🇦🇺 Built for Australia

Turn your architecture into a professional Security Design Review.

STANCE gives anyone who needs to document, analyse, and deliver a professional security design review a structured platform to do it — without the weeks of manual work.

Launching soon. Free tier available at launch — no credit card required.

Security Design Review
Healthcare Integration Platform · v1.2
PROTECTED
Insufficient API Authentication
Patient data API endpoint lacks MFA enforcement
STRIDE: EoP T1078 E8 ML3
Unencrypted Internal Data Flow
HL7 messages transmitted over HTTP between zones
STRIDE: ID T1040
Logging Coverage Gap
Audit trail incomplete on admin access paths
STRIDE: R E8 ML2
Design principles assessed9/12 aligned
🛡️ Essential Eight aligned
🏛️ APRA CPS 234 ready
📋 Privacy Act (APPs) mapped
🌏 Data stored in AWS Sydney
🔒 ISO 27001 framework included
How it works

From architecture to review in five steps

STANCE structures the security design review process end to end — from the first diagram to the final document.

01

Document

Describe your architecture. STANCE generates a structured diagram automatically.

02

Enrich

AI interrogates each component. You confirm what's real.

03

Analyse

STRIDE threat analysis and 12 design principles evaluated automatically.

04

Kill Chain

Attack paths simulated with ALE financial risk quantification.

05

Export SDR

A professional Security Design Review document, ready to deliver.

The platform

Three products. One platform.

Architecture-first security assessment, risk management, and compliance evidence — connected by design.

📊

Assessments

Structured security risk assessments grounded in your real technology stack. Risk register with ALE financial modelling.

  • Essential Eight maturity
  • ISO 27001 assessment
  • Risk register with ALE
  • Treatment planning
  • Linked to your blueprints
📁

Compliance Vault

Centralised evidence library mapped to Australian frameworks. Manage compliance artefacts across your organisation.

  • Essential Eight (all 8 strategies)
  • APRA CPS 234
  • Privacy Act (13 APPs)
  • NSW Cyber Security Policy
  • Zero AI cost — included at all tiers
Built for Australia

Designed around Australian regulatory requirements.

STANCE was built by a practising Cyber Security Practitioner with deep experience in the Australian health and government sector. Every framework, every control, every benchmark reflects the Australian context — not a US or European template adapted for local use.

  • Essential Eight maturity levels 1–3 built in
  • APRA CPS 234 mapped across all three products
  • Privacy Act 1988 — all 13 APPs covered
  • NSW Cyber Security Policy — all 31 mandatory requirements
  • ISO 27001:2022 controls library included
🌏
AU Data Residency
All data stored in AWS ap-southeast-2, Sydney
🏥
Health Sector Experience
Built by a practitioner with health and government sector experience
🏛️
Government Ready
Supports IRAP-adjacent security review workflows
🔐
OT / Clinical Systems
Covers BMS, HVAC, medical OT — not just IT

Start your first Security Design Review today.

Free tier available. No credit card, no onboarding call, no sales process.

Join the waitlist →
Secure Design

Architecture-driven security design reviews.

From a description of your system to a professional Security Design Review document — structured, evidence-based, and compliant with Australian frameworks.

Join the waitlist →
Workflow

Every step in one place.

Step 1
🗺️
Describe
Step 2
🤖
AI Dialogue
Step 3
🔷
Diagram
Step 4
🔍
Enrich
Step 5
Analyse
Step 6
💀
Kill Chain
Step 7
📄
SDR Export
Capabilities

What Secure Design produces.

🔷 AI-Assisted Architecture Diagrams

Describe your system in plain language. STANCE asks clarifying questions to understand your stack, then generates a structured architecture diagram. Vendor names, hosting models, and data flows captured automatically.

STRIDE Threat Analysis

Every component and connection analysed against all six STRIDE categories. High and critical findings mapped to MITRE ATT&CK technique IDs for operational handoff. No rule matching — reasoned from your actual architecture.

📐 12 Secure Design Principles

Each blueprint evaluated against 12 framework-agnostic design principles — defence in depth, least privilege, zero trust, encryption in transit, network segmentation, and more. Rated Aligned, Gap Identified, or Not Assessed with AI rationale.

💀 Kill Chain Simulation

Branching attack path simulation from your highest-severity findings. ALE (Annual Loss Expectancy) calculated per scenario using Australian breach benchmarks. Gives your review financial weight, not just technical findings.

📄 SDR Document Export

A nine-section Security Design Review document generated from your blueprint. Covers executive summary, architecture documentation, threat analysis, control assessment, design principles scorecard, findings, compliance alignment, and residual risk. Edit each section before export.

