Products

Cyber Capability Catalogue

Five products for endpoint assurance, fleet governance, remediation planning, network assurance and governed AI. Each product states its current capability and limits plainly.

Australian ownedLocal controlRepeatable evidence2026 catalogue

One-page catalogue

2026 product summary

This compact view is designed to print on one A4 page. Open the detailed catalogue below for more information.

PROD_01 | Detect

NebulE8

Detect-only Essential Eight endpoint assessment with evidence, maturity scoring and audit-ready outputs.

Best fit: baseline assessment, GRC evidence and single-site assurance.

PROD_02 | Manage

FederE8

Self-hosted fleet audit orchestration using mTLS agents, API access, a dashboard and tenant separation.

Best fit: enterprise, government, distributed and managed estates.

PROD_03 | Plan

RemedE8

Risk-ranked remediation plans generated from assessment findings in dry-run and simulation mode.

Current: no public claim of live production apply.

PROD_04 | Network

ACR

Local-first network discovery, modelling, intent comparison and controlled change planning.

Current: fixture-backed Cisco IOS XE demonstration.

PROD_05 | AI

Project Thalamus

Governed LLM memory and learning middleware with human approval before memory is written.

Best fit: research and controlled AI deployments.

Rutledge Consulting Services Pty Ltd | Australian-owned | ABN 46 670 714 888

enquiry@rutledgeconsulting.com.au0422 983 493
View full catalogue

Cyber compliance platform

NebulE8 Security Suite

Three products take an organisation from a representative Essential Eight assessment to fleet visibility and remediation planning.

PROD_01 | Endpoint Assurance

NebulE8

See your Essential Eight posture with evidence behind every result.

What it does

Collects read-only endpoint evidence and maps it to Essential Eight controls, maturity scoring and audit-ready outputs.

Where it runs

Windows and Ubuntu. Live read-only assessment or offline simulation. No host hardening or configuration changes.

ML1 | ML2 | ML3JSONHTMLCSVOSCAL
Detect-only assessment
Single-site assuranceView product
PROD_02 | Enterprise Governance

FederE8

Run the same evidence-based assessment across multi-site fleets.

What it does

Coordinates fleet audits through mTLS agents, API access, a dashboard, scheduled checks and tenant separation.

Where it runs

A self-hosted control plane for Windows and Ubuntu estates, keeping evidence and control inside the customer environment.

mTLSMulti-tenantAPIDashboard
Fleet audits: detect-only
Enterprise fleet assuranceView product
PROD_03 | Remediation Planning

RemedE8

Turn assessment findings into a plan that can be reviewed before changes are made.

What it does

Builds control-scoped, risk-ranked Essential Eight remediation plans with human-readable and structured outputs.

Current limit

Dry-run and simulation are the current public position. Live production apply is not presented as enabled, and higher-risk actions can be marked for manual handling.

Dry-runRisk ceilingWindowsUbuntu
Apply status: simulation only
Governed change planningEnquire

Specialist products

Network assurance and governed AI

These products apply the same principle outside endpoint assurance: collect evidence, state the operating boundary and keep change under control.

PROD_04 | Network Assurance

ACR

Automatic Compliance and Remediation. A local-first network assurance concept that brings discovery, modelling, policy comparison and change planning into one workflow.

  • Collect scoped, read-only SSH and API evidence with provenance and clear failure states.
  • Build canonical inventory plus physical, L2, L3 and security views without inventing links.
  • Compare observed state with declared intent and versioned policy rules.
  • Preview plans, approvals, checks and rollback before any future write action.
Current status: fixture-backed Cisco IOS XE demonstration. Live router collection and device writes are not presented as production features.
PROD_05 | Governed AI

Project Thalamus

A middleware layer for LLM deployments focused on approved memory, local operation, uncertainty and controlled learning.

  • Memory is not written until a person approves it.
  • Repeated questions can be served from associative memory instead of always calling the backing model.
  • Memory can survive restarts and run on one machine, including offline with a local model.
  • Autonomous actions can be written to a hash-chained, optionally signed log.
Research status: benchmark results and assumptions are stated separately. The project is not represented as a security control.

Framework coverage

Evidence mapping, not certification

Essential Eight is the primary complete control set represented by the suite. Other frameworks are presented as mappings to technically verifiable controls, not as certification claims.

Essential EightISMISO 27001 mappingSOC 2 mappingNIST CSF 2.0 mappingNIST 800-171 mapping

Contact

Discuss a product or pilot

Tell us which environment you want to assess, what evidence you need and whether you are starting with one endpoint or a larger fleet.