This overview describes E1's security posture for Australian Defence tender information. Control positions are current assessments for review, not audited statements. PROTECTED information is not yet formally supported. Prepared July 2026. Commercial in confidence.
E1 supports the markings that commercial Defence tender packages typically carry. The boundary below sets out what may and may not be placed on the platform.
| Information marking | E1 position |
|---|---|
| OFFICIAL | ✓Supported |
| OFFICIAL: Sensitive | ✓Supported, subject to customer and project requirements |
| PROTECTED | ✓Not yet universally supported; Subject to project requirements and risk assessment |
| SECRET | ✗Not supported |
| TOP SECRET | ✗Not supported |
E1 applies security controls across the platform. Access to each tender remains controlled by the customer and the permissions they assign.
Access stays with the customer. Access to each tender is invite-only and strictly need-to-know. Customers assign and revoke permissions themselves, and every action is captured in a full audit trail, so you always know who has seen what.
Strong authentication. Every user signs in with multifactor authentication, and access is limited to trusted, managed devices rather than passwords alone.
Encryption in transit and at rest. Tender documents are encrypted throughout their lifecycle using strong, current algorithms, with managed and access-restricted keys.
Australian data residency. E1 stores Australian document data in AWS's Sydney region, and these documents are not sent to overseas processors. Customers should confirm any additional residency, sovereignty or personnel-access requirements in their contract.
Not used in public AI. Defence tender documents are never used to train or run public AI models.
Restricted, monitored administration. Administrative access is least-privilege, separated from everyday accounts and granted only when needed. The platform is continuously monitored, with security event detection and alerting.
Patched and recoverable. Vulnerabilities are tracked and patched across the platform. Backups are immutable and replicated to a separate, isolated store, with recovery tested on a defined cycle.
Audited and governed. Access and activity are captured in full audit trails, under an information security management system aligned with ISO/IEC 27001.
The sections that follow set these controls out in depth, including E1's strong self-assessed alignment with the ACSC Essential Eight.
Australian Government information markings indicate the potential harm that could result if information is compromised. As sensitivity increases, the systems handling that information will generally require stronger security controls, governance and assurance.
Essential Eight maturity levels do not formally map to information classifications as shown below. However, Australian Government policies, Defence requirements and contracts commonly use Essential Eight maturity assessments as a benchmark for cyber security. This provides a useful way to understand how closely an organisation’s security posture aligns with the increasing protection expected for more sensitive information.
| E8 benchmark | Information type | Security expectation |
|---|---|---|
| Maturity Level 1 | OFFICIAL | Establishes foundational protections against common and opportunistic attacks. It reduces the likelihood that information will be exposed through unpatched systems, weak authentication, malicious documents, unsupported applications or basic ransomware. |
| Maturity Level 2 | OFFICIAL: Sensitive | Strengthens controls against adversaries that deliberately target the organisation, use convincing phishing, steal credentials or attempt to bypass common security controls. It introduces tighter administrative access, stronger application control, faster remediation and greater resistance to account and endpoint compromise. |
| Maturity Level 3 | PROTECTED | Provides stronger resistance to adaptive and persistent adversaries that change techniques when initial attacks fail. It reduces reliance on standing privileges, extends preventative controls across more systems and requires more rigorous enforcement, making it harder for an attacker to establish access, move through the environment or reach sensitive information. |
For PROTECTED information types, Essential Eight is only one part of the broader security framework. What is actually required will be determined by the contract requirements. E1 has assessed what is generally required to support PROTECTED contract types and our assessment is outlined on pages 10-11.
E1's self-assessed status at each maturity level, strategy by strategy. This is E1's own gap analysis, not a formal or independent assessment.
| E8 strategy area | ML1 | ML2 | ML3 |
|---|---|---|---|
| Patch applications | ✓ | ✓ | ✓ |
| Multi-factor authentication | ✓ | ✓ | ✓ |
| Restrict administrative privileges | ✓ | ✓ | ✓ |
| Application control | ✓ | ✓ | ✓ |
| Restrict Office macros | ✓ | ✓ | ✓ |
| User application hardening | ✓ | ✓ | ✓ |
| Patch operating systems | ✓ | ✓ | ✓ |
| Regular backups | ✓ | ✓ | ✓ |
E1's controls already extend significantly beyond the requirements normally associated with OFFICIAL: Sensitive information. Most of the technical foundation for Essential Eight Maturity Level 3 is in place.
The remaining work is concentrated in evidence, formalisation and several specific control refinements, rather than the absence of fundamental security capabilities.
E1 already meets or substantially meets most Maturity Level 2 and 3 requirements. The assessment below indicates the status of E1's self-assessed status for every requirement of Essential Eight across all maturity levels.
E1 is not yet formally certified or independently assessed against the Essential Eight. The positions shown are E1's own self-assessment, and will be confirmed by evidence and, where required, independent assessment.
Reaching and evidencing Essential Eight Maturity Level 3 is an important part of supporting PROTECTED information, but it is not the only requirement. E1 must also determine and implement the applicable ISM controls, prepare the required security documentation and complete an independent IRAP assessment.
Informing a risk assessment. E1 does not hold IRAP certification. Customers should review their own requirements and use this document to inform a risk assessment before uploading PROTECTED information. E1 is close on the Essential Eight and has much of the underlying platform capability; formal PROTECTED support would still involve independent assessment.
E1 secures the platform. Customers remain responsible for how they classify, share and manage their own information.
Where a tender, contract or security instruction expressly requires DISP membership, an accredited system, Australian-based personnel, security clearances or another specific control, customers should confirm those requirements with their Defence contract manager or legal adviser before uploading the information.
E1 supports OFFICIAL: Sensitive today. Its platform already implements strong security controls, including near-complete alignment with Essential Eight Maturity Level 3. This provides a substantial foundation for future PROTECTED support, although further evidence, ISM alignment and independent assessment are still required.
This statement describes E1's standard platform scope. It is not a determination that every Defence project or contract permits the use of E1.