Black Shard

External security monitoring without the noise.

Assay monitors your internet-facing systems for exposed services, vulnerable software and configuration changes. Results are mapped to the Essential Eight and SMB1001, with a clear distinction between what has been verified, what presents a risk, and what the scanner cannot determine.

Live: create your account and run your first scan today.

Four verdicts. Nothing implied.

Every check returns one of four verdicts. A check that could not run is reported as not assessed and is never counted as a pass. A control that cannot be seen from outside is reported as not observable.

  • OK

    OK

    The scan verified it.

  • AT RISK

    At risk

    The scan found a gap: exploitable software, a missing control, an exposed service.

  • NOT ASSESSED

    Not assessed

    A scanner could not complete, so Assay claims nothing. Never treated as a pass.

  • NOT OBSERVABLE

    Not observable

    Cannot be seen from outside. Assay reports that as the result.

What every scan checks.

Every assessment runs the same six disciplines against what your systems expose to the internet, and maps the results to the Essential Eight and SMB1001.

  • Attack-surface discovery

    Every exposed host and service catalogued, with remote-access and database ports flagged when they appear.

  • Vulnerability checks

    Curated checks for known CVEs, misconfigurations, default logins, and TLS problems, run against what your systems serve.

  • Email authentication

    SPF and DMARC checked over DNS: missing records, softfail, p=none, and broken policies.

  • Exploited-in-the-wild ranking

    Findings ranked with CISA’s Known Exploited Vulnerabilities catalogue and EPSS probabilities.

  • Attack paths

    When a gap matters, the route an attacker could take to reach it, expressed in MITRE ATT&CK techniques.

  • Change tracking

    Scheduled scans diff every assessment against the last one, so you see the moment something gets worse.

Plans.

  • Monitor

    $349a month

    or $3,840 a year

    One business, the whole product: daily scans, change alerts, attack paths, the insurance evidence pack.

  • Group

    $549a month

    or $6,040 a year

    Three businesses under one account, everything included.

  • Portfolio

    $999a month

    or $10,990 a year

    Ten businesses under one account, built for IT providers and multi-entity groups.

Plans start at $349 AUD per month. Prices in AUD, including GST. Billed through Stripe.

Fixing what Assay finds is separate consultancy work: breach remediation and defensive & advisory.

Want the scans read for you?

Managed exposure monitoring adds a senior engineer who reads every Assay result and reports it with context.

Managed exposure monitoring

Assay is built and run by Black Shard, an Australian software engineering and cybersecurity firm that builds and operates production platforms in law, health, property, capital and recruitment.

The work behind itWhat we hold, verified on the public registry

See what is reachable from the internet.

Brisbane head office. Work delivered across Australia.

Open a briefinfo@blackshard.com.au