Citizen services that scale,
on foundations that survive audit
Public sector delivery has two hard constraints: the procurement process that got you here, and the scrutiny that follows. We work inside both rather than pretending they are someone else's problem.
What agencies and universities bring us
Legacy applications with a hard end date
A platform out of vendor support, a datacentre contract expiring, or a machinery-of-government change that forces a separation nobody planned for.
Essential Eight maturity on paper only
The strategies are documented and partially implemented, with no continuous measurement and no clear line between the policy and the configuration in the account.
Demand that arrives all at once
Enrolment periods, grant rounds, emergency events. Services sized for average load and judged on peak behaviour.
What we deliver in the public sector
Sovereignty, transparency and handover are treated as requirements, not afterthoughts.
Essential Eight implementation
Which of the eight strategies map cleanly onto AWS-native controls, which need additional tooling, and which are organisational — with maturity measured continuously rather than annually.
- Control implementation mapped to maturity levels
- Continuous measurement and drift alerting
- Clear separation of technical and process controls
Legacy remediation and exit
Assessment, disposition and migration for applications that must move, including the ones whose original owners have long since left the agency.
- Portfolio assessment with 6R disposition
- Documented sunset paths for unsupportable systems
- Evidence pack for the decommissioning decision
Citizen service platforms
Elastic, observable services for enrolment, applications and grants — with accessibility and performance treated as delivery requirements.
- Elastic architecture for demand spikes
- WCAG-aware delivery practices
- Public-facing SLO definition and reporting
Data sharing with lineage
Inter-agency and inter-faculty data sharing where every access is logged, every dataset has a custodian, and lineage answers the question before it is asked.
- Catalogue with named data custodians
- Lineage from source to published product
- Purpose-based access controls
The frameworks we design against
We are not an assessor. We build to the standard your assessor will apply, and we produce the artefacts the assessment needs.
Essential Eight
ACSC mitigation strategies mapped to deployable AWS controls, with maturity level targets agreed before build.
ISM & IRAP-informed
Architecture aligned to Information Security Manual controls, structured to support an IRAP assessment where one is required.
Privacy Act & APPs
Collection, use and disclosure obligations for citizen and student data, including cross-border disclosure limits.
What public sector clients ask first
Panel arrangements change; ask us for our current status and we will confirm in writing, including where we would need to work through a prime. We would rather tell you upfront than waste your probity officer's time.
In the AWS Asia Pacific (Sydney) region by default, with the Melbourne region as a secondary where required. Any proposed exception is documented and requires written approval before implementation.
That is the design goal. Enablement and pairing are scoped from week one, everything is in version control, and the final milestone in our public sector engagements is always a handover with runbooks and a shadow period.
No. Delivery is by Australian-based staff. If a specialist capability is required that we do not hold, we name the partner in the proposal rather than after award.
Start with the assessment your business case needs
A portfolio assessment gives you dispositions, sequencing, a costed roadmap and the evidence trail for the decisions inside it.