Security testing methodology
Public nowTesting perspectives, governed coverage, methodology references, evidence outputs, mapping types, limitations and the boundary between technical assurance and certification.
View methodology →For security reviewers, procurement teams, risk teams, enterprise buyers and MSPs/MSSPs evaluating Damocles Security and Guardian.
Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.
The public site now exposes the technical scope, service boundaries, product responsibilities, methodology, approved Australian Guardian data-residency position and evidence model needed for an initial security and procurement review. Controlled material is requested only where the review genuinely needs it.
Testing perspectives, governed coverage, methodology references, evidence outputs, mapping types, limitations and the boundary between technical assurance and certification.
View methodology →Detailed service pages and downloadable technical briefs explain scope, test areas, evidence, deliverables, responsibilities and material exclusions.
Browse service briefs →Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.
View Guardian →Detailed Guardian product pages explain what the product does, what the customer sees, what Damocles manages, evidence, commercial responsibility and scope boundaries.
Browse Guardian products →Guardian Core, Assurance and Managed Defence are compared using the approved package model, with inclusions, allowance notes and separately scoped activity kept explicit.
Compare Guardian packages →Damocles publishes certification, attestation and formal compliance statements only where approved evidence supports the claim. No certification or compliance status should be inferred from framework references, control mappings, product features or technical testing.
Published product, service, methodology, approved residency or boundary information can be reviewed directly on this website.
Architecture, detailed data-flow, supplier, resilience or other security-review material is supplied only when approved for the relevant procurement purpose.
Certification, attestation, compliance, service-level or recovery claims are not inferred from product features, framework references or technical testing. Australian Guardian data residency is separately approved and published as a verified platform fact.
Approved public facts, including Australian Guardian data residency, are stated directly. More sensitive architecture, data-flow, supplier and security-review evidence remains controlled and is supplied where relevant to a real procurement or security review.
Platform boundaries and relevant architecture information can be reviewed under an appropriate procurement process.
Australian Guardian data residency is publicly confirmed. Detailed data flows, retention, privacy handling and architecture evidence remain available through the controlled procurement review process.
Relevant identity and access information can be supplied for a scoped security review.
Secure-development information and supporting material can be discussed with authorised reviewers.
Incident-management information is shared through a controlled review rather than presented as an unsupported service-level claim.
Guardian backups and recovery copies for Australian customers remain stored within Australia. Product-specific resilience and recovery commitments are handled during review and the applicable agreement.
Current, scope-relevant supplier information is handled through the procurement process.
Damocles publishes certification, attestation and formal compliance statements only where approved evidence supports the claim. Technical evidence may support assurance activities; it does not establish whole-framework compliance.
Each option uses the existing governed contact workflow and preselects the review purpose and information category. The request still remains subject to the approved disclosure boundary for the relevant product or service.
Security and platform architecture, trust boundaries and product-relevant control placement.
Start this review →Data handling, privacy, Australian data residency, approved information flows, retention context and disclosure boundaries.
Start this review →Authentication, administrative access, role boundaries and identity-control information.
Start this review →Incident-management, backup, resilience and recovery information relevant to the proposed scope.
Start this review →Current scope-relevant supplier and subprocessor information for procurement review.
Start this review →Approved certification, attestation, compliance or assurance evidence relevant to the decision.
Start this review →A useful procurement request identifies the product or service under review, the security or compliance question being assessed, the specific information required, the authorised audience and the desired response timeframe.
Request only the architecture, detailed data-flow, access, supplier, resilience, incident or assurance information relevant to the scoped decision. Evidence is shared according to its approved disclosure boundary.
Request security information →