User and organisational control
Authentication, authorisation, roles, procedures and accountable operation define who may use QES and for what purpose.
Security architecture
This page explains how QES approaches access, file protection, transfer, restoration and software operations at a level suitable for public review. Detailed implementation material is available only through controlled technical due diligence.
The public model
QES is designed around a clear progression: an authorised user enters the workflow, protects the selected information, moves protected output through approved channels and restores the original only where legitimate use requires it.
This model allows teams to understand responsibilities and deployment fit without exposing proprietary engineering decisions or release-specific security configuration.
Authorised accessProtected movementControlled restorationOperational policyArchitecture layers
The public architecture is described as a set of control layers rather than a diagram of internal implementation.
Authentication, authorisation, roles, procedures and accountable operation define who may use QES and for what purpose.
QES clients enforce the supported workflow, input handling, protected-file operations and release-specific safeguards.
The QES file format and associated controls are designed to preserve confidentiality and detect unauthorised alteration.
Build, release, distribution, update, support and administrative processes are treated as security-relevant functions.
Testing, review, vulnerability reporting, customer evidence and independent scrutiny inform corrective action and future releases.
Deployment surfaces
Each QES surface is engineered for the capabilities and constraints of its environment. Functions are not assumed to be identical where the platform does not support identical operational behaviour.
Supports large, repeatable and managed file workflows suited to a desktop environment.
Provides focused protection and restoration functions within browser security and performance boundaries.
Extends authorised QES file handling to supported Android devices and mobile operating contexts.
Shared responsibility
A defensible deployment combines QES with strong organisational controls across people, devices, identity, infrastructure, recovery and governance.
Controlled technical review
Qualified customer security teams, government assessors, procurement reviewers and independent specialists may request deeper technical material under appropriate confidentiality arrangements.
Review scope is matched to the actual decision—such as product selection, pilot approval, integration planning or independent assurance—so evaluators receive relevant evidence without creating an unnecessary public disclosure surface.
Request architecture due diligenceGo deeper under control
QES will align the architecture briefing and technical material to the evaluator, scope and confidentiality requirements.
Encrypt everything.