Trust & Procurement Centre

Review the public evidence first. Request controlled material only where the procurement decision needs it.

For security reviewers, procurement teams, risk teams, enterprise buyers and MSPs/MSSPs evaluating Damocles Security and Guardian.

Australian Guardian data residency

Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.

Procurement evidence path

Start with material that is already public and governed.

The public site now exposes the technical scope, service boundaries, product responsibilities, methodology, approved Australian Guardian data-residency position and evidence model needed for an initial security and procurement review. Controlled material is requested only where the review genuinely needs it.

Security testing methodology

Public now

Testing perspectives, governed coverage, methodology references, evidence outputs, mapping types, limitations and the boundary between technical assurance and certification.

View methodology →

Damocles service briefs

Public now

Detailed service pages and downloadable technical briefs explain scope, test areas, evidence, deliverables, responsibilities and material exclusions.

Browse service briefs →

Australian Guardian data residency

Public now

Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.

View Guardian →

Guardian product briefs

Public now

Detailed Guardian product pages explain what the product does, what the customer sees, what Damocles manages, evidence, commercial responsibility and scope boundaries.

Browse Guardian products →

Guardian packages and allowances

Public now

Guardian Core, Assurance and Managed Defence are compared using the approved package model, with inclusions, allowance notes and separately scoped activity kept explicit.

Compare Guardian packages →
Certification and compliance boundary

Damocles publishes certification, attestation and formal compliance statements only where approved evidence supports the claim. No certification or compliance status should be inferred from framework references, control mappings, product features or technical testing.

How to read this centre

Public, controlled and unclaimed information are deliberately separated.

Public now

Published product, service, methodology, approved residency or boundary information can be reviewed directly on this website.

Controlled on request

Architecture, detailed data-flow, supplier, resilience or other security-review material is supplied only when approved for the relevant procurement purpose.

Not claimed without evidence

Certification, attestation, compliance, service-level or recovery claims are not inferred from product features, framework references or technical testing. Australian Guardian data residency is separately approved and published as a verified platform fact.

Controlled security review

Material that requires purpose, scope or evidence control.

Approved public facts, including Australian Guardian data residency, are stated directly. More sensitive architecture, data-flow, supplier and security-review evidence remains controlled and is supplied where relevant to a real procurement or security review.

Security & platform architecture

Available during procurement review

Platform boundaries and relevant architecture information can be reviewed under an appropriate procurement process.

Data handling & privacy

Residency public; detail controlled

Australian Guardian data residency is publicly confirmed. Detailed data flows, retention, privacy handling and architecture evidence remain available through the controlled procurement review process.

Identity & access

Available during procurement review

Relevant identity and access information can be supplied for a scoped security review.

Secure development

Available during procurement review

Secure-development information and supporting material can be discussed with authorised reviewers.

Incident management

Evidence-controlled

Incident-management information is shared through a controlled review rather than presented as an unsupported service-level claim.

Backup, resilience & recovery

Available during procurement review

Guardian backups and recovery copies for Australian customers remain stored within Australia. Product-specific resilience and recovery commitments are handled during review and the applicable agreement.

Suppliers / subprocessors

Available during procurement review

Current, scope-relevant supplier information is handled through the procurement process.

Assurance & compliance

Not publicly claimed

Damocles publishes certification, attestation and formal compliance statements only where approved evidence supports the claim. Technical evidence may support assurance activities; it does not establish whole-framework compliance.

Start a scoped evidence request

Choose the review area so the procurement request arrives with useful context.

Each option uses the existing governed contact workflow and preselects the review purpose and information category. The request still remains subject to the approved disclosure boundary for the relevant product or service.

Architecture

Security and platform architecture, trust boundaries and product-relevant control placement.

Start this review →

Data & privacy

Data handling, privacy, Australian data residency, approved information flows, retention context and disclosure boundaries.

Start this review →

Identity & access

Authentication, administrative access, role boundaries and identity-control information.

Start this review →

Incident & resilience

Incident-management, backup, resilience and recovery information relevant to the proposed scope.

Start this review →

Suppliers

Current scope-relevant supplier and subprocessor information for procurement review.

Start this review →

Assurance

Approved certification, attestation, compliance or assurance evidence relevant to the decision.

Start this review →
What to include in a request

Tell us the decision you are trying to make, not just the document name.

A useful procurement request identifies the product or service under review, the security or compliance question being assessed, the specific information required, the authorised audience and the desired response timeframe.

Available during procurement review

Controlled evidence request

Request only the architecture, detailed data-flow, access, supplier, resilience, incident or assurance information relevant to the scoped decision. Evidence is shared according to its approved disclosure boundary.

Request security information →