Enter the QES workflow
The user authenticates and accesses the functions permitted for their account and operating context.
How QES works
QES inserts a controlled protection step before sensitive files enter shared infrastructure, then restores those files only for authorised use at the destination.
The four-stage workflow
The public model explains what users and organisations can expect. Release-specific technical detail is handled through qualified due diligence rather than published as an implementation recipe.
The user authenticates and accesses the functions permitted for their account and operating context.
The selected file or folder is converted into a QES-protected form before onward transfer or storage.
The protected output can travel through existing email, cloud, portal, collaboration or archival channels.
An authorised QES user restores the original content when it is required for legitimate work.
Authorised userApproved channelAuthorised recipientProtected fileWhat changes—and what does not
Organisations keep their established storage, email, collaboration, portal and archival systems. QES changes the condition in which sensitive files enter those systems.
What users experience
The controls presented to each user depend on the QES operating surface and the functions enabled for their role.
QES verifies the user before protected-file operations become available.
The user chooses the information to protect or restore using the functions available on desktop, web or Android.
QES presents status and completion information so the user can confirm the outcome before proceeding.
The protected output can be sent, uploaded, stored or archived using the organisation's normal channel.
How organisations adopt QES
Select the information class, user group and workflow where stronger file protection matters most.
Agree the security, usability, performance, support and evidence outcomes the evaluation must demonstrate.
Test representative files and operating conditions with named owners, support channels and review points.
Document the deployment scope, procedures, responsibilities, software lifecycle and expansion plan.
Technical due diligence
Release-specific implementation detail, hardening procedures and other sensitive evidence are provided through a controlled review process that protects both the evaluator and the product.
Qualified customer, government and independent-review teams can request controlled technical material under appropriate confidentiality arrangements. The scope is tailored to the procurement or assurance question being evaluated.
Request technical due diligenceSee QES in context
We will map the QES operating model to the people, systems and approval points involved.
Encrypt everything.