← All products
Cloud Access Security · CISOs · IT & SecOps · Cloud admins

QAuth

Secure your cloud universe with Quantum Enhanced Encryption.

QAuth is a full-strength cloud access security broker (CASB) and integrated SSO platform designed to secure today's cloud-centric organizations across their SaaS applications, data, and users.

Capabilities

What QAuth ships with?

Access Control & SSO

Single sign-on with granular, policy-driven access control across every sanctioned SaaS application from one console.

CASB

Cloud access security broker coverage for Google Workspace, Microsoft 365, Slack, Atlassian Jira and Confluence, and other popular SaaS.

Data Loss Prevention (DLP)

Prevent data exfiltration and enforce enterprise data governance policies across cloud apps, users, and endpoints.

Email Security

Protect cloud mailboxes from phishing, account takeover, and inbound threats with policy-based email controls.

Zero Trust

Continuous verification of users, devices, and context before granting access to any SaaS resource.

Shadow IT visibility

Discover unsanctioned SaaS usage, quantify risk, and bring cloud activity under a single governance model.

Quantum Enhanced Encryption

Secure and protect data deployed via agents using quantum secure encryption keys.

Compliance & Governance

Support enterprise data governance, meet regulatory requirements, and maintain continuous compliance across cloud environments.

Heritage

Caretakers of your cloud security since 2011.

QAuth began life in 2011 with a single objective: bring innovative, agile cloud security to businesses worldwide. Today it is part of the QSE Corp family, pairing more than a decade of cloud access security broker (CASB) engineering with QSE's quantum-secure encryption stack.

QAuth gives enterprises the freedom to adopt cloud collaboration without inheriting cloud data risk. Gain complete visibility and control to reduce your threat surface, block known and unknown intrusions, and implement layered security across every sanctioned SaaS application.

QAuth is recognised by analyst firm Gartner as a sample vendor for Cloud Security and SaaS Security across multiple published reports, and operates as a SOC Type-II certified platform.

300+
Enterprise customers
200K+
Protected users worldwide
30+
Industries served
2011
Securing cloud since
Coverage

Broad security in one integrated SSO platform.

Protect your…

Support enterprise data governance, prevent attacks, and take action against threats and data loss in:

  • Google Workspace
  • Microsoft 365
  • Slack
  • Atlassian Jira and Confluence
  • Dropbox
  • Salesforce, Zoho, Zendesk and Freshdesk
  • Amazon Web Services workloads
  • Other popular SaaS applications

Use it for…

Deploy a simple, powerful spectrum of enterprise cloud security capabilities and services to enable:

  • Visibility
  • Compliance
  • Threat identification and protection
  • Access control
  • Data loss prevention (DLP)
  • Shadow IT discovery
  • Identity management and SSO
  • Quantum enhanced encryption

Serving…

End-to-end CASB services with unmatched data security and ease of deployment. Among others, we serve customers in:

  • Finance
  • Government
  • Pharmaceuticals
  • Media
  • Retail
  • Aviation
  • Healthcare
  • Education
  • Manufacturing
  • Logistics
  • Automobiles
  • Technology
  • Power
  • Travel
Security modules

Every control, in one console.

QAuth offers a control point for continuous visibility, compliance, threat protection, and cloud security. Collaborate without limits and work safely across cloud services, on any device, anywhere in the world.

Cloud apps offer the flexibility of data access from anywhere, any device, any time — and that flexibility can be misused. What if a user copies proprietary data after work hours and uses it after exit? Forgets to log out from a public machine? Connects an unofficial, malware-infected machine? QAuth Access Control gives companies macro-level visibility into data and user behaviour, letting them restrict unauthorised access while leaving enough freedom for smooth day-to-day work.

IP Restriction
Restrict user access to business data through one or more specified IP addresses only. Whitelist or blacklist for the entire organisation, an OU, or a single user. No firewall settings or local installation required.
Browser Restriction
Allow business data only from browsers the IT admin approves — Chrome, Firefox, Safari, Edge. Managed via the Chrome management console with organisational-unit granularity and automated rollout.
Device Restriction
Block access from unknown, public, or unauthorised devices using the device MAC ID. Policy violation reports are sent to the admin daily. Supports Windows, macOS, Linux, and Chromebook, with self-service rollout.
Geo-Fencing
Create virtual work boundaries so data cannot be reached from unidentified locations. Restrict by city or country, applied to one user, an OU, or the whole organisation. No additional apps required.
Time Restriction
Restrict access to defined workdays and hours — for example Monday to Friday, 9am to 5pm — so no suspicious activity happens in the small hours. Supports multiple time zones with no extra extension.
Session Timeout
Terminate idle sessions and cap total session duration so unattended machines cannot be used to reach corporate data.
Third-party App Blacklisting
Employees register for third-party apps with their corporate ID, handing over calendar and drive permissions. QAuth prevents sign-in to any third-party app unless the admin has whitelisted it — a preventive control rather than a post-breach revocation.
Domain Whitelisting
Define which external domains users may communicate and share with, and block everything outside that list.

