External security monitoring without the noise.
Assay monitors your internet-facing systems for exposed services, vulnerable software and configuration changes. Results are mapped to the Essential Eight and SMB1001, with a clear distinction between what has been verified, what presents a risk, and what the scanner cannot determine.
Live: create your account and run your first scan today.
Four verdicts. Nothing implied.
Every check returns one of four verdicts. A check that could not run is reported as not assessed and is never counted as a pass. A control that cannot be seen from outside is reported as not observable.
- OK
OK
The scan verified it.
- AT RISK
At risk
The scan found a gap: exploitable software, a missing control, an exposed service.
- NOT ASSESSED
Not assessed
A scanner could not complete, so Assay claims nothing. Never treated as a pass.
- NOT OBSERVABLE
Not observable
Cannot be seen from outside. Assay reports that as the result.
What every scan checks.
Every assessment runs the same six disciplines against what your systems expose to the internet, and maps the results to the Essential Eight and SMB1001.
Attack-surface discovery
Every exposed host and service catalogued, with remote-access and database ports flagged when they appear.
Vulnerability checks
Curated checks for known CVEs, misconfigurations, default logins, and TLS problems, run against what your systems serve.
Email authentication
SPF and DMARC checked over DNS: missing records, softfail, p=none, and broken policies.
Exploited-in-the-wild ranking
Findings ranked with CISA’s Known Exploited Vulnerabilities catalogue and EPSS probabilities.
Attack paths
When a gap matters, the route an attacker could take to reach it, expressed in MITRE ATT&CK techniques.
Change tracking
Scheduled scans diff every assessment against the last one, so you see the moment something gets worse.
Plans.
Monitor
$349a month
or $3,840 a year
One business, the whole product: daily scans, change alerts, attack paths, the insurance evidence pack.
Group
$549a month
or $6,040 a year
Three businesses under one account, everything included.
Portfolio
$999a month
or $10,990 a year
Ten businesses under one account, built for IT providers and multi-entity groups.
Plans start at $349 AUD per month. Prices in AUD, including GST. Billed through Stripe.
Fixing what Assay finds is separate consultancy work: breach remediation and defensive & advisory.
Want the scans read for you?
Managed exposure monitoring adds a senior engineer who reads every Assay result and reports it with context.
Managed exposure monitoringAssay is built and run by Black Shard, an Australian software engineering and cybersecurity firm that builds and operates production platforms in law, health, property, capital and recruitment.
The work behind itWhat we hold, verified on the public registry
See what is reachable from the internet.
Brisbane head office. Work delivered across Australia.

