Q‑Tel for organisations

Your organisation.
Your identity.
Your trust model.

Q‑Tel combines hardware-bound identity, end-to-end encrypted communication and a protected vault. The enterprise platform with its own instance is being built on this foundation.

Available (pilot) In pilot operation today: iOS (TestFlight) and Android.

Private communication for organisations – built step by step
The Q‑Tel trust chain

Trust is not a feature.
It is the architecture.

From identity to confirmed action: every layer has a defined role in the security model.

01 / 05

Q Identity

Cryptographic identity instead of a phone number.

02 / 05

Trusted device

Keys in the device’s security chip.

03 / 05

Protected communication

End-to-end encrypted chats and calls.

04 / 05

Protected data

Vault with its own code, key only on the device.

05 / 05

Confirmed action

Approval with a dedicated key instead of a mere tap.

Why Q‑Tel

When everything depends on one platform, too much depends on it.

Standard platforms bundle communication, identity, administration and infrastructure. Q‑Tel separates these areas into controllable, connected layers.

Separate keys

Identity, approvals, communication and vault each have their own single-purpose keys.

Servers without plaintext

The server relays, verifies signatures and delivers – it never sees content or private keys.

More than a messenger

Communication, files and confirmed approvals in one trust model.

Architecture comparison

Two models. Different control.

A factual look at operating model and responsibility – not at blanket security promises.

Model A

Shared platform

InfrastructureShared platform environment
User baseManaged within the platform
PoliciesLimited by platform rules
IdentityPart of the shared ecosystem
Model B / Q‑Tel target

Own Q‑Tel instance Architecture goal

InfrastructureOwn instance with a defined operating model
User baseDetermined by the organisation
PoliciesOrganisation-specific rules and approvals
IdentityOwn trust model for users and devices

Model B describes Q‑Tel’s target for organisations. Today Q‑Tel runs as a shared pilot environment.

The Q‑Tel system

One platform. One shared trust model.

Every building block with its status – what you can use today, what is in preparation and what is a goal.

01 / iOS, Android

Q-ID & device identity

Account without phone number or e-mail. Device keys are created in the Secure Enclave or Android Keystore and never leave the device.

Limitation: StrongBox only on Android devices with a dedicated security chip; otherwise Keystore (TEE).

Available (pilot)
02 / iOS, Android

Chat & groups

End-to-end encrypted one-to-one and group chats. Group changes live in a signed chain that every member verifies itself. Delivery and read status.

Limitation: Delivery receipts in one-to-one chats only; on iPhones once Q-Tel is opened.

Available (pilot)
03 / iOS, Android

Calls

Encrypted voice and video calls that check the stored contact key before connecting.

Limitation: Call wake-up on Android uses Google services; without them calls only ring while the app is open.

Available (pilot)
04 / iOS, Android

Q Vault

Locally encrypted storage for photos, documents and notes with its own code. The key exists only on the device.

Limitation: No versioning, folders or roles – single-user storage.

Available (pilot)
05 / iOS, Android

Vault transfer

Send files from the vault encrypted to one contact – for that contact’s verified receiving key.

Limitation: No approval workflows, no multi-recipient packages.

Available (pilot)
06 / iOS, Android

Q-Verify

Sensitive actions are confirmed with a separate, biometrically protected approval key – the server can verify signatures but cannot forge them.

Available (pilot)
07 / Enterprise

Q Trust credentials

Make attributes and credentials verifiable with as little disclosure of personal data as possible.

Architecture goal
08 / Enterprise

Private AI

Answers and summaries on your own knowledge base within your own environment.

Architecture goal
09 / Enterprise

Administration & audit

Roles, policies and approvals for organisations with traceable workflows.

Architecture goal
Q‑Tel Secure Device

Security does not end at the app.

Architecture goal

For particularly sensitive communication, Q‑Tel is to be provided on specially configured, hardened devices.

Already today Q‑Tel uses the Secure Enclave on iPhones and the hardware-backed keystore on Android – with StrongBox where the device has a dedicated security chip.

