Trust centre / public record

Proof is useful only when its limits stay visible.

A dated account of the controls observable at The SEEN Group’s public website boundary, the evidence behind them and what those observations do not establish.

Scope first

This receipt covers one public website.

The boundary is deliberately narrow so every statement can be read at the right scale.

Inside

Published pages and their delivery path

Static pages, local assets, public response headers, the content origin configuration and the published security contact.

Outside

Products and the wider organisation

Product systems, internal devices, Microsoft 365, operational practices and organisation-wide controls are outside this record.

Language

Observations, not badges

Product-specific statements are scoped and maintained on the relevant product site. No maturity, certification or accreditation is inferred here.

01Delivery boundaryObserved live

HTTP redirects to HTTPS. TLS 1.2 or later is required at the viewer boundary, with HSTS enabled and HTTP/2 and HTTP/3 available.

Evidence basis
Live HTTPS response and delivery configuration
Evidence class
Publicly verifiable + operator verified
Checked
4 August 2026 · 08:28 AEST
Limit
No penetration test or client-compatibility assessment was performed.
02Response policyObserved live

The live response includes Content Security Policy, frame denial, MIME-sniffing protection, restrictive referrer and browser-permission policies, and cross-origin opener and resource policies.

Evidence basis
Headers returned by the live website
Evidence class
Publicly verifiable
Checked
4 August 2026 · 08:28 AEST
Limit
Presence of a header does not establish the effectiveness of every browser or application control.
03Content originConfigured when checked

The storage origin is not publicly readable. Public-access blocks are enabled, the bucket policy is non-public and website objects are delivered through restricted origin access at the edge.

Evidence basis
Storage and content-delivery configuration
Evidence class
Operator verified
Checked
4 August 2026 · 08:28 AEST
Limit
Account administration, identity controls and provider effectiveness were not assessed.
04Published runtimeObserved live

At the check date, no third-party executable script, advertising tag, analytics runtime or embedded contact form was present in the published pages inspected. Fonts, styles, scripts and media are served locally.

Evidence basis
Deployed pages, assets and network requests
Evidence class
Publicly verifiable
Checked
4 August 2026 · 08:28 AEST
Limit
Network and email providers still process routine connection data; email correspondence occurs outside this website.
05Object recoveryConfigured when checked

Storage object versioning was enabled when checked. Versioning may help recover an overwritten website object.

Evidence basis
Storage configuration
Evidence class
Operator verified
Checked
4 August 2026 · 08:28 AEST
Limit
This is not evidence of an independent backup, immutable retention, disaster-recovery capability or a tested restore.
06Request visibilityKnown limitation

Standard content-delivery request logging was not enabled when checked.

Evidence basis
Content-delivery configuration
Evidence class
Operator verified
Checked
4 August 2026 · 08:28 AEST
Limit
No statement is made here about request-level monitoring or incident-detection coverage.
07Security contactObserved live

A canonical machine-readable security contact is published with an expiry of 31 July 2027 and points back to this policy record.

Evidence class
Publicly verifiable
Checked
4 August 2026 · 08:28 AEST
Limit
Email contact only; no response-time commitment or bug-bounty programme is stated.
What this does not establish

A public-site record is not an organisational assessment.

Not assessed
This website does not establish an Essential Eight maturity level.

ASD describes the Essential Eight as a package of mitigation strategies for organisations’ internet-connected IT networks. A maturity claim requires a defined assessment boundary and evidence of the implementation and effectiveness of the applicable controls across all eight strategies. The checks published here cover only this public website boundary.

No Essential Eight maturity level, independent assessment, certification, accreditation or compliance status is claimed.

Material record / 04.08.2026

Baseline trust record published. It records the static public-site boundary, delivery and origin configuration, local runtime, object versioning, request-logging limitation and security contact. Product systems and the wider organisation remain outside this record.

Responsible contact

Report a security concern.

If you believe you have found a security issue affecting this public website or a The SEEN Group domain, email the shared contact with “Security” in the subject. Please do not include secrets, credentials or unnecessary personal information.