Published pages and their delivery path
Static pages, local assets, public response headers, the content origin configuration and the published security contact.
A dated account of the controls observable at The SEEN Group’s public website boundary, the evidence behind them and what those observations do not establish.
The boundary is deliberately narrow so every statement can be read at the right scale.
Static pages, local assets, public response headers, the content origin configuration and the published security contact.
Product systems, internal devices, Microsoft 365, operational practices and organisation-wide controls are outside this record.
Product-specific statements are scoped and maintained on the relevant product site. No maturity, certification or accreditation is inferred here.
HTTP redirects to HTTPS. TLS 1.2 or later is required at the viewer boundary, with HSTS enabled and HTTP/2 and HTTP/3 available.
The live response includes Content Security Policy, frame denial, MIME-sniffing protection, restrictive referrer and browser-permission policies, and cross-origin opener and resource policies.
The storage origin is not publicly readable. Public-access blocks are enabled, the bucket policy is non-public and website objects are delivered through restricted origin access at the edge.
At the check date, no third-party executable script, advertising tag, analytics runtime or embedded contact form was present in the published pages inspected. Fonts, styles, scripts and media are served locally.
Storage object versioning was enabled when checked. Versioning may help recover an overwritten website object.
Standard content-delivery request logging was not enabled when checked.
A canonical machine-readable security contact is published with an expiry of 31 July 2027 and points back to this policy record.
This website does not establish an Essential Eight maturity level.
ASD describes the Essential Eight as a package of mitigation strategies for organisations’ internet-connected IT networks. A maturity claim requires a defined assessment boundary and evidence of the implementation and effectiveness of the applicable controls across all eight strategies. The checks published here cover only this public website boundary.
No Essential Eight maturity level, independent assessment, certification, accreditation or compliance status is claimed.
Baseline trust record published. It records the static public-site boundary, delivery and origin configuration, local runtime, object versioning, request-logging limitation and security contact. Product systems and the wider organisation remain outside this record.
If you believe you have found a security issue affecting this public website or a The SEEN Group domain, email the shared contact with “Security” in the subject. Please do not include secrets, credentials or unnecessary personal information.
hello@theseengroup.com.au