QEHSQEHS

Integrations / Storage + documents

Amazon S3

Attachment storage + evidence mount.

Storage + documentsGenerally availableEnterprise only

Store record attachments in your own S3 bucket with server-side encryption, tenant-scoped prefix, and optional Object Lock for WORM retention.

Capabilities

  • BYO S3 bucket per tenant
  • KMS-managed encryption (Enterprise)
  • Object Lock WORM retention
  • Lifecycle rules + Glacier archive

Setup steps

  1. Enable the Amazon S3 connector in Settings → Integrations.
  2. Copy the QEHS metadata URL and paste it into your IdP application.
  3. Map user attributes to the required QEHS claims.
  4. Test the connection with a sandbox user.
  5. Enable for all users and verify provisioning logs.

Every integration is auditable

HMAC-signed webhooks, OpenAPI 3.1, SDKs in every major language.

Integrations layer sits on top of the same audit log your security team already reviews, nothing bypasses the tenant boundary.