AUTOFYEDGE mark AUTOFYEDGE
Our Framework

The EDGE Framework

AUTOFYEDGE engagement follows the same four-stage framework - regardless of sector or standard. We design automation and AI-driven systems that hold up under audit, not just in a demo.

E
Stage 01

Evidence Mapping

We diagnose your actual exposure against the specific standard that governs you — a scored gap assessment, not a generic checklist.

Regulatory workshop

We identify exactly which standards, instruments, and clauses apply to your organisation — not a generic AI framework.

Scored gap assessment

Every control area is scored against current evidence on file, not assumptions about what's "probably fine."

Evidence register

A living index of what an auditor will ask for, and exactly where it currently lives — or doesn't.

D
Stage 02

Design for Compliance

Automation and AI workflows are designed against those control requirements from the outset, not retrofitted after a finding.

Control-first architecture

Every workflow is built against the control requirements surfaced in Evidence Mapping, before a line of automation ships.

Human-in-the-loop points

Decision points your standard requires a human to review are flagged and built into the workflow, not automated away.

Change-impact mapping

Every new automation is checked against each clause it touches before it goes live — not discovered at the next audit.

G
Stage 03

Governed Automation

Every deployment ships with data handling, explainability, and disclosure controls built in — ready for the Privacy Act's ADM transparency rules.

Data handling controls

Storage, access, and retention rules aligned to the Privacy Act and any sector-specific requirements.

Explainability by default

Every AI-assisted decision produces a plain-language rationale an auditor — or a client — can actually read.

Disclosure-ready

Automated decision-making disclosures are pre-built to meet the Privacy Act's ADM transparency deadline of 10 December 2026.

E
Stage 04

Execution & Assurance

An ongoing service that keeps your evidence and monitoring current as standards and audit cycles change.

Live evidence dashboard

Your evidence register updates as your systems run, so you're never scrambling in the week before an audit.

Standards-change monitoring

We track amendments to the standards governing you and flag exactly what needs to change, before it becomes a finding.

Quarterly assurance review

A structured check-in ahead of every audit cycle, so nothing is left to be discovered on the day.

Regardless of Sector or Standard

Six frameworks, one evidence trail

EDGE isn't a methodology for one standard — it's the same four stages mapped against whichever of these actually govern you, so evidence gathered for one never needs re-mapping for another.

ACSC

Essential Eight

Patching, application control, backups, and access management, benchmarked to Maturity Level Two.

ASD

ISM

The Information Security Manual — the control catalogue behind Essential Eight and most government security baselines.

Government

PSPF

The Protective Security Policy Framework — core security obligations for Australian Government entities and their suppliers.

APRA

CPS 234

Information security capability requirements for banks, insurers, and superannuation funds.

OAIC

Privacy Act

Australian Privacy Principles and automated-decision-making transparency, ahead of the December 2026 mandate.

CISC

SOCI Act

Risk management program obligations for organisations in scope as critical infrastructure.

Where Execution & Assurance Goes Deeper

15 domains, authorisation-gated

Nothing here runs without a signed Rules of Engagement and an explicit go-ahead. Once authorised, testing spans 15 domains, aligned to OWASP, MITRE ATT&CK/ATLAS, CIS, and MASVS — non-destructive by default.

External attack surface

Recon and internet-facing exposure mapping.

Web application

OWASP-aligned, Burp Suite & SQLmap.

API

REST & GraphQL, auth and rate-limit testing.

Network & Active Directory

Kerberoasting, lateral movement, BloodHound.

Vulnerability management

CVE/EPSS-prioritised scanning.

Cloud

AWS, Azure, GCP — ScoutSuite.

Container & Kubernetes

Image scanning and cluster hardening.

Wireless

Wi-Fi and RF security testing.

Mobile

iOS & Android, aligned to OWASP MASVS.

Secure code review

SAST and dependency auditing.

AI / LLM security

Prompt injection and model risk, aligned to MITRE ATLAS.

OT / ICS

Industrial control systems, safety-first by design.

Physical security

Facility and access-control testing.

Phishing & social engineering

Controlled simulations run via Gophish.

Red team

Full adversary emulation, mapped to MITRE ATT&CK.

Tangible, Not Abstract

What Execution & Assurance actually hands you

A branded audit report

An executive dashboard, maturity gauge, framework-by-framework bars, gap donut, and remediation roadmap — not a raw findings dump.

The two contracts

A Passive Assessment Agreement upfront, and a Rules of Engagement before any active testing runs — auto-generated, not an afterthought.

A weekly threat-intel sync

CISA KEV, CVE/EPSS, MITRE ATT&CK/ATLAS, and ACSC advisories, kept current so your maturity claim doesn't quietly go stale.

How an Engagement Runs

From diagnostic to ongoing assurance

01

Regulatory Risk Diagnostic

A short, no-obligation call to confirm the standard governing you and where a sprint would focus.

02

Evidence & Automation Sprint

A fixed-scope, typically 4–6 week engagement covering Evidence Mapping through Governed Automation.

03

Assurance Retainer

An optional ongoing service that keeps Execution & Assurance running between audit cycles.

See where EDGE would start with your organisation.