Australian-built and operated

Developed and run by Extranet Systems Pty Ltd from its Asia-Pacific headquarters in Wollongong NSW, with a Sydney office for sales and operations.

Data stays in Australia

The platform is hosted in Australia on infrastructure operated by Extranet Systems. Customer data is stored in Australia.

Proof, not guesswork

Safe automated exploitation validates findings under signed Rules of Engagement, with scope enforcement and a full evidence trail.

Independently certified vendor

Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances. A copy is available on request.

An Australian platform for Australian estates

Most Australian organisations run the same shape of estate. There is a cloud footprint that grew faster than the documentation, a corporate network spread across a head office, branch sites and a hybrid workforce, an on-premise directory carrying a decade of restructures, and a supplier list holding credentialed access to all of it. Each layer is usually assessed by a different tool, at a different time, against a different definition of scope.

The other constant is change velocity. A product squad ships on Thursday, a new subdomain answers on the public internet on Friday, and the asset register catches up somewhere around the next quarterly review. A point-in-time assessment describes only the version of the estate that existed during the week it ran, which is why so many Australian security teams are carrying a report that was accurate once.

PentestOps is designed to close that gap. Scheduled scans, 7-day asset re-verification and drift detection keep the inventory current, and safe automated exploitation demonstrates which exposures an attacker could actually use rather than handing over a list of theoretical severities. See continuous penetration testing for how that cadence works.

Where we are, and where your data lives

PentestOps is a product of Extranet Systems Pty Ltd. Our Asia-Pacific headquarters is at 77 Market Street, Wollongong NSW 2500, and our Sydney office is at Level 39, Suite 4, 264 George Street, Sydney NSW 2000, covering sales and operations. Those are the offices we have in Australia, and we do not claim any others.

The platform is hosted in Australia on infrastructure operated by Extranet Systems. Customer data is stored in Australia. Specific data-residency arrangements are available to Enterprise customers on request, and Enterprise also includes an on-premise deployment option for organisations that need scan data to stay inside their own boundary.

Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances. The platform itself is built to SOC 2-aligned controls, and a SOC 2 attestation is on our roadmap. Every customer runs in an isolated environment with its own dedicated database, data is encrypted at rest, traffic is protected with TLS in transit, and audit logs are retained for 365 days. The detail sits in our Trust Centre.

What gets tested

Assessments follow a seven-phase methodology aligned to PTES, the OWASP Web Security Testing Guide v4.2 and NIST SP 800-115, and aligned to CREST testing methodology guidance. Every scan and every exploitation attempt is tied to signed Rules of Engagement, with scope enforcement that automatically stops activity outside authorised assets.

  • Perimeter. 24+ external recon modules map what the internet can see, including services published years ago and never decommissioned. See external network testing.
  • Internal network. The on-premise agent runs 18+ internal modules natively on the LAN instead of tunnelling every packet out to a remote scanner. See internal network testing.
  • Applications and APIs. OWASP Top 10 and API Top 10 coverage across REST and GraphQL, with a live finding stream while the scan runs.
  • Cloud. 800+ automated checks across AWS, Azure, GCP and M365 with CIS Benchmark coverage, plus agentless Kubernetes auditing through a read-only kubeconfig.
  • Identity. Active Directory enumeration, credential testing and password-policy auditing show where a standard account reaches administrative control.
  • Prioritisation. CVE correlation, CVSS v3.1 scoring, exploit-availability indicators and CISA KEV prioritisation, so a small team works the findings that actually matter first.

The assurance conversations driving Australian testing

Australian buyers rarely test for its own sake. The trigger is usually a regulator, an auditor, a customer security questionnaire or a board that has started asking harder questions. Testing does not make an organisation compliant with anything, and we will never say it does. What it supplies is the technical evidence those conversations are usually missing.

Australian contextWhere testing usually starts
Government and their delivery partners working to the Essential EightPerimeter discovery and identity testing, with customer data stored in Australia
Banking, insurance and superannuation under APRA CPS 234External perimeter and internal network, then continuous coverage between independent annual assessments
Organisations holding personal information under the Australian Privacy ActWhich paths reach systems holding personal information, and how far an attacker gets before detection
Merchants and payment platforms in scope for PCI DSS v4.0Web application and API testing across OWASP Top 10 and API Top 10 risks, re-run after each release
Vendors answering enterprise security questionnairesFull-scope assessment with reports mapped to the frameworks the questionnaire asks about

Local compliance landscape

Four Australian regimes come up in almost every scoping call. None of them is a certification you can buy, and none is satisfied by running a scan. What they share is a point at which somebody asks for technical evidence about the real state of your estate, and that is the part a testing platform can supply.

Keep the boundary clear. The Essential Eight, the ISM and the Privacy Act are not among the 8 frameworks PentestOps maps findings to in reports. Testing gives you evidence to carry into a maturity assessment or a privacy review; it does not replace either, and we will not claim it does. Our Australian security compliance guide covers the wider picture.

