Australian-developed encryption for government, critical infrastructure and enterprise Australian-developed · Sydney Confidential briefings available

Security architecture

A public overview of the QES control model.

This page explains how QES approaches access, file protection, transfer, restoration and software operations at a level suitable for public review. Detailed implementation material is available only through controlled technical due diligence.

The public model

Four operating states. One controlled workflow.

QES is designed around a clear progression: an authorised user enters the workflow, protects the selected information, moves protected output through approved channels and restores the original only where legitimate use requires it.

This model allows teams to understand responsibilities and deployment fit without exposing proprietary engineering decisions or release-specific security configuration.

AuthoriseProtectMoveRestore
Authorised accessProtected movementControlled restorationOperational policy

Architecture layers

Security outcomes are reinforced across the lifecycle.

The public architecture is described as a set of control layers rather than a diagram of internal implementation.

01

User and organisational control

Authentication, authorisation, roles, procedures and accountable operation define who may use QES and for what purpose.

02

Application security

QES clients enforce the supported workflow, input handling, protected-file operations and release-specific safeguards.

03

Protected information

The QES file format and associated controls are designed to preserve confidentiality and detect unauthorised alteration.

04

Operational integrity

Build, release, distribution, update, support and administrative processes are treated as security-relevant functions.

05

Assurance and improvement

Testing, review, vulnerability reporting, customer evidence and independent scrutiny inform corrective action and future releases.

Deployment surfaces

Different operating environments. Consistent product intent.

Each QES surface is engineered for the capabilities and constraints of its environment. Functions are not assumed to be identical where the platform does not support identical operational behaviour.

WindowsDesktop

Operational depth

Supports large, repeatable and managed file workflows suited to a desktop environment.

BrowserWeb

Controlled accessibility

Provides focused protection and restoration functions within browser security and performance boundaries.

AndroidMobile

Field mobility

Extends authorised QES file handling to supported Android devices and mobile operating contexts.

Shared responsibility

QES strengthens file protection. Secure operation remains a joint discipline.

A defensible deployment combines QES with strong organisational controls across people, devices, identity, infrastructure, recovery and governance.

QES responsibilities

Provide the supported product and security lifecycle

  • Maintain supported QES software and protected-file compatibility
  • Operate defined release, update, support and vulnerability processes
  • Provide applicable product guidance and controlled assurance material
  • Address confirmed product security issues through the established response path
Customer responsibilities

Operate QES within a secure organisational environment

  • Protect identities, devices, credentials and authorised user access
  • Maintain backup, recovery, retention and incident-response arrangements
  • Define approved workflows, information handling rules and user procedures
  • Deploy supported releases and apply updates in accordance with guidance

Controlled technical review

Detailed architecture is provided where it can be evaluated responsibly.

Qualified customer security teams, government assessors, procurement reviewers and independent specialists may request deeper technical material under appropriate confidentiality arrangements.

Review scope is matched to the actual decision—such as product selection, pilot approval, integration planning or independent assurance—so evaluators receive relevant evidence without creating an unnecessary public disclosure surface.

Request architecture due diligence
Executive architectureBusiness outcome, operating model and responsibilities
Public + briefing
Security architectureRelease-relevant design and control evidence
Controlled
Implementation reviewQualified examination tied to an agreed scope
Under NDA
Independent assessmentEngagement-specific coordination and evidence
Scope-based

Go deeper under control

Tell us the decision your review must support.

QES will align the architecture briefing and technical material to the evaluator, scope and confidentiality requirements.

Encrypt everything.