Software engineering and cybersecurity services.
Software delivery and security under one team: engagements start with a build, a penetration test, an assessment, a compliance requirement or an incident.
Software engineering
Product development, internal platforms, web and mobile applications, integrations, Azure infrastructure and automation.
- Product & platform engineering
- Web development
- Mobile app development
- UI/UX design
- Cloud engineering on Azure
- AI & automation engineering
- Secure-by-design development
AI and data solutions
- Data platform engineering
- Integration and pipelines
- Reporting and dashboards
- AI workflow automation
- Document and speech intelligence
- Guardrails and audit for AI features
Physical AI
- Computer vision systems
- Sensor and telemetry pipelines
- Edge inference and device fleets
- Robotics and building-system integration
- Safety, monitoring and audit
Cloud and agentic infrastructure
- Azure landing zones and platform engineering
- Managed hosting and operations
- Delivery pipelines and environments
- Agent runtime and tool permissions
- Agent observability and audit
- Model and AI endpoint hosting in Australia
Cybersecurity
Penetration testing & red teaming
- Penetration testing
- Red teaming
- Phishing & social-engineering simulation
Security advisory & vCISO
- Security posture assessment
- vCISO: fractional security leadership
- Azure cloud security review
- Entra ID & Microsoft 365 identity security
- Managed exposure monitoring
- Detection & response advisory
Breach remediation & incident response
- Incident containment & triage
- Root-cause analysis & remediation engineering
- Notifiable Data Breaches support
- Incident readiness
Compliance & certification readiness
- Essential Eight uplift
- SMB1001 certification readiness
- ISO 27001 readiness
- Privacy Act / APP uplift
- AML/CTF independent evaluation
Secure development & code review
- Secure code review
- Security architecture & threat modelling
AI cyber defence
- AI security assessment
- AI penetration testing
- Microsoft Copilot security review
- AI governance & ISO 42001 readiness
- Defence against AI-enabled attacks
- Secure AI engineering
Before, between, and after an incident.
Before
Testing, review and compliance work ahead of an incident.
Between
Ongoing security leadership and external exposure monitoring.
After
Containment, remediation and verification of the affected surface.
Work outside these families.
The systems we operate also needed brand identities, editorial sites, deal-flow tooling, speech and OCR pipelines, outreach engines and compliance portals, and we built those too.
We build Xero integrations: custom apps on the Accounting API, bank-feed and transaction sync, and the bank leg of a trust reconciliation for practices that report against a regulated ledger.
Open a briefSectors we work in.
Regulated data, real users, systems that have to stay up.
- LegalMatter, trust and client-portal systems
- HealthClinical documentation and AI workflow platforms
- Financial servicesInvestor portals, fund operations, compliance
- PropertyListings, CRM and campaign platforms
- RecruitmentCandidate pipelines and placement platforms
- Government & suppliersEssential Eight uplift and supplier readiness
- Professional servicesPractice systems, client portals, security
- EducationLearning platforms and student data security
- Not-for-profitDonor systems and Essential Eight on a budget
- Energy & utilitiesOperational security and field systems
Engagements sized to where you are.
From a one-off test to a standing engineering team. Scope, timeframe and price are agreed before work starts.
Fixed-scope engagement
Startups & SMB
A penetration test, review, or build with a clear target, timeframe, and deliverable.
Ongoing advisory / vCISO
Mid-market & enterprise
A standing security seat: strategy, review, and board-ready reporting on a regular cadence.
Compliance program
Regulated businesses
A milestone-driven program toward Essential Eight, SMB1001, ISO 27001, or Privacy Act readiness.
Embedded engineering
Product owners
A standing build team that designs, ships, and operates software under an ongoing engagement.
SMB1001:2026 Gold (Level 3), issued by CyberCert. Essential Eight Maturity Level 3, with controls mapped to the ASD ISM and CIS Controls v8.


