Product · Australian Sovereign Compliance

AuditPro — the sovereign compliance platform for Australia's regulated organisations.

PSPF-classified end-to-end. Hosted only in ap-southeast-2. Designed to exclude US CLOUD Act exposure. Built for IRAP assessors, in-house implementers and certification bodies — three personas, three interfaces, one platform.

AU data residencyCLOUD Act excludedMulti-tenant · RLS-enforcedOrg-level RBAC

Three personas · Three interfaces

One platform. Purpose-built for each side of the certificate.

IRAP & Lead Assessors

Assessor workbench — SSP, SRMP and SAR generation (DOCX + PDF + one-click ZIP), evidence index, peer / technical / lead reviewer workflow. ASD-format exports and ISO 27006 §9.4.9 minor-NC thresholds baked in.

Implementers & GRC Teams

Zero Trust Builder, Essential Eight Maturity Simulator, Integrated Journeys (ISM↔ISO 27001, E8+ISM+ISO, ISO 9001+27001, ISO 27001+42001), ERM with MTTD / MTTR / MTTC, controls, policies and tasks.

Certification Bodies

White-label the assessor side under your own brand, JAS-ANZ number and sub-domain. Full reviewer workflows, sovereign hosting, sub-tenant isolation.

Frameworks covered

Every framework an Australian regulated organisation actually has to answer to.

IRAPEssential Eight (ML0 → ML3)ACSC ISMPSPFDEWR RFFR + TPESSOCI Act / CIRMPISO/IEC 27001ISO/IEC 42001ISO 9001ISO 14001ISO 45001

Why AuditPro, not a US GRC platform

Built for Australia. Not translated for it.

PSPF-aware everywhere

Every artefact is classified UNOFFICIAL → TOP SECRET. Cross-classification flows are blocked at the platform level — not by policy PDF.

IRAP-native

ASD-format exports, ISO 27006 §9.4.9 minor-NC thresholds and reviewer workflows built for the way lead assessors actually work.

SOCI / CIRMP native

Critical asset register and annual CIRMP report to CISC — not an afterthought bolted onto a US GRC schema.

Assessor ↔ Implementer handshake

Zero re-keying between the two sides. Evidence submitted once, referenced everywhere, versioned end to end.

Certification-body white-label

Full branding, sub-domain, JAS-ANZ number and reviewer workflows — a CB can run their entire assessor practice from within AuditPro.

Sovereign by construction

Hosted only in Australian regions (ap-southeast-2). CLOUD Act exclusion attestation. Multi-tenant isolation enforced by RLS, not trust.

The platform behind the engagements

I don't just advise. I ship the platform your compliance runs on.

Every ISO 27001, IRAP and Essential Eight engagement I run is accelerated by AuditPro — the same platform certification bodies white-label for their own assessor practice.

That means less spreadsheet, less re-keying, and evidence that survives day-to-day operations rather than sitting in a shared drive between audits.

Commercial shape

Multi-tenant. Invitation-gated. Tenant isolation by construction.

Plans

FreeProBusinessEnterprise

Free for solo implementers. Pro / Business for consulting practices and mid-market GRC teams. Enterprise for certification bodies and government-adjacent providers.

  • Org switcher across multiple tenants
  • Invitation and approval-gated signup for Assessor and CB roles
  • Org-level RBAC with permissions summary
  • Row-level security enforcing tenant isolation

See AuditPro run against your framework.

Launch the app directly, or book a 30-minute walkthrough tailored to your framework mix — IRAP, ISO 27001, Essential Eight, PSPF or SOCI.