Australian-developed encryption for government, critical infrastructure and enterprise Australian-developed · Sydney Confidential briefings available

Security

Security built for scrutiny—with disclosure on the right terms.

QES publishes the principles, reporting channels and assurance framework customers need to evaluate our posture. Sensitive implementation detail is reserved for controlled review by qualified parties.

Security principles

The public commitments behind the QES product direction.

These principles describe the outcomes QES is engineered to support without exposing the implementation detail that belongs in a confidential technical review.

Protect before movement

Sensitive files should be protected before they are handed to shared services, transfer channels or downstream platforms.

Authorise meaningful operations

QES file operations are designed to begin only within an authenticated and authorised user workflow.

Preserve confidentiality and integrity

Protection must address both unauthorised reading and unauthorised modification of the information being handled.

Minimise unnecessary exposure

System design should avoid collecting, retaining or revealing sensitive material that is not required for the service outcome.

Control the software lifecycle

Build, release, update and support processes are treated as part of the security boundary—not as routine administration.

Respond to evidence

Security findings, customer feedback and independent review should drive traceable remediation and product improvement.

Cryptographic direction

Designed for current protection requirements and the post-quantum transition.

QES follows a standards-based cryptographic engineering approach and is designed to support organisations planning for long-term data confidentiality. The product direction accounts for both established threats and the migration pressures created by quantum-capable adversaries.

Release-specific cryptographic profiles, implementation choices and supporting evidence are not published as marketing content. They are discussed with qualified evaluators under confidentiality controls appropriate to the engagement.

Standards-based directionMigration-aware designControlled evidence
QES official logo

Security information model

Public where it helps. Restricted where disclosure creates risk.

Transparency and security are not opposites. The right approach is to publish what customers need to understand the product while protecting details that would reduce defensive advantage or disclose proprietary implementation.

Public

Security posture and process

Product principles, high-level architecture, reporting instructions, advisory notices, privacy material and assurance framework.

Controlled

Detailed technical review

Release-specific design, configuration, implementation evidence, hardening detail and other sensitive material for qualified evaluation.

Security lifecycle

Security does not end when code compiles.

The QES security programme spans product decisions, implementation, release control, deployment support, reporting and remediation.

01

Design and threat analysis

Define the security outcome, intended operating context and risks that the release must address.

02

Implementation and verification

Apply engineering controls, testing and review appropriate to the change and its security consequence.

03

Controlled release

Package, approve and distribute supported software through a managed release path.

04

Operate, learn and improve

Use findings, support experience and assurance activity to strengthen subsequent releases and customer guidance.

Security resources

A clear path for evaluation, reporting and assurance.

The QES security and trust pages provide persistent locations for the information serious customers, researchers and procurement teams need.

Credibility comes from making the right evidence available to the right evaluator under the right controls.

That is the QES approach to security communication and technical due diligence.

Security and procurement

Request the level of review your decision requires.

QES can support executive, architecture, product-security and procurement discussions under appropriate confidentiality arrangements.

Encrypt everything.