Security & compliance

Our posture, in plain words.

We hold no certificates yet, and we do not claim any. What we can show today is the discipline the standards ask for, applied to real work: a documented management system, published policies, and controls you can verify. This page states exactly where we stand.

Status

Where we stand, framework by framework.

One verb per framework, no inflation: aligned means our management system follows the standard; in progress means the work is underway; in preparation means the paperwork has started and nothing is claimed before it exists.

◇

ISO/IEC 27001:2022 (information security)

Our platform and delivery run under a documented management system aligned with ISO/IEC 27001:2022. Certification of the system is in progress; the controls themselves already shape how we scope, review and deliver.

AlignedCertification in progress
◇

ISO 9001:2015 (quality)

Quality is an operating discipline, defined, measured and improved engagement by engagement, governed by our published Quality Policy.

Aligned
◇

ISO/IEC 42001:2023 (AI management)

AI assistance runs inside a governed management system: a named senior engineer owns every merge, estimate and answer, and AI systems are registered and assessed before they operate.

Aligned
◇

ISO 14001 (environment)

Environmental management aligned with ISO 14001 governs the energy, hardware, lab work and travel our footprint actually consists of. We do not claim offsets, neutrality or certification we do not hold.

Aligned
✓

Essential Eight (ASD)

We are implementing the Australian Signals Directorate’s Essential Eight mitigation strategies, working toward Maturity Level 2 (ML1 baseline October 2026). Multi-factor authentication and privileged-access controls are in operation. Self-assessment evidence is available to clients under NDA.

ImplementingWorking toward ML2Evidence under NDA
○

SOC 2

We maintain a SOC 2 readiness programme; a Type I or Type II report can be commissioned on client request.

Readiness programmeReport on request
▸

DISP Entry (Defence Industry Security Program)

A DISP Entry application is in preparation. We state this as a fact of preparation, not membership; membership language will appear here only once Defence grants it.

Application in preparation

A certification roadmap and control disclosures are available on request. The policies behind all of this are public.

References to standards are statements of alignment, not certification, unless an accredited certificate is published on this page.

Controls in operation

What runs today, not what we plan.

Every line below is a control you can ask us to evidence under NDA, today.

Identity and access

Multi-factor authentication on mail and the client portal; least-privilege access control; administration restricted to an encrypted WireGuard-only path.

Data protection

Encryption in transit and at rest; Australia and Canada data-residency options agreed per contract.

Software supply chain

Dependency and CVE scanning in the build; secure development standard with human gates on every merge.

Detection and response

Centralised logging, a documented incident response plan, and rule-based protection on internet-facing services.

Resilience

Nightly backups with 90-day retention and regularly tested restores; restore drills recorded as evidence.

Accountability

A named senior engineer owns every merge, every estimate and every answer; AI raises draft velocity, the gates stay human-owned.

Evidence & assurance

How to verify us.

📚

Public policy library

23 governance documents, version 1.2, each published with its PDF and approval line: conduct, privacy, safety, quality, sustainability and people.

Read the policies

🔒

Evidence under NDA

Essential Eight self-assessment evidence, control disclosures and the certification roadmap are available to clients and reviewers under NDA or on request; a SOC 2 Type I or Type II report can be commissioned.

Request evidence

📋

Procurement and vendor onboarding

Registration forms, vendor questionnaires and compliance statements are completed and returned; entity, insurance and residency answers are summarised on our capability page.

Capability statement

References to standards are statements of alignment, not certification, unless an accredited certificate is published on this page.