Trust centre

A precise account of what is true now.

This page separates the public website’s current controls, each product’s stated availability and standards used only as contextual references.

Scope
Public web estate
Product status
Stated individually
Last reviewed
4 August 2026
01 / Public website

A deliberately small attack surface.

This is a static marketing website. It has no user accounts, public file upload, payment flow or application database. The contact action opens the visitor’s email client; the site does not submit a form payload.

02 / Product portfolio

Status is stated product by product.

Backstage TP and Proof GRC are in development. QuoteMaker is in early access in Australia and maintains its own availability, product and trust statements on quotemaker.com.au.

03 / Assurance language

No maturity level or certification is implied.

Framework names may be used to explain context. That does not state or imply certification, accreditation, compliance or a completed independent assessment.

Current web baseline

Controls visible at the website boundary.

These are technical characteristics of the public website as presently published - not an audit opinion on the wider organisation.

Transport

Encrypted delivery

HTTPS is enforced at the content-delivery layer with a modern TLS policy and HTTP Strict Transport Security.

Origin

Private content origin

Website files are delivered through the content-distribution service rather than exposed from a publicly readable storage origin.

Browser

Restrictive response policy

Content Security Policy, clickjacking protection, MIME sniffing protection and restrictive browser permissions reduce unnecessary browser capability.

Dependencies

No third-party runtime scripts

The published pages use local styles, scripts, fonts and media. No advertising tag or third-party analytics runtime is required to render the site.

Recovery

Versioned website objects

Published content is stored with object versioning, supporting recovery from an unintended overwrite of the website files.

Collection

No embedded contact form

Contact links open the visitor’s email application. This website does not collect or store a form submission in the browser or application database.

Essential Eight context
A website does not “pass” the Essential Eight.

The Australian Cyber Security Centre’s Essential Eight Maturity Model applies to an organisation’s technology environment and operating practices. A static marketing site cannot, by itself, establish an organisational maturity level.

The model is a useful contextual reference where relevant. The SEEN Group does not claim an Essential Eight maturity level or independent Essential Eight assessment on this website.

Responsible contact

Report a security concern privately.

If you believe you have found a security issue affecting this public website or a The SEEN Group domain, email the shared contact with “Security” in the subject. Please do not include secrets, credentials or unnecessary personal information.

A machine-readable contact is also available in security.txt.

Read the privacy notice
Trust is maintained

Scope changes as products move forward.

Material product, privacy and assurance statements are reviewed when availability or operating scope changes.

Ask a trust question