Private by default.
S3 public access is blocked; CloudFront uses origin access control.
Public assurance record
This centre separates controls evidenced for the public marketing estate from product design intentions, customer commitments and organisation-wide assurance that still require a defined scope and evidence.
Trust centre / navigate
Each part of this record answers a different question.
Public website / 01
The evidence below applies to theseengroup.com.au and theseengroup.ai as public static websites. It does not automatically apply to Backstage TP, Proof GRC or QuoteMaker.
Static content is delivered through Amazon CloudFront from a private Amazon S3 origin. Origin access control, blocked public access and bucket-owner-enforced ownership prevent the bucket from acting as a public website origin.
The delivery configuration enforces HTTPS, modern TLS, HSTS, a restrictive Content Security Policy, frame denial, content-type protection, referrer controls and a restrictive browser permissions policy.
S3 public access is blocked; CloudFront uses origin access control.
Viewer requests redirect to HTTPS and use a TLS 1.2 minimum security policy.
CSP, HSTS, frame denial, nosniff and Permissions Policy are delivered at the edge.
S3 Versioning provides limited object recovery evidence; it is not represented as a complete backup program.
The current static estate does not include an AWS WAF control.
CloudFront access logging, an account trail and configuration recording are not represented as enabled for this estate.
Product assurance / 02
A product briefing must identify the architecture and operating model for the initiative and use case being assessed.
Systems in scope, material flows, storage, processing and service boundaries.
Provider identity, purpose, access, processing location, retention and any cross-border movement.
Customer and privileged access, administration, support, logging and incident responsibilities.
The obligations expressly agreed for the relevant service and engagement.
No universal product architecture, hosting region, data-residency promise, common subprocessor list, certification or support model is claimed at group level.
Responsible AI / 03
These principles describe product direction. They are not a statement that every feature is implemented.
A reviewer should be able to return to what shaped a suggestion.
Automation should not hide the conditions under which an output was produced.
Human involvement means authority and context - not a ceremonial click.
Acceptance, correction and rationale remain with the authorised person.
Fitness, failure modes and safeguards depend on the actual task and affected people.
Data pathway, retention, training terms and provider role belong in a product briefing.
Essential Eight / 04
The Essential Eight applies across an organisation’s technology environment. A static website can contribute scoped evidence, but it cannot establish organisation-wide maturity by itself.
| Strategy | Evidence from this website estate | Evidence required beyond it | Public status |
|---|---|---|---|
| Patch applications | Static, self-hosted assets and managed hosting services; no customer application server. | Asset discovery, dependency process, scans, remediation timing, endpoints and CI. | Partial / scoped |
| Patch operating systems | No customer-managed server operating system in this hosting layer. | Provider assurance plus workstation, CI, server and network-device evidence. | Inherited / scoped |
| Multi-factor authentication | Not evidenced by the public website. | AWS, Microsoft 365 and organisational MFA configuration, testing and logs. | Not assessed here |
| Restrict administrative privileges | Private origin and edge-only read path are evidenced. | IAM least privilege, approvals, separation, revalidation and activity logs. | Partial / scoped |
| Application control | No general-purpose host exists in this static serving layer. | Endpoint and applicable server allowlisting configuration and testing. | Outside site scope |
| Restrict Office macros | Not applicable to static website delivery. | Managed Microsoft 365 and endpoint policy evidence. | Outside site scope |
| User application hardening | Security headers harden the website boundary, not users’ applications. | Browser, Office, PDF and PowerShell policy and testing. | Outside site scope |
| Regular backups | S3 Versioning provides limited object-recovery evidence. | Retention, resilient copies, protected administration and tested restoration. | Partial / scoped |
The SEEN Group does not claim Essential Eight certification, compliance or Maturity Level 0, 1, 2 or 3 on the basis of this website estate.
Framework context / 05
| Reference | How it may inform the work | What is not claimed |
|---|---|---|
| ISO/IEC 27001 | Context for information-security risk ownership, policies and controls. | No certification claim. |
| ISO/IEC 42001 | Context for governance and oversight of relevant AI-assisted features. | No certification claim. |
| ACSC ISM | Australian Government cyber-security guidance whose relevance depends on system and risk context. | No blanket conformance claim. |
| Essential Eight | Prioritised mitigations assessed across a defined technology environment. | No maturity level claim. |
| Privacy Act 1988 and APPs | Australian privacy context whose obligations depend on entity, information and activity. | No legal conclusion for every proposed use. |
For a product-specific assurance discussion, contact hello@theseengroup.com.au with the initiative and use case you are assessing.
Ask for the evidence relevant to the product and use case in view.
Ask a trust question