Security, continuity and compliance for Australian accounting firms, law firms and professional practices. Fixed price. Written down. Your data stays in Sydney.
Accounting and law firms, SMSF auditors, financial advisers, insolvency practitioners and finance brokers. Five to fifty people, Microsoft 365, maybe one server, no internal IT. You carry the same Privacy Act obligations as a firm of five hundred, and increasingly your clients and insurers want that proven in writing.
Two weeks, fixed price, a written report telling you where you actually stand.
Staged remediation against a ceiling you set. Nothing open ended.
A monthly service that keeps it fixed, and gives you something to show an auditor.
Run it yourself against your own domain. Security headers, TLS, DNS and email authentication including SPF, DKIM and DMARC, and exposed library versions, all mapped to the Essential Eight. It exists so you can see we can do the technical work before you have paid us anything. Run it now.
We review your external attack surface, your Microsoft 365 tenant configuration, and Entra ID access: who holds administrator rights, who has left and still has access, where multi-factor authentication is missing. We check what is backed up, whether a restore has ever been tested, and how long a recovery would genuinely take. We assess patch currency and application control.
You receive a report rating you against each Essential Eight strategy at Maturity Level One, Two or Three, a list of what is wrong ranked by what would actually hurt your firm, a costed remediation plan, and a one page summary for a partners' meeting. If little is wrong, we say so, and you keep the report.
A narrower version for firms that are entirely cloud based with no server. A sensible way to test us before committing to anything larger.
Multi-factor authentication enforced, conditional access configured, administrator accounts separated from daily-use accounts, departed staff removed, and access documented as a register you can maintain yourself. The highest value fix for most firms, and it produces an artefact an auditor can read.
Business hours support, thirty days notice to cancel, no exit fee. Three packages.
It stops client information and matter detail being pasted into ChatGPT, Copilot, Claude and similar tools, and blocks prompt injection arriving inside documents and emails. Detect-only if you want visibility first, or block mode if you want it enforced. For a firm that has just realised its junior staff are drafting with AI, this is usually the whole conversation.
Security awareness training with phishing simulation and quarterly click-rate reporting is available alongside any package. Every engagement starts with a fixed onboarding: tenant connection, policy configuration, first full backup verified, baseline report.
We prepare. We do not certify. We are never the auditor. Where a firm needs certification, we say so and tell them who does that. On SMB1001, Bronze, Silver and Gold are self-attested, which is the work we deliver. Platinum and Diamond require independent audit and sit outside what we offer.
A system that reads documents before a professional does. It extracts the figures, reconciles them against the accounts, matches every assertion to the evidence supporting it, applies the compliance tests, and hands the reviewer a queue already ranked by risk.
The line we do not cross. The machine prepares. The professional decides. Every finding cites the document it came from. Nothing is asserted without a source. The registered professional forms and signs the opinion exactly as they do today. We are not building something that audits. We are building something that does the reading.
Technically: Claude via Amazon Bedrock in the AWS Sydney region, inside an account you own, encrypted with keys you control. Nothing retained, nothing used to train any model, and every document processed logged in a form your own auditors can read.
These are not productised and we will not price them in a first meeting. They are scoped against your specific environment and objectives.
Managed services in a Sydney datacentre. Advisory and AI work in the AWS Sydney region, in an account you own. Reports, evidence packs and working papers on Australian infrastructure. Where you need a second copy, we hold it on Australian infrastructure or on storage you own, never offshore.
On request we provide the platform provider's SOC 2 Type 2 report and ISO 27001 certificate, a data processing agreement and sub-processor list, and our position on termination.
No twenty four hour monitoring or on-call security operations centre. No helpdesk or general IT support. No hardware. No endpoint detection and response with a response time commitment, until there is a team to carry that service level agreement. Where something falls outside what we do, we say so, and we say who should do it instead.
Fixed price wherever scope can genuinely be fixed. Otherwise an agreed day rate in blocks against a ceiling you set. Nothing open ended. Your reports and configuration belong to you from day one. Findings always go in writing. You get the principal on the engagement, not a graduate.
Two weeks, a fixed price, and a written report that tells you where your firm actually stands. If little is wrong, we will say so.