QR Scevio — Engineering record
APP STORE ↗free · iPhone
Problem
A QR code hides its destination until it is too late.
Scanning normally hands the decoded content straight to another app. The person never sees the URL, the redirect chain, or the tracking parameters attached to it. QR Scevio separates decoding from acting so the destination is inspected first and the decision stays with the person holding the phone.
Constraints
Nothing leaves the device.
- Inspection runs locally. There is no account, analytics, advertising, telemetry, embedded web view, or networking code.
- Because nothing is fetched, the app cannot visit the site, follow redirects, expand short links, resolve DNS, or query a reputation service. Those limits are stated in the product rather than hidden.
- Warnings must inform without alarming, and they are warnings, not guarantees.
- Decoded content stays inert until the user chooses an explicit action.
Decisions
An explicit-action boundary, enforced in the architecture.
The trust boundary is a product decision and a code structure at the same time: decoding reveals information; only a deliberate tap opens, copies, shares, or saves it. Local checks flag plain HTTP, private network addresses, mixed writing systems in a hostname, and common tracking parameters, and offer a sanitized open that strips utm_, fbclid, gclid, dclid, and msclkid. History is kept on the device, bounded to 30 days or 500 scans, and the app declares its data practices in a privacy manifest.
[ INSPECT ]Inspection flow
example
- 01Capture
Camera frame or a single imported image; up to four codes recognized per frame.
- 02Decode locally
Payload extracted with no network access.
- 03Classify
Scheme, host shape, address range, script mixing, and tracking parameters evaluated on device.
- 04Verdict
No Local Warnings Found, Caution, or High Risk, with the specific findings listed.
- trust boundary: nothing happens until the user acts05Explicit action
Open, open sanitized, copy, share, save, or walk away.
- 06Local history
Stored on device, bounded to 30 days or 500 entries.
interpretation
This flow was drawn for the archive after the fact from the release-candidate architecture. It summarizes; it is not a historical design document.
Validation
Evidence before release.
Release verification covered the unit suite and the UI suite on two iOS versions, plus a signed build on physical hardware. The matrix lists only what the release verification report recorded.
[ INSPECT ]Release verification matrix
example
| Scenario | Target | Coverage | Result |
|---|---|---|---|
| Unit suite | iOS 18.5 simulator | 190+ executions | All passed |
| Unit suite | iOS 26.5 simulator | 190+ executions | All passed |
| UI suite | iOS 18.5 simulator | 50 cases | 50 of 50 passed |
| UI suite | iOS 26.5 simulator | 50 cases | 50 of 50 passed |
| Signed device build | iPhone 13 mini | Install and run | Signed build recorded |
| Release archive | Xcode archive | 1.4 MB | Produced |
interpretation
Values are transcribed from the release report. Internal identifiers, device UDIDs, and signing details are omitted.
[ INSPECT ]The boundary as the user sees it
original



interpretation
Three states of the verdict screen. In each, the decoded destination is visible and no action has been taken.
Outcomes
Shipped to the App Store, verified on hardware first.
Version 1.0 build 1 reached release-candidate state with the verification above complete and a signed build running on an iPhone 13 mini. QR Scevio is now on the App Store: free, for iPhone on iOS 17 or later, with privacy details that declare no collected data. No usage or adoption figures are claimed.
Tradeoffs
Local-only is a limit worth stating.
Refusing network access means the app cannot expand short links or consult a reputation service, so some risky destinations will read as No Local Warnings Found. The product says so plainly instead of implying safety. The lesson carried into later work: a security boundary earns trust only when the interface makes clear what was checked, what was not, and what happens next.