# SQRC: the QR code with a private compartment

> SQRC is a Denso Wave format that splits a code into public data any scanner can read and a private part readable only by readers holding a matching key. The symbol looks like an ordinary QR code. It suits access control with dedicated hardware; it is not encryption for public campaigns.

Source: https://useqr.app/docs/basics/sqrc-secure-qr · Last reviewed 2026-08-21 · UseQR is free forever, no signup.

---

## The two-compartment design

SQRC (Security QR Code) is a proprietary [Denso Wave](/glossary/denso-wave) variant with
one distinctive property: its payload is split in two.

- **The public part** is ordinary QR data. Any phone or scanner reads it and sees a normal
  result: a message, a URL, an ID number.
- **The private part** is scrambled with a key. Only readers configured with the matching
  key (Denso Wave hardware and SDK-based scanners) recover it. Every other scanner
  reads the public part and reports success, never revealing that hidden data exists.

That silence is the clever bit. A tampered or counterfeit symbol fails the keyed read even
though it scans "fine" on a phone, so the checking station catches what the public never
notices.

## What SQRC is not

The name invites more than the design delivers, so the boundaries matter:

- **It is not encryption of what you see.** The public part is plain, ordinary QR data.
  Only the hidden compartment is protected.
- **It is not open cryptography.** The scheme is proprietary; keys are provisioned into
  Denso-compatible readers. You are trusting a vendor mechanism, not a published,
  publicly audited algorithm.
- **It is not for the public.** A phone cannot read the private part, ever, by design.
  Any use case where consumers must access the protected data is disqualified before it
  starts.
- **It does not make QR "safe".** The scanning-safety questions people usually mean:
  [malicious links, quishing](/docs/security/are-qr-codes-safe), are unrelated to SQRC.

## Where it genuinely fits

SQRC's habitat is the closed loop: employee and student ID cards checked at gates,
event and transit tickets validated by controlled scanners, internal logistics tags
carrying data that casual scanning should not expose, and anti-counterfeit marks where a
keyed reader at the checkpoint separates genuine from copied labels. In each case one
organisation issues the codes, owns the readers and manages the keys, the three
conditions that make the model work.

Note the honest caveat even there: anyone who obtains a configured reader can read every
private part it holds keys for, so SQRC's security is only as good as the physical and
organisational control of the reader fleet.

## The open alternatives

Most problems that sound like SQRC problems have open-standard solutions readable
everywhere:

- **Authenticity** (is this code genuinely from us?) →
  [signed QR payloads](/docs/security/signed-qr-codes-and-authenticity): sign the data,
  verify the signature in your app or server. Open crypto, auditable, no special readers.
- **Confidentiality** (secret data) → do not put the secret in the code at all. Encode a
  reference and let an authenticated server release the data: the pattern behind
  tickets, [2FA enrolment](/docs/security/qr-codes-for-2fa-security-model) and most
  serious systems.
- **Tamper evidence on labels** → [physical tamper-evident measures](/docs/security/tamper-evident-qr-labels)
  complement anything digital.

Choose SQRC when you are already committed to Denso reading hardware and want the split
payload specifically. Choose the open patterns for everything else.

## FAQ

### What is an SQRC code?
SQRC is a proprietary Denso Wave QR variant whose payload has a public part any scanner can read and a private part recoverable only by readers holding the matching key. Visually and to a phone it behaves like a normal QR code.

### Is SQRC the same as an encrypted QR code?
Not in the usual sense. The visible payload is unencrypted, and the private compartment uses a proprietary vendor scheme rather than open cryptography. For verifiable authenticity with standard tools, signed payloads are the open alternative.

### Can a phone read the hidden data in an SQRC?
No. The private part requires a reader provisioned with the key, which means Denso Wave-compatible hardware or SDKs. A phone sees only the public portion and gives no indication anything more exists.

### What is SQRC used for?
Closed-loop systems: ID cards, controlled-access tickets, internal logistics and anti-counterfeit labels where the issuing organisation also owns the scanners and manages the keys.

## Try it

- https://useqr.app/text
- https://useqr.app/url
- https://useqr.app/validate
