We build software. Then we break it before attackers do.
Black Shard builds production software and secures the systems businesses already rely on. We design and operate web applications, mobile apps, internal platforms and cloud infrastructure. Our security work covers penetration testing, red teaming, cloud and identity reviews, compliance, secure code review and incident remediation. The firm is based in Brisbane and works across Australia.
Engineering and security under one roof
Software engineering and security work, delivered by one firm.
- Software engineering
Web applications, mobile apps, internal platforms and integrations. We can take a product from design through to production, or work inside an existing engineering team.
- Offensive security
Penetration testing, red teaming and social-engineering assessments across applications, APIs, networks and people.
- Security advisory
Security assessments, vCISO engagements, Azure and Microsoft 365 reviews, and ongoing exposure monitoring.
- Incident response
Technical investigation, containment and remediation when a compromise has occurred or is suspected.
- Compliance
Essential Eight, SMB1001, ISO 27001 and Australian Privacy Principle readiness, including the technical work and evidence needed to support the assessment.
- Secure development
Code review, threat modelling and security architecture for software already in production or still being designed.
Work in production
Black Shard has delivered software and security work across legal, clinical, property, recruitment and financial-services environments. The public case studies show the systems, the problem each one solves and the security controls behind it.
Clients



Restart Recruitment
Fox Valuations
Zenith Cardiology- PowerSync
- Sentry
Platforms we use
40+ systems and engagements on the public register alone
Open the work registerThe marks shown are the ones that can be shown publicly.
Assay · External security monitoring without the noise.
External security monitoring without the noise.
Assay monitors your internet-facing systems for exposed services, vulnerable software and configuration changes. Results are mapped to the Essential Eight and SMB1001, with a clear distinction between what has been verified, what presents a risk, and what the scanner cannot determine.
Every plan includes the whole product. Plans start at $349 AUD per month.
Every finding is reported as one of four verdicts. A check the scanner could not complete is reported as such.
- OK
The scan verified it. Nothing else in the report uses this green.
- AT RISK
The scan found a gap: exploitable software, a missing control, an exposed service.
- NOT ASSESSED
A scanner could not complete, so Assay claims nothing. Never treated as a pass.
- NOT OBSERVABLE
Cannot be seen from outside. Assay reports that as the result.
What we hold and what we build on
The certification below is independently issued and can be checked on CyberCert's public registry. The platforms beside it are what our production systems run on. We also build on AWS, Google Cloud and client-run infrastructure when needed.
- SMB1001:2026 GoldLEVEL 3 · CYBERCERT · PUBLIC REGISTRYVerify ↗Black Shard’s certification on the CyberCert public registry, opens in a new tab
Microsoft Azure


- Docusign
- Stripe

- Xero
- Microsoft 365
Frameworks we work against: ASD Essential Eight, OWASP, MITRE ATT&CK, CISA KEV, SMB1001:2026, ISO 27001, and the Australian Privacy Principles.
How we work
Scope
We scope the system first, including the information it holds, the way it is used and the obligations around it.
Test and review
Testing and review then focus on the paths that could produce meaningful impact.
Verify
Where remediation is included, fixes are verified before the engagement is closed.
[email protected]
Tell us what you need built, reviewed or secured. 1800 370 270. Our head office is in Brisbane, and we deliver work across Australia.

