ATO READINESS · SECURITY ASSESSMENT · PROFESSIONAL DOCUMENTATION

ATO readiness, assessment and documentation.
One operational workspace.

CyberSeeds runs framework control assessments, captures evidence, manages risk and POA&M, and generates your SAR, SSP and IRP — all in one auditable workspace built for ATO sign-off.

Book a demo
Platform owner issued you a registration token?
cyberseeds / assessments / overview
CyberSeeds assessment overview showing control progress, compliance score, open RFIs and risks, and the assessment lifecycle from draft to closed
800+
ISM controls built in
ML1–3
Essential Eight auto-scoring
Seconds
SAR · SSP · IRP from live data
Air-gap → SaaS
One platform, every deployment

The full NatSec & Federal ecosystem

CyberSeeds is designed for customers who need ATO documentation, security assessment, or the full operating model. Product profiles and deployment models let each tenant see the right modules while keeping data residency aligned to the customer environment.

🛡️

National Security & Intelligence

Government and regulated teams that need controlled framework assessment, IRAP-aligned evidence traceability, formal documentation, and clear authority decision paths.

IRAP supportAir-gap deployClassified environmentsRole isolation
🏛️

Government & Public Sector

Federal, state, provincial and local government agencies. Compliance workflow support, IRAP-ready evidence packs, full audit trail for regulatory reviews, multi-team assessment coordination, and deployment-aligned data residency.

IRAP evidenceData residencyAudit trailMulti-agency
⚔️

Defence & Defence Industry

Military agencies, primes, and supply chain partners. Defence framework compliance, readiness for international contracts, and full audit trails for programme reviews.

Defence frameworksSupply chainAudit trailMulti-framework
🏢

Critical Infrastructure & Private Sector

Banks, telcos, utilities, healthcare and other regulated operators that need repeatable assessment workflows, risk treatment, evidence, and executive-ready reporting.

RiskEvidenceReportsATO readiness
🔧

MSSPs & Assessment Bodies

Accredited assessors and managed security service providers managing multiple client assessments. Multi-tenancy, per-client assessment isolation, bulk evidence management, and comparison reporting.

Accredited assessorsMulti-clientBulk exportWhite-label
☁️

Cloud Service Providers

Cloud service providers seeking or maintaining compliance authorisations. Cloud compliance sync (AWS, Azure, GCP), automated evidence from cloud posture tools, and continuous monitoring.

AWS / Azure / GCPContinuous monitoringAuto-evidenceCompliance auth
DEPLOYMENT MODELS

Deploy where your data must live

No external runtime dependencies. No cloud vendor required. One binary, one SQLite file — runs identically from a laptop to a SECRET-classified enclave.

Zero internet calls at runtime No CDN · no telemetry · no callbacks Data residency configurable by deployment
On-Premises

VM or bare-metal inside your agency network. Standard Python deployment — no container runtime required. Integrate with your existing LDAP directory and internal certificate authority.

  • LDAP / Active Directory SSO
  • Internal PKI / custom TLS certificate
  • Systemd service or Docker container
  • Agency network fully isolated
  • Local backup to agency storage
PROTECTEDAgency LANDISP
Regional Sovereign Cloud

Run in the customer-approved region and cloud environment. Containerised with cloud-native hosting, persistent storage, IAM-style role access, and audit logging. Data stays where the customer deploys it.

  • Customer-approved regional hosting paths
  • Container and managed-cloud deployment support
  • Cloud identity / role-based access control
  • Data residency: configurable per deployment
  • AWS Marketplace listing (roadmap)
Regional cloudCloud-hostedData residency
Local / Single Assessor

Run on a laptop for solo assessors or small teams. No network required, no server to manage. Single portable SQLite file — back up, transfer, or archive alongside artefacts at engagement close.

  • pip install + one command to start
  • Single-file SQLite database
  • No configuration needed
  • Portable assessment archive
  • Works fully offline
OfflineSolo assessorPortable
Never locked out
Licence issues degrade gracefully — read access and export always survive
Bundled SQLite
One file — no database server
Zero external calls
No CDN, no telemetry, no callbacks
Regional residency
Configured per customer deployment

From zero to signed-off in four steps

CyberSeeds structures the full compliance assessment lifecycle — no configuration required. Start an assessment and the workflow guides you from setup to authority submission.

STEP 1
1

Create an assessment

Name the workload, select or import the framework in scope, define the boundary, choose the customer package, and invite the right team members with role-aware access.

Day one — controls seeded instantly
STEP 2
2

Assess controls in parallel

Assessors and system owners work simultaneously in the same platform — each seeing only their own fields. Real-time progress, zero contamination risk.

No spreadsheet merges, no version chaos
STEP 3
3

Close findings and treat risks

Raise RFIs from control rows, log risks against the ASD 5×5 heatmap, track treatment to closure. Gap analysis shows exactly what's blocking sign-off.

See exactly what blocks sign-off
STEP 4
4

Generate and submit

Click Generate SAR. Your Security Assessment Report, SSP, IRP and supporting annexes are produced directly from live assessment data — ready for your AO.

SAR · SSP · IRP in seconds

Every role sees exactly what it should

Assessor

Run the assessment: statuses, findings, RFIs and risks — with assessor fields strictly separated from system-owner input.

System owner

Answer implementation questions, attach evidence and submit claims for review. Nothing else to learn, nothing else visible.

Authorising officer

A live ATO-readiness view and generated SAR, SSP and IRP — decision-ready, with the full audit trail behind every number.

One platform. Every compliance workflow.

From framework scope to ATO sign-off, CyberSeeds keeps assessment work, documentation, evidence, risks, RFIs and approvals in one operating model.

