Data & privacy advisory, independent
Data and privacy advisory is an independent review for Australian organisations with a bespoke platform or CRM where no one has recently asked the hard questions about hosting, access, backups or breach response. The OAIC's Notifiable Data Breaches reports consistently show that compromised credentials and misconfigured access controls cause most Australian breaches. We sit with your platform developer, ask the questions you do not have time to ask, and write down what we find. A clear picture, a risk-rated list, and a plan you can hand to your MSP.
You grew into your stack, now no one knows how it works
A custom CRM was built years ago. The MSP runs the network and devices but is not across the application layer. The developer of the bespoke platform is the only one who really knows how it works. You are between them.
You do not need a 200 page audit. You need someone independent to ask the right questions, write down the answers, and tell you what to do next in plain language. We sit with the developer or platform owner, work through hosting, encryption, access, backups, supply chain and incident response, and produce a report you can act on.
The four areas we cover
Platform review
Hosting, location and data sovereignty. Encryption in storage and in transit. Login, MFA, password policy and SSO. Redundancy and high availability. Backup, recovery and resilience including restore testing. Logging and audit trails. Certifications (SOC 2 Type 2, ISO 27001, IRAP) and when last reviewed. Supply chain and third parties.
Data lifecycle and retention
The categories of personal and sensitive data being held. How long each type is kept and whether that is configurable. How data is destroyed or archived. Whether copies sit outside the main environment.
Access and permissions
Current roles and permissions model. How access is set up, changed and removed when staff start, change roles or leave. How admin and privileged accounts are handled, including any developer or third-party access. How often access is reviewed.
Incident response readiness
What should happen if there is a data breach. Gaps between current practice and good practice. Escalation paths between you, the platform developer and any sub-processors. Whether the developer has notification commitments in writing. We include our ADM disclosure template to cover automated decision-making notifications under the 2026 Privacy Act reforms.
How the engagement runs
Confirm scope and platform
Short call with the project sponsor to confirm the platform in scope, priorities, stakeholders and timing.
Working sessions with the developer
Working sessions with the platform developer or owner. We review documents, policies, sub-processor lists and certification reports where available.
Draft advisory report
Findings, risks rated low, medium or high, and practical recommendations with the right owner indicated. Issued for your review.
Final report and plan
Walkthrough session with the leadership team. Final report incorporating any clarifications. Ready to hand to your MSP or another delivery partner.
We work with one nominated platform per engagement, typically a bespoke CRM or line-of-business system. If you have multiple platforms in scope, we will discuss sequencing on the scoping call.
What you walk away with
What we found across each area. Risks rated low, medium or high. Practical recommendations based on good practice. Plain language for leadership.
- ✓Findings by area
- ✓Risk-rated issues
- ✓Recommendations
- ✓Suggested owners
A documented view of the supply chain behind your core platform: hosting, databases, backups, monitoring, email, SMS, analytics and AI components.
- ✓Sub-processor list
- ✓Where each sits
- ✓Assessment status
- ✓Concentration risk
A session to step through the report, answer questions and agree priorities. Ready to hand to your MSP, internal team or a third party.
- ✓Leadership walkthrough
- ✓Stakeholder Q&A
- ✓Priority agreement
- ✓Action-ready output
fixed price quote agreed before any work starts.
What this engagement is not
A formal compliance audit
We do not certify against ISO 27001, SOC 2 or IRAP. We point at where you sit.
A penetration test
We do not run vulnerability scans. We tell you whether one is the right next step.
An implementation project
We make findings and recommendations. Action sits with your MSP, internal team or a third party.
Legal advice
We are not lawyers. We will tell you when a privacy lawyer is the right call.
Vendor management
We do not negotiate contracts on your behalf. We give you the questions to ask.
When to call us in
Asking about data handling
A board or funder is asking questions about data handling that the executive cannot confidently answer.
New obligations on the horizon
A new privacy obligation is coming, for example the WA Privacy and Responsible Information Sharing (PRIS) reforms.
Evidence required
A grant, tender or contract requires written evidence of data handling practices for a bespoke or third-party platform.
No one has looked at it in years
A bespoke platform has been in place for years and no one has recently looked at how it is built or run.
Application layer is unowned
The MSP is doing good work at the infrastructure layer but no one is reviewing the application or data layer.
Personal and sensitive data
Disability, aged care, allied health, education, NFP. Sectors where personal and sensitive data is part of day-to-day operations.
The full capability list
Consulting, automation, security and training, plus the build and fix work when you need it. These are the eight we lead with; 32 in total. Your AI consultant in Perth, working nationally.
AI Consulting
Map your ops, find where AI makes sense, build an implementation plan your team can follow.
Learn moreAutomation
n8n, Make, Power Automate, custom integrations. The boring weekly tasks, automated.
Learn moreAI Security & DLP
Stop data leaking into AI tools. Usage policy, M365 controls, Privacy Act and Essential Eight aligned.
Learn moreAI Training
Train your whole team to use AI well. Role-based programs, workshops and coaching across Claude, ChatGPT and Copilot.
Learn moreApp Development
Apps, tools, MVPs and internal systems built with AI-assisted dev, with senior engineering oversight.
Learn moreVibe Code Audit & Fix
Built with Claude, Cursor, Bolt or Lovable? We find what's broken, patch it, hand it back production-ready.
Learn moreAI Agents
Custom agents for CRM, accounting, project management. Built with Claude, GPT and MCP.
Learn moreAgentic Coding
Autonomous coding agents build features end-to-end. We review, steer, and ensure production quality.
Learn moreAn independent advisory review of a third-party SaaS platform holding sensitive client data. We sat with the client's team on site, worked through the vendor's policy library and penetration test evidence, and came out the other side with a 31-page report and a prioritised list for leadership.
Read the case studyFrequently asked questions
No. We are not your MSP and we do not want to be. The MSP runs the network, devices and infrastructure. We sit at the application and data layer, often the bit no one is reviewing right now. The report is written so your MSP can pick up the actions that are theirs to do.
No. We are not building a replacement and we are not pitching you a different platform. We are independent. Most developers we work with appreciate the engagement once they understand the framing: we are there to make their platform stronger, not to attack it.
Yes. The discovery sessions are with the platform developer or owner. We come prepared with the right questions and we know what good answers look like. You do not need to be in every session, though many sponsors choose to be.
That is common, especially for bespoke platforms built for a single client. The advisory does not require certification. We document where you sit against the relevant standards, what good practice looks like, and what would need to happen if a certification ever became a requirement.
Yes. We do a lot of work with not-for-profits, disability and aged care providers. Personal and sensitive data, board oversight, funder questions and sector-specific obligations make this engagement particularly relevant.
A penetration test looks at whether the platform can be technically broken into. This advisory looks at how the platform is built, run and supported, including the things a pen test does not cover: supply chain, retention, access reviews, breach response. The two are complementary. We will tell you whether a pen test is the right next step.
Need answers about a platform you can't fully see? Start with a 30 minute scoping call
we will tell you whether this engagement is the right fit. No pitch deck.