An Australian platform for Australian estates
Most Australian organisations run the same shape of estate. There is a cloud footprint that grew faster than the documentation, a corporate network spread across a head office, branch sites and a hybrid workforce, an on-premise directory carrying a decade of restructures, and a supplier list holding credentialed access to all of it. Each layer is usually assessed by a different tool, at a different time, against a different definition of scope.
The other constant is change velocity. A product squad ships on Thursday, a new subdomain answers on the public internet on Friday, and the asset register catches up somewhere around the next quarterly review. A point-in-time assessment describes only the version of the estate that existed during the week it ran, which is why so many Australian security teams are carrying a report that was accurate once.
PentestOps is designed to close that gap. Scheduled scans, 7-day asset re-verification and drift detection keep the inventory current, and safe automated exploitation demonstrates which exposures an attacker could actually use rather than handing over a list of theoretical severities. See continuous penetration testing for how that cadence works.
Where we are, and where your data lives
PentestOps is a product of Extranet Systems Pty Ltd. Our Asia-Pacific headquarters is at 77 Market Street, Wollongong NSW 2500, and our Sydney office is at Level 39, Suite 4, 264 George Street, Sydney NSW 2000, covering sales and operations. Those are the offices we have in Australia, and we do not claim any others.
The platform is hosted in Australia on infrastructure operated by Extranet Systems. Customer data is stored in Australia. Specific data-residency arrangements are available to Enterprise customers on request, and Enterprise also includes an on-premise deployment option for organisations that need scan data to stay inside their own boundary.
Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances. The platform itself is built to SOC 2-aligned controls, and a SOC 2 attestation is on our roadmap. Every customer runs in an isolated environment with its own dedicated database, data is encrypted at rest, traffic is protected with TLS in transit, and audit logs are retained for 365 days. The detail sits in our Trust Centre.
What gets tested
Assessments follow a seven-phase methodology aligned to PTES, the OWASP Web Security Testing Guide v4.2 and NIST SP 800-115, and aligned to CREST testing methodology guidance. Every scan and every exploitation attempt is tied to signed Rules of Engagement, with scope enforcement that automatically stops activity outside authorised assets.
- Perimeter. 24+ external recon modules map what the internet can see, including services published years ago and never decommissioned. See external network testing.
- Internal network. The on-premise agent runs 18+ internal modules natively on the LAN instead of tunnelling every packet out to a remote scanner. See internal network testing.
- Applications and APIs. OWASP Top 10 and API Top 10 coverage across REST and GraphQL, with a live finding stream while the scan runs.
- Cloud. 800+ automated checks across AWS, Azure, GCP and M365 with CIS Benchmark coverage, plus agentless Kubernetes auditing through a read-only kubeconfig.
- Identity. Active Directory enumeration, credential testing and password-policy auditing show where a standard account reaches administrative control.
- Prioritisation. CVE correlation, CVSS v3.1 scoring, exploit-availability indicators and CISA KEV prioritisation, so a small team works the findings that actually matter first.
The assurance conversations driving Australian testing
Australian buyers rarely test for its own sake. The trigger is usually a regulator, an auditor, a customer security questionnaire or a board that has started asking harder questions. Testing does not make an organisation compliant with anything, and we will never say it does. What it supplies is the technical evidence those conversations are usually missing.
| Australian context | Where testing usually starts |
|---|---|
| Government and their delivery partners working to the Essential Eight | Perimeter discovery and identity testing, with customer data stored in Australia |
| Banking, insurance and superannuation under APRA CPS 234 | External perimeter and internal network, then continuous coverage between independent annual assessments |
| Organisations holding personal information under the Australian Privacy Act | Which paths reach systems holding personal information, and how far an attacker gets before detection |
| Merchants and payment platforms in scope for PCI DSS v4.0 | Web application and API testing across OWASP Top 10 and API Top 10 risks, re-run after each release |
| Vendors answering enterprise security questionnaires | Full-scope assessment with reports mapped to the frameworks the questionnaire asks about |
Local compliance landscape
Four Australian regimes come up in almost every scoping call. None of them is a certification you can buy, and none is satisfied by running a scan. What they share is a point at which somebody asks for technical evidence about the real state of your estate, and that is the part a testing platform can supply.
Keep the boundary clear. The Essential Eight, the ISM and the Privacy Act are not among the 8 frameworks PentestOps maps findings to in reports. Testing gives you evidence to carry into a maturity assessment or a privacy review; it does not replace either, and we will not claim it does. Our Australian security compliance guide covers the wider picture.
| Regime | Who it reaches | What testing can evidence |
|---|---|---|
| Essential Eight (ACSC) | Commonwealth entities, and increasingly the suppliers and delivery partners that sell to them | Patch currency on internet-facing and internal systems, and whether restrictions on administrative privilege hold when a standard account is compromised |
| Information Security Manual (ISM) | Australian Government systems and the providers that build, host or operate them | Exposed services, default or weak configuration and hardening gaps on in-scope systems, with evidence attached to every finding |
| Privacy Act 1988 and the Australian Privacy Principles | APP entities holding personal information, which covers a large share of the private sector | Which reachable paths lead to systems holding personal information, and which of those an attacker could actually traverse |
| Notifiable Data Breaches scheme | The same APP entities, once a breach is suspected | How far an attacker gets before detection, which informs the assessment your organisation has to make about likely serious harm |
Serving every state and territory
PentestOps is delivered as software, so where your offices sit changes very little about how testing runs. External testing needs no agent at all. Internal testing runs through an on-premise agent your own team installs as a Docker container, RPM or DEB package in about 5 minutes, connecting outbound-only over TLS 443 with 0 inbound firewall rules and no VPN or jump host. One host can cover multiple subnets, which suits organisations with sites in several states.
Whether you are a mining services firm in Perth, a council in regional Queensland or a SaaS company in Melbourne, you get the same platform, the same methodology and the same evidence. What being Australian changes is everything around the testing: scoping calls in your own business hours, procurement and security questionnaires answered by people who understand local expectations, and no overnight wait for a response from another hemisphere.
Support runs Mon-Fri 9am-6pm AEST, with 24/7 support for Enterprise customers. City pages for Sydney, Melbourne and Brisbane cover the local picture in more detail, and we also serve New Zealand.
Why Australian teams choose PentestOps
- Australian-built and operated, with customer data stored in Australia and data-residency arrangements available to Enterprise customers on request.
- Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances, and operates across three continents.
- Evidence-first testing: safe automated exploitation demonstrates real impact instead of listing theoretical severities.
- Reports map findings to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes, in multiple report formats including PDF, CSV and JSON/API.
- AI analysis is self-hosted by default, so scan data is analysed on infrastructure Extranet Systems operates rather than being sent to third-party model providers. External providers are opt-in per tenant.
- Asset-wise pricing: you pay for the assets in scope, and scans against them are unlimited within fair use. No procurement cycle is required to see your first result.
Who you are dealing with
PentestOps is a product of Extranet Systems Pty Ltd, ABN 29 632 743 189, with its Asia-Pacific headquarters at 77 Market Street, Wollongong NSW 2500. Call +61 1300 290 196 during Mon-Fri 9am-6pm AEST, or write to us any time through contact. Enterprise customers have 24/7 support.