Industries · Financial services
Systems built around the licence.
We build the operating systems an AFSL holder runs on, and the security posture its investors diligence. Stone Leaf Capital already runs on ours.
An AFSL is a records regime as much as a licence: obligations to keep adequate risk-management systems, retain financial records, and prove to ASIC, to auditors, and to investors that the firm operates the way it says it does. The systems underneath either make that provable or make it hard.
Stone Leaf Capital, an Australian capital-markets firm, engaged us to build exactly that: a staff portal structured around the firm’s AFSL perimeter, with critical-event tracking, policy modules, and a compliance audit log capturing actor, action, and before-and-after state on every change.
What you carry, and what we do about it.
AFSL record-keeping is unforgiving: records must exist, be attributable, and be retrievable years later.
We design operating portals around the licence perimeter, with compliance audit logs that capture actor, action, and before-and-after state on every change: the system Stone Leaf Capital runs on.
Product & platform engineeringInvestor due diligence now includes security questionnaires, and vague answers read as findings.
A posture assessment maps where you stand against recognised controls, and a vCISO retainer gives you a named security lead whose answers you can put in front of investors.
vCISO & posture assessmentOperational resilience sits inside the general obligations: could the firm keep operating, and recover, through an incident?
Incident readiness built before you need it: a response plan written for your team, a tabletop exercise that pressure-tests it, and backup recovery verified against a real restore.
Incident readinessWhen a regulator or auditor asks what happened, the audit trail is the answer, or the problem.
We review your logging and alerting coverage so you would actually see an attack, and we build audit trails into the systems we ship so the record exists before anyone asks.
Detection & response advisory
The obligations in play
- Corporations Act, s 912A
- AFSL general obligations include adequate risk-management systems, a head ASIC has already litigated over cyber failures.
- Corporations Act, s 286
- Financial records must be kept for seven years, in a form that lets them be conveniently audited.
- AML/CTF Act 2006
- Many licensees are reporting entities: programs, customer identification, and transaction reporting.
- Privacy Act 1988
- Client personal and financial information under the APPs, with the Notifiable Data Breaches scheme behind it.
- APRA CPS 234
- Where a firm is APRA-regulated, information-security capability becomes a board-owned obligation.
This list orients the engineering work. It is not legal advice; your advisers own the interpretation.
The build behind this page
Stone Leaf Capital
An Australian capital-markets firm (funds management, capital raising, corporate advisory) running day-to-day on the brand, public site, and staff portal we built: critical-event tracking, policy modules, and a compliance audit log, structured around the firm’s AFSL perimeter.
See the workThe services behind this page.
Defensive & advisory
Ongoing security leadership and review, without hiring a full-time CISO.
Read more
Software engineering
Engineering for the systems a business runs on: web, native mobile, portals, and the platform underneath.
Read more
Breach remediation
Incident response and remediation engineering for organisations that have had, or suspect, a security incident.
Read more
Answer the due-diligence questionnaire with evidence.
Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

