HighEndDIY policy
Security Policy
HighEndDIY’s approach to encryption, data minimization, system safeguards, vulnerability review, incident response, and responsible disclosure.
Effective date and last updated: July 20, 2026
1. Security commitment
HighEndDIY uses reasonable administrative, technical, and organizational measures designed to protect its Website, systems, and information. No online service or transmission method can guarantee absolute security.
2. Technical safeguards
Our security approach may include:
- HTTPS/TLS encryption for information transmitted to and from the Website.
- Restricted administrative access and strong authentication for privileged services.
- Secure static hosting, content delivery, and protective response headers.
- Software and dependency updates, data minimization, backups, and recovery procedures.
- Logging, abuse detection, and provider review proportionate to risk.
3. QR generator design
QR creation and supported logo processing occur in the visitor’s browser. The generator does not intentionally upload the QR payload or logo to HighEndDIY. URL inputs use supported web protocols, displayed input is not injected as executable HTML, and the generator does not visit the destination on the user’s behalf.
Uploaded logos are limited by file type and size, decoded, and re-rendered locally. SVG logo uploads are rejected to reduce active-content risk.
4. Vulnerability assessments
We periodically review Website code, dependencies, hosting configuration, access controls, and exposed services on a risk-based basis. Findings are prioritized according to likelihood, impact, and exposure. No automated result is treated as proof that a system is invulnerable.
5. Incident and breach response
If an incident occurs, HighEndDIY may:
- Contain and investigate the event.
- Preserve relevant records and remove unauthorized access.
- Assess affected information, systems, providers, and individuals.
- Notify providers, insurers, regulators, law enforcement, or affected individuals where appropriate or legally required.
- Apply corrective measures and monitor for recurrence.
Notifications will be made in accordance with applicable requirements, including New York breach-notification law and relevant international privacy obligations.
6. Responsible disclosure
Report a suspected vulnerability to [email protected]. Include the affected URL or feature, reproduction steps, potential impact, and safe supporting evidence.
Researchers must not:
- Access, retain, alter, or disclose another person’s information.
- Disrupt availability or use denial-of-service techniques.
- Install malware, persistence, or destructive payloads.
- Use social engineering, extortion, or premature public disclosure.
- Probe a third-party system without that provider’s authorization.
HighEndDIY does not currently offer a bug bounty or promise compensation for a report.
7. User security practices
- Use unique, strong passwords if accounts are introduced.
- Enable multi-factor authentication where available.
- Keep browsers, devices, and security software updated.
- Do not enter sensitive information into general-purpose tools.
- Verify that messages and links use the official HighEndDIY domain.
- Never send passwords, private keys, or payment credentials by ordinary email.