🏛️ Australian Framework Alignment

Every finding and control assessment mapped to Essential Eight, APRA CPS 234, Privacy Act, and NSW Cyber Security Policy. Compliance alignment section generated automatically in every SDR.

Ready to run your first review?

Free tier includes one blueprint and full access to the Secure Design workflow.

Join the waitlist →
Pricing

Simple, transparent pricing.

All prices in AUD. Join the waitlist — launching soon.

Free

Try the full Secure Design workflow with one blueprint.

$0
 
  • 1 blueprint
  • 3 analysis credits / month
  • 5 assessments / month
  • 2 SDR exports / month
  • Kill Chain (view only)
  • Compliance Vault — standard frameworks
  • Client-branded SDR
  • API access
Starter

For solo consultants and internal security architects.

A$ 149 / mo
A$1,788 / year
  • 3 blueprints
  • 15 analysis credits / month
  • 20 assessments / month
  • 5 SDR exports / month
  • Kill Chain — full export
  • Compliance Vault — standard frameworks
  • Client-branded SDR
  • API access
Scale

For MSSPs and organisations running multiple concurrent reviews.

A$ 999 / mo
A$11,988 / year
  • 25+ blueprints
  • Unlimited analysis credits
  • Unlimited assessments
  • Unlimited SDR exports
  • Kill Chain — full export
  • White-label SDR + portal branding
  • API access
  • MSSP client portal (coming soon)
Enterprise
Custom pricing for large organisations and government.
Unlimited everything · White-label · SSO (SAML/Okta) · Custom frameworks · Multi-tenant hierarchy · AU data residency SLA · Purchase order billing
Contact us →
Compare tiers

What's included

Free Starter Growth Scale
Blueprints131025+
Analysis credits / month31550Unlimited
Assessments / month520UnlimitedUnlimited
SDR exports / month2520Unlimited
Kill Chain simulationView only✓ Export✓ Export✓ Export
Client-branded SDR
White-label portal
API access
Compliance Vault (standard)
Custom compliance frameworksEnterprise
FAQ

Common questions

What is an analysis credit?

One credit is consumed by a Full Analysis run (STRIDE + design principles), a Kill Chain simulation, an SDR generation, or a blueprint finalisation. Consult messages, diagram edits, assessments, and all Compliance Vault actions are free at every tier.

Is my data stored in Australia?

Yes. All data is stored in AWS ap-southeast-2 (Sydney). STANCE is built for Australian organisations — data sovereignty is not an afterthought.

Can I trial before committing?

Yes — the Free tier is permanent, not a time-limited trial. Create one blueprint and run the full Secure Design workflow including Kill Chain before deciding whether to upgrade.

What is client-branded SDR?

On Growth and above, exported SDR documents include your client's logo and organisation name on the cover and footer. STANCE branding is replaced by your firm's identity — suitable for consultancies billing clients for design review work.

Do you offer annual billing?

Annual billing is available with two months free equivalent. Contact us to set up an annual subscription.

What frameworks are in the Compliance Vault?

Standard tiers include Essential Eight (all 8 strategies, ML1–3), ISO 27001:2022, APRA CPS 234, Privacy Act (all 13 APPs), and NSW Cyber Security Policy (all 31 mandatory requirements). Custom frameworks available on Enterprise.

About

Built by a practitioner, for practitioners.

STANCE exists because producing a credible security design review shouldn't require weeks of manual work or a team of consultants. So we built the platform.

The origin

Why STANCE exists.

Security design reviews sit at the intersection of architecture, risk, and compliance. The person doing that review — whether they are a security architect, a consultant, a developer leading a project, or an IT manager preparing for an accreditation — needs to produce a document that is credible enough to present, specific enough to act on, and aligned to the frameworks their organisation actually uses.

Existing platforms serve developers writing code and compliance teams chasing certifications. Nobody built a platform for the person doing a design-time security review — assessing whether a proposed system is safe to deploy, whether a vendor integration introduces unacceptable risk, whether a new architecture meets the requirements of APRA CPS 234 or the Essential Eight.

STANCE was built from that gap. It was designed by a Cyber Security Practitioner with deep experience in the Australian health and government sector — contexts where security design reviews have real consequences, where the output goes to project steering committees and accreditation bodies, and where the frameworks that matter are Essential Eight, APRA CPS 234, and the Privacy Act — not SOC 2.

DigiSecure

STANCE is a product of DigiSecure, a Sydney-based cybersecurity firm specialising in security architecture and compliance for Australian organisations in healthcare and government.

