Australian-built security tooling

Security tooling that starts useful and stays honest.

link42 builds small, focused tools for people who actually do security. Rule1 is live now. Patch8 and threat10 are coming back once their data pipelines are ready. No reporting dashboards for launch day, no pretend coverage, just the working parts first.

Congratulations, Your Platform Is IRAP-Assessed. Your Product Is Still Wearing a Fake Moustache.

A field guide to assessed infrastructure, products, on-premises software, cloud services, and the customer’s continuing right to say no.

Read article

How it started

We spent years working in cyber — writing policies, triaging controls, sitting through vendor pitches for tools that cost six figures and solved problems nobody had. The ISM had 800+ controls buried in a PDF. We needed to actually work with them. So we built rule1 — a searchable, filterable, version-diffable ISM explorer.

It worked. People started using it. Not because we marketed it, but because it solved a real problem that practitioners actually had. That was the proof we needed: small, focused tools built from direct experience are worth more than enterprise platforms built from pitch decks.

So now we're building more. Same philosophy — find a problem we've lived through, build the tool we wished existed, ship it carefully, keep it sharp. No roadmap theatre. Rule1 is live for public use today; the other products stay quiet until their data is ready.

And yes — we use AI to build this. Unapologetically. It lets a small team ship at the pace of a large one. But we're not hiding behind it. Every piece of AI-generated content in our tools is clearly labelled. Our opinions are ours. The code is ours to maintain. AI is the power tool, not the craftsman.

What we're building

One live tool, two focused products returning once the pipelines are ready.

rule1

Where it all started

The Australian Information Security Manual has 800+ controls across dozens of topics. The official format is a PDF. We turned it into a searchable, filterable, version-diffable explorer — because reading security controls shouldn't require a magnifying glass and a stiff drink.

Live · Free
threat10

Threat intel without the price tag

Open-source threat feeds exist, but they're scattered across a dozen formats and APIs. threat10 pulls them together — normalises IOCs from Abuse.ch, MITRE ATT&CK, PhishTank, and more into one searchable source of truth.

Pipeline rebuild
patch8

Vulnerability intel, unified

NVD, EPSS, CISA KEV — the data you need to prioritise patching lives in three different government feeds that don't talk to each other. patch8 pulls them into one searchable database with risk scoring and enrichment.

Pipeline rebuild

One integrated platform

Rule1 is the first public surface on the rebuilt platform. The rest comes online when each service is boring, observable, and genuinely useful.

Shared Identity

login2 is the account layer for the platform. Public tools remain usable without an account where that makes sense.

Unified Experience

A consistent design language and a persistent PlatformBar means you can jump between apps without losing your context.

Container Deployed

The rebuild is moving to container-friendly Node services on DigitalOcean, with static public data served from snapshots where possible.

How we build

Small and sharp

Every tool does one thing well. We'd rather ship three focused tools in order than one platform-shaped promise that pretends everything is ready at once.

Free where it counts

The basic tools will stay free for non-commercial use, permanently. Premium tiers will exist — running infrastructure costs money — but the core experience won't be paywalled.

Predictable by default

Public intelligence data is served from local SQLite snapshots, mutable user data lives in Postgres, and every service can run as a boring, inspectable container.

Born from experience

Years of doing the work — the audits, the policies, the board decks. We don't guess what practitioners need. We were practitioners. We build what we wished existed.

AI-assisted, human-owned

We use AI heavily to write code and generate content — and we label every bit of it. You'll always know what's a human opinion and what came from a model. Transparency isn't optional.

Practitioners first

Built for the people at the coalface — the analysts triaging alerts, the GRC leads wrestling frameworks, the mentors giving their time. If it doesn't help them, it doesn't ship.

Jump in

No sign-up required for the public tools. No "book a demo" button. Just go use what is live.

AI-generated content

We didn't write this page. An AI did, based on our direction. We were busy building the actual tools. That's the point.