Supported platforms

Protect the applications your business already runs on.

Google Workspace

Seamlessly secure Google Workspace and ensure compliance.

Take macro-level control and visibility over all enterprise data in Gmail, Google Drive, and Chromebook through flexible yet stringent cloud security policies, alerts, and reports. Industries from manufacturing and pharmaceuticals to finance, aviation, logistics, education, and retail rely on QAuth to keep Workspace data safe — whether a user forgets to log out on a public machine, mishandles sensitive data, shares documents with strangers, clicks a phishing link, transfers files to a personal drive, or authorises an unvetted third-party app.

  • Access Control — IP, browser, device, time, and geo-fencing restrictions
  • Data Loss Prevention across Drive, Gmail, and Chromebook
  • Single Sign-On with SAML and provisioning / de-provisioning
  • Identity Management with password policy, MFA, and biometrics
  • Consumer Gmail Block with auto-logout and admin notification
  • Shared Drive for team-owned documents and reclaimed drive space
  • Email Signature templating with custom fields and per-OU rollout
  • Value add-ons: custom login page, employer branding, broadcasts, agreements

Microsoft 365

Choose seamless security for your Microsoft 365 data.

Microsoft delivers a highly secure productivity platform, but Microsoft 365 security is a shared responsibility. QAuth adds user-behaviour analytics, cloud storage data protection and governance, and control over Shadow IT applications. Granular control offers automated workflow visibility — admin alerts, restraint of unauthorised tasks, access permission modification, and customised coaching messages for end users.

  • Access Control — browser, IP, login time, device, and geo-fencing policies
  • OneDrive DLP — block upload and download of confidential items
  • SharePoint DLP — govern sharing, downloading, and external exposure
  • Email DLP for Outlook with attachment containerisation
  • Single Sign-On and Identity Management
  • Integration with Active Directory and Azure AD as identity provider
  • Shadow IT discovery across sanctioned and unsanctioned services
  • Out-of-box compliance checks for PII, PCI, PHI, and HIPAA

Amazon Web Services

Continuous workload assessment against CIS benchmarks.

As AWS adoption grows it becomes a hurricane task to monitor every aspect of hosted infrastructure from a security perspective. QAuth provides continuous security assessment of AWS workloads against Center for Internet Security (CIS) benchmarks, monitoring S3 buckets, CloudTrail, IAM policies, IAM users, and Config in real time and alerting on threats and violations by email.

  • Real-time evaluation of AWS resources against CIS benchmarks
  • Coverage for IAM, CloudTrail, S3, and AWS Config
  • Access key created for admins to evaluate all hosted applications
  • Email alerts the moment a policy breach is detected
  • Reduces security risk and strengthens compliance posture

Dropbox

Govern enterprise data collaboration on Dropbox.

Extend visibility and granular control over Dropbox with best-in-class DLP and CASB technology. QAuth secures Dropbox by adding a control layer with native SSO and multi-factor authentication, plus contextual awareness of location, service, device, and content — coaching end users away from unsanctioned alternatives.

  • Access Control
  • Data Loss Prevention
  • Single Sign-On
  • Identity Management
  • Shadow IT
  • Value Add-Ons

Slack

Security for internal and external teams and projects.

Slack accumulates a searchable log of every conversation inside the organisation, which makes it a high-value target. QAuth configures Slack across domains and blocks malicious attempts at data theft and leakage, with admin control over application authorisation, certificate downloads, and domain/user email mapping. Policy violations resolve through the single sign-on end-user dashboard.

  • Access Control
  • Single Sign-On
  • Identity Management
  • Shadow IT

Atlassian Jira & Confluence

Secure project management and proprietary data.

Jira sends critical issue and roadmap data to the cloud, often without security protocols attached. QAuth implements a robust control set for Jira and Confluence, delivering security analytics, live data monitoring, and audit logs, with selective encryption of Jira and Confluence content so only authenticated, entitled users can open confidential files.

