Independent security monitoring for Australian business.
Our scanner, pointed at your business.
Assay scans your internet-facing systems, maps every finding to the Essential Eight and SMB1001, and gives you evidence you can hand to your insurer, your board, and your customers.
Live: create your account and run your first scan today.
The verdict grammar
Four verdicts. Nothing implied.
Most scanners imply certainty they do not have. Assay publishes exactly what a scan can and cannot see, and a check that could not run is never dressed up as a pass.
- OK
OK
The scan verified it. Nothing else in the report uses this green.
- AT RISK
At risk
The scan found a gap: exploitable software, a missing control, an exposed service.
- NOT ASSESSED
Not assessed
A scanner could not complete, so Assay claims nothing. Never treated as a pass.
- NOT OBSERVABLE
Not observable
Cannot be seen from outside. Assay says so instead of guessing.
What every scan checks.
Every assessment runs the same six disciplines against what your systems actually expose to the internet, and maps the results to the Essential Eight and SMB1001.
Attack-surface discovery
Every exposed host and service catalogued, with remote-access and database ports flagged when they appear.
Vulnerability checks
Curated checks for known CVEs, misconfigurations, default logins, and TLS problems, run against what your systems actually serve.
Email authentication
SPF and DMARC checked over DNS: missing records, softfail, p=none, and broken policies.
Exploited-in-the-wild ranking
Findings ranked with CISA’s Known Exploited Vulnerabilities catalogue and EPSS probabilities.
Attack paths
When a gap matters, the route an attacker could take to reach it, expressed in MITRE ATT&CK techniques.
Change tracking
Scheduled scans diff every assessment against the last one, so you see the moment something gets worse.
Plans.
Monitor
$349a month
or $3,840 a year
One business, the whole product: daily scans, change alerts, attack paths, the insurance evidence pack.
Group
$549a month
or $6,040 a year
Three businesses under one account, everything included.
Portfolio
$999a month
or $10,990 a year
Ten businesses under one account, built for IT providers and multi-entity groups.
Prices in AUD, including GST: the price on the page is the price. Billed through Stripe.
Fixing what Assay finds is separate. That’s us, the consultancy: breach remediation and defensive & advisory.
Want the scans read for you?
A senior engineer reads every result under managed exposure monitoring: the same Assay scans, interpreted by the team that built the scanner.
Managed exposure monitoringAssay is built and run by Black Shard: the Brisbane team that designs, builds, and attacks production platforms in law, health, property, capital, and recruitment.
The work behind itWhat we hold, verified on the public registry
See what an attacker can reach.
Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

