Security and data handling
Once a document is in QueryTek Review, it is encrypted, access-controlled, and audited. AES-256-GCM at rest with per-tenant data encryption keys. TLS 1.2+ in transit on the portal. Keycloak SSO with role-based access. Immutable audit logging of upload, access, download, and status changes.
Files can arrive by portal upload (the default), optional email, or a Box or Drive folder your company connects. Encryption, role access, and the Review audit log start when Review stores its copy — not when you hit Send, and not while the file still sits only in your Box or Drive folder. Email travels ordinary email (including our inbound mail provider) until that store.
Full customer security packet available on request.
Responsible disclosure
If you believe you have found a security vulnerability in QueryTek Review, please report it to security@extanto.com. Include enough detail for us to reproduce the issue. We ask that you allow reasonable time for remediation before public disclosure and avoid accessing or modifying data that is not yours.