Managed security · Projects · Sydney

Security that runs every day, not just audit week.

exit.codes is an independent security practice in Sydney. We monitor and defend Australian businesses month to month, take contract work from providers who need a specialist, and build the web infrastructure underneath both.

managed-status.sh
$exit-codes status --client acme
Monitoring 14 endpoints, 6 domains endpoint agents 14/14 reporting tls certificates 6/6 valid, none due dmarc policy acme.com.au p=none dns records no changes in 24h detection 1 alert triaged 04:12 Next report: Friday 09:00 AEST
$

Managed security

What being covered actually means

No dashboard you never open, and no alert queue handed straight back to you. We watch it, we triage it, and we tell you what needs doing.

Always on

  • Endpoint detection agents across your fleet, monitored and kept current
  • DNS record change monitoring on every domain you own
  • TLS certificate expiry and chain validation before anything lapses
  • Email authentication drift, so SPF, DKIM and DMARC stay enforced
  • External attack surface tracking as your estate changes
  • Patch and hardening posture against the Essential Eight

What lands in your inbox

  • Alerts that a person has already triaged, with the noise removed
  • A plain English monthly report you can hand to your board or insurer
  • A running remediation list, prioritised, showing what changed since last month
  • Direct access to the person doing the work, not a ticket queue
  • Immediate contact when something is genuinely urgent
We alert, we do not act without you. Detection and triage are included. Anything beyond that, isolating a machine or locking an account, needs your written authorisation first. You will always know who changed what.

For MSPs, IT providers and consultancies

Capacity you can put your name on.

Providers bring us in when a job needs a specialist, or simply another pair of hands. We work under your brand, report in your format, and stay out of your client relationship. We carry our own professional indemnity and cyber liability cover, and can provide a certificate of currency for your vendor onboarding.

What we take on

  • Incident response and digital forensics, including imaging and chain of custody
  • Threat hunting across an estate you already manage
  • Overflow assessment and reporting work when your team is at capacity
  • Named expert engagements, including evidence for proceedings

How it works

  • You stay the prime. We contract to you, not to your client
  • White labelled deliverables, or co-branded if you prefer
  • A signed master agreement once, then a short scope per job
  • Wholesale rates that leave you margin on the engagement
Talk about capacity →

How we work

Findings you can act on

Every finding comes with how we found it and what to do about it, written for the person who has to fix it.

No lock in

We document as we go and hand it over. If you leave, your team keeps everything we built and knows how it works.

Properly contracted

A master agreement and a written scope before work starts. Professional indemnity and cyber liability cover, certificate of currency on request.

One person, not a queue

You deal with the practitioner doing the work. Nothing is handed to a first level desk that has to escalate it back.

We work to

ASD Essential EightISO 27001NIST CSFNIST 800-61SOC 2PCI DSSOWASP Top 10CIS BenchmarksMITRE ATT&CKPrivacy Act 1988Notifiable Data Breaches

Free tools, open to everyone

We build monitoring tools and give them away. They run the same checks we run for clients, and they are how most people meet us.

DNS Canary

DNS change monitoring and an A to F domain health grade.

SSL Sentinel

Certificate expiry, chain and protocol monitoring.

Email Security

Deep SPF, DKIM, DMARC, MTA-STS and BIMI analysis.

DNS Map

Subdomain discovery across certificate and passive DNS sources.

Not sure which of the three you need?

Tell us what you are trying to protect and we will tell you where to start, including when the answer is that you do not need us yet.

Book a scoping call →