Know which controls are defensible now.
See evidence freshness, residual risk and decision state without launching another evidence chase.
Provided and written by cleared Australian nationals.
GRiCk lets AI agents, developers and security tools send assurance evidence from where work already happens. MCP supplies the context. Scoped APIs keep control health current, without waiting for screenshots and email.
Available direct, through a trusted MSP, or through Microsoft Azure and AWS hosted marketplace routes.
Australian sovereign delivery
GRiCk is provided and written by cleared Australian nationals.
Built by Yuma IT, a Supply Nation certified business.
Executives, assurance teams and engineers work from one record. Each role sees the evidence provenance, freshness and control state it needs.
See evidence freshness, residual risk and decision state without launching another evidence chase.
Connect intake, system scope, evidence, assessment notes, approvals and reassessment dates.
Use MCP for assurance context and scoped APIs for evidence, without leaving engineering tools.
Buy GRiCk direct, operate it with an approved MSP, or use a Microsoft Azure or AWS hosted marketplace route. Each option keeps the control boundary explicit.
Bound partner access with organisation and workspace roles, scoped API keys, MCP context and an audit trail. MSP tooling can send evidence from existing CI/CD, SIEM, SOC and cloud workflows.
Microsoft commercial marketplace fulfilment, Bicep and ARM packaging, Container Apps, Azure Blob Storage and Azure OpenAI integration support an Azure-aligned operating boundary.
Container deployment, Amazon S3 evidence storage, Amazon Bedrock integration and Australian-region configuration support an AWS-aligned hosted offering.
Marketplace availability, private-offer structure, hosting responsibility and support model are confirmed during the technical review.
API-delivered evidence joins intake, assessment scope, requests, assessor notes, follow-ups and approvals. It stays linked to the system, control and risk context supplied through MCP.
System context enters once and follows the package.
Required artefacts stay attached to the assessment record.
Notes, findings and follow-ups retain ownership and provenance.
GRiCk can assist with evidence handling and operational signals without obscuring accountability. Assessors and authorising officers review the package, record conditions, sign and timestamp the outcome.
Deploy GRiCk into infrastructure you control. Keep your established identity, storage and cloud patterns. Connect advisory AI through your chosen provider while people retain the decision.
Agents discover the relevant tenant-scoped records and work with current assurance context.
Evidence writes require scoped credentials, are idempotent where needed and are recorded in the audit trail.
Use Amazon Bedrock or Azure OpenAI for advisory work. Assessors and authorising officers retain the decision.
Identity, tenancy, audit, integration and deployment ship with the platform. They do not wait behind a professional-services engagement.
Procurement and architecture teams can review deployment boundaries, identity integration, API scope and supply-chain artefacts before committing to a rollout.
Bring your assurance model, developer workflow, identity constraints and hosting boundary. We will trace evidence from an agent or pipeline through the API, into control health and the ATO decision record.