Built to PROTECTED. Run to PROTECTED.

Three managed services built on the patterns we've taken through PROTECTED authorisations — designed to the ISM PROTECTED baseline, hosted in Australia, operated by cleared personnel. With the shared responsibility matrix and control evidence your assessor expects, included.

§ 01 · Why Managed

The same engineering that earns PROTECTED authorisations — delivered as a service.

Most managed services hand you an SLA and a portal. Ours hand you evidence. Every service on this page ships with a documented control implementation and a shared responsibility matrix mapped to the ISM — so if you're pursuing your own authorisation, our services shorten the path rather than adding to your assessment scope.

The operating discipline is the same one that defines our project work: documentation written concurrently with operation, controls mapped before an assessor asks, and no claim on this page we can't evidence.

Claim boundary: these services are designed and operated to the ISM PROTECTED baseline. Where a third-party platform holds an IRAP assessment, we say so — and we say exactly what it covers. Your authorisation remains yours; our job is to make it shorter.

Evidence Included Operations documentation and evidence
§ 02 · MSS · 01

PROTECTED Secure File Transfer.

Email wasn't built to carry OFFICIAL: Sensitive and PROTECTED material. Consumer file sharing can't evidence the controls the ISM requires.

A managed, auditable, Australian-hosted channel for exchanging files with government agencies, defence primes and external parties. ASD-approved cryptography in transit and at rest, multi-factor authentication, full transfer audit logging — and data that never leaves Australian jurisdiction. Recipient access is controlled and time-limited, so a file sent is not a file lost.

Built For
  • Defence industry entities exchanging deliverables and technical data with the Commonwealth
  • Agencies and regulated organisations receiving sensitive material from external parties
  • Organisations replacing ad hoc email attachments and unsanctioned file-sharing tools
Included
  • Australian-hosted platform, designed and operated to the ISM PROTECTED baseline
  • Onboarding of internal users and external parties
  • Transfer auditing, retention and reporting
  • Shared responsibility matrix and control documentation for your assessor
  • Patching, monitoring and operations by cleared Australian staff
MFTASD-Approved CryptoMFAAudit TrailAustralian Hosted
Sovereign infrastructure at night
Plate I · Sovereign by design
§ 03 · MSS · 02

PROTECTED SASE.

Legacy VPN concentrators are an architecture your assessor will question — and your users already resent.

Zero trust network access, secure web gateway and inline inspection for your workforce wherever they operate — built on FortiSASE, which has completed IRAP assessment, and operated from Australia to the ISM PROTECTED baseline.

We design the policy model around your data flows, not a template: per-application access tied to verified identity and device posture, TLS inspection where the ISM expects it, and logging integrated with your security operations. The result is remote access you can put in front of an assessor with the evidence already written.

Built For
  • Agencies and defence industry entities replacing legacy VPN for remote and hybrid workforces
  • Organisations extending PROTECTED-aligned controls to users outside the office network
  • Security teams consolidating web filtering, ZTNA and inspection into one operated service
Included
  • Managed SASE built on IRAP-assessed FortiSASE
  • ZTNA policy design mapped to your applications and data flows
  • Secure web gateway, TLS inspection and threat protection
  • ISM-mapped control documentation and shared responsibility matrix
  • Australian-based operations, monitoring and policy lifecycle management
ZTNASWGTLS InspectionIRAP-Assessed PlatformFortiSASE
§ 04 · MSS · 03

PROTECTED Application Hosting.

A landing zone for applications that need PROTECTED authorisation — with the assessment evidence included.

Standing up PROTECTED-capable hosting from scratch means months of platform engineering before your application team touches configuration — and a documentation debt your assessor will find. We host line-of-business applications on infrastructure built with the same Azure patterns we've taken through PROTECTED ATO processes.

Your application lands on a hardened, monitored platform: web application firewall at the edge, ISM-aligned identity and access, Essential Eight-aligned patching, encrypted storage, and logging that feeds assessment evidence rather than sitting unread. You inherit the platform layer's control implementation, documented and mapped to the ISM — so your authorisation effort covers your application, not the entire stack beneath it.

Built For
  • Agencies and industry partners with applications requiring PROTECTED-level authorisation
  • Software vendors selling into government who need credible hosting behind their offer
  • Organisations exiting unaccredited or end-of-life hosting arrangements
Included
  • Hardened Australian-hosted platform, designed to the ISM PROTECTED baseline
  • Managed web application firewall and edge protection
  • Identity and access, monitoring, patching and backup
  • Control implementation documentation and shared responsibility matrix, assessor-ready
  • Ongoing operations by cleared Australian personnel
AzureWAFEssential 8Evidence PackISM Mapped
Operations infrastructure detail
Plate II · Operations, evidenced
§ 05 · Operating Discipline

Operated the way we build.

Every managed service runs on the same discipline as the PROTECTED Programme's Operate phase. If we built your environment, these services extend it. If we didn't, they stand alone — with their own evidence.

01 · People

Cleared Australian operations

Operated onshore by AGSVA-cleared Australian personnel. No follow-the-sun offshore SOC, no ambiguity about who touches your service.

02 · Evidence

Evidence-first reporting

Service reporting doubles as assessment evidence — control status, patching cadence, incident records — in the formats assessors expect.

03 · Boundaries

Shared responsibility, documented

Every service ships with a shared responsibility matrix mapped to the ISM. You know exactly which controls are ours, which are yours, and where the evidence lives.

04 · Jurisdiction

Sovereign by default

Australian hosting, Australian jurisdiction, Australian operations. Data residency isn't a premium tier — it's the only tier.

Ready to hand over the running?

Talk to a cleared ISM PROTECTED specialist about which service fits your authorisation path — and what you'd inherit on day one.

Start a conversation →