Provided and written by cleared Australian nationals.

Close the evidence gap.

GRiCk lets AI agents, developers and security tools send assurance evidence from where work already happens. MCP supplies the context. Scoped APIs keep control health current, without waiting for screenshots and email.

Available direct, through a trusted MSP, or through Microsoft Azure and AWS hosted marketplace routes.

Agent context
MCP
Evidence ingress
Scoped API
Assurance state
Freshness tracked
Assurance dashboard Live posture
GRiCk dashboard showing active ATOs, system inventory, policy coverage, high risks, compliance posture, framework coverage and the ATO pipeline
One operational view of authorisations, control coverage, evidence posture and risk.

Australian sovereign delivery

Australian ownership your procurement team can verify.

GRiCk is provided and written by cleared Australian nationals.

Built by Yuma IT, a Supply Nation certified business.

Yuma IT
ASD ISM PSPF Essential Eight IRAP workflows ATO lifecycle Custom frameworks

For teams that cannot work from stale evidence.

Executives, assurance teams and engineers work from one record. Each role sees the evidence provenance, freshness and control state it needs.

CISO

Know which controls are defensible now.

See evidence freshness, residual risk and decision state without launching another evidence chase.

Government assurance

Keep the ATO record moving.

Connect intake, system scope, evidence, assessment notes, approvals and reassessment dates.

Developers and platform teams

Submit proof from the delivery path.

Use MCP for assurance context and scoped APIs for evidence, without leaving engineering tools.

Buy through the partner or cloud route procurement already uses.

Buy GRiCk direct, operate it with an approved MSP, or use a Microsoft Azure or AWS hosted marketplace route. Each option keeps the control boundary explicit.

Trusted MSP

Give the MSP scoped access, not an open tenant.

Bound partner access with organisation and workspace roles, scoped API keys, MCP context and an audit trail. MSP tooling can send evidence from existing CI/CD, SIEM, SOC and cloud workflows.

Microsoft Azure

Procure through Microsoft and deploy into Azure.

Microsoft commercial marketplace fulfilment, Bicep and ARM packaging, Container Apps, Azure Blob Storage and Azure OpenAI integration support an Azure-aligned operating boundary.

Amazon Web Services

Run an AWS-aligned offering in your AWS estate.

Container deployment, Amazon S3 evidence storage, Amazon Bedrock integration and Australian-region configuration support an AWS-aligned hosted offering.

Marketplace availability, private-offer structure, hosting responsibility and support model are confirmed during the technical review.

Evidence should arrive before the assessor asks.

The control is often operating. The delay is proving it. GRiCk gives agents and systems a governed path from engineering work into the evidence record.

AI agents MCP exposes tenant-scoped system, ATO and cloud-assurance context. Work with the right record before evidence is submitted.
Developer API Write external evidence with scoped keys and idempotent requests. Links, attestations, scans, screenshots and document metadata.
Automation Bulk-ingest up to 100 records from scanners and CI/CD checks. Keep the artefact in its source system. Preserve its URI and provenance.
Continuous assurance Freshness and verification state flow into control health. Current, expiring, expired, invalid or requiring review.
  1. 1.0

    Observe where work happens.

    An AI agent, developer workflow, CI/CD job, scanner or security platform produces the evidence while the control is being operated.

    Source evidence
  2. 2.0

    Send context, not screenshots.

    MCP gives agents the relevant GRiCk system and ATO context. Scoped API endpoints write links, attestations, scans, screenshots or document metadata from the source.

    MCP + API
  3. 3.0

    Link once. Reuse safely.

    One evidence record can satisfy controls, requirements, risks, policies and ATOs without copying the underlying artefact or breaking provenance.

    Audit-linked record
  4. 4.0

    Keep the attestation current.

    Freshness, expiry and review states feed control health so assurance teams can see what is current, expiring or no longer defensible.

    Continuous attestation

Evidence moves with the assessment.

API-delivered evidence joins intake, assessment scope, requests, assessor notes, follow-ups and approvals. It stays linked to the system, control and risk context supplied through MCP.

01 Structured intake

System context enters once and follows the package.

02 Evidence requests

Required artefacts stay attached to the assessment record.

03 Assessor record

Notes, findings and follow-ups retain ownership and provenance.

ATO detail and evidence package Tenant scoped
GRiCk ATO detail screen showing intake data, evidence requests, assessor notes and approval workflow
Actual product capture. The full record continues through findings, follow-ups and decisions.

Automation prepares the case. People make the decision.

GRiCk can assist with evidence handling and operational signals without obscuring accountability. Assessors and authorising officers review the package, record conditions, sign and timestamp the outcome.

  • Package readiness visible before approval
  • Residual risk and security category in context
  • Named approver, typed signature and reassessment date
  • Conditions retained with the authorisation record
Secure GRiCk approval page with ATO readiness, approver identity, signature and reassessment fields
Secure approval view

Run GRiCk inside your operating boundary.

Deploy GRiCk into infrastructure you control. Keep your established identity, storage and cloud patterns. Connect advisory AI through your chosen provider while people retain the decision.

RuntimeCompose, Kubernetes and Helm
InfrastructureTerraform, Bicep and ARM
ImagesMulti-architecture images in GHCR
Supply chainSBOM and build provenance
IdentitySAML/OIDC SSO and SCIM
AI providersBedrock and Azure OpenAI

AI inside the assurance boundary.

MCP

Agents discover the relevant tenant-scoped records and work with current assurance context.

API

Evidence writes require scoped credentials, are idempotent where needed and are recorded in the audit trail.

Models

Use Amazon Bedrock or Azure OpenAI for advisory work. Assessors and authorising officers retain the decision.

Batteries included means the control plane is already there.

Identity, tenancy, audit, integration and deployment ship with the platform. They do not wait behind a professional-services engagement.

Control plane Included capability Operating property
Sovereign delivery Provided and written by cleared Australian nationals Australian delivery boundary
Partner delivery Trusted MSP access through scoped roles, API keys and integrations Tenant-bounded and audit logged
Procurement Direct, partner-led, Azure and AWS hosted marketplace offerings Commercial route matched to the engagement
Identity SAML/OIDC SSO and SCIM provisioning Organisation-scoped configuration and audit
Access control Role and workspace permissions Tenant-scoped enforcement
Auditability Linked actions, evidence and decisions Recorded actor, time and provenance
Integration Scoped API keys, OpenAPI, SDK, MCP and webhooks CI/CD, SIEM and SOC event paths
Deployment Docker Compose, Kubernetes and Helm Self-hosted runtime
Infrastructure Terraform, Bicep and ARM Repeatable environment delivery
Supply chain Multi-architecture images and SBOM Build provenance
AI boundary Amazon Bedrock and Azure OpenAI Advisory output with human decisions retained

Procurement and architecture teams can review deployment boundaries, identity integration, API scope and supply-chain artefacts before committing to a rollout.

Trace your evidence path before you buy.

Bring your assurance model, developer workflow, identity constraints and hosting boundary. We will trace evidence from an agent or pipeline through the API, into control health and the ATO decision record.