Assess framework controls inline

Click any control row and it expands in-place — no modal, no page reload. Every field saves in real time with an immutable per-field audit entry. Assessors and system owners each see exactly their own inputs.

Framework-led control scope, including imported or customer-specific frameworks
Immutable per-field audit log with who, when, what
Bulk status updates across filtered control sets
Gap analysis highlights exactly what's blocking sign-off
Controls — ACME Security Assessment Framework v2026-03
All chapters All statuses 12 gaps
ID
CONTROL
STATUS
EVIDENCE
CTL-0002
Complete
CTL-0091
In progress
Assessor
Sys Owner
History
Status In progress ▾
Implementation
CTL-0210
Not started

Raise risks, track treatment, close findings

Raise a risk directly from any failing control. The ASD 5×5 heatmap computes inherent and residual ratings automatically. Every risk is linked to a POAM entry and tracked to closure.

ASD 5×5 heatmap — inherent and residual
Raise risks directly from control findings
POAM linked to every open risk
Risk register exports for AO submission
Likelihood →
Critical
Treating
High
Open
Medium
Accepted

SAR, SSP and IRP — generated in seconds

All assessment documents are generated directly from live control data. No copy-paste, no manual formatting. Click generate, download, submit to your Authorising Official.

SAR with executive summary and maturity scores
SSP and SSP Annex from control data
IRP and CMP auto-populated from risk register
Customisable templates per assessment
CYBERSEEDS
PROTECTED // SENSITIVE
Security Assessment Report
ATO
Readiness
View
SAR
SSP
IRP
Annex

Assessor and system owner — strictly separated

Field-level RBAC enforced at both the UI and API layer. Assessors cannot see system owner inputs and vice versa. No contamination of evidence — ever.

Field-level RBAC enforced in frontend AND backend
Per-assessment role overrides without global changes
5 roles: Org Admin / Lead / Assessor / SysOwner / Auditor
Separate audit entries per role — fully traceable
Assessor
System Owner
History
Status In progress
Implementation
Evidence
System Owner Context — read-only
Provider resp.
Compliance Compliant ✓
Assessor tab · read-only for System Owners

One platform, any framework

CyberSeeds can incorporate any customer framework or control catalogue. Each framework carries its own terminology, groupings, implementation fields, assessor fields, feature flags and scoring rules, so the workspace adapts per assessment without hardcoding one standard.

🇦🇺 Australian Government
IRAP assessment support Evidence, control implementation, assessor review and ATO-ready reporting
ISM 2026-03 800+ controls · Chapters · PROTECTED / SECRET / TS
Essential Eight ML1 · ML2 · ML3 · 8 strategies · auto-maturity scoring
Defence Industry Security DISP requirements · supply chain security
🌐 International Standards
ISO/IEC 27001:2022 93 controls · Annex A domains · ISMS
NIST CSF 2.0 Available when loaded into the customer catalogue
NIST SP 800-53 Rev 5 1000+ controls · 20 control families
🇺🇸 US Federal & Compliance
FedRAMP High NIST 800-53 baseline · US federal cloud
CMMC 2.0 Use when included in the licensed framework catalogue
SOC 2 Type II Trust Services Criteria · 5 categories
PCI DSS 4.0 12 requirements · cardholder data environment
🇬🇧 UK & Custom
Cyber Essentials Plus NCSC-backed · 5 technical controls
NCSC CAF Critical national infrastructure · 14 principles
Any Customer Framework Import or configure customer-specific catalogues, fields and groupings

From one laptop to a whole agency

Start where you are. The same platform, controls and reports scale from a solo engagement to multi-client, sovereign operations.

Solo assessor

Run engagements on a laptop. Single portable SQLite file, fully offline — archive the whole assessment alongside your artefacts at close.

  • Works fully offline
  • No server to manage
  • Portable engagement archive

Agency & MSP

Multi-client operations with per-client isolation, controlled registration and licensing, and sovereign or air-gapped deployment paths.

  • Multi-client / multi-tenant operation
  • Sovereign, on-prem and air-gap deploys
  • Controlled registration and licensing
Talk to sales

AI assistance your accreditor can accept

No autonomous agents acting on your compliance data. CyberSeeds AI drafts and reviews under your control — in-region, auditable, and switched off entirely for restricted deployments.

In-region inference — vendor-managed AI runs on AWS Bedrock in Australia
Bring your own key — route to your organisation's approved provider
Your data is never used to train models
Every suggestion is logged, attributed and governed by per-org allowances
AI Co-pilot — draft suggestion
Implementation summary · ISM-0843
Accept draft Discard
Logged: who, when, model, tokens
Tenant-aware access and audit trails
Deployment model matched to customer need
Restricted and air-gapped deployment paths
Data residency configured per deployment
Sovereign-deployable, region-aware and air-gap ready

Public support and knowledge base

SaaS, BYOC, self-hosted and air-gapped customers can use the public support hub for knowledge base guidance, product updates, support boundaries and escalation steps without needing direct access to the app.

?
Knowledge baseSetup, workflow and package guidance
!
Air-gapped supportExternal support path for disconnected environments
i
Product updatesCustomer-facing changes and release notes

See CyberSeeds in 30 minutes

We'll walk through the full flow: product profile, deployment model, framework scope, workload setup, evidence, risk, documentation and ATO readiness.

  • SaaS, BYOC, self-hosted and restricted deployment pathways
  • Product profiles for ATO documentation, security assessment and full-platform customers
  • Any framework or customer catalogue with implementation and assessor fields
  • Traceable evidence, risk treatment and authority sign-off

Book a walkthrough

30 minutes focused on the product profile, framework, deployment and ATO workflow that matches your use case.