  • Access Control
  • Single Sign-On
  • Identity Management
  • Shadow IT

Salesforce

Best-in-class CRM security for your enterprise.

QAuth applies an API connector to Salesforce to protect enterprise data without impacting the way users work — real-time data security checks and granular controls to prevent breaches while maintaining visibility across the CRM and its service platform.

  • Access Control
  • Single Sign-On
  • Identity Management
  • Shadow IT
  • Value Add-Ons

Zoho

Strong safety across the complete Zoho account.

Protect the Zoho online suite and every SaaS program your business runs on it — CRM, Email, HR, marketing, and address book — so online productivity stays safe and secure.

  • Single Sign-On
  • Access Control
  • Identity Management
  • Shadow IT
  • Value Add-Ons
  • Additional security for GST-compliant Zoho Books

Zendesk

Protect customer service data end to end.

Bring CASB controls to Zendesk so support conversations, customer records, and ticket attachments stay inside your security perimeter.

  • Single Sign-On
  • Access Control
  • Identity Management
  • Shadow IT

Freshdesk

Secure helpdesk operations without slowing them down.

Apply the same access, identity, and DLP policy framework across Freshdesk that governs the rest of your SaaS estate.

  • Single Sign-On
  • Access Control
  • Identity Management
  • Shadow IT

Chromebook

Defence in depth for Chrome OS fleets.

Chromebook works on the principle of defence in depth — if one layer is bypassed the remaining layers still hold. QAuth adds a cloud data protection layer through DLP standards, giving depth of visibility and control so officials can detect, track, and block information breaches whether data is in use, at rest, or in transit.

  • Agent-based and agentless deployment models
  • Track / block download, delete, print, and screenshot
  • Block clipboard operations out of Drive documents
  • External sharing controls with blacklisted domains
  • Personal Gmail block on company-owned devices

Education

Cloud security purpose-built for schools and universities.

Institutions running Google Workspace for Education use QAuth to keep student and faculty data governed, restrict access outside campus hours and networks, and satisfy regulatory obligations without adding administrative burden.

  • Access Control
  • Data Loss Prevention
  • Single Sign-On
  • Identity Management
  • Shadow IT
Admin feature set

Login, identity, and control features available to administrators.

Login features
  • Custom login page
  • Landing pages
  • Email agreement
  • Login broadcast
Identity features
  • Dashboard and reports
  • Password policies
  • Forgot password / self-service reset
  • Two-factor authentication
  • Active Directory integration
Control features
  • Browser restriction
  • IP restriction
  • Domain whitelisting
  • Device restriction
  • Consumer Gmail block
  • Time restriction
  • Third-party application block
  • Session timeout
AWS workload continuous assessment

Continuous CIS benchmark assessment for AWS workloads.

QAuth monitors AWS resources — S3 buckets, CloudTrail, IAM policies, IAM users, and Config — against Center for Internet Security benchmarks, evaluating resources in real time and alerting administrators by email the moment a threat or violation appears.

Category
IAM
  • Avoid the use of the "root" account
  • Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password
  • Ensure credentials unused for 90 days or greater are disabled
  • Ensure access keys are rotated every 90 days or less
  • Ensure IAM password policy requires at least one uppercase letter
  • Ensure IAM password policy requires at least one lowercase letter
  • Ensure IAM password policy requires at least one symbol
  • Ensure IAM password policy requires at least one number
  • Ensure IAM password policy requires a minimum length of 14 or greater
  • Ensure IAM password policy prevents password reuse
  • Ensure IAM password policy expires passwords within 90 days or less
  • Ensure no root account access key exists
  • Ensure MFA is enabled for the "root" account
  • Ensure hardware MFA is enabled for the "root" account
  • Ensure security questions are registered in the AWS account
  • Ensure IAM policies are attached only to groups or roles
  • Ensure a support role has been created to manage incidents with AWS Support
  • Do not set up access keys during initial user setup for all IAM users that have a console password
  • Ensure IAM policies that allow full "*:*" administrative privileges are not created
Category
CloudTrail
  • Ensure CloudTrail is enabled in all regions
  • Ensure CloudTrail log file validation is enabled
Category
S3
  • Ensure the S3 bucket used to store CloudTrail logs is not publicly accessible
  • Ensure S3 bucket access logging is enabled on the CloudTrail S3 bucket
Category
Config
  • Ensure AWS Config is enabled in all regions
Why QAuth

Controls most CASB platforms leave out.

