Am Joseph 15
DE 61273 Wehrheim
Contact
Mr. Kristian Körting
  • +49 151 12265040
  • +49 151 12265040
  • E-mail
Products and innovations

QGROUP S1EDROP (SentinelOne On‑Prem by QGROUP)

QGROUP S1EDROP (SentinelOne On‑Prem by QGROUP)
Innovation

Robust endpoint defense: QGROUP S1EDROP delivers a fully on-premises, integrated EDR platform. As an appliance available from QGroup, it includes - in addition to the hardware - the SentinelOne detection engine, a central console, logging, and optional administrative controls - all without any reliance on the cloud.


Key Features and Benefits

  • Full data control (on-prem)
  • Unified management for Windows/macOS/Linux
  • Deployment as an appliance with a preconfigured stack
  • Expandable with QTrust Admin Proxy and audit logging
  • Scalable, tested to military standards
  • Air-gap capable, ISO-compliant, and KRITIS-ready
  • Complete data sovereignty & legal independence
  • Supported by QGroup SecOps with 24/7 support

Product groups

Product range

QTrust® Admin Proxy

Securing Administrative Processes in Critical Infrastructures

The QTrust® Admin Proxy enables secure remote maintenance of critical internal systems by external service providers. Based on General Dynamics’ Multilevel Trusted OS PitBull, the QTrust Admin Proxy functions as a secure terminal or jump server. External or non-company administrators log in to it for remote maintenance using strong authentication (QTrust ID) and manage the systems from there.

Always know who connected to what and when

The Multilevel Security (MLS) protection of the QTrust Admin Proxy ensures full control of the session immediately after the first step of uniquely verifying the user’s identity and prevents the service provider from escaping its authorization context. This prevents malicious code from being introduced into critical infrastructure, as well as access to unauthorized systems (island hopping)—that is, accessing a third-party system via another system—or even data leakage.

A customizable command blacklist prevents the intentional or unintentional execution of unauthorized commands. Centralized logging and session recording also enable secure monitoring of the service provider’s individual activities. The PitBull operating system also prevents users from modifying these logs.

Secure Remote Maintenance with Admin Proxy

  • Full session control (taking control,
  • ability to terminate a session immediately, etc.)
  • Configurable on a per-client basis
  • Ability to set up multiple control instances
  • Approval function for pending sessions
  • Session review status for auditors
  • Secure and logged file transfer
Product range

QTrust® Server

The QTrust® Server with Trusted OS is the logical security foundation that traditional, inadequate patchwork IT security has always lacked. It enables maximum efficiency in setting up your infrastructure and processes and significantly simplifies your certification processes for the covered areas.

Designed for cross-domain installations, the QTrust Server acts as a gateway between insecure and secure networks, preventing unauthorized direct data exchange.

In addition to application proxying, the QTrust Server features comprehensive logging capabilities that enable detailed diagnostics.

Separate, hardened session controls and logs, combined with biometric multi-factor authentication and the strict separation of administrative tasks, ensure not only resilience but also consistent support for compliance requirements and admissibility in court. Risks related to sabotage, manipulation, or errors are systematically reduced.

The QTrust server with Trusted OS is therefore also ideally suited as the essential foundation of trust and security for IoT, AI, and 5G. It serves as the preferred solution for alliance management among competing parties in military mission systems and enables the necessary multilevel mapping of different access permissions to the same application. It consistently supports business-critical processes, the protection of trade secrets, sensitive data, and all digital assets, as well as critical infrastructure and much more.

Key Features

  • Based on a Trusted Operating System
  • Expandable via QEE and CDAP
  • IT Security 2.0 Compliant
  • Multilevel firewall and gateway
  • Interruption of data flow in all directions
  • Maximum availability and service provided by HPE or Stratus ftServer
  • Fully managed service available through QLine
  • Foundation for highly secure application access: QTrust ID
  • Easy to administer

- Role-based administration

- Web-based administration

- Graphical configuration tools

- Based on PitBull technology

The QTrust server, running this Trusted OS, serves as the foundation for implementing the new IT Security Strategy 2.0, which ensures maximum resilience and segregability.

Product range

QTrust® ID

Our QTrust® ID solution ensures the user’s unique, personal identity through biometrics (fingerprint or facial recognition) and grants the user access exclusively to an individually authorized set of data and applications. This means that even lost or stolen passwords cannot be misused. When used in combination with other QTrust MLS solutions, QTrust ID serves as the first step in the QTrust end-to-end compliance process. It is used by the military and government to ensure data integrity throughout the entire lifecycle of data objects, right up to proving their admissibility in court.

This solution is therefore ideal for home offices, business travelers, or administrators, as well as companies with high requirements for confidentiality and data integrity. External service providers can also be connected to QTrust ID. The fact that they can only communicate via a fixed protocol reduces the likelihood of misuse to zero.

QTrust ID is a unique gateway to compliance and significant risk mitigation.

Company profile

As an IT security service provider, QGroup applies the principles of military IT security to its clients – in the age of digital sovereignty. Our QTrust platform stands for security by design: modular, integrating third-party solutions, built for resilience and interoperability. With S1EDROP we deliver full SentinelOne EDR/XDR capability completely On-Prem – sovereign, air-gap capable, no data leaves your infrastructure. Our Security Operations Team monitors client networks 24/7, plus penetration tests, audits and vulnerability assessments. In an incident, our response teams deploy on site.

Contact / Appointment Request

×