Bluebird Bluebird Fenceline
Public web exposure review for government agencies How it runs The write-test Platform and hosting Book a review
Authorised · Read and write-test · Analysed onshore · Nothing leaves Australia
Outside-in review · Daily watch · Authorised write-test

Know what a stranger can reach on your public sites, and what they could change. Every morning.

In June an AI crawler found an old Services Australia statistics portal, was refused, kept going, took files that were not yet public and wrote files to the server. Nobody in the agency saw it happen. The agency found out in September, from an email to its public inbox. Fenceline is the answer to the question every accountable authority has been asked since: could that happen here.

What is reachable

Files on your public sites that were never meant to be published, and the internal names and paths they give away.

What accepts a write

Public-facing forms, upload points and interfaces that would take content from a stranger, proved with a canary we write and restore.

Who would know

Whether anyone would be alerted if either of those happened, or whether you would find out by email.

The review

What we do

Four checks, run the way a stranger or a crawler would see your sites, with a letter of authority in hand and our name on the door.

01

Inventory

Every internet-facing web property the agency owns, including the legacy sites that have fallen off the register. The June incident was an old site; ASD's posture reports have called legacy IT an enduring risk for years.

02

Reachable content

Everything obtainable without a credential is read and classified against what the agency says is public: its website, publication scheme, FOI disclosure log and open data listings. Reachable but unlisted is a finding.

03

Write surfaces

Forms, upload points and interfaces on public sites that would accept an unauthenticated write, found by inspection and proved by the write-test, then restored.

04

Detection

A logging and alerting review, or a short tabletop including an AI-agent scenario, on whether the agency would notice an unauthorised read or write on those sites.

Fenceline Watch

The daily check

The review is how an agency starts. The daily check is why it stays. Every morning Fenceline walks each property again and compares it with yesterday, so a newly reachable file, a new host or a new write surface reaches you the next day rather than in next year's review.

  • What it watches. Every property in your register. Sitemaps and listings are compared daily, known items are checked with light conditional requests, and new hosts in your zones are picked up from certificates and DNS. A deeper sample runs weekly.
  • What triggers an alert. A reachable item not in the baseline and not in your publication register. A new host. A new interface that accepts input. A directory listing where there was none. A change to an item already marked sensitive. Everything else goes in the weekly digest.
  • Who gets it. A person at the Bluebird service desk first, with the evidence. They confirm it is real, then call your contact. You get a phone call, not an automated email.
  • What it is not. Not intrusion detection, and it never sees inside your network. It sees what a stranger can reach, which is exactly the thing the June incident showed nobody was watching.
Morning check · 6 propertiesIllustration
New reachable item, not in the publication register
stats.agency.example/reports/2026/draft-quarterly.xlsx · first seen 05:40 · classified: draft, internal markings
New host in your zone
legacy-portal.agency.example · certificate issued yesterday · not in the property register
Directory listing appeared
data.agency.example/uploads/ · 212 items now visible · was 403 yesterday
No change
4,812 known items unchanged · 0 new write surfaces · next deep sample Sunday
Confirmed by a Bluebird analyst before your contact is called. Domains shown are placeholders.
Method

How it runs

Written authorisation from the accountable authority, scoped by domain list. Our crawler identifies itself, runs from fixed Australian addresses you whitelist, is rate limited and read-only. No exploitation, no credential attempts. The walk is read-only; the write-test is a separate, authorised step described below. Every document is analysed on Australian infrastructure operated by us.

1

Letter

The accountable authority signs the scope: domains, dates, methods, contacts. Nothing runs without it.

2

Whitelist

You add our fixed addresses to your web application firewall. Our requests carry our name and a contact.

3

Walk

Read-only, rate limited, inside the allowlist. Every item captured with a hash as evidence.

4

Classify onshore

Each item is judged by one locally hosted model and checked by a second. Where they disagree, a person decides. A third pass re-samples items classified public, because the failure that matters is a non-public file marked public.

5

Report

Findings mapped to the ISM, the Essential Eight and PSPF Policy 10, with a list the web team can act on the same day.

The write-test

The question the read cannot answer

A read-only review says what a stranger can reach. It does not say whether a stranger can change your site. The write-test answers that. On your authorisation we write a canary to each form, upload point and interface, prove it landed, restore it, and prove the restoration. The write and the restore both go in the report with evidence.

  • What we write. A marked canary carrying our identifier and a timestamp, on the named surfaces only. Nothing destructive, nothing personal, nothing left behind.
  • What we prove. That the write landed, read back and logged. Then that the restore landed, read back and logged again. A surface that accepts a write is a finding; a restore that fails is an incident, handled before you read about it.
  • Who authorises it. The accountable authority signs the write-test into the letter, with the surfaces named and the restore plan attached. Without that, we do not write.
Write-test · /contact/uploadIllustration
Canary written
fenceline-canary-8f3c1d2e · 05:40 · read back and logged
Landed
The write was accepted: this surface takes content from an unauthenticated stranger.
Restored
Original state read back and verified · evidence captured
Finding
Open write surface, with the proof it was open and the proof it was restored.
Every write is authorised, named, and restored. Domains shown are placeholders.
Deliverables

What you receive

  • ✓Exposure register. Every property and every reachable item, classified, with evidence.
  • ✓Findings report mapped to the ISM, the Essential Eight and PSPF Policy 10.
  • ✓Remediation list the web team can act on the same day, as a spreadsheet or a ticket import.
  • ✓Executive brief. One page for the secretary or board.
  • ✓Fenceline Watch. The daily check, a quarterly full re-walk, an exposure dashboard, a governed question-and-answer layer over your findings, re-testing of remediated items, and an annual assurance statement for the audit committee.
  • ✓Write-test report. Every write surface tested with a canary: the write, the proof it landed, the restore, and the proof of restoration, each with evidence.
  • ✓Rapid option. Report in ten business days when the question has already been asked upstairs.
Positioning

Where it sits

Fenceline answers the question the others leave open: what can a stranger reach, and would you know.

ASD CHIPs

Configuration hygiene

Free for Commonwealth entities. Checks settings and known weaknesses. Does not read content, and is not available to state, territory, university or local government bodies.

Penetration test

Patches and TLS

Finds what is exploitable. Says nothing about whether a document should be public, and stops the day the report lands.

IRAP assessment

Certifies a system

Assesses controls against the ISM for accreditation. A different product for a different question.

Bluebird Fenceline

Reachable, writable, proved

Reads and judges every reachable item against what you say is public, writes a canary to each write surface and restores it, tests whether you would notice, then checks again every morning.

Platform and hosting

Analysed onshore, on the AxoQuant sovereign stack

Locally hosted models

Fenceline runs on deterministic rules, and a named model that reads images only under a clause in the letter. Every classification is checked by a second, independent model before a person signs it off. No offshore processing, ever. Nothing about your sites touches an overseas AI service.

Findings handled as sensitive

Findings are held as OFFICIAL: Sensitive at minimum, in an engagement-scoped store, with ISM-aligned handling, and destroyed on engagement close unless you ask us to keep them.

Delivered by Bluebird Advisory

A Commonwealth panel supplier and DISP member with Australian delivery staff and a service desk. Available to Commonwealth non-corporate and corporate entities, state and territory agencies, universities and local government.

Book a Fenceline Review

One subscription bundles the review, the daily watch and the write-test, billed annually on a three-year term. Three levels, set by whichever you hit first, the property count or the page count: Essential to 5 properties, Department to 15, Estate to 40, each with an included page allowance. A ten-business-day Rapid option is available when the question has already been asked upstairs. Ask for the service sheet or book a scoping call.

Request the service sheet Book a review