Australian-developed encryption for government, critical infrastructure and enterprise Australian-developed · Sydney Confidential briefings available

Assurance and independent review

Evidence matched to the decision and deployment scope.

QES uses a staged assurance model that combines engineering verification, customer due diligence and appropriately scoped independent review. Sensitive reports and implementation evidence are handled through controlled channels.

The QES assurance model

Progressive scrutiny from engineering evidence to independent assessment.

The assurance level required for an evaluation depends on the information consequence, deployment context, customer policy and procurement stage.

Layer 1

Engineering verification

Release-relevant checks, review records and test evidence produced within the product development lifecycle.

Layer 2

Customer due diligence

Architecture briefings, product demonstrations, workflow evidence and responses to security and procurement questions.

Layer 3

Specialist review

Independent examination commissioned against an agreed product, release, method and reporting scope.

Layer 4

Operational assurance

Deployment evidence covering process, support, change, response and the customer's actual operating environment.

Controlled evidence

Detailed reports belong in a protected review process.

Independent reports, technical evidence and release-specific findings can contain information that should not be indexed publicly. QES provides applicable material to qualified evaluators under appropriate confidentiality, access and use restrictions.

  • Evidence is tied to the product and release actually examined
  • Findings are considered together with remediation and residual context
  • Distribution is limited to people with a legitimate evaluation need
  • Public claims are made only where the evidence supports public use
QES official logo

Review categories

Assurance is built around the question being asked.

A procurement decision may require several forms of evidence. QES works with the evaluator to define the scope, method, release and intended reliance before a review begins.

Product security reviewApplication behaviour, attack surface and release-relevant controls
Scope-based
Cryptographic implementation reviewQualified examination of the implemented security profile
Controlled
Penetration and misuse testingAdversarial testing against defined products and environments
Engagement-based
Build and release reviewIntegrity, provenance and software-delivery controls
Evidence-based
Operational and governance reviewProcedures, support, change and customer-facing responsibilities
Deployment-based

How a review is commissioned

Define the reliance before choosing the test.

The most useful assurance engagement begins with the decision the report must support.

01

Set the objective

Identify the procurement, deployment or risk decision that requires independent evidence.

02

Fix the scope

Record the product surface, release, environment, methods, exclusions and report recipients.

03

Select the reviewer

Use a qualified specialist with the independence and technical capability appropriate to the question.

04

Review findings and action

Assess the report together with remediation, limitations, release changes and the intended deployment.

Public reporting: QES may publish an assurance summary when publication is appropriate, contractually permitted and useful to customers. A public summary will identify the assessed scope and date so it is not mistaken for a blanket statement about every product, release or deployment.

Assurance planning

Tell us what your organisation must be able to rely on.

QES will help define the evidence package, confidentiality controls and independent-review scope appropriate to the decision.

Encrypt everything.