Security Code: How to Protect Your Digital Card So Only Those You Choose Can See It
With CardQR's security code, your digital card is only accessible with an 8-character code. What it protects and doesn't, why it's incompatible with Google indexing, and when it makes sense to use it.
The security code turns your public digital card into a restricted-access card: it can only be viewed by entering an 8-character alphanumeric code generated by the system. Without the correct code, anyone trying to access it only sees a prompt asking for it β never your information. It's a Pro feature and lives in the Basic tab of the editor, inside "Security Settings".
This guide explains how to activate it, what it actually protects and doesn't, why it's incompatible with appearing in Google, and in what situations it makes sense to use it.
How to activate it
- Open your card editor and go to the Basic tab.
- Scroll down to "Security Settings" and enable the toggle. In the Free plan it appears locked β it's a Pro feature.
- Save. The system automatically generates a unique 8-character code associated with your card.
- Share the code along with your link or QR, through whichever channel you prefer. The code doesn't travel inside the QR itself, so you can distribute the QR widely β print it, put it on a storefront, send it by email β and give the code only to those who need it.
- Regenerate the code whenever you want to revoke access from someone who already had it. Your URL and QR don't change β only the old code stops working.
What it protects and what it doesn't
It's important to be honest about what this feature does: it's an access control for your card's public page, not end-to-end encryption or an identity management system. The code prevents someone without it from seeing your card's content when they enter through the URL, QR, or NFC. It doesn't verify who the person is β anyone with the correct code gets in, regardless of who they are β and it doesn't protect anything outside the card itself: if someone takes a screenshot or forwards the code to a third party, that person can also access it.
In other words: the security code controls access distribution, not the identity of who accesses it. It's the right tool for "only those I decide should see it", not for "verifying that it's really you".
The protection applies the same way regardless of how someone arrives: through the direct link, scanning the QR, or tapping the NFC on their phone, they're always asked for the same code before seeing the content. And it only affects that specific card β if you have multiple cards in your account, activating the code on one doesn't change anything on the others.
The trade-off: no Google indexing
The security code and Google indexing are mutually exclusive by design, and this is verified directly in the code that decides which cards get indexed: a card with the code activated never gets indexed, regardless of whether you have "Appear in Google" enabled. It makes sense β a search engine can't index content that requires a code to view.
This aligns with how CardQR treats indexing in general: it's optional and comes disabled by default on any card, with or without a code. For a card to be indexed, you need to explicitly enable the toggle and also pass five minimum quality checks β photo, a description of at least 40 characters, company or position, at least one contact method, and at least one external link (website, social media, or a widget with a URL). Privacy and indexing are two deliberate axes of the product, not an oversight: you can have completely private cards, indexable cards, or both combinations at once across different cards.
This has an additional consequence worth knowing: by not being indexed, a card with a code also can't appear cited by AI assistants like ChatGPT or Perplexity, which rely on indexed content to answer questions about people and businesses. It's the same reason indexing matters on public cards β here, you're simply giving it up in exchange for privacy.
How to distribute the code in practice
- Private or invitation-only event: distribute the code only among confirmed attendees, for example in the confirmation email, leaving the access QR or general printed materials without it.
- Corporate template: if several employees use cards with the code activated, each person distributes their own code along with their own card β there's no need for a shared code for the entire company.
- Specific client: a card with terms, rates, or links that aren't for the general public β the code goes only to that client, separate from the link or QR.
In all three cases the pattern is the same: the link or QR can be distributed through whatever channel you'd already use β a slide, a poster, an email signature β and the code is distributed separately, through a channel where you know who receives it: a personal email, a direct message, an in-person conversation. Mixing the two channels β putting the code next to the QR on the same poster, for example β defeats the purpose of having it.
When to regenerate it
Regenerating the code doesn't change your URL or force you to reprint anything β it just invalidates the previous code. It makes sense to do it when:
- Someone who had access leaves the company or project.
- The event or promotion for which you distributed the code has ended.
- You suspect the code has been forwarded beyond who you authorized.
Scenario: code or no code?
| Scenario | Code? | Why |
|---|---|---|
| General networking card | No | The easier to share and index, the better β the code would prevent that |
| Company internal directory | Yes | Only those with the code should see it, not anyone with the link |
| Executive profile with direct contact info | Yes | Control over who can reach that contact |
| Private or invitation-only event | Yes | Only confirmed attendees should have access |
| Product card you want to rank in Google | No | The code blocks indexing completely |
Works with all other features
Activating the security code doesn't disable anything else: a protected card can still have Lead Capture active, or widgets for bookings, video, or PDF. The code restricts who can view the card; once inside, the rest of the features behave just like on any other card.
And if you need both things at once β a public part you want found in Google and a private part that only those you decide should see β the solution isn't to choose just one card, but to use two: you can have several cards in your account, each with its own URL, and apply the security code only to the one that needs it.
Frequently asked questions
Can I change the code later? Yes, regenerate it whenever you want from the same security settings section.
Does my QR change when I regenerate the code? No. Your card's QR and URL stay the same; only the previous code stops working.
Does it appear in Google search results? No, never, while the code is active β it's incompatible with indexing by design, regardless of whether you have "Appear in Google" enabled.
Can it give access to multiple people at once? Yes. The same code works for everyone who receives it; there's no usage limit or different codes per person.