 Trust Service Criteria, but we have not yet undergone a formal SOC 2 Type 2 audit. Enterprise Plus customers receive comprehensive compliance documentation showing our implemented controls.
All data is stored in DigitalOcean's Amsterdam (AMS3) data center in the Netherlands, European Union. This ensures GDPR compliance and EU data residency requirements.
Yes. All data is encrypted at rest using AES-256 encryption with PBKDF2 key derivation. Data in transit uses TLS 1.3. Each workspace has its own unique encryption key.
Yes. Under GDPR Articles 17 and 20, you can export all your data in JSON format or request complete account deletion. Both options are available in your account settings.
Yes. Enterprise Plus customers receive a Data Processing Agreement for GDPR compliance. Contact enterprise@elkqr.com for details.
Please email security@elkqr.com with details of the vulnerability. We take all reports seriously and will respond within 48 hours.
Enterprise Plus customers receive full SOC 2 documentation package, DPA agreement, and custom SLA with 99.9% uptime guarantee.
View Enterprise PlusOr contact enterprise@elkqr.com for custom requirements