Bluebird bluebird Fenceline
Authorised · Read and write-test · Analysed onshore · Nothing leaves Australia
Outside-in review · Daily watch · Authorised write-test

Know what a stranger can reach on your public sites, and what they could change. Every morning.

In June an AI crawler found an old Services Australia statistics portal, was refused, kept going, took files that were not yet public and wrote files to the server. Nobody in the agency saw it happen. The agency found out in September, from an email to its public inbox. Fenceline is the answer to the question every accountable authority has been asked since: could that happen here.

The incident: reported by Cyber Daily, 24 September 2026, "Medicare and at least three other government systems were compromised by an AI agent in June". Read the reporting.

1,266
captures in our own site's review, run by us on ourselves
474
findings, each with evidence, from the same run
0
bytes of your estate sent offshore. Ever.
Your public estateIllustration
THE FENCELINE a stranger reachable: draft-quarterly.xlsx write surface: /contact who would know?
walk: read-only, announced, rate limitedwatch: daily diff
Morning check · 6 propertiesIllustration
New reachable item, not in the publication register
stats.agency.example/reports/2026/draft-quarterly.xlsx · first seen 05:40 · classified: draft, internal markings
New host in your zone
legacy-portal.agency.example · certificate issued yesterday · not in the property register
Directory listing appeared
data.agency.example/uploads/ · 212 items now visible · was 403 yesterday
No change
4,812 known items unchanged · 0 new write surfaces · next deep sample Sunday
Confirmed by a Bluebird analyst before your contact is called. Domains shown are placeholders.

What is reachable

Files on your public sites that were never meant to be published, and the internal names and paths they give away.

What accepts a write

Public-facing forms, upload points and interfaces that would take content from a stranger, proved with a canary we write and restore.

Who would know

Whether anyone would be alerted if either of those happened, or whether you would find out by email.

The review

What we do

Four checks, run the way a stranger or a crawler would see your sites, with a letter of authority in hand and our name on the door.

01

Inventory

Every internet-facing web property the agency owns, including the legacy sites that have fallen off the register. The June incident was an old site; ASD's posture reports have called legacy IT an enduring risk for years.

02

Reachable content

Everything obtainable without a credential is read and classified against what the agency says is public: its website, publication scheme, FOI disclosure log and open data listings. Reachable but unlisted is a finding.

03

Write surfaces

Forms, upload points and interfaces on public sites that would accept an unauthenticated write, found by inspection and proved by the write-test, then restored.

04

Detection

A logging and alerting review, or a short tabletop including an AI-agent scenario, on whether the agency would notice an unauthorised read or write on those sites.

Fenceline Watch

The daily check

The review is how an agency starts. The daily check is why it stays. Every morning Fenceline walks each property again and compares it with yesterday, so a newly reachable file, a new host or a new write surface reaches you the next day rather than in next year's review.

  • What it watches. Every property in your register. Sitemaps and listings are compared daily, known items are checked with light conditional requests, and new hosts in your zones are picked up from certificates and DNS. A deeper sample runs weekly.
  • What triggers an alert. A reachable item not in the baseline and not in your publication register. A new host. A new interface that accepts input. A directory listing where there was none. A change to an item already marked sensitive. Everything else goes in the weekly digest.
  • Who gets it. A person at the Bluebird service desk first, with the evidence. They confirm it is real, then call your contact. You get a phone call, not an automated email.
  • What it is not. Not intrusion detection, and it never sees inside your network. It sees what a stranger can reach, which is exactly the thing the June incident showed nobody was watching.
Week 6 · digest summaryIllustration
34 morning checks completed
6 properties · 0 missed days · all alerts confirmed by an analyst before the call
2 alerts this quarter
One new host (a marketing microsite, expected). One new file (a media release, listed).
Quarterly full re-walk
Re-reads every property against the current register, so drift never compounds.
Annual assurance statement
One page for the audit committee, signed, tabled.
Watch is included in the subscription at every level.
Evidence, not assertion

We run it on ourselves first

In September we pointed Fenceline at our own site, bluebirdadvisory.com.au. The numbers below are from that run, 30 September 2026. We publish them because the method is the argument.

1,266

captures in the full walk, each hashed as evidence.

474

findings, classified and mapped to the ISM and the Essential Eight.

12

API-exposure findings the previous review had missed: the media library endpoint listing records without a credential.

Refused

the write-test canary. Our own public forms correctly rejected a scripted write. The proof goes both ways.

Method

How it runs

Written authorisation from the accountable authority, scoped by domain list. Our crawler identifies itself, runs from fixed Australian addresses you whitelist, is rate limited and read-only. No exploitation, no credential attempts. The walk is read-only; the write-test is a separate, authorised step described below. Every document is analysed on Australian infrastructure operated by us.

1

Letter

The accountable authority signs the scope: domains, dates, methods, contacts. Nothing runs without it.

2

Whitelist

You add our fixed addresses to your web application firewall. Our requests carry our name and a contact.

3

Walk

Read-only, rate limited, inside the allowlist. Every item captured with a hash as evidence.

4

Classify onshore

Each item is judged by one locally hosted model and checked by a second. Where they disagree, a person decides. Every classification is screened and grounded by the AxoQuant Governor, AxoQuant's control layer, before it reaches the report: an answer that cannot cite its source is refused. A third pass re-samples items classified public, because the failure that matters is a non-public file marked public.

5

Report

Findings mapped to the ISM, the Essential Eight and PSPF Policy 10, with a list the web team can act on the same day.

The write-test

The question the read cannot answer

A read-only review says what a stranger can reach. It does not say whether a stranger can change your site. The write-test answers that. On your authorisation we write a canary to each form, upload point and interface, prove it landed, restore it, and prove the restoration. The write and the restore both go in the report with evidence.

