Black Shard

Businesses run on this work.

Every case study here is a business that runs on systems we designed, built, and secure. We threat-model, harden, and review them the same way we would yours. What can be shown publicly is here; much of what we ship runs privately inside the businesses that use it. Open any one for the full case study.

Bold Property Group, Buyer’s advocacy
Live

Bold Property Group

Buyer’s advocacy

Bold Property Group is the Black Shard buyer’s advocacy arm.

The problem
A new buyer’s agency needed an operating stack it could iterate on weekly: brand, marketing site, deal-pipeline tooling, and a private portal for clients tracking an active acquisition.
What we built
We designed the identity, shipped the editorial site, built the agent-network data layer for sourcing off-market opportunities, and stood up the client portal, with CRM and operating playbook on the same data model.
How it is secured
Compliance is enforced in code, fail-closed: the portal will not let an engagement letter be signed or a property address be revealed until verification of identity is recorded.
What it does now
Bold is operating today. We keep building underneath it as the playbook evolves.
Read the full case study
GRM LAW, Legal
Live · private portal

GRM LAW

Legal

GRM LAW is a Brisbane law firm. Black Shard built and operates the compliance and operations portal the firm runs on.

The problem
A Brisbane law firm needed a system to run on day-to-day: secure intake, conflicts checks, a matter register and AML/CTF readiness, with the audit trail underneath, sitting over the practice tools it already used.
What we built
We built the operations and compliance portal: secure intake, conflicts checks, the matter register, and AML/CTF readiness.
How it is secured
Role-based access over a hardened content-security policy, with an append-only audit ledger enforced on every state change.
What it does now
The firm operates from the portal. We ship to it weekly under an ongoing engagement, and the build evolves with the workflow.
Read the full case study
Aurii, Clinical software
Live

Aurii

Clinical software

Aurii is the Black Shard clinical-software venture.

The problem
Australian private-hospital specialists were typing their own clinical notes, letters and billing. The product Black Shard wanted on every specialist desk did not exist, so we built it ourselves.
What we built
We built the entire stack: the iOS and Android apps, the web app, the speech and OCR pipelines, the multi-tenant data layer with row-level security, and the clinical messaging gateway, on Microsoft Azure in the Australia East region.
How it is secured
Tenant health data isolated with PostgreSQL row-level security, tamper-evident audit trails, and rate limiting, on Azure in Australia.
What it does now
Aurii is live. Built for Australian clinical and privacy obligations, not retrofitted to them.
Read the full case study
Restart Recruitment, Recruitment
Live

Restart Recruitment

Recruitment

Restart Recruitment is the Black Shard talent venture.

The problem
An executive search firm built to run fewer searches at a time, properly. That model needed an internal stack that judges every brief the same way: recruiter dashboard, pipeline, and structured scorecard screening.
What we built
We built the brand, the editorial site, the candidate intake and screening flows, the scorecard model, and the outreach engine over Outlook OAuth behind them.
How it is secured
Tenant data behind forced Postgres row-level security on eight core tables, TOTP two-factor sign-in, and eleven invariant tests (TOTP replay, OAuth timing, webhook input caps) pinning the security model.
What it does now
The platform is complete: portal, outreach engine and screening flows ready to run the first searches end to end.
Read the full case study
Stone Leaf Capital, Capital markets
Live

Stone Leaf Capital

Capital markets

Stone Leaf Capital is an Australian capital-markets firm. Black Shard was engaged to build the firm's technology, brand, and operating systems.

The problem
An Australian capital-markets firm (funds management, capital raising, corporate advisory for wholesale clients) needed the technology it operates on: the brand, the public site, and the staff portal underneath.
What we built
We built the brand and public marketing site, and the staff portal that is the operational backbone: critical-event tracking and policy modules.
How it is secured
A compliance audit log captures actor, action, and before-and-after state on every change, sealed monthly into hash-manifested archives. Sign-in is Microsoft Entra; retention purges are provenance-guarded.
What it does now
The public marketing site is live. We ship to the portal under an ongoing engagement, structured around the firm’s AFSL perimeter and retention obligations.
Read the full case study
Fox Valuations, Property valuation
Live

Fox Valuations

Property valuation

Fox Valuations is an independent Brisbane property valuation practice led by a registered valuer.

The problem
An independent valuation practice needed everything around the valuer's signature: a brand, a public site that wins work, report templates worthy of the figure they carry, and the mail and ICT plumbing of a modern practice.
What we built
We built the identity (the leaping fox, rust on warm paper), a hand-crafted public site with working calculators and a valuation insights library, the designed report template system, and the Microsoft 365 tenant and custom-domain mail underneath.
How it is secured
The public site is hardened static delivery: a strict Content-Security-Policy, no dynamic surface beyond the request pipeline, served through Cloudflare.
What it does now
Live at foxvaluations.com.au under an ongoing ICT and growth engagement: hosting, mail, search foundations and the document pipeline all run on Black Shard rails.
Read the full case study

The work without screenshots.

Not everything we deliver is a build. A growing share of the practice is security engagements, and the clients stay unnamed because that is the nature of the work.

Penetration testing

Authenticated application and cloud-configuration testing under signed authority, most recently against a Queensland financial-services platform, with findings remediated by the same engineers who found them and retested to closure.

Offensive security

Essential Eight uplift and assessment

Per-strategy assessment against ASD’s maturity model, then the uplift work itself: authentication, patching, privilege, backups. We run our own estate at Maturity Level 2 and take clients through the same program we applied to ourselves.

Compliance readiness

ISO 27001, SOC 2 and SMB1001 readiness

Evidence-first audit readiness: scoping, gap analysis, the control set, and the documentation an assessor actually asks for. Built for a clinical software platform and for our own certification, the one on the trust page you can verify.

Audit readiness

Continuous security review

Structured security audits of running estates: configuration, identity, exposure and data paths, with findings registered, fixed and re-verified. Our external scanning platform watches client perimeters between the audits.

Defensive security

Want this standard on your systems?

The same team that builds and secures these companies will test, harden, or build yours. Same standard, same accountability.

Running procurement? Download the capability statement (PDF).