Security & Trust at CodeREADr

Last updated: August 21, 2026

Data security, availability, and regulatory compliance are core priorities for CodeREADr. In the spirit of transparency, this page summarizes how we protect Client Data, keep the platform available, and comply with applicable data protection law — and links out to our full legal and compliance documentation for anyone, including automated vendor-review tools, evaluating CodeREADr.

Stability & Uptime

The CodeREADr platform has an uptime of more than 99.9% — downtime of less than 4.38 minutes per month on average, backed by a Basic Service Level commitment in our Terms of Service. An optional paid Service Level Agreement is also available.

Authentication & Access Control

Whether on the website or the mobile app, CodeREADr requires authentication. The account holder (admin) issues unique usernames and passwords to each app user and sets specific permissions per user, so users have access only to what they need. Access to Client Data internally is restricted on a need-to-know, least-privilege basis using unique individual user IDs — never shared logins. Personnel with access to Client Data undergo background checks and receive annual information security and confidentiality training.

Encryption

In transit: Data traveling from the mobile app to our servers — including scan details such as service type, user, device, and location — is encrypted via TLS. The website login and all admin viewing/downloading of scans is likewise TLS-encrypted, with automatic redirection from http:// to https:// in case a user omits the “s.” The APIs used to retrieve or configure data are also TLS-encrypted, using token-based authentication and IP filtering so only your server can connect to your data; API keys can be revoked and reset at any time.

At rest: Data stored on our servers is encrypted (“Data at Rest Encryption”).

Data Hosting & Residency

CodeREADr’s Cloud Service is hosted in a single geographic region located in the United States, using Amazon Web Services (AWS) for application hosting and backups, and MongoDB Atlas for database hosting. We do not currently offer alternate geographic hosting regions. Transfers of Personal Data from the EEA, UK, and Switzerland to our US infrastructure are governed by our Data Transfer Addendum, which incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.

Availability, Backups & Business Continuity

Our database is highly scalable and synchronously replicated across multiple data centers. If the primary database server goes down, a standby database takes over automatically — no human intervention or waiting required. Maintenance is performed on the standby, which is then promoted to primary, with the old primary becoming the new standby, so patches and updates are applied without downtime.

We back up snapshots continuously, allowing restoration from any point in time (except the previous 5 minutes) within the past 30 days. We also perform automatic full daily snapshots (retained for a month) plus weekly and monthly database backups. Everything is backed up except barcode images, which can simply be regenerated. Our file system uses an automated replication service that synchronously stores data across multiple facilities at the time of file creation, with checksums calculated on all network traffic to detect data corruption.

Data Breach Notification

We commit to notifying affected Clients within 24 hours of discovering and verifying a Security Incident — well inside the GDPR’s 72-hour regulatory notification window — and to cooperating on investigation, remediation, and any required regulatory or data-subject notifications.

Sub-Processors

See our full Sub-Processors list for the purpose and processing location of every vendor we engage.

Data Protection Agreements

No AI training on your data: We do not use Client Data, or any other personal information we process, to train artificial intelligence or machine learning models, whether our own or a third party’s.

Data Retention & Deletion

Client Data is retained only as long as necessary to provide the Service. Clients may request deletion or export of their data at any time, subject to certain logs and encrypted backups that are deleted automatically in accordance with our retention schedule. See our Data Destruction Policy.

Payments

Credit card processing is handled by Stripe, Authorize.net, and First Data (Fiserv). CodeREADr does not store full credit card numbers — only encrypted reference data (the last four digits and expiration date).

Compliance Policy Library

Our full policy library is published at codereadr.com/compliance, including our Information Security Policy, Incident Response Policy, Data Destruction Policy, Disaster Recovery and Business Continuity Plan, Vendor Access Policy, Network Security Policy, Physical Security Policy, Patch Management Policy, Secure Software Development Lifecycle Policy, Change Management Policy, IT Risk Assessment Policy, Acceptable Use Policy, Ethics Statement, Human Rights Policy, Modern Slavery Act Statement, and our Attestation of Compliance.

Legal & Privacy Documents

Questions?

Contact our Data Protection Officer at dpo@codereadr.com with any security or compliance questions.