Find the holes before a stranger does.
An audit is a structured look at the systems your staff and your AI actually use — Microsoft 365, the on-prem kit, the MCP server, the website, the backups. You get a plain-English list of what to fix first. Then a monthly watch so it does not drift.
Not a 80-page scare PDF. A punch-list your team can act on.
Tenant & serversM365, Google, the box in the cornerLogins, MFA, sharing links, backups that actually restore, the admin account still named Password1.
Apps & sitesThe software we or someone else builtExposed admin pages, old plugins, API keys in the front end. Fix or flag.
| Offer | What you walk away with | From |
|---|---|---|
| Point-in-time audit | Half-day to two days on the stack you name. Written findings, severity, who should fix what. | A$2,900–8,400 |
| AI / on-prem audit | The kit, the model allow-list, the MCP licence, data egress. Built for firms that cannot send files to a US tenant. | A$4,900–12,000 |
| Audit Care | Quarterly re-check plus a monthly watch on the same systems. Recurring. That is the line that pays. | A$490–1,690 / mo |
| Remediation sprint | We fix what the audit found — with sysadmin or development Care if it is ongoing. | Quoted from the report |
This is a practical review for Australian SMEs and mid-market, including government-adjacent offices. It is not a claim that you are ISO-certified when you are not, and it is not a SECRET clearance product.
Is this a hack-the-company pentest?
No. That is a different, scoped engagement if you need one. The standard audit is configuration, access, backups, the AI surface and the obvious holes. Say if you want a deeper test.
Can you audit a system you did not build?
Yes. Bring the tenant, the kit or the repo. We will say what we can see and what we cannot.
