Black Shard

Security and compliance,
run in our own environment.

SMB1001:2026 Gold, issued by CyberCert.

SMB1001:2026 GoldVerify ↗
Standard
SMB1001:2026 Gold (Level 3)
Held by
Black Shard Pty Ltd · ABN 66 696 910 773
Issued by
CyberCert
Active
16 June 2026 to 17 June 2027
Basis
Formal director attestation against the standard’s 27 controls
Verify on the CyberCert registry ↗

The team also holds an individual Exemplar Global Certified Lead Auditor credential for ISO/IEC 27001:2022 (certificate C-560291, valid to 25 August 2027).

Contracts, governance and privacy are led by a director who is a Queensland Law Society Accredited Specialist (Business Law). Verify on the QLS register ↗

Gold is the third of SMB1001’s five tiers, which run from Bronze at Level 1 to Diamond at Level 5.

Frameworks we work against.

The same controls run in our own environment.

ASD Essential Eight

Maturity Level 3 · assessed September 2026

The Australian Signals Directorate’s eight mitigation strategies, the baseline Australian government supply chains ask for. Black Shard’s own environment runs at Maturity Level 3 against ASD’s published maturity model, assessed in September 2026 with the evidence on file for every strategy.

Privacy Act 1988 · Australian Privacy Principles

The Australian Privacy Principles apply to Black Shard as an Australian organisation handling personal information. Collection limits, purpose, access and correction, and notifiable breach handling are built into the systems we operate.

ASD Information Security Manual (ISM)

The Australian Government framework for systems that handle official information. Controls on engagements that carry government obligations are designed and operated against the ISM.

CIS Controls v8

The Center for Internet Security vendor-neutral critical security controls, used as a cross-check on the Australian frameworks in our engineering and operations.

Production runs on Microsoft Azure in Australian regions.

Australia East carries most of it. Azure is IRAP-assessed to PROTECTED and holds ISO 27001 and SOC 2 at the platform level; those assessments are Microsoft’s.

Microsoft’s IRAP assessment ↗

We build under the Xero, Twilio and Apple partner programs.

  • Xero Developer Partner Program

    Development partner

    Xero developer partner badge

    We build Xero integrations for regulated businesses: trust account reconciliation, bank feeds and finance automation.

  • Twilio Partner Connection

    Consulting partner

    We build messaging, voice and verification into the platforms we deliver.

  • Apple Developer Program

    Organisation

    We publish the iOS apps we build on the App Store under the Black Shard organisation account.

Operational security.

Staff sign-in, enforced by conditional access
Phishing-resistant MFA
Data in transit and at rest
Encrypted
Backup health checks
15 minutes
Restore drills from stored backups
Monthly
Access and sign-in

Access to client environments is limited to what an engagement requires. Staff accounts in the firm’s Microsoft 365 tenant sign in with phishing-resistant multi-factor authentication, enforced by conditional access.

Administrative privilege

Administrative access to the firm’s own infrastructure runs over a private network with key-based SSH authentication. The control plane sits behind an identity-aware access layer restricted to the firm’s own domain. Credentials are held in a secrets vault with owners and rotation recorded.

Encryption

Data is encrypted in transit and at rest.

Backups

Production data is backed up on schedule, including database dumps and repository bundles, and backup health is checked by the firm’s own monitoring every 15 minutes. Restores from the stored backups are drilled every month.

Australian hosting and audit trails

Client data is hosted in Australian Azure regions. The systems we operate for clients carry their own audit records: the GRM LAW portal keeps an append-only audit ledger enforced on every state change, and the Stone Leaf Capital portal keeps a compliance audit log sealed monthly into hash-manifested archives.

Release controls

Source is held in private repositories. Continuous-integration checks run on each change.

Edge and public site

Hosted systems sit behind a web application firewall and CDN, with origins locked to the edge provider’s addresses. Cookie use on the public site is limited to Google Analytics and, with visitor consent, Google Ads measurement.

Third parties

Third parties are kept to the minimum required to deliver the service. Australian regions are used for services that host client data.

Black Shard maintains professional indemnity, public liability, cyber and workers’ compensation insurance. Certificates of currency are available on request.

Azure, Microsoft 365, Cloudflare, Xero, Twilio and Tyro.

The systems we build and operate run on these in production, and on AWS, Google Cloud or client-run infrastructure when an engagement calls for it.

Platforms we use

Coordinated disclosure.

  • Report: email info@blackshard.com.au with enough detail to reproduce the vulnerability.
  • Acknowledgement: within 48 hours.
  • Good-faith research: no legal action.
  • Credit: for reporters who want it.
  • security.txt: published per RFC 9116.

Incidents follow a defined path.

The path covers identification, containment and communication. Under the Privacy Act 1988 Notifiable Data Breaches scheme, we notify affected parties and the OAIC when required.