The Trust Practice
How the work is done.
Digital trust advisory is only useful if the method is sound and the findings are grounded in evidence. This page explains how The Trust Practice structures its work.
Digital trust is visible — but rarely managed as a whole
Organisations accumulate digital presence over time: domains from prior campaigns, DNS delegations made by teams that have since changed, email authentication configured years ago and never reviewed, certificates renewed automatically without anyone checking what they protect. The signals these systems emit are always on. They are always observable.
The problem is not that organisations are indifferent to digital trust. It is that they rarely have a structured way to see it, interpret it, and govern it. Technical teams may see fragments. Leadership teams may not see it at all. And the gap between observation and action — especially when that action requires a governance decision — is where exposure accumulates.
The Trust Practice exists to close that gap. Not by finding vulnerabilities to exploit, but by making visible signals legible and connecting them to practical decisions.
Assessment, interpretation, action, governance
Every engagement follows the same underlying logic, regardless of scope.
Agree what surfaces are in scope. Capture known concerns, planned changes, and the organisational context that shapes how findings will be received.
Collect observable signal evidence across agreed surfaces. No active exploitation, no internal access required. All assessment is conducted from publicly observable data.
Translate findings from technical observations into operational and governance terms. Evidence is compiled and prioritised. Findings are connected to real risk, not abstract ratings.
Deliver clear, prioritised actions with ownership guidance. The output is designed to be usable — not a report that sits in a drawer.
A note on evidence
The Trust Practice only reports what is observable. Findings are evidence-backed. Recommendations are prioritised by real-world impact, not theoretical risk scores. If something cannot be evidenced from publicly observable signals, it is not reported as a finding.
TrustSurface — the structure behind the work
The work is structured by the TrustSurface framework — a public framework for understanding the observable signals that shape digital trust. TrustSurface defines the domains of assessment, the signal types within each, and the interpretation logic that connects observations to governance implications.
TrustSurface is not the front door of The Trust Practice. It is the method behind it. Buyers do not need to understand the framework to engage with the practice. But they may want to know that the work is structured — not improvised — and that the framework is public, documented, and independent of any vendor or tooling.
TrustSurface covers six observable domains: Identity, Domains & DNS, Email Integrity, Digital Services, Infrastructure & Platforms, and Third-Party Ecosystem. Advisory engagements may cover all six domains or focus on a defined subset, depending on the scope agreed.
Diagnostic tools that support the work
Assessment is supported by two instruments developed alongside the practice.
ThreatScope Check is a public-facing diagnostic instrument for reviewing domain trust signals. The .auDo Observatory is a private signal observability system for .au domain baseline telemetry. Both inform advisory work without replacing the interpretation and governance work that is the core of each engagement.
What this work is — and is not
What this is
- A practical advisory service for making digital trust visible and manageable
- Assessment of observable, public-facing trust signals
- Interpretation that connects findings to operational and governance implications
- Prioritised, evidence-backed recommendations
- Plain-language output designed for non-technical audiences
What this is not
- A penetration test or active security assessment
- A managed security service or SOC function
- An audit opinion or compliance certification
- A claim that the organisation is secure
- Implementation or managed remediation delivery
Questions about how the practice works
No. All assessment work is conducted against publicly observable signals. No internal access, credentials, or administrative access to systems is required or requested. The review is conducted from the outside — the same vantage point as any external observer.
No. The Trust Practice does not conduct penetration testing, active exploitation, or formal compliance audits. It does not produce an audit opinion or certify compliance with any framework or regulation. It assesses observable trust signals and provides governance-oriented interpretation and recommendations.
If an organisation needs a formal penetration test or a compliance audit, that is a different engagement with a different kind of provider.
It depends on the service. An Email Trust Review typically completes within one to two weeks of scope confirmation. A Digital Trust Snapshot typically takes two to three weeks. A Domain Governance Review depends on the size of the domain portfolio. An Executive Trust Briefing is scoped to the session format and preparation needed.
All timelines are agreed upfront at scope confirmation. No engagement begins without a clear scope and delivery expectation.
No. The Trust Practice is advisory, not implementation. Findings and recommendations are designed to equip internal teams — or to be handed to an implementation partner — with a clear, prioritised action plan. The practice can provide advisory support during a remediation program through Digital Trust Advisory, but does not execute technical changes on behalf of clients.
More questions? The FAQ page covers scope, fit, and how engagements work in more detail.
Ready to see how this applies to your organisation?
A short consultation is the best way to confirm fit and identify the right entry point.