One ruleset.
Audited, or built by it.
Qawex is the platform behind everything Qawex Solutions builds. Point it at a URL and it produces a scored audit. Point it at a description and it produces a running system built to the same rules. The Standard doesn't change — only the verb does.
Quick answer
What is Qawex?
Qawex is a platform built around one published engineering standard, The Qawex Standard, which defines 63 rules across five pillars — Intelligence, Engineering, Paperless, Cyber and Growth — each with a severity and a verification method. Every module in the platform works in two directions off the same ruleset: pointed at an existing system, it produces a scored Audit; pointed at a written description of a new system, it Generates one built to satisfy the Standard by construction rather than corrected afterward. Every module reads and writes the same live model of a customer's system, the Project Graph, which is what lets Qawex surface findings that span pillars — something no single-purpose security scanner, SEO tool or dev platform can do on its own.
Five vendors. Five bills.
Nothing connected.
A security firm doesn't check discoverability. A search agency doesn't check database policies. Systems fail in the gaps between specialisms.
Failure 01
The disconnected stack
A scanner passes the site. A search audit passes the site. Neither one saw that the scanner's "pass" and the audit's "indexed" together mean private records are public.
Failure 02
The audit with no fix
Two hundred findings, no order, no owner. Everything gets logged, nothing gets closed.
Failure 03
The rebuild that repeats the mistake
The old system is replaced. The new one ships with the same unstructured access policy, because nobody wrote the rule down the first time.
Four things, not a feature list.
One standard underneath everything, applied at whatever depth a system needs.
01
The Qawex Standard
63 published rules across 5 pillars, each with a severity and a verification method — not an opinion, a test you can run yourself.
02
The Project Graph
One live model of a system's stack, routes, database, policies, forms, agents, schema and headers, shared across every module.
03
Two verbs, one ruleset
Audit an existing system for a scored report, or Generate a new one built to satisfy the Standard from the first commit.
04
Five modules
Each pillar runs independently or together.
Five steps, in this
order, every time.
The same sequence whether you're pointing Qawex at a live system or a new one.
- 1
Point
Give it a URL to audit, or a description of what you want built.
- 2
Run
The relevant modules scan or generate, writing into the same Project Graph.
- 3
Score
Each pillar scored against the Standard, with any Critical finding capping the total.
- 4
Fix
Ranked findings with a remediation path, or a generated system that already passes.
- 5
Monitor
Re-score on every deploy, so a passing system doesn't quietly stop being one.
Rules in the Qawex Standard, across all five pillars.
Pillars, each independently enabled or run together.
Maximum score possible while any Critical finding stays open.
Why one shared model catches what five separate tools cannot.
A security scanner reads your database policies. A search tool reads what's indexed. A build tool reads whether a page is server-rendered. None of them read each other's findings, so a table with no row-level security, on an indexed route, fully server-rendered, passes all three checks individually while quietly serving private records to any crawler that asks. The Project Graph is what closes that gap — every module writes into the same live model, so a cross-pillar finding like this one is visible the moment all three conditions exist together, not discovered later by whoever finds it first.
Source: The Qawex Standard v1.0 · /standard/Answers, not brochures.
Is Qawex a no-code builder like Lovable?
Partly, in Build mode. The difference is what ships underneath: default-deny access policies, server rendering and declared agent boundaries are generated automatically as part of satisfying the Standard, not left for you to remember or add later.
Can I run an audit without building anything?
Yes. Every module works standalone in Audit mode, and the AI Visibility Audit specifically is free to run with no account required. Nothing about using Qawex commits you to building with it.
What if I only need one pillar?
Modules are entitlements, not a bundle you have to take all of. Enable Cyber alone, or Growth alone, or all five together — the Project Graph works the same way regardless of how many are active.
Who does the work the platform can't?
Qawex Solutions, for anything requiring judgement rather than verification — architecture trade-offs, red-teaming, content strategy, business-process redesign. Same standard, same team, no handoff to a different vendor.
Is this specific to healthcare?
No. Qawex Health is the first Vertical Pack built on the platform, and the proof that the Standard holds under the domain with the least tolerance for failure — but the platform itself is horizontal, applied across every industry Qawex Solutions works in.
Point it at what you have. Or what you want.
The audit is free and yours to keep either way.