  1. 01Mapping user identities across directories — rarely offered by competing CASB vendors
  2. 02Time restriction and device restriction as first-class access control policies
  3. 03Geo-location fencing on both web and mobile access paths
  4. 04Enterprise-grade password policy with self-service reset and anti-phishing login control
  5. 05Personal Gmail block, session timeout, and session duration controls
  6. 06Agentless and agent-based Shadow IT discovery in the same platform
  7. 07Google Drive and Dropbox DLP covering download, share, delete, and desktop sync
  8. 08Email signature and shared folder add-ons included rather than sold separately
Pricing

Choose the plan that suits your estate.

Licensing is per user, per year. For customisation, volume, and partner pricing, speak to the QAuth team.

Cloud
Contact usper user / year
  • Single Sign-On
  • Identity Management
  • Multi-Factor Authentication
  • Integration with AD / LDAP
  • Access Control
Talk to us
Cloud DLP
Contact usper user / year
  • DLP for Google Drive
  • DLP for OneDrive
  • Gmail and Google Drive compliance
  • Web filtering
  • Everything in Cloud
Talk to us
Deployment

Agent-based, agentless, or both — configured in hours.

  1. Agent-based

    A lightweight agent on the end-user machine acts as a web proxy. Only traffic for monitored applications passes through it; everything else goes straight to the web. The agent stores none of the content it inspects. It enables sharing controls across OUs, delete and download tracking, external sharing control against blacklisted domains, personal Gmail block, and clipboard restrictions.

  2. Agentless

    QAuth polls cloud provider APIs — Google Drive, OneDrive, and others — for document events, allowing multiple policies for different user sets with action taken in near real time and nothing to install on the endpoint.

  3. Directory integration

    The SSO server sits in the same domain as Active Directory and acts as the authentication agent inside your network. Complex structures including multiple forests are supported, and users can be bound to a specific domain controller per location. Azure AD is supported as identity provider.

Recognition

Awards, recognitions, and customer proof.

  • Recognised by Gartner as a sample vendor for Cloud Security and SaaS Security
  • SOC Type-II certified platform
  • Gold medal from SoftwareReviews
  • Top 10 security solutions — Industry Era
  • Recommended for secure remote working environments
  • Exhibitor at Gartner Symposium and GITEX Technology Week
QAuth CASB solutions have given me peace of mind by empowering me with the ability to implement additional security to Google Apps for my organisation. I would recommend the cloud security solution to everyone who uses Google Workspace for work.
Hiral Pancholi · Director, packaging manufacturer
We have some very sensitive information that staff can access and so are very concerned about keeping it in house. Keeping staff productive while minimising the opportunities for negative actions against our organisation is why we chose QAuth. I feel a lot more secure having it onboard and highly recommend it.
John Smith · CEO & Founder, OnTax Accountants Ltd
Case studies

Proven across 19 industry deployments.

Every enterprise and every industry faces challenges unique to them. These engagements outline how QAuth helped enterprises overcome security challenges while using SaaS applications — without disturbing existing infrastructure or management.

Aviation
  • CASB solution for the aviation industry

    Crew and ground staff sign in from airports worldwide, so access was locked to approved devices, IP ranges and geo-fenced regions. Single sign-on with MFA replaced shared logins across ops and maintenance apps.

Healthcare
  • CASB solution for a healthcare segment

    Patient records in Google Drive and OneDrive were placed under DLP rules that block external sharing, downloads and desktop sync of identifiable data, with a full audit trail for compliance reviews.

  • Case study for the healthcare industry

    Shadow IT discovery surfaced unsanctioned cloud apps clinicians had adopted, which were then blocked or brought under managed access without disrupting patient-facing workflows.

Education
  • CASB solution for the education sector

    Time-based and browser restrictions kept student Workspace accounts usable in lab hours only, while a personal Gmail block stopped coursework and staff data leaving through consumer accounts.

  • CASB solution for a well-known university

    Tens of thousands of student and faculty identities were consolidated behind SSO with AD integration and self-service password reset, cutting helpdesk load without weakening login security.

  • Cloud security for the education sector

    Chromebook fleets were brought under browser and device restrictions, and unique landing pages routed students and staff to the right sign-in experience on a single Workspace domain.

Power
  • CASB for power quality and energy management

    Engineering teams at distributed generation sites were given device-bound access to cloud apps, so design and grid data stays reachable in the field but never on unmanaged endpoints.

