AUTOFYEDGE engagement follows the same four-stage framework - regardless of sector or standard. We design automation and AI-driven systems that hold up under audit, not just in a demo.
We diagnose your actual exposure against the specific standard that governs you — a scored gap assessment, not a generic checklist.
We identify exactly which standards, instruments, and clauses apply to your organisation — not a generic AI framework.
Every control area is scored against current evidence on file, not assumptions about what's "probably fine."
A living index of what an auditor will ask for, and exactly where it currently lives — or doesn't.
Automation and AI workflows are designed against those control requirements from the outset, not retrofitted after a finding.
Every workflow is built against the control requirements surfaced in Evidence Mapping, before a line of automation ships.
Decision points your standard requires a human to review are flagged and built into the workflow, not automated away.
Every new automation is checked against each clause it touches before it goes live — not discovered at the next audit.
Every deployment ships with data handling, explainability, and disclosure controls built in — ready for the Privacy Act's ADM transparency rules.
Storage, access, and retention rules aligned to the Privacy Act and any sector-specific requirements.
Every AI-assisted decision produces a plain-language rationale an auditor — or a client — can actually read.
Automated decision-making disclosures are pre-built to meet the Privacy Act's ADM transparency deadline of 10 December 2026.
An ongoing service that keeps your evidence and monitoring current as standards and audit cycles change.
Your evidence register updates as your systems run, so you're never scrambling in the week before an audit.
We track amendments to the standards governing you and flag exactly what needs to change, before it becomes a finding.
A structured check-in ahead of every audit cycle, so nothing is left to be discovered on the day.
EDGE isn't a methodology for one standard — it's the same four stages mapped against whichever of these actually govern you, so evidence gathered for one never needs re-mapping for another.
Patching, application control, backups, and access management, benchmarked to Maturity Level Two.
The Information Security Manual — the control catalogue behind Essential Eight and most government security baselines.
The Protective Security Policy Framework — core security obligations for Australian Government entities and their suppliers.
Information security capability requirements for banks, insurers, and superannuation funds.
Australian Privacy Principles and automated-decision-making transparency, ahead of the December 2026 mandate.
Risk management program obligations for organisations in scope as critical infrastructure.
Nothing here runs without a signed Rules of Engagement and an explicit go-ahead. Once authorised, testing spans 15 domains, aligned to OWASP, MITRE ATT&CK/ATLAS, CIS, and MASVS — non-destructive by default.
Recon and internet-facing exposure mapping.
OWASP-aligned, Burp Suite & SQLmap.
REST & GraphQL, auth and rate-limit testing.
Kerberoasting, lateral movement, BloodHound.
CVE/EPSS-prioritised scanning.
AWS, Azure, GCP — ScoutSuite.
Image scanning and cluster hardening.
Wi-Fi and RF security testing.
iOS & Android, aligned to OWASP MASVS.
SAST and dependency auditing.
Prompt injection and model risk, aligned to MITRE ATLAS.
Industrial control systems, safety-first by design.
Facility and access-control testing.
Controlled simulations run via Gophish.
Full adversary emulation, mapped to MITRE ATT&CK.
An executive dashboard, maturity gauge, framework-by-framework bars, gap donut, and remediation roadmap — not a raw findings dump.
A Passive Assessment Agreement upfront, and a Rules of Engagement before any active testing runs — auto-generated, not an afterthought.
CISA KEV, CVE/EPSS, MITRE ATT&CK/ATLAS, and ACSC advisories, kept current so your maturity claim doesn't quietly go stale.
A short, no-obligation call to confirm the standard governing you and where a sprint would focus.
A fixed-scope, typically 4–6 week engagement covering Evidence Mapping through Governed Automation.
An optional ongoing service that keeps Execution & Assurance running between audit cycles.