HighEndDIY policy

Security Policy

HighEndDIY’s approach to encryption, data minimization, system safeguards, vulnerability review, incident response, and responsible disclosure.

Effective date and last updated: July 20, 2026

1. Security commitment

HighEndDIY uses reasonable administrative, technical, and organizational measures designed to protect its Website, systems, and information. No online service or transmission method can guarantee absolute security.

2. Technical safeguards

Our security approach may include:

3. QR generator design

QR creation and supported logo processing occur in the visitor’s browser. The generator does not intentionally upload the QR payload or logo to HighEndDIY. URL inputs use supported web protocols, displayed input is not injected as executable HTML, and the generator does not visit the destination on the user’s behalf.

Uploaded logos are limited by file type and size, decoded, and re-rendered locally. SVG logo uploads are rejected to reduce active-content risk.

4. Vulnerability assessments

We periodically review Website code, dependencies, hosting configuration, access controls, and exposed services on a risk-based basis. Findings are prioritized according to likelihood, impact, and exposure. No automated result is treated as proof that a system is invulnerable.

5. Incident and breach response

If an incident occurs, HighEndDIY may:

  1. Contain and investigate the event.
  2. Preserve relevant records and remove unauthorized access.
  3. Assess affected information, systems, providers, and individuals.
  4. Notify providers, insurers, regulators, law enforcement, or affected individuals where appropriate or legally required.
  5. Apply corrective measures and monitor for recurrence.

Notifications will be made in accordance with applicable requirements, including New York breach-notification law and relevant international privacy obligations.

6. Responsible disclosure

Report a suspected vulnerability to [email protected]. Include the affected URL or feature, reproduction steps, potential impact, and safe supporting evidence.

Researchers must not:

HighEndDIY does not currently offer a bug bounty or promise compensation for a report.

7. User security practices