Black Shard

Independent security monitoring for Australian business.

Our scanner, pointed at your business.

Assay scans your internet-facing systems, maps every finding to the Essential Eight and SMB1001, and gives you evidence you can hand to your insurer, your board, and your customers.

Live: create your account and run your first scan today.

The verdict grammar

Four verdicts. Nothing implied.

Most scanners imply certainty they do not have. Assay publishes exactly what a scan can and cannot see, and a check that could not run is never dressed up as a pass.

  • OK

    OK

    The scan verified it. Nothing else in the report uses this green.

  • AT RISK

    At risk

    The scan found a gap: exploitable software, a missing control, an exposed service.

  • NOT ASSESSED

    Not assessed

    A scanner could not complete, so Assay claims nothing. Never treated as a pass.

  • NOT OBSERVABLE

    Not observable

    Cannot be seen from outside. Assay says so instead of guessing.

What every scan checks.

Every assessment runs the same six disciplines against what your systems actually expose to the internet, and maps the results to the Essential Eight and SMB1001.

  • Attack-surface discovery

    Every exposed host and service catalogued, with remote-access and database ports flagged when they appear.

  • Vulnerability checks

    Curated checks for known CVEs, misconfigurations, default logins, and TLS problems, run against what your systems actually serve.

  • Email authentication

    SPF and DMARC checked over DNS: missing records, softfail, p=none, and broken policies.

  • Exploited-in-the-wild ranking

    Findings ranked with CISA’s Known Exploited Vulnerabilities catalogue and EPSS probabilities.

  • Attack paths

    When a gap matters, the route an attacker could take to reach it, expressed in MITRE ATT&CK techniques.

  • Change tracking

    Scheduled scans diff every assessment against the last one, so you see the moment something gets worse.

Plans.

  • Monitor

    $349a month

    or $3,840 a year

    One business, the whole product: daily scans, change alerts, attack paths, the insurance evidence pack.

  • Group

    $549a month

    or $6,040 a year

    Three businesses under one account, everything included.

  • Portfolio

    $999a month

    or $10,990 a year

    Ten businesses under one account, built for IT providers and multi-entity groups.

Prices in AUD, including GST: the price on the page is the price. Billed through Stripe.

Fixing what Assay finds is separate. That’s us, the consultancy: breach remediation and defensive & advisory.

Want the scans read for you?

A senior engineer reads every result under managed exposure monitoring: the same Assay scans, interpreted by the team that built the scanner.

Managed exposure monitoring

Assay is built and run by Black Shard: the Brisbane team that designs, builds, and attacks production platforms in law, health, property, capital, and recruitment.

The work behind itWhat we hold, verified on the public registry

See what an attacker can reach.

Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

Open a briefinfo@blackshard.com.au