Finance
  • CASB solution for the finance segment

    Access control policies enforced the segregation regulators expect: IP-restricted logins from branch networks, MFA on every privileged account, and reporting that maps to audit requirements.

  • Financial and stock broking giant

    A nationwide broking network standardised on SSO with AD integration, adding geo-fencing and login-time policy so branch staff can only trade from sanctioned locations during market hours.

Trading
  • CASB solution for the trading industry

    Login time windows aligned to market hours and session timeouts on idle terminals reduced the window for account misuse on dealing desks handling client order flow.

Pharmaceuticals
  • CASB solution for the pharmaceutical industry

    Research and trial documentation was protected with Drive DLP and quantum-secure encryption keys on agent-deployed data, keeping formulation IP inside a controlled group of collaborators.

KPO
  • Case study for the KPO industry

    Outsourced analyst teams handling client data were confined to office IPs and approved browsers, with email DLP blocking client deliverables from being forwarded outside the engagement.

Telecom
  • CASB solution for the telecom sector

    Subscriber and network configuration data was protected with role-aware access policies across a large distributed workforce, backed by dashboards showing who accessed what and from where.

Supply chain
  • CASB solution for a supply chain company

    Vendors and partners were granted scoped access to shared folders, with sharing, download and delete controls preventing pricing and contract documents from spreading beyond the intended parties.

Ecommerce
  • CASB solution for the ecommerce industry

    Customer and payment-adjacent data in SaaS tools was covered by DLP and blacklisting of risky apps, while MFA protected seasonal and contract staff accounts during peak trading.

Logistics
  • CASB solution for the logistics industry

    Depot and driver access was geo-fenced to operating regions and device-restricted on mobile, keeping consignment and routing data available on the road but out of reach if a handset is lost.

Automobiles
  • CASB solution for the automobile industry

    Design and supplier documentation shared between plants and dealer networks was governed by shared-drive controls, with agent-based encryption protecting files at rest on engineering machines.

Manufacturing
  • CASB solution for the manufacturing industry

    Plant floor and back-office users were separated by policy, so production schedules and process documents stay inside the corporate network while head office retains full cloud collaboration.

Technology
  • CASB solution for the IT industry

    Source code and client project data was defended with Shadow IT discovery, Drive and Dropbox DLP, and strict password policy across a fast-growing, largely remote engineering team.

Partner program

Build your cloud security practice on QAuth.

Partners choose QAuth because we build and deliver managed cloud services, with the solutions and support they need to simplify their customers' cloud requirements. Partner benefits increase as members reach each tier.

Premium ResellersMSP PartnersTechnology Partners

Premier Partner

For partners with superior sales and technical expertise in selling and supporting the QAuth product range. Premier Partners earn the most extensive range of benefits and discounts, and an exclusive direct relationship with QSE.

Reseller Partner

Access to online sales, marketing, training and education tools to build QAuth product knowledge and business, with immediate discounts and benefits from day one.

Sales benefits
  • Greater discounts at higher partner levels
  • Special pricing campaigns and incentives
  • Deal registration program with higher margins on registered opportunities
  • Protected leads program and qualified sales lead program
  • Volume discounts, sales collateral, and dedicated partner sales manager
Marketing benefits
  • Co-branding of promotional materials, free of charge
  • Use of QAuth partner logos and listing on the QSE website
  • Campaign promotional materials and partner newsletter
  • Customer reference and case study program
  • MDF program agreed case by case, plus joint PR opportunities
Technical benefits
  • Pre-launch product evaluations
  • Web-based technical training
  • QAuth knowledge base
  • Priority chat in the web chat portal
  • Dedicated named support contact
FAQ

Frequently asked questions.

Outcomes

What customers measure after deploying QAuth.

  • Unified visibility and compliance across sanctioned SaaS applications
  • Identify and neutralise cloud threats and insider data loss
  • Deploy enterprise-grade cloud security in a single integrated platform
Specifications
Category
Cloud Access Security Broker (CASB) + SSO
Supported apps
Google Workspace · Microsoft 365 · Slack · Jira · Confluence · other SaaS
Capabilities
Access Control · CASB · DLP · Email · Zero Trust · Shadow IT · Quantum Enhanced Encryption · Compliance & Governance
Industries
Finance · Government · Pharmaceuticals · Media · Retail · Aviation
Heritage
Founded 2011 · Recognised by Gartner · Part of the QSE Corp family