Security you
can verify.
We sell security, so we hold ourselves to it. What we hold is independently issued and checkable; what we self-assess is labelled exactly that. Follow any credential straight to the registry, the standard, or the platform that holds it.
One certification, independently issued.
SMB1001:2026 Gold is held by the legal entity, Black Shard Pty Ltd, and verifiable on CyberCert’s public registry.
- Standard
- SMB1001:2026 Gold (Level 3)
- Held by
- Black Shard Pty Ltd · ABN 66 696 910 773
- Issued by
- CyberCert
- Active
- 16 June 2026 to 17 June 2027
- Basis
- Formal director attestation against the standard’s 27 controls
If the standard itself is new to you, we wrote the plain-English explainer: the five tiers, how a certificate is issued, and how to check one you have been sent.
The frameworks we build to.
We design and operate to the frameworks that govern serious Australian ICT, the ones a regulated buyer expects us to know cold. We measure ourselves against each one and build toward it. Where a framework is a design standard rather than a certification we hold, we say so plainly.
ASD Essential Eight
Self-assessed · Maturity Level 1
The Australian Signals Directorate’s eight mitigation strategies: patching, application control, multi-factor authentication, restricting administrative privileges, and the remaining strategies. We self-assess at Maturity Level 1, and most of these controls overlap directly with the SMB1001 controls we attest to, so the two reinforce one another rather than sitting apart.
Privacy Act 1988 · Australian Privacy Principles
Aligned
As an Australian operator handling personal information, we build to the Australian Privacy Principles under the Privacy Act 1988: collection limits, purpose, access and correction, and breach handling. This is the regime that applies to us, designed in rather than retrofitted.
ASD Information Security Manual (ISM)
Aligned
The Australian Government cyber security framework for systems that handle official information. We design and operate the controls behind our software to the ISM where it applies, so work that touches government-grade obligations starts from the right baseline.
CIS Controls v8
Self-assessed
The Center for Internet Security vendor-neutral critical security controls. We measure our engineering and operations against them as a cross-check on the Australian frameworks, so nothing important falls between the two.
Platforms that hold their own assessments.
We build on Microsoft Azure, in Australian regions. Azure’s infrastructure is independently IRAP-assessed to PROTECTED and holds ISO 27001 and SOC 2, at the platform level, never as Black Shard certifications. Inheriting a platform’s assurance is not the same as holding it ourselves, and we keep that line clear.
Microsoft’s IRAP assessment ↗The programs we belong to.
Partner and membership programs appear here only once acceptance is in writing. Applications in flight stay off this page; if it is listed, we hold it.
Twilio Partner Connection
Consulting partner
Twilio’s program for consultancies that build communications into software. We embed messaging, voice and verification in the platforms we deliver.
The posture behind the certificate.
A certificate is a snapshot; these are the working habits that keep it honest between renewals. We describe the posture rather than naming specific tooling.
- Least-privilege access.
- People and systems get only the access the work requires, and no more. Administrative privilege is restricted and granted deliberately, not by default, and access is reviewed as roles change.
- Encryption in transit and at rest.
- Data is encrypted on the wire and where it is stored. We rely on the encryption primitives the underlying platforms provide rather than rolling our own.
- Backups and recovery.
- Production data is backed up so we can recover from loss or corruption. Recovery is treated as something to rehearse, not assume.
- Incident handling.
- We have a defined path for identifying, containing, and communicating a security incident, including the notification obligations the Privacy Act places on us where a breach is likely to cause serious harm.
- Vendor and sub-processor discipline.
- We keep the set of third parties that touch data deliberately small, prefer platforms that hold their own independent assessments, and choose Australian regions for the services that host client data.
The firm holds current professional indemnity, public liability, and cyber insurance. Certificates of currency are available to clients on request.
The platforms behind the work.
The systems we ship are built with and run on these platforms and services, in production, every day. Marks are shown plainly: platform facts, not certifications.
Platform partners
- Microsoft Azure
- Microsoft 365
- Cloudflare
- Stripe
- Docusign
- Twilio
- Xero



Coordinated disclosure.
If you believe you have found a vulnerability in a Black Shard system, email info@blackshard.com.au with enough detail to reproduce it. We acknowledge reports within 48 hours, we do not take legal action against good-faith research, and we credit reporters who want it. Our security.txt is published per RFC 9116.
Incident response.
Security incidents are triaged by the same engineers who build and test the systems. Black Shard complies with the Privacy Act 1988 Notifiable Data Breaches scheme, notifying affected parties and the OAIC when required.
Questions a trust page cannot answer?
Running procurement or due diligence? The capability statement is below. Ask for our answers to your security questionnaire and someone will contact you as soon as possible with plain-English answers.


