This overview describes E1's security posture for Australian Defence tender information. Control positions are current assessments for review, not audited statements. PROTECTED information is not yet formally supported. Prepared July 2026. Commercial in confidence.
E1 supports the markings that commercial Defence tender packages typically carry. The boundary below sets out what may and may not be placed on the platform.
| Information marking | E1 position |
|---|---|
| OFFICIAL | ✓Supported |
| OFFICIAL: Sensitive | ✓Supported, subject to customer and project requirements |
| PROTECTED | ✓Not yet formally supported; E1 is approaching the required support |
| SECRET | ✗Not supported |
| TOP SECRET | ✗Not supported |
E1 applies security controls across the platform. Access to each tender remains controlled by the customer and the permissions they assign.
Access stays with the customer. Access to each tender is invite-only and strictly need-to-know. Customers assign and revoke permissions themselves, and every action is captured in a full audit trail, so you always know who has seen what.
Strong authentication. Every user signs in with multifactor authentication, and access is limited to trusted, managed devices rather than passwords alone.
Encryption in transit and at rest. Tender documents are encrypted throughout their lifecycle using strong, current algorithms, with managed and access-restricted keys.
Australian data residency. E1 stores Australian document data in AWS's Sydney region, and these documents are not sent to overseas processors. Customers should confirm any additional residency, sovereignty or personnel-access requirements in their contract.
Not used in public AI. Defence tender documents are never used to train or run public AI models.
Restricted, monitored administration. Administrative access is least-privilege, separated from everyday accounts and granted only when needed. The platform is continuously monitored, with security event detection and alerting.
Patched and recoverable. Vulnerabilities are tracked and patched across the platform. Backups are immutable and replicated to a separate, isolated store, with recovery tested on a defined cycle.
Audited and governed. Access and activity are captured in full audit trails, under an information security management system aligned with ISO/IEC 27001.
The sections that follow set these controls out in depth, including E1's strong self-assessed alignment with the ACSC Essential Eight.
Australian Government information markings indicate the potential impact if information is compromised. As the sensitivity increases, the expected security maturity of the systems handling that information also increases. The Essential Eight maturity model provides a practical benchmark for this progression, with higher maturity levels designed to withstand more capable and persistent adversaries.
| Essential Eight benchmark | Information type | Security expectation |
|---|---|---|
| Maturity Level 1 | OFFICIAL | Protects against common, opportunistic attacks using publicly available tools and known vulnerabilities. |
| Maturity Level 2 | OFFICIAL: Sensitive | Protects against more focused adversaries that invest additional time, use targeted phishing and attempt to bypass common security controls. |
| Maturity Level 3 | PROTECTED | Protects against adaptive, targeted adversaries using stronger techniques. Supported by applicable ISM controls, formal governance and independent assurance. |
The classification does not operate as a standalone label. It indicates the level of harm that could result from compromise, and therefore informs the strength of security controls expected around the information. As information moves from OFFICIAL to OFFICIAL: Sensitive and then PROTECTED, organisations are expected to apply progressively stronger controls across areas such as:
The Essential Eight therefore provides a clear way to understand how security expectations increase alongside the sensitivity of Defence information.
A benchmark, not a universal rule. This mapping is a useful guide, but the controls actually required are determined by the PSPF, the ISM, Defence requirements, the contract and the system's risk assessment. The Essential Eight covers only eight mitigation strategies; the ISM contains many more, as the next page sets out.
Meeting the Essential Eight is necessary but not sufficient. Each marking carries handling obligations under the Protective Security Policy Framework and other frameworks that go well beyond the eight mitigation strategies.
Each level inherits all controls of the level below it. Contract or project-specific instructions may impose additional residency, personnel, clearance or handling requirements, which remain the customer's responsibility to confirm.
E1 already meets or substantially meets most Maturity Level 3 requirements. The assessment below sets out each strategy across all three maturity levels, with E1's self-assessed status for every requirement.
E1 is not yet formally certified or independently assessed against the Essential Eight. The positions shown are E1's own self-assessment, and will be confirmed by evidence and, where required, independent assessment.
E1's self-assessed status at each maturity level, strategy by strategy. This is E1's own gap analysis, not a formal or independent assessment.
| E8 strategy area | ML1 | ML2 | ML3 |
|---|---|---|---|
| Patch applications | ✓ | ✓ | ✓ |
| Multi-factor authentication | ✓ | ✓ | ✓ |
| Restrict administrative privileges | ✓ | ✓ | ✓ |
| Application control | ✓ | ✓ | ✓ |
| Restrict Office macros | ✓ | ✓ | ✓ |
| User application hardening | ✓ | ✓ | ✓ |
| Patch operating systems | ✓ | ✓ | ✓ |
| Regular backups | ✓ | ✓ | ✓ |
E1's controls already extend significantly beyond the requirements normally associated with OFFICIAL: Sensitive information. Most of the technical foundation for Essential Eight Maturity Level 3 is in place.
The remaining work is concentrated in evidence, formalisation and several specific control refinements, rather than the absence of fundamental security capabilities.
Reaching and evidencing Essential Eight Maturity Level 3 is an important part of supporting PROTECTED information, but it is not the only requirement. E1 must also determine and implement the applicable ISM controls, prepare the required security documentation and complete an independent IRAP assessment.
Informing a risk assessment. E1 does not hold IRAP certification. Customers should review their own requirements and use this document to inform a risk assessment before uploading PROTECTED information. E1 is close on the Essential Eight and has much of the underlying platform capability; formal PROTECTED support would still involve independent assessment.
E1 secures the platform. Customers remain responsible for how they classify, share and manage their own information.
Where a tender, contract or security instruction expressly requires DISP membership, an accredited system, Australian-based personnel, security clearances or another specific control, customers should confirm those requirements with their Defence contract manager or legal adviser before uploading the information.
E1 supports OFFICIAL: Sensitive today. Its platform already implements strong security controls, including near-complete alignment with Essential Eight Maturity Level 3. This provides a substantial foundation for future PROTECTED support, although further evidence, ISM alignment and independent assessment are still required.
This statement describes E1's standard platform scope. It is not a determination that every Defence project or contract permits the use of E1.