Security for Sensitive Investigations.

Keep sensitive casework in the right hands, with access controls, encrypted data, and backups in two US locations.

Illustrative case folder with an attached access sheet listing three fictional people: Maya Chen is the owner, Alex Rivera is a contributor, and Sam Patel is a viewer.

Choose Who Can See Each Case.

Case-level permissions let you choose who can contribute and who can only view. For especially sensitive work, compartments add an extra access restriction to keep the investigation within an approved group.

Summary viewers follow the case description, library details, and top-level attachments. This role provides an overview without opening the underlying case file.

Our own staff need authorization and multi-factor authentication (MFA) for remote access to customer data or production systems. We review that access regularly.

  • Your Organization’s Sign-In, Included

    Single sign-on is available on request to every customer at no additional cost. Use your organization’s identity provider, or nQuest’s passwordless sign-in.

  • Visibility into Data Access

    Your account administrators can review security activity in nQuest’s audit log, including access to your data by our staff. Entries show who acted, what they did, and when.

Keep Your Work Protected.

Your data is encrypted in transit and at rest: protected while it travels between systems and while it is stored, including backup copies.

Your case data is yours. We protect its confidentiality under our Terms of Service.

Prevent accidental deletion with optional protection across your library. Archive completed cases and return to them when a new question arises.

US-Based Companies and US Hosting.

All companies we use to process customer data are based in the United States.

Our cloud services run in Oregon and Ohio, United States, with managed database storage in Oregon. Your data is backed up in Oregon and copied to Ohio for long-term storage.

External AI services have their own processing locations.

Security Built into How We Work.

Documented security procedures guide how we develop nQuest, release updates, and respond to vulnerabilities.

  • Signed, Traceable Releases

    Desktop releases are digitally signed, and our builds meet SLSA Build Level 2. Signed build records let your IT team check where a release came from.

  • Regular Checks and Prompt Fixes

    Automated security scans and monthly reviews of third-party software help us identify vulnerabilities. Urgent risks receive fixes outside our normal update schedule, with customer advisories when action is needed.

  • Adversarial Testing with AI

    We regularly use AI to test nQuest from an attacker’s perspective, identify security weaknesses, and strengthen our defenses.

  • Built by Experienced Engineers

    Our engineers bring Silicon Valley experience to the design, development, and security of nQuest. Developers receive secure coding training, and all staff receive annual security training. We keep production customer data out of development and test environments.

Questions Worth Asking.

Can we use our organization’s sign-in?

Yes. Single sign-on (SSO) is available on request to every customer at no additional cost. Your team can use your organization’s identity provider. nQuest also offers passwordless sign-in.

What can our administrators see in the audit log?

Account administrators can filter recorded activity by date, user, and action. Entries show the time, user, action, and related case or resource, and identify activity by nQuest staff. You can export the records as CSV for your own security reviews.

What technical protections are in place?

We encrypt sensitive data in transit and at rest, including backups. Public services use HTTPS with TLS, redirect HTTP to HTTPS, and use HSTS to keep compatible clients on secure connections. API responses send Cache-Control: no-store to instruct browsers and proxies not to cache returned data.

How do you protect software releases?

Windows and macOS releases are digitally signed, and macOS installers are notarized by Apple. Our builds meet SLSA Build Level 2, with signed records of the source and build process. Application credentials stay out of source code in dedicated secret stores; cloud configuration secrets use KMS encryption.

How quickly are security issues fixed?

We prioritize vulnerabilities that materially affect security for the next two-week release cycle. Our policy requires patches within 90 days of discovery, with out-of-cycle hotfixes for active exploitation or significant risk.

What happens if there is a security breach?

If a breach affects sensitive information, we notify affected parties within 72 hours of discovery and share updates as we learn more. When customers need to take action, we send a security advisory.

Can you help with our security review?

Yes. We can provide a production-like test environment for your team or a security partner, with no production data. Contact us to agree the testing scope. We also assess the companies that process customer data on our behalf annually and make our current subprocessor list available on request.

Talk Security with Our Team.

Ask about data handling, review our controls, or arrange security testing with your team or a specialist you choose.