Designed to earn access to sensitive telemetry.
Qestrel uses narrow, read-only connections to collect cryptographic metadata. Private keys, secrets and plaintext remain in your systems.
Least privilege by design.
- Metadata only
No keys or plaintext
Qestrel processes algorithms, certificates, configurations and related inventory metadata, not private keys or customer plaintext.
- Read only
Narrow API scopes
Integrations use the smallest read-only permissions needed and cannot alter or delete connected systems.
- Revocable
Controlled credentials
Connection credentials are encrypted, scoped per connection and revocable at any time, with activity available for review.
- No agents
Nothing deployed to endpoints
API-based connections avoid adding endpoint software or an unnecessary operational footprint.
From your tools to your report, and nothing more.
Read-only connection
You grant Qestrel the narrowest read-only API scope that does the job. No agents, no inbound access to your network.
Metadata only
Qestrel reads cryptographic metadata: algorithms, certificates, configurations. Keys, secrets and plaintext never leave your systems.
Held in the UK
Inventory data is stored and processed in the United Kingdom, and access can be revoked by you at any time.
Prepared for enterprise review.
All data stored & processed in the UK
UK government-backed baseline
Personal data processed lawfully
Actively working towards certification
The materials your procurement team will ask for.
Request the security pack and we can share the documentation assurance teams need before any production connection is approved:
- Read-only scope matrix
- Data processing summary
- Architecture overview
- Audit logging model
- Credential handling notes
- Security pack on request
Found a security issue? Email ben@qestrel.co.uk and we will respond promptly.
