---
title: Security engine | Qventis One
description: "The security engine runs on the Qventis Engine: plain-English checks for sign-in, sessions, headers, secrets and roles."
---

[Skip to content](https://qventis.ai/engines/security#main)

[![qventis](https://qventis.ai/hubfs/raw_assets/public/qventis-one/images/qventis-logo.svg)![qventis](https://qventis.ai/hubfs/raw_assets/public/qventis-one/images/qventis-logo-reverse.svg)](https://qventis.ai/?hsLang=en)

- Platform
  
  [**Qventis Engine**The core of the platform. Automate any app, any stack, in plain English, with zero AI tokens at run time.WebDesktopTerminalAPIDataOne plain-English suite](https://qventis.ai/engine?hsLang=en)
  
  Platform
  
  [**Qventis One**The engine, scaled to one pane of glass](https://qventis.ai/one?hsLang=en) [**Release Intelligence**Every vendor change, mapped to your processes](https://qventis.ai/release-intelligence?hsLang=en) [**App Model**One model of your app, learned once](https://qventis.ai/one/app-model?hsLang=en) [**Quality View**Evidence and a signed go or no-go](https://qventis.ai/one/quality-view?hsLang=en)
  
  Automation
  
  [**Studio**Anyone can automate, in plain English](https://qventis.ai/platform/studio?hsLang=en) [**Eight engines**Functional to accessibility in one flow](https://qventis.ai/one#engines) [**Integrations**CI, ALM, chat and coding agents](https://qventis.ai/platform/integrations?hsLang=en) [**Trust and security**AI on your terms, people approve](https://qventis.ai/platform/trust?hsLang=en)
  
  How it works[Detect](https://qventis.ai/release-intelligence?hsLang=en)→[Assess](https://qventis.ai/one/app-model?hsLang=en)→[Automate](https://qventis.ai/engine?hsLang=en)→[Assure](https://qventis.ai/one/quality-view?hsLang=en)
- [Release Intelligence](https://qventis.ai/release-intelligence?hsLang=en)
- Platforms
  
  [**Release in confidence**Certify every vendor update and configuration change before your business feels it.PreviewTestProdNextImpact known before the window opens](https://qventis.ai/platforms?hsLang=en)
  
  Enterprise platforms
  
  [**Oracle**Quarterly updates](https://qventis.ai/platforms/oracle?hsLang=en)[**Workday**R1 and R2](https://qventis.ai/platforms/workday?hsLang=en) [**SAP**S/4HANA releases](https://qventis.ai/platforms/sap?hsLang=en)[**Salesforce**Three a year](https://qventis.ai/platforms/salesforce?hsLang=en) [**ServiceNow**Family releases](https://qventis.ai/platforms/servicenow?hsLang=en)[**Dynamics 365**Release waves](https://qventis.ai/platforms/dynamics-365?hsLang=en) [**nCino**Two calendars](https://qventis.ai/platforms/ncino?hsLang=en)[**Coupa**Major releases](https://qventis.ai/platforms/coupa?hsLang=en) 
  
  [**All 40+ platforms**ERP, HCM, CRM, ITSM, banking, insurance](https://qventis.ai/engines/packaged-apps?hsLang=en)
  
  By need
  
  [**Release testing**Test only what a change affects](https://qventis.ai/solutions/release-testing?hsLang=en) [**Industries**Regulated and complex businesses](https://qventis.ai/industries?hsLang=en) [**Legacy desktop**Apps automation never reached](https://qventis.ai/solutions/legacy-desktop?hsLang=en) [**Quality CoE**One standard across the business](https://qventis.ai/solutions/quality-coe?hsLang=en)
  
  Certify an upgrade[Release notes in](https://qventis.ai/release-intelligence?hsLang=en)→[Impact traced](https://qventis.ai/release-intelligence?hsLang=en)→[Tests run](https://qventis.ai/engine?hsLang=en)→[Signed off](https://qventis.ai/one/quality-view?hsLang=en)
- Resources
  
  [**Brochures and guides**Platform briefs sent to your inbox](https://qventis.ai/resources?hsLang=en) [**Customers**How teams release in confidence](https://qventis.ai/customers?hsLang=en) [**Blog**Field notes on releases, quality and AI](https://qventis.ai/blog?hsLang=en) [**Editions**Start with one need, grow into One](https://qventis.ai/editions?hsLang=en) [**Support**Guides and community for customers](https://qventis.ai/support?hsLang=en)
- Company
  