  • What we write. A marked canary carrying our identifier and a timestamp, on the named surfaces only. Nothing destructive, nothing personal, nothing left behind.
  • What we prove. That the write landed, read back and logged. Then that the restore landed, read back and logged again. A surface that accepts a write is a finding; a restore that fails is an incident, handled before you read about it.
  • Who authorises it. The accountable authority signs the write-test into the letter, with the surfaces named and the restore plan attached. Without that, we do not write.
Write-test · /contact/uploadIllustration
Canary written
fenceline-canary-8f3c1d2e · 05:40 · read back and logged
Landed
The write was accepted: this surface takes content from an unauthenticated stranger.
Restored
Original state read back and verified · evidence captured
Finding
Open write surface, with the proof it was open and the proof it was restored.
Every write is authorised, named, and restored. Domains shown are placeholders.
Levels

One subscription, three levels

The read, the daily watch and the write-test are bundled at every level. Your level is whichever you hit first, the property count or the page count. Ask for the service sheet for pricing.

Essential

For small agencies and single-portfolio bodies

  • Properties 1 to 5
  • Included pages 100,000
  • Write surfaces tested 20
  • Fenceline Watch included
Ask about Essential

Department

For mid-size agencies and multi-brand portfolios

  • Properties 6 to 15
  • Included pages 300,000
  • Write surfaces tested 60
  • Executive briefing included
Ask about Department

Estate

For large departments and whole-of-portfolio coverage

  • Properties 16 to 40
  • Included pages 1,000,000
  • Write surfaces tested 200
  • Portfolio coordination included
Ask about Estate

Above the included pages, overage is pro-rated and never a cliff: per additional 100,000 pages, and per additional write surface, quoted on the service sheet. Rapid Fenceline is the ten-business-day crisis review, read-only, for when the question has already been asked upstairs.

Deliverables

What you receive

  • ✓Exposure register. Every property and every reachable item, classified, with evidence.
  • ✓Findings report mapped to the ISM, the Essential Eight and PSPF Policy 10.
  • ✓Remediation list the web team can act on the same day, as a spreadsheet or a ticket import.
  • ✓Executive brief. One page for the secretary or board.
  • ✓Write-test report. Every write surface tested with a canary: the write, the proof it landed, the restore, and the proof of restoration.
  • ✓Fenceline Watch. The daily check, a quarterly full re-walk, an exposure dashboard, re-testing of remediated items, and an annual assurance statement for the audit committee.
Positioning

Where it sits

Fenceline answers the question the others leave open: what can a stranger reach, and would you know.

ASD CHIPs

Configuration hygiene

Free for Commonwealth entities. Checks settings and known weaknesses. Does not read content, and is not available to state, territory, university or local government bodies.

Penetration test

Patches and TLS

Finds what is exploitable. Says nothing about whether a document should be public, and stops the day the report lands.

Attack surface tool

Discovers and scans

Finds assets and lists exposures. Does not judge what should be public, does not watch with a person who calls, and does not prove a write surface is locked.

Bluebird Fenceline

Reachable, writable, proved

Reads and judges every reachable item against what you say is public, writes a canary to each write surface and restores it, tests whether you would notice, then checks again every morning.

The difference

What we answer that a scanner does not

A vulnerability scanner, or a crowd of testers, finds how a stranger could get in. Fenceline answers what a stranger can already see, judges what should be public, and proves nothing was left open.

Reads and judges content

A scanner finds flaws. It never asks whether the file should have been published. We read every reachable item against your publication scheme and flag what was never meant to be public.

Proves, not infers

A scanner infers a surface is locked because it found no exploit. We write a marked canary, prove it landed, restore it, and prove the restoration.

Nothing leaves Australia

Crowdsourced testing sends your estate to a global crowd of researchers. Fenceline keeps every byte onshore, analysed on Australian infrastructure we operate.

Procurement

How to buy

Fenceline is bought through Bluebird Advisory's Commonwealth panel position. Bluebird is a panel supplier and DISP member with Australian delivery staff, based in Canberra and Melbourne. The sequence is standard and the letter does the work.

1. Scoping call

We count your properties and pages, name the write surfaces, and tell you your level the same day.

2. Letter of authority

Your accountable authority signs the scope: domains, dates, methods, contacts. The write-test is a separate clause, surfaces named, restore plan attached. Template on request.

3. Whitelist and walk

You add our fixed Australian addresses to your WAF. The walk runs read-only inside the allowlist.

4. Report

Findings, register, remediation list and executive brief. Rapid Fenceline delivers in ten business days when the question has already been asked upstairs.

Platform and hosting

Analysed onshore, on the AxoQuant sovereign stack

Locally hosted models, grounded output

Fenceline runs on deterministic rules, and a named model that reads images only under a clause in the letter. Every classification is checked by a second, independent model, screened and grounded by the AxoQuant Governor, then signed off by a person. No offshore processing, ever. Nothing about your sites touches an overseas AI service.

Findings handled as sensitive

Findings are held as OFFICIAL: Sensitive at minimum, in an engagement-scoped store, with ISM-aligned handling, and destroyed on engagement close unless you ask us to keep them.

Delivered by Bluebird Advisory

A Commonwealth panel supplier and DISP member with Australian delivery staff and a service desk, based in Canberra and Melbourne. Available to Commonwealth non-corporate and corporate entities, state and territory agencies, universities and local government. bluebirdadvisory.com.au

Book a Fenceline Review

One subscription bundles the review, the daily watch and the write-test, billed annually on a three-year term. Three levels, set by whichever you hit first, the property count or the page count. A ten-business-day Rapid option is available when the question has already been asked upstairs. Ask for the service sheet or book a scoping call.

Request the service sheet Book a review