We build software. Then we break it before attackers do.
An Australian software engineering and cybersecurity firm. We build and run software in regulated industries, then attack it the way an adversary would. Penetration testing, red teaming, advisory, compliance, breach remediation, secure-by-design builds.
Two practices. One team.
Software that ships fast and stands up to attack, from one team accountable for both. We build it, then break it the way an adversary will, so weaknesses are closed before production finds them.
- Software engineering
Product and platform builds on Azure: web, native mobile, portals, and the operations systems underneath. We run what we ship.
- Offensive testing
Penetration testing, red teaming, phishing simulation. An adversary's attack, then a ranked fix list.
- Defensive & advisory
Posture assessments, vCISO, Azure security reviews. A security seat at your table, without the full-time hire.
- Breach remediation
Containment, root cause, and remediation after an incident. We fix what let it happen, then re-test.
- Compliance readiness
Essential Eight, SMB1001, ISO 27001, and Privacy Act uplift. Audit-ready, with the evidence to prove it.
- Secure development
Secure code review, threat modelling, and security architecture at the level attacks actually happen: the code.
- Assay, our scanner
Continuous external scanning, mapped to the Essential Eight and SMB1001. Live, from $349 a month.
Some of the brands we've worked for and secure.
Every name here has trusted us with real work: systems we build and run, and systems we test and secure.
Clients




Fox Valuations- PowerSync
- Sentry
Platform partners
- Microsoft Azure
- Microsoft 365
- Cloudflare
- Stripe
- Docusign
- Twilio
- Xero



What can be shown publicly is here. The rest runs privately.
Assay · Independent security monitoring for Australian business.
Our scanner, pointed at your business.
Assay scans your internet-facing systems, maps every finding to the Essential Eight and SMB1001, and gives you evidence you can hand to your insurer, your board, and your customers.
Every plan includes the whole product. From $349 a month, flat AUD.
Every finding lands as one of four verdicts, and a check that could not run is never dressed up as a pass.
- OK
The scan verified it. Nothing else in the report uses this green.
- AT RISK
The scan found a gap: exploitable software, a missing control, an exposed service.
- NOT ASSESSED
A scanner could not complete, so Assay claims nothing. Never treated as a pass.
- NOT OBSERVABLE
Cannot be seen from outside. Assay says so instead of guessing.
Technology you can trust with the work your organisation relies on.
We build under the obligations our clients are held to. The one credential here is independently issued and verifiable on a public registry. Beside it, the platforms we build with in production every day.
- SMB1001:2026 GoldLEVEL 3 · CYBERCERT · PUBLIC REGISTRYVerify ↗
- Microsoft Azure


- Docusign
- Stripe

- Xero
- Microsoft 365
We test and build against ASD Essential Eight, OWASP, MITRE ATT&CK, CISA KEV, SMB1001:2026, ISO 27001, and the Australian Privacy Principles.
Three steps. One commitment.
Read the real risk
We learn the system before we test it: the attack surface, the data that matters, the obligations you carry.
Test like an adversary
We attack applications, networks, and people against the OWASP and ASD playbooks. We test for the objective an attacker is actually after.
Fix like an engineer
Plain-English findings, concrete fixes, and a re-test to prove the holes are closed.
info@blackshard.com.au
Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.