RegimeWho it reachesWhat testing can evidence
Essential Eight (ACSC)Commonwealth entities, and increasingly the suppliers and delivery partners that sell to themPatch currency on internet-facing and internal systems, and whether restrictions on administrative privilege hold when a standard account is compromised
Information Security Manual (ISM)Australian Government systems and the providers that build, host or operate themExposed services, default or weak configuration and hardening gaps on in-scope systems, with evidence attached to every finding
Privacy Act 1988 and the Australian Privacy PrinciplesAPP entities holding personal information, which covers a large share of the private sectorWhich reachable paths lead to systems holding personal information, and which of those an attacker could actually traverse
Notifiable Data Breaches schemeThe same APP entities, once a breach is suspectedHow far an attacker gets before detection, which informs the assessment your organisation has to make about likely serious harm

Serving every state and territory

PentestOps is delivered as software, so where your offices sit changes very little about how testing runs. External testing needs no agent at all. Internal testing runs through an on-premise agent your own team installs as a Docker container, RPM or DEB package in about 5 minutes, connecting outbound-only over TLS 443 with 0 inbound firewall rules and no VPN or jump host. One host can cover multiple subnets, which suits organisations with sites in several states.

Whether you are a mining services firm in Perth, a council in regional Queensland or a SaaS company in Melbourne, you get the same platform, the same methodology and the same evidence. What being Australian changes is everything around the testing: scoping calls in your own business hours, procurement and security questionnaires answered by people who understand local expectations, and no overnight wait for a response from another hemisphere.

Support runs Mon-Fri 9am-6pm AEST, with 24/7 support for Enterprise customers. City pages for Sydney, Melbourne and Brisbane cover the local picture in more detail, and we also serve New Zealand.

Why Australian teams choose PentestOps

  • Australian-built and operated, with customer data stored in Australia and data-residency arrangements available to Enterprise customers on request.
  • Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances, and operates across three continents.
  • Evidence-first testing: safe automated exploitation demonstrates real impact instead of listing theoretical severities.
  • Reports map findings to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes, in multiple report formats including PDF, CSV and JSON/API.
  • AI analysis is self-hosted by default, so scan data is analysed on infrastructure Extranet Systems operates rather than being sent to third-party model providers. External providers are opt-in per tenant.
  • Asset-wise pricing: you pay for the assets in scope, and scans against them are unlimited within fair use. No procurement cycle is required to see your first result.

Who you are dealing with

PentestOps is a product of Extranet Systems Pty Ltd, ABN 29 632 743 189, with its Asia-Pacific headquarters at 77 Market Street, Wollongong NSW 2500. Call +61 1300 290 196 during Mon-Fri 9am-6pm AEST, or write to us any time through contact. Enterprise customers have 24/7 support.

Frequently Asked Questions

Is PentestOps actually Australian?

Yes. PentestOps is built and operated by Extranet Systems Pty Ltd, an Australian company headquartered at 77 Market Street, Wollongong NSW 2500, with a Sydney office at Level 39, Suite 4, 264 George Street, Sydney NSW 2000. The platform is hosted in Australia and customer data is stored in Australia.

Which parts of Australia do you serve?

All of them. The platform is software, so testing is delivered nationally regardless of where your sites are. Our offices are in Wollongong and Sydney; we do not claim offices in other capitals, and none are needed for an assessment to run. See our locations for the local pages.

Where is our scan data stored?

The platform is hosted in Australia on infrastructure operated by Extranet Systems. Customer data is stored in Australia. Specific data-residency arrangements are available to Enterprise customers on request, and Enterprise includes an on-premise deployment option.

Does this help with the Essential Eight?

It contributes evidence; it is not a maturity assessment, and the Essential Eight is not one of the frameworks findings map to in reports. Testing does produce technical evidence relevant to several of the strategies, particularly patch currency on internet-facing and internal systems and whether restrictions on administrative privilege hold when a standard account is compromised. Use it alongside a maturity assessment, not instead of one. Our government page goes further.

We are regulated by APRA. Does continuous testing help with CPS 234?

APRA CPS 234 sets expectations around testing the effectiveness of information security controls, and a once-a-year snapshot is a hard thing to point at when the estate changes weekly. Continuous scanning, perimeter re-checks and drift detection give you a dated, evidenced record between independent assessments. We supply evidence; your obligations remain yours.

Do you replace an independent penetration test?

No, and we will not pretend otherwise. Automation runs the repetitive, high-volume testing so your people and your independent testers can concentrate on the creative work that automation handles poorly, such as business logic flaws and process abuse. PentestOps is designed to sit alongside a periodic independent assessment rather than replace it, keeping coverage running in between.

Can you test our internal network without firewall changes?

Yes. The on-premise agent connects outbound-only over TLS 443 through a reverse tunnel, so 0 inbound firewall rules are required. It has no inbound listeners, supports HTTP CONNECT through restrictive corporate proxies and reconnects automatically after a link drop. Discovered credentials are redacted before findings ship.

How long are findings and reports kept?

Assessment findings are retained for 1 year on Starter, 3 years on Professional and 7 years on Enterprise and MSP plans, then automatically deleted. Audit logs are kept for 365 days. Exported reports, signed authorisation records and legal documents are not removed by the retention process, and findings can be placed on legal hold.

How is it priced, and can we try it first?

Pricing is asset-wise. One asset is one item the platform can scan or monitor: a public IP, hostname, web application, internal subnet target, cloud account or Kubernetes cluster. Scans against an asset are unlimited within fair use. Run a free demo scan at demo scan, then start a trial when you are ready. All paid plans start with a 7-day free trial. A card is required to start your trial and is only charged after the trial ends, unless you cancel first. Live plan detail is on pricing.

Run your first Australian-hosted assessment

Start with the perimeter, add the internal network when you are ready, and keep coverage running between assessments. All paid plans start with a 7-day free trial. A card is required to start your trial and is only charged after the trial ends, unless you cancel first.