  [**About qventis**Why we built one platform](https://qventis.ai/about?hsLang=en) [**Trust center**How we protect your data](https://qventis.ai/platform/trust?hsLang=en) [**Contact**Talk to a person](https://qventis.ai/contact?hsLang=en)
  
  Talk to usSend a request

Search platforms, releasesCtrl K

[Book a demo](https://qventis.ai/contact#demo)

[Qventis One](https://qventis.ai/one?hsLang=en)/Engines/Security

Security engine

# Catch security regressions before the pen test does

The security engine runs on the Qventis Engine. Every build checks sign-in, sessions, headers, secrets and permissions in plain English, on the same roles and screens your functional tests already reach, desktop and terminal included.

[Book a demo](https://qventis.ai/contact#demo)[See trust and security](https://qventis.ai/platform/trust?hsLang=en)

- No separate security suite
- Role matrix built for you
- Zero AI tokens at run time

**Viewers can't reach payroll admin**Security, 5 steps

1. Use the 'Sign in as viewer' flow
2. Open the 'Payroll admin' screen
3. Check that access is denied for role 'Viewer'
4. Check that header 'Strict-Transport-Security' is present
5. Check that the session ends after 15 minutes idle

## The quiet changes that open gaps

### Every build, not yearly

A new screen without a permission check or a debug header left on is caught on the next run.

### Roles defined once

The engine reads your roles from the App Model, so a new screen gets its permission checks the day it is added.

### Secrets stay vaulted

Steps name a secret by reference. Values come from your vault at run time and evidence redacts them.

## How the security engine works

ChecksSessions, headers, secrets, roles

Role matrixWho may reach what

SecretsReferences, never values

One model, one paneShared roles, one results view

### What gets checked

Most security regressions are ordinary changes. These checks run wherever your tests already go.

- Logout ends the session, idle timeouts hold and old tokens are refused
- Required headers such as Content-Security-Policy appear on every tested page
- Keys, tokens and passwords are flagged in pages, API bodies or headers
- Each role sees what it should and is refused what it shouldn't

[Runs inside functional tests](https://qventis.ai/engines/functional?hsLang=en)

### A matrix from your roles

The engine builds checks for every role against every screen and API it knows about.

| Screen or API | Viewer | Clerk | Manager |
| --- | --- | --- | --- |
| Edit employee | Denied | Allowed | Allowed |
| Payroll admin | Denied | Denied | Allowed |
| GET /payroll/runs | Denied | Allowed | Allowed |

[Roles in the App Model](https://qventis.ai/one/app-model?hsLang=en)

### Secrets by reference

A step never holds a password, key or token. It names the secret, and the value is fetched at run time.

- Values come from your vault, never from the test
- Screenshots and logs redact secret values, so evidence is safe to share
- Secret access follows role-based access and audit

[Trust and security](https://qventis.ai/platform/trust?hsLang=en)

### One picture for release

Roles and screens are defined once in the [App Model](https://qventis.ai/one/app-model?hsLang=en), and findings map back to them.

- Findings land in [Quality View](https://qventis.ai/one/quality-view?hsLang=en) next to functional results from the same run
- Nobody merges three reports before a release meeting

[Explore Quality View](https://qventis.ai/one/quality-view?hsLang=en)

## Questions

Does this replace a penetration test?

No. It catches regressions in the controls you have on every build. Keep penetration tests and dedicated tools for depth.

Who can read the results?

Anyone on the release team. Each check is a sentence with a pass or a fail, mapped to its screen and role.

## See your access rules checked every build

Bring the roles and screens that worry you most, and leave with checks running against them.

[Book a demo](https://qventis.ai/contact#demo)

Get the brief

[![qventis](https://qventis.ai/hubfs/raw_assets/public/qventis-one/images/qventis-logo.svg)![qventis](https://qventis.ai/hubfs/raw_assets/public/qventis-one/images/qventis-logo-reverse.svg)](https://qventis.ai/?hsLang=en)

[Support](https://qventis.ai/support?hsLang=en)[Trust](https://qventis.ai/platform/trust?hsLang=en)[Privacy and terms](https://qventis.ai/legal?hsLang=en)Contact

© 2026 qventis.aiThird-party product names are trademarks of their respective owners.