THE SECURITY MODEL / 04 LAYERS
LAYER 01HARDWARE ANCHOR
LAYER 02HARDENED DEVICE
LAYER 03Q‑TEL SECURITY
LAYER 04OWN INFRASTRUCTURE

Hardened operating system

Restrictive system configuration with a smaller attack surface.

Secure boot & hardware root of trust

Trust anchor from system start, depending on hardware platform.

Device attestation

Device state as a signal for access decisions.

Approved apps

Only defined applications in each security profile.

Restricted interfaces

Camera, USB, Bluetooth and NFC restrictable per profile; on selected hardware individual sensors can be physically removed.

Controlled updates

Updates only through the separate release chain.

Remote revocation

Revoke access specifically when a device is lost.

Security profiles

Profiles by organisation, role and protection needs.

Device image illustrative. The Secure Device programme is an architecture goal; available measures depend on hardware platform, security profile and the specific deployment.

Own environment / Private AI

Use knowledge. Keep control.

Architecture goal

Private AI is to help find answers, summarise documents and prepare tasks on your own knowledge base – within your own environment.

AnswersSummariesLink knowledgePrepare tasks
Q‑Tel Private AIKnowledge base / internal
Summarise the key points of the project documents.
Q
Prepared summary

The documents cover three relevant topics. I can structure the results by source and mark open points for the next approval.

Own knowledge base
Concept view · illustrative
Security principles

Precise in claims. Clear in status.

What is implemented today, what is in preparation and what is a goal are never presented as the same.

01 / Security principles

Implemented today

In the current app on iOS and Android.

  • Q-ID & device identity
  • Chat & groups
  • Calls
  • Q Vault
  • Vault transfer
  • Q-Verify
  • App lock
  • No downloaded code updates
02 / Security principles

At launch & in preparation

Ready before public launch, or built and not yet shipped everywhere.

  • Separate release chain At launch
  • Multiple sites At launch
  • Share to Q-Tel In preparation
  • Trust history In preparation
  • Device attestation In preparation
03 / Security principles

Architecture goal

Direction of the platform – explicitly not promised today.

  • Own instance
  • Administration & audit
  • Q Trust credentials
  • Private AI
  • Q-Tel Secure Device
Infrastructure

One instance. Several sites. One trust model.

At launch

At launch Q‑Tel runs on a distributed infrastructure with a standby site and controlled, safeguarded failover. Until then the pilot runs in one data centre in Germany.

DISTRIBUTED ARCHITECTURE / CONCEPT
CONTROLLED USER BASEOne Q‑Tel instance.

Identity, communication and vault in one defined trust model.

AT LAUNCH: SEVERAL SITES
SITE ASITE BSITE C
Today

Pilot operation in one data centre in Germany; servers see no content.

Available (pilot)
At launch

Dedicated Q‑Tel servers at several sites, encrypted backups with tested restore, separate release chain.

At launch
After that

More sites and dedicated instances for organisations as needed.

Architecture goal

Server image illustrative. Several sites are planned for launch and not yet in operation today.

Use cases

For communication where context matters.

Board & management

Law firms & legal

Confidential project teams

Organisations with elevated protection needs

Partner communication

Enterprise models

The security model grows with your protection needs.

Three planned tiers. We are looking for pilot organisations to shape the model with us.

01 / ENTERPRISE · Concept

Q‑Tel Enterprise

The private foundation for controlled collaboration.

  • Own instance and defined user base
  • Identity, chat & calls, vault
  • Vault transfer and administration
03 / SECURE DEVICE · Concept

Q‑Tel Enterprise Secure Device

Extends security to the entire device.

  • Everything in Enterprise Secure
  • Specially hardened devices
  • Controlled hardware and system configuration
Q‑Tel for organisations

One organisation.
One trust model.
One Q.

Talk to us about how Q‑Tel can fit your organisation – as a pilot or for the enterprise platform.