Security & trust

Trust begins with precise claims.

QEP is being built for sensitive engineering environments. We communicate what is designed, planned and implemented without substituting aspiration for evidence.

Security approach

Controls shaped around engineering data.

Authentication

Designed to support centrally managed identity and appropriately scoped access.

Tenant isolation

Customer boundaries are a core architectural concern. Isolation controls will be documented as deployment architecture is finalised.

Encryption

Designed to support encryption in transit and at rest using managed cloud capabilities.

Repository access

Access is intended to be least-privileged, explicit and limited to the analysis required.

Secrets

Credentials and tokens should be held in managed secret stores—not source code or browser-delivered configuration.

Retention & deletion

Retention and deletion controls are being defined for enterprise deployment and will be communicated transparently.

Auditability

Evidence provenance and traceable engineering actions are foundational product principles.

Optional AI

AI-assisted investigation is optional. Deployment-specific data handling will be disclosed before use.

Source-code handling

Proprietary source is sensitive; access and processing paths are designed to be minimised.

Deployment direction

Designed to support enterprise deployment patterns.

Future deployment options may include customer-hosted edge capabilities where appropriate. Availability, scope and security properties will be documented only when implementation is ready.

Have a security question?

We welcome direct, technical conversations about QEP’s architecture and the controls relevant to your environment.

Contact Mclasa