Skip to content

What we do, and what it involves

Four pillars, each delivered as a fixed-scope engagement with a fixed term including the ongoing ones. Every engagement below lists what it is for, roughly how long it runs, and exactly what you receive at the end of it.

AI solutions

Most businesses are being sold AI before anyone has worked out which problem it solves. The result is a pilot nobody owns and a subscription nobody cancels.

We start by finding out where AI actually helps and, just as importantly, where it does not. Then we build one system properly and measure it against your own data rather than a vendor benchmark. If the numbers do not hold up, we say so.

Evaluation scorecard

Delivered at the end of week two.

ProcessEffortImpactVerdict
Ticket triageLowHigh
Invoice codingMediumHigh
Contract reviewHighLowDo not build

Illustrative format — not client data.

Engagements

AI opportunity review

2 weeks

Work out which processes are worth automating with AI, and which are not, before committing to a build.

What you receive
  • A ranked shortlist of candidate processes, scored on effort and impact
  • A written recommendation on what not to pursue, and why
  • An assessment of whether your data is in a fit state to support it
  • A costed outline of the first build worth doing

Pilot build

4 to 6 weeks

Put one AI-assisted process into production, with a way of telling whether it is working.

What you receive
  • One working system in production, with a named owner in your team
  • An evaluation harness that measures accuracy against your data
  • A runbook covering failure modes and what to do about them
  • A handover session, and the code, in your repository

Ask about AI solutions

Process automation

Work that runs on copy-paste, spreadsheets and reminder emails is slow, and it fails quietly. The cost rarely appears on a budget line, which is why it survives for years.

We map the process as it actually runs, not as the documentation claims, and put a time and cost figure against it. Then we automate the steps worth automating and leave the rest alone. Everything we build is documented so your team can change it without calling us back.

Process map

The workflow as it runs today, and what it becomes.

Today — 6 steps, 5 handoffs

  • Export
  • Reformat
  • Email
  • Chase
  • Re-key
  • File

Automated — 3 steps, exceptions only

  • Ingest
  • Match
  • Post

Illustrative format — not client data.

Engagements

Process audit

2 weeks

Establish what a target workflow really costs today, and what could be removed from it.

What you receive
  • A process map of the workflow as it runs in practice
  • A time and cost baseline you can measure improvement against
  • A ranked automation backlog, with effort estimates
  • A build-or-buy recommendation for each step

Automation build

4 to 8 weeks

Put the agreed automation into production and hand it over.

What you receive
  • The automated workflow, running in production
  • Exception handling and alerting, so failures are visible rather than silent
  • Documentation written for your team, not for us
  • A handover session and an agreed support arrangement

Ask about process automation

ISO 27001 readiness and advisory

ISO 27001 usually arrives as a customer requirement with a deadline attached. The standard is not the hard part; keeping the business running while you meet it is.

We assess where you stand against the controls, then sequence the remediation so the work fits around delivery. We write the documentation with you rather than handing over a template pack, because your certification auditor will ask your team about it, not us. We prepare you for that audit; we do not conduct it.

Gap register

Mapped to Annex A, with an owner against every gap.

ControlDescriptionStatus
A.5.1Policies for information security
A.5.15Access controlPartial
A.8.16Monitoring activitiesGap
A.5.19Supplier relationshipsGap

Illustrative format — not client data.

Engagements

ISO 27001 gap assessment

3 weeks

Establish the real distance between where you are and a successful certification audit.

What you receive
  • A gap register mapped to Annex A controls
  • A prioritised remediation plan with owners and effort estimates
  • A draft Statement of Applicability
  • A realistic timeline to certification, including where it is likely to slip

Certification readiness

3 to 6 months

Close the gaps and take you through to a certification audit.

What you receive
  • A complete ISMS documentation set
  • Risk assessment and risk treatment plan
  • An internal audit and the management review pack
  • Support through the Stage 1 and Stage 2 audits

Ask about ISO 27001 readiness

Managed services

Systems decay quietly. An upstream field changes, a model starts drifting, an access review gets skipped for two quarters. Nobody notices until something fails in front of a customer or an auditor.

For the work we have delivered, we can keep watching it. Fixed term, fixed price, a named contact and a scheduled review at the end — not a retainer that renews while nobody looks at it. If a term ends and there is nothing useful left for us to do, we will say so.

Evidence calendar

Run on schedule, so the audit is not a scramble.

ActivityQ1Q2Q3Q4
Access reviewScheduled in Q1Scheduled in Q2Scheduled in Q3Scheduled in Q4
Risk reviewScheduled in Q1Not scheduled in Q2Scheduled in Q3Not scheduled in Q4
Supplier checkNot scheduled in Q1Scheduled in Q2Not scheduled in Q3Scheduled in Q4
Internal auditNot scheduled in Q1Not scheduled in Q2Scheduled in Q3Not scheduled in Q4

Illustrative format — not client data.

Engagements

Automation support

12-month term, reviewed quarterly

Keep automations and AI-assisted processes working as the systems around them change.

What you receive
  • Monitoring and alerting on the workflows we built, so failures surface rather than accumulate
  • An agreed response time for breakages, and a named contact who already knows the system
  • A quarterly review of what has drifted, with the evidence behind it
  • An agreed allowance for small changes, so minor fixes do not need a new engagement

ISMS operation

12-month term, aligned to your audit cycle

Keep an ISO 27001 management system running between certification audits, rather than rebuilding it each year.

What you receive
  • The evidence calendar run on schedule — access reviews, risk reviews, supplier checks
  • The annual internal audit and the management review pack
  • Preparation and support for your surveillance audit
  • A quarterly report on where the system is slipping, while it is still cheap to fix

Infrastructure management

12-month term, reviewed quarterly

Keep your onprem/cloud infrastructure patched, monitored and running, without carrying the overhead of a dedicated ops hire.

What you receive
  • Monitoring and alerting across your AWS infrastructure, so incidents surface before they reach your customers
  • Patching and maintenance on an agreed schedule, with change records kept for audit purposes
  • An agreed response time for incidents, and a named contact who already knows your environment
  • A monthly report on cost, performance and anything that needs attention before it becomes a problem

Ask about managed services

Questions we get asked

If yours is not here, ask it directly — we would rather answer it before you commit to anything.

How do you price engagements?

Each engagement above is fixed scope, quoted as a fixed price after a scoping call. You get the figure before the work starts, and it does not move unless the scope does. We do not bill by the hour, because that charges you for our learning curve.

Do you replace our existing team?

No. We work alongside your team and hand the work over to them. If an engagement finishes and nobody in your business can maintain what we built, we have failed regardless of whether the system works.

What if we are not convinced AI is the right answer?

That is a reasonable position and often the correct one. The AI opportunity review exists partly to say no. If the honest answer is that a process should be simplified or automated conventionally rather than handed to a model, that is what the recommendation will say.

We have already started ISO 27001. Can you pick it up midway?

Yes. The gap assessment works just as well on a part-finished implementation, and it is usually faster because some of the evidence already exists. We will tell you what is reusable and what needs redoing.

Do you only work with businesses in Melbourne?

No. We are based in Melbourne and work with businesses across Australia. Most delivery is remote, with on-site time where it genuinely helps, such as process mapping and audit preparation.

What size of business do you usually work with?

Small and mid-market Australian businesses, typically those large enough to feel the cost of manual process or a compliance requirement, but without a dedicated internal team to absorb it.

Not sure which of these you need?

Most conversations start with a problem rather than a service. Describe what is going wrong and we will tell you which engagement fits, or whether none of them do.

Start a conversation