Tas Secure is a privacy-engineering and applied-cryptography consultancy based in Tasmania. We help organisations use sensitive data safely, ship software that holds up to scrutiny, and meet the Privacy Act and Essential Eight — without sending the work to the mainland.
We're a Tasmanian security practice built on the hard part — cryptographic systems, privacy-preserving machine learning, and secure software at the code level.
Most security firms tell you where the gaps are and hand you a report. We go further: we can review the key-wrapping, fix the architecture, build the system, and prove the sensitive data never left the building. Our work is grounded in active research, which means you get depth usually locked inside large mainland consultancies — delivered locally, in person, at a scale Tasmanian organisations can actually afford.
Whether you're a government agency facing new privacy obligations, a startup shipping a security-sensitive product, or a research network that can't move its data, we start the same way: by understanding exactly what you're protecting.
A clear read on where you stand against the Privacy Act 1988 (including the 2024–25 reforms) and the ASD Essential Eight. We assess what data you hold, where it flows, and what's exposed — then hand you a prioritised, plain-language plan you can act on, not a 90-page PDF that sits in a drawer.
We build and audit software where security is the point, not an afterthought — credential and password systems, encryption and key management, browser extensions, and full-stack web apps. Have an existing codebase? We do focused cryptographic and security code review and tell you exactly what's wrong and how to fix it.
Want to learn from your data — across sites, partners, or devices — without centralising it? This is our research specialty. We design federated learning and privacy-preserving analytics so models train where the data lives. Ideal when the data is too sensitive, too regulated, or too distributed to pool.
Ongoing security architecture guidance, incident-readiness reviews, and applied research for problems the off-the-shelf vendors don't cover. We also run plain-language training and talks — turning genuinely hard topics like cryptography and AI privacy into something your team and board can actually use.
AI that respects the people in your data. We help you deploy machine learning responsibly — assessing privacy risk, bias, and transparency, and building safeguards that keep individuals' data protected and decisions explainable. Practical guidance aligned with Australia's AI Ethics Principles, not abstract policy.
Compliance is hard to prove when you're small. TrustProof helps Australian SMEs show they manage AI, cyber, and privacy risk — turning a simple assessment into action tasks, evidence records, policies, staff training, and a client-ready trust report.
A plain-language assessment of your AI, cyber, and privacy posture.
Findings become a prioritised list of tasks your team can actually do.
Record proof as you go — an auditable trail of what you've done.
Generate the policies you're expected to have, ready to adopt.
Built-in staff training so your whole team meets the bar.
Export a client-ready trust report that wins you the deal.
Privacy and security posture reviews mapped to the Privacy Act and Essential Eight, in language your whole team understands.
Secure full-stack software — from encrypted credential systems and browser extensions to APIs and key-management layers.
Cryptographic and security code review that finds the real flaws and tells you exactly how to close them.
Federated learning and privacy-preserving analytics so you can use sensitive data without ever centralising it.
Ongoing architecture guidance, incident-readiness reviews, and a sounding board for hard security decisions.
Workshops and talks that make cryptography, privacy, and AI risk genuinely usable for teams and boards.
Research-grade expertise, delivered locally — without the distance or the markup.
Most consultancies stop at findings. We can implement the fix, write the secure code, and redesign the architecture — so problems actually get closed.
Our work is grounded in active research in applied cryptography and privacy-preserving machine learning — not surface-level checklists.
We're local. We show up in person, understand your constraints, and work at a scale that fits Tasmanian organisations — not mainland pricing.
We translate hard security into decisions your team and board can act on. No jargon used to impress, no reports written to confuse.
Tas Secure exists because good security shouldn't be reserved for organisations big enough to afford a mainland consultancy.
The practice is built on hands-on technical depth — not just advising on security, but building it: cryptographic systems, secure software, and privacy-preserving AI that lets organisations use sensitive data without ever putting it at risk. That work is grounded in active academic research, which is what lets us tackle problems the off-the-shelf vendors can't.
We're based in Tasmania and proud of it. For local clients that means someone who shows up in person and understands your constraints; for clients across Australia it means research-grade expertise delivered remotely, honestly, and in plain language. We'd rather tell you the truth about your risk than sell you something you don't need.
We work to the standards Australian organisations are held to — the Privacy Act, the ASD Essential Eight, and the national AI Ethics Principles — across the sectors where getting security right matters most.
Tell us what you're protecting. We'll tell you honestly whether we're the right fit — and where to start if we're not. The first call is free.
Email is the fastest way to get a considered reply. For anything sensitive, ask and we'll share an encrypted channel.