DigiSecure was founded with a clear view: that security is most effective when it is embedded in the design of systems, not bolted on after the fact. STANCE is the platform expression of that philosophy.

Headquartered in
🇦🇺 Sydney, New South Wales, Australia
Data residency
AWS ap-southeast-2 (Sydney)
What we believe

The principles behind the platform.

🏗️

Architecture first

Security decisions made at design time are more effective and less expensive than those made after deployment. The architecture document is the starting point, not an afterthought.

📄

The output is the product

A security review is only as useful as the document it produces. STANCE is built around the deliverable — the SDR that can be presented, challenged, and acted on.

🇦🇺

Australian context, not adapted

Essential Eight, APRA CPS 234, the Privacy Act. These frameworks are built in, not bolted on. STANCE was designed for the Australian regulatory environment from day one.

💰

Risk in financial terms

Findings are more persuasive when they have a dollar value. ALE calculations, Australian breach benchmarks, and financial risk quantification are core — not optional modules.

🔒

No loose ends

Incomplete metrics, half-built features, and misleading labels do not ship. Every number shown is accurate. Every feature released is complete.

🤝

Relationship over volume

STANCE is not a self-serve volume play. It is a platform for practitioners who care about their work. We'd rather have ten organisations getting real value than a thousand accounts gathering dust.

Contact

Get in touch.

Questions about STANCE, enterprise pricing, or whether it's the right fit for your organisation — send us a message.

📧
Email
hello@stancesec.com
🌏
Location
Sydney, NSW, Australia
🏢
Company
DigiSecure Pty Ltd
Already want to try it?

STANCE is launching soon. Join the waitlist to be notified the moment the platform goes live.

Join the waitlist →

Send a message

Message sent.

Thanks for reaching out. We'll be in touch within 1–2 business days.

🚀
Early access

STANCE is launching soon.

Be the first to know when the platform goes live. No spam — one email when we launch, that's it.

One email when we launch. No marketing, no spam.

Security

Security by design — not an afterthought.

STANCE helps organisations assess security. Here is how we secure the platform itself.

📋
Self-assessed disclosure

The security posture described on this page is based on our own internal assessment conducted in June 2026. We make no claim of independent certification. We publish this to be transparent about what is and is not in place, and we update this page after each significant security sprint.

🌏 Data Residency

All customer data is stored in AWS ap-southeast-2 (Sydney, Australia). No data is transferred outside Australia. STANCE is built for Australian organisations — data sovereignty is a design requirement, not a configuration option.

  • AWS ap-southeast-2 (Sydney)
  • Supabase hosted in Sydney region
  • No cross-region replication
  • No third-party data processors outside Australia

🔒 Data Isolation

Every database query is filtered by organisation ID using Supabase Row Level Security. It is architecturally impossible for one organisation's data to be returned in another organisation's query — this is enforced at the database layer, not the application layer.

  • Row Level Security on every table
  • org_id filter enforced on every query
  • Separate storage buckets per organisation
  • Multi-tenancy enforced from day one — never retrofitted

🔐 Authentication

Authentication is powered by Clerk, which holds SOC 2 Type II certification. All session controls are enforced at the platform level.

  • Clerk — SOC 2 Type II certified
  • Session timeout enforced
  • Idle timeout enforced
  • MFA available (TOTP)
  • Email verification required before access
  • Session revocation on password change
  • Login attempt limits with lockout

🛡️ Application Security

Phase 1 security assessment completed June 2026. 17 findings across 8 domains identified and assessed. All critical and high severity findings remediated.

  • DOMPurify on all HTML rendering surfaces
  • No API keys in client-side code
  • Rate limiting on all AI endpoints
  • Token logging removed from all code paths
  • All npm dependencies audited — 0 known vulnerabilities
  • Git history purged of historical credential exposure

🏗️ Infrastructure

STANCE runs on established cloud infrastructure with a clear separation between production and development environments.

  • Production and development environments fully separated
  • Separate Supabase projects, Clerk instances, API keys per environment
  • Vercel serverless — no persistent compute to compromise
  • Cloudflare DNS and DDoS protection
  • Encryption in transit (TLS 1.2+) on all connections
  • Encryption at rest on all stored data

📣 Responsible Disclosure

If you discover a security vulnerability in STANCE, please report it responsibly. We commit to acknowledging all reports within 24 hours and providing a resolution timeline within 5 business days.

  • Security contact: security@stancesec.com
  • Acknowledge within 24 hours
  • Resolution timeline within 5 business days
  • No legal action against good-faith researchers
Questions about our security posture?

Contact our security team.

For security enquiries, vulnerability reports, or enterprise security documentation requests.

security@stancesec.com