Yuma IT builds software for field work, assurance and private networking. Beside RangerOS and the rest of the country line, five products now have public sites you can read without a sales call.
Each one solves a concrete job. None of them ask you to buy a platform first.
Kelpie
Kelpie is incident response and SOC case management. Triage, investigation, governed response, evidence and closure sit on one operational record.
It is built for focused SOC and incident-response teams that need response data to stay in their own infrastructure. Cases move through ownership, hand-offs and SLAs. Playbooks cover common SOC scenarios. Response actions such as blocking or isolating a device need human approval, with a second admin where required, and requests expire after fifteen minutes.
Deploy it with Docker Compose or your own containers. Customer-managed PostgreSQL and Redis. Built and maintained by Yuma IT in Canberra. We are a Supply Nation Certified Supplier.
GRiCk
GRiCk is Australian enterprise GRC and continuous assurance software. AI agents, developers and security tools submit evidence where the work already happens, through MCP and scoped APIs.
Evidence stays current, expiring, expired, invalid or under review. One record can support several controls, risks, policies or ATOs with clear provenance. Frameworks on the site include ASD ISM, PSPF, Essential Eight and IRAP-oriented ATO workflows.
You can buy direct, work with a trusted MSP, or use a Microsoft Azure marketplace path. An AWS Marketplace listing is not open yet; AWS-hosted delivery is available under a statement of work. GRiCk is built by Yuma IT, a Supply Nation certified business, and written by cleared Australian nationals.
DingoDocs
DingoDocs is MCP-connected penetration-testing and assessment delivery. The agent tests. Findings, evidence and reports stay on one engagement record.
Scope moves through capture, review, report and verify. Scanner results from tools such as Nuclei, Nmap, Nessus, OpenVAS, ZAP and Burp can be ingested. Findings stay draft until a person publishes. Reports come out as PDF, DOCX, HTML or Markdown, including white-label options for client delivery.
Contact Yuma IT for commercial and AWS Marketplace procurement.
AttestHub
AttestHub is independent technology assurance. Governed security reviews of cloud, mobile, software and SaaS, AI and cybersecurity programs, with scope-bound outcomes you can verify.
A request becomes a versioned scope and itemised quote, then a shared evidence workspace, then a deliverable another assessor has reviewed. The catalogue covers fifteen defined assessments across six practice areas. A public attestation register lets anyone check a verification ID, validity window, signature and revocation status without an account.
There is a free cyber snapshot: eighteen plain-English questions and a thirty-minute human review call. Paid work starts only after an approved scope and price.
BlakTail
BlakTail is secure, open, self-hosted private networking in Australia. It links work computers, phones and offices into one private network over the internet so staff can open office systems from home, the field or another site.
There is no BlakTail cloud. It runs on computers you control. Staff lists, access rules and connection records stay with you. Device keys are generated on-device and never sent off-device.
You can self-host for free, run it in your AWS account through AWS Marketplace, or pay for priority support from the builders. Self-host instructions are public.
Where to start
Pick the job you have this quarter. Incident response points to Kelpie. Continuous assurance and ATO evidence point to GRiCk. Assessment delivery with MCP points to DingoDocs. Independent review and a public attestation trail point to AttestHub. Private networking without a vendor cloud points to BlakTail.
Talk with us if you want a walkthrough of any of them.
