Engineering for software that has to survive scrutiny.
We take ideas and prototypes to production-ready products, for industries where the software will be audited, assessed, or trusted with sensitive data.
Anyone can produce a prototype now. Almost nobody can produce a product their customer's security review will accept.
The demo takes an afternoon. The rest takes judgement: keeping one customer's data genuinely separate from another's, proving who did what and when, handling documents safely, surviving a questionnaire from an insurer or a government department, and still being maintainable in two years by someone who is not you.
That gap is the whole of our work.
Idea or prototype to production
AI tools now produce convincing mockups in an afternoon. They do not produce a product an enterprise, a government department or an insurer will buy. If you have no prototype at all, that is fine: we can build a working clickable version early, and it doubles as the specification for everything that follows, which is far cheaper than discovering the requirements halfway through a build.
The missing 80% is what we build: multi-tenant architecture that keeps customers' data genuinely separate, authentication and access control, audit trails, encryption and key handling, file and document pipelines, deployment, backups and restore, tests that catch regressions, and the operational runbooks that let someone else keep it alive.
Getting to your first paying customer usually takes more than software, so a build can include the launch pieces: a landing page, product copy that says what the thing actually does, onboarding emails, and a demo walkthrough you can send to prospects.
Compliance-grade engineering, and documentation that matches it
Two halves of the same problem, usually bought from two different suppliers, which is exactly why they so rarely agree with each other.
The engineering: data residency, tenant isolation with automated proof, immutable audit records, access control that survives review, and evidence an auditor can follow without a scramble. The documentation: system security plans, incident response and continuous monitoring plans, policies, control matrices, and the evidence pack an assessor or an enterprise customer will ask for.
We do both, so the document describes what the system actually does. Whether the standard is ISO 27001, the Essential Eight, privacy obligations, IRAP, or a customer's own security questionnaire, the work underneath is largely the same, and it is the part most teams postpone until a deal depends on it.
This is readiness and remediation. We are not accredited assessors, and we refer assessment itself out, which keeps the independence line clean.
AI features that hold up under questioning
Most AI in products is demo-ware: impressive until someone asks how it knows that. We build the defensible version. Answers cite verifiable sources or they do not ship. An evaluation harness catches quality regressions before customers do. Human decisions stay in the record with attribution. Costs are capped and metered. Customer data trains nobody's model, and inference stays in Australia when it needs to.
Fixed scope, fixed price, milestones.
You know the number before we start, and you pay against delivered milestones rather than hours consumed.
Published, because you should not have to sit through a call to find out.
| Engagement | Duration | Indicative |
|---|---|---|
| Discovery sprint: architecture, plan, firm quote | 2 to 3 days | from $2,800 |
| Clickable prototype that becomes the build specification | 1 week | from $6,000 |
| Production build, from a prototype or a clear brief | 6 to 12 weeks | $30,000 to $80,000 |
| Compliance readiness: controls, documentation, evidence pack | 4 weeks and up | from $16,000 |
| Security and architecture review of an existing product | 1 week | from $5,000 |
| Independent test and quality pass before a launch or an audit | 1 week | from $4,500 |
Prices exclude GST and cloud costs, and durations are elapsed time from the start of work to delivery. The review and the quality pass are standalone: you get written findings and a prioritised list, not a rebuild. If a full build is more than you want to commit to at once, it can be staged: a working core that earns its first customer, then extensions paid from revenue rather than savings.
Software that stops being maintained stops being sellable.
Dependencies age, certificates expire, cloud providers deprecate things, and your customers' security questionnaires get harder every year. Care plans cover that, priced on outcomes rather than counted hours.
| Managed | Care | Partner | |
|---|---|---|---|
| Infrastructure managed, patched, monitored | ✓ | ✓ | ✓ |
| Backups run and restore-tested | ✓ | ✓ | ✓ |
| Security updates and dependency currency | ✓ | ✓ | ✓ |
| Incident response, business hours | next day | same day | priority |
| Fixes and small changes, batched monthly | — | ✓ | ✓ |
| Scheduled development time each month | — | — | 2 days |
| Roadmap and architecture input | — | — | ✓ |
| From | $650/mo | $1,200/mo | $4,200/mo |
You own your cloud account and your data throughout, and we manage it inside your tenancy, so there is no lock-in and no question about who holds what. Larger changes are quoted as fixed-price pieces of work rather than billed hourly. Plans run month to month after an initial three months, and you can leave with everything documented.
Two people, both senior, both doing the work.
You will not be handed to someone else after the sale.
Arun Jose
Seventeen years in software, much of it on systems that are audited before they are trusted, and his own software company since 2021. He owns products end to end: architecture, security, payments, deployment and delivery.
- Cybersecurity compliance platform, sole engineer. A four-application SaaS platform for IRAP, Essential Eight and NIST CSF assessments, in production across cloud and air-gapped deployments. Around 150 data models, multi-tenant billing with ledger controls, single sign-on and permission-based access, and cryptographic offline licensing proven by golden-vector tests.
- AI compliance-analysis SaaS, built solo. Multi-tenant with isolation proven by automated tests, Australian data residency, append-only audit, and AI output that cites its sources and is challenged by a second adversarial pass before a human signs it.
- Enterprise and government delivery at national scale. From 2009 to 2021 at Janison, part of the team behind its assessment and learning platforms, including the platform that became the basis of NAPLAN Online. Delivery across 50 or more client organisations including ASIC, Deloitte, ADFA, Corrective Services, Ramsay Health, David Jones, city councils, universities and banks.
Master of Information Technology (Web Technologies), University of Wollongong
Red Hat Certified Engineer
Mariya Baby
A cybersecurity consultant working on security assessment engagements: researching controls against a client's real environment, drafting the assessment documentation, collating evidence, and quality-checking every deliverable before it reaches the client.
She works across the major frameworks and the mappings between them, including government assessments under IRAP. Six years in software testing behind that, most recently as quality analyst on a security assessment platform.
Graduate Certificate in IT Practice (Cybersecurity), Queensland University of Technology
We build our own software too, which is why we know what the last 20% actually costs.
Everything we ask you to trust us with, we have done for ourselves first, at our own expense, with nobody else to blame for the shortcuts.
A compliance analysis platform: it reads a standard, reads an organisation's evidence, and produces a clause-cited gap analysis that a consultant reviews and signs their name to. Multi-tenant with isolation proven by automated tests, Australian data residency, append-only audit, verbatim citations, and a second adversarial pass that argues with the first before anything reaches a human. Designed, built and operated by us.
enclause.com.au →The product itself sits behind a login, as most do. If you want to see how the parts we are describing actually behave, ask and we will walk you through it live.
Naming these saves us all time.
- Staff augmentation. We do not sit inside someone else's team as an extra pair of hands.
- Pager duty. Care plans respond during Australian business hours, and systems are built so that nights and weekends stay quiet.
- Open-ended hourly work. Scope is fixed and priced before it starts, or it is quoted as a separate piece.
- More than one build at a time. Compliance and quality work can run alongside, but if we are booked we will tell you when we are free rather than take your money and stretch.
Tell us what you are building and what it has to survive. If we are not the right people for it, we will usually know someone who is.
Or reach us directly.
Coffs Harbour, NSW · working remotely with clients across Australia