Black Shard

Software engineering and cybersecurity services.

Software delivery and security under one team: engagements start with a build, a penetration test, an assessment, a compliance requirement or an incident.

Start a conversation

Before, between, and after an incident.

Before

Testing, review and compliance work ahead of an incident.

Between

Ongoing security leadership and external exposure monitoring.

After

Containment, remediation and verification of the affected surface.

Work outside these families.

The systems we operate also needed brand identities, editorial sites, deal-flow tooling, speech and OCR pipelines, outreach engines and compliance portals, and we built those too.

We build Xero integrations: custom apps on the Accounting API, bank-feed and transaction sync, and the bank leg of a trust reconciliation for practices that report against a regulated ledger.

Open a brief

Sectors we work in.

Regulated data, real users, systems that have to stay up.

Engagements sized to where you are.

From a one-off test to a standing engineering team. Scope, timeframe and price are agreed before work starts.

  • Fixed-scope engagement

    Startups & SMB

    A penetration test, review, or build with a clear target, timeframe, and deliverable.

  • Ongoing advisory / vCISO

    Mid-market & enterprise

    A standing security seat: strategy, review, and board-ready reporting on a regular cadence.

  • Compliance program

    Regulated businesses

    A milestone-driven program toward Essential Eight, SMB1001, ISO 27001, or Privacy Act readiness.

  • Embedded engineering

    Product owners

    A standing build team that designs, ships, and operates software under an ongoing engagement.

SMB1001:2026 Gold (Level 3), issued by CyberCert. Essential Eight Maturity Level 3, with controls mapped to the ASD ISM and CIS Controls v8.

Tell us what you need built, reviewed or secured.