Public assurance record

Trust starts with a precise account.

This centre separates controls evidenced for the public marketing estate from product design intentions, customer commitments and organisation-wide assurance that still require a defined scope and evidence.

Public website / 01

A small, hardened marketing estate.

The evidence below applies to theseengroup.com.au and theseengroup.ai as public static websites. It does not automatically apply to Backstage TP, Proof GRC or QuoteMaker.

Current evidenced boundary

Static content is delivered through Amazon CloudFront from a private Amazon S3 origin. Origin access control, blocked public access and bucket-owner-enforced ownership prevent the bucket from acting as a public website origin.

The delivery configuration enforces HTTPS, modern TLS, HSTS, a restrictive Content Security Policy, frame denial, content-type protection, referrer controls and a restrictive browser permissions policy.

Origin

Private by default.

S3 public access is blocked; CloudFront uses origin access control.

Transport

HTTPS enforced.

Viewer requests redirect to HTTPS and use a TLS 1.2 minimum security policy.

Browser boundary

Restrictive headers.

CSP, HSTS, frame denial, nosniff and Permissions Policy are delivered at the edge.

Recovery signal

Object versions retained.

S3 Versioning provides limited object recovery evidence; it is not represented as a complete backup program.

Known limit

No WAF asserted.

The current static estate does not include an AWS WAF control.

Known limit

Logging is incomplete.

CloudFront access logging, an account trail and configuration recording are not represented as enabled for this estate.

Product assurance / 02

One company does not mean one technical boundary.

A product briefing must identify the architecture and operating model for the initiative and use case being assessed.

Architecture and data flow

Systems in scope, material flows, storage, processing and service boundaries.

Providers and location

Provider identity, purpose, access, processing location, retention and any cross-border movement.

Identity and operations

Customer and privileged access, administration, support, logging and incident responsibilities.

Contractual position

The obligations expressly agreed for the relevant service and engagement.

Current position

No universal product architecture, hosting region, data-residency promise, common subprocessor list, certification or support model is claimed at group level.

Responsible AI / 03

Assistance should make the work more inspectable.

These principles describe product direction. They are not a statement that every feature is implemented.

Source

Keep original material within reach.

A reviewer should be able to return to what shaped a suggestion.

Context

Expose assumptions and limits.

Automation should not hide the conditions under which an output was produced.

Review

Give people a real gate.

Human involvement means authority and context - not a ceremonial click.

Ownership

Record who decided.

Acceptance, correction and rationale remain with the authorised person.

Evaluation

Test the use case.

Fitness, failure modes and safeguards depend on the actual task and affected people.

Disclosure

Describe the service used.

Data pathway, retention, training terms and provider role belong in a product briefing.

Essential Eight / 04

Relevant evidence,
not an invented maturity level.

The Essential Eight applies across an organisation’s technology environment. A static website can contribute scoped evidence, but it cannot establish organisation-wide maturity by itself.

Essential Eight applicability register
StrategyEvidence from this website estateEvidence required beyond itPublic status
Patch applicationsStatic, self-hosted assets and managed hosting services; no customer application server.Asset discovery, dependency process, scans, remediation timing, endpoints and CI.Partial / scoped
Patch operating systemsNo customer-managed server operating system in this hosting layer.Provider assurance plus workstation, CI, server and network-device evidence.Inherited / scoped
Multi-factor authenticationNot evidenced by the public website.AWS, Microsoft 365 and organisational MFA configuration, testing and logs.Not assessed here
Restrict administrative privilegesPrivate origin and edge-only read path are evidenced.IAM least privilege, approvals, separation, revalidation and activity logs.Partial / scoped
Application controlNo general-purpose host exists in this static serving layer.Endpoint and applicable server allowlisting configuration and testing.Outside site scope
Restrict Office macrosNot applicable to static website delivery.Managed Microsoft 365 and endpoint policy evidence.Outside site scope
User application hardeningSecurity headers harden the website boundary, not users’ applications.Browser, Office, PDF and PowerShell policy and testing.Outside site scope
Regular backupsS3 Versioning provides limited object-recovery evidence.Retention, resilient copies, protected administration and tested restoration.Partial / scoped
Assessment statement

The SEEN Group does not claim Essential Eight certification, compliance or Maturity Level 0, 1, 2 or 3 on the basis of this website estate.

Framework context / 05

References are useful only when scope is explicit.

Framework reference position
ReferenceHow it may inform the workWhat is not claimed
ISO/IEC 27001Context for information-security risk ownership, policies and controls.No certification claim.
ISO/IEC 42001Context for governance and oversight of relevant AI-assisted features.No certification claim.
ACSC ISMAustralian Government cyber-security guidance whose relevance depends on system and risk context.No blanket conformance claim.
Essential EightPrioritised mitigations assessed across a defined technology environment.No maturity level claim.
Privacy Act 1988 and APPsAustralian privacy context whose obligations depend on entity, information and activity.No legal conclusion for every proposed use.
Ask a question

For a product-specific assurance discussion, contact hello@theseengroup.com.au with the initiative and use case you are assessing.

Trust grows when the boundary stays visible.

Ask for the evidence relevant to the product and use case in view.

Ask a trust question