QuantGov Cloud

IRAP assessed edge platform

The whole QuantGov Cloud platform is IRAP assessed at the OFFICIAL:Sensitive level — global CDN, WAF, edge functions, application hosting, and an Australian-sovereign AI platform, on Australian infrastructure with immutable audit logging.

Government Compliance
IRAP ASSESSED
🇦🇺
Australian Data Residency
Your data stays in Australia
Melbourne
Primary region
Active
Sydney
Secondary region
Standby
Security Compliance
Web Application Firewall Enabled
DDoS Protection Active
Encryption at Rest AES-256
Audit Logging Enabled
50+ gov clients 99.99% uptime
Contact us
OFFICIAL:​Sensitive
IRAP Assessed
7 years
Audit Retention
AU
Data Sovereignty
600+
Edge Locations

About IRAP

What IRAP assessment means

The Information Security Registered Assessors Program (IRAP) is administered by the Australian Signals Directorate. Independent, ASD-endorsed assessors evaluate a system’s security controls against the Australian Government Information Security Manual (ISM).

An IRAP assessment is not a certification. It produces an independent report on the design and implementation of security controls, which your agency’s authorising officer uses to make a risk-informed decision. QuantGov Cloud has been assessed at the OFFICIAL:Sensitive level.

  • Assessed at OFFICIAL:Sensitive
  • Controls mapped to the ISM
  • Assessment report available on request

Learn more about QuantGov Cloud

ISM-0585

Privileged action logging

Multi-region audit trails with log file validation record every administrative and privileged action across the platform.

ISM-0580

Network traffic logging

Flow logs are captured on every network in the platform and retained alongside audit logs for analysis and investigation.

ISM-1782

Protective DNS

DNS firewall with managed malware and botnet blocklists prevents workloads from resolving known malicious domains.

Sovereign AI

An AI platform with the ISM encoded in

Every prompt runs on AWS Bedrock in Melbourne or Sydney — no third-party providers, no cross-region fallback. We were among the first companies through Australia’s new ISM controls for AI, with agents and workflows built for government from the ground up.

  • Every prompt to AWS Bedrock in Melbourne or Sydney — no third-party providers

  • Guardrail presets named for OFFICIAL, OFFICIAL:Sensitive, and PROTECTED, with AU PII detection

  • An aiEnabled kill switch, model allowlists, and spend caps per org
  • Immutable AI audit log in S3 Object Lock COMPLIANCE mode
  • Current ISM, Essential Eight, WCAG 2.2 AA, and Privacy Principles encoded into every agent

Research Project
2/5 complete
Gather market data
Researcher
Analyse competitors
Researcher
Process findings
Analyst
Generate insights
Analyst
Write report
Writer
3 agents assigned
Processing

The controls behind every assessed service

Audit logging, backups, encryption, access control, and network security apply across the platform — not just hosting.

Immutable audit logging

Multi-region audit trails with log file validation capture every administrative action.

  • 7-year (2,555-day) retention
  • Object Lock in COMPLIANCE mode
  • Network flow logs on every VPC

Automated backups

Daily database backups, plus on-demand database and filesystem backups you control.

  • 30-day automated retention
  • Restore to any environment
  • Multi-AZ database option

Australian data sovereignty

Workloads run in Melbourne with Sydney as the secondary region. Data at rest stays in Australia.

  • Melbourne primary region
  • Sydney secondary region
  • Australian owned and operated

Encryption everywhere

Encryption at rest and in transit for every workload, with managed key infrastructure.

  • AES-256 at rest
  • TLS 1.2 minimum in transit
  • HTTPS-only origins

Access control

Strong authentication and least-privilege access for every account and API client.

  • MFA and passkeys
  • SAML single sign-on
  • Role-based access and scoped API tokens

Network security

Defence in depth from the edge to the container.

  • WAF with OWASP paranoia levels
  • DDoS protection and rate limiting
  • Protective DNS and per-tenant isolation

IRAP assessed platform FAQs

Is QuantCDN IRAP assessed?

Yes. QuantGov Cloud, our government edge platform, has been IRAP assessed at the OFFICIAL:Sensitive level. The assessment covers CDN and edge delivery, WAF, edge functions, application hosting, and supporting infrastructure in the Melbourne and Sydney regions.

Is the whole platform assessed, or just hosting?

The whole platform. The IRAP assessment covers the QuantGov Cloud edge platform end to end — CDN, WAF, edge functions, application hosting, and the supporting infrastructure — at OFFICIAL:Sensitive, not hosting alone.

Is the AI platform sovereign and IRAP assessed?

Yes. Every prompt runs on AWS Bedrock in Melbourne or Sydney with no third-party providers, behind guardrail presets named for OFFICIAL, OFFICIAL:Sensitive, and PROTECTED, with an immutable AI audit log in S3 Object Lock COMPLIANCE mode. We were among the first companies through Australia's new ISM controls for AI.

What does IRAP assessed mean?

IRAP is the Information Security Registered Assessors Program, administered by the Australian Signals Directorate. An ASD-endorsed assessor independently evaluates a system against the Information Security Manual (ISM) and produces an assessment report agencies use to make authorisation decisions.

Is an IRAP assessment the same as certification?

No. IRAP assessments are not certifications or accreditations. The assessment report describes how security controls are designed and implemented; your authorising officer uses it to make a risk-informed decision for your agency.

Where is my data hosted?

Workloads run in the Melbourne region with Sydney as the secondary region. Data at rest stays in Australia, and QuantCDN is Australian owned and operated.

How long are audit logs retained?

Infrastructure audit logs and network flow logs are retained for 7 years (2,555 days), with immutable storage using Object Lock in COMPLIANCE mode. Dashboard activity logs are retained for 12 months.

Which applications can run on IRAP assessed infrastructure?

Drupal, WordPress, and Craft CMS via one-click templates; Laravel, Symfony, and Node.js frameworks such as Next.js and Nuxt; and any custom application packaged as a Docker Compose definition. Every application inherits the same platform controls.

Ready to build on an assessed platform?

Join federal, state, and local government organisations on the IRAP assessed QuantGov Cloud platform.

IRAP assessed at OFFICIAL:Sensitive
Australian data sovereignty
7-year audit retention
24/7 P1 support