Evidence-led ASIC agent software

Trust signals for firms handling ASIC records, annual reviews, signing packs and client evidence.

This page states who the product is for, what it is built to do, the official sources that inform the workflow, and the exact boundary between software readiness and external ASIC approval.

Why firms can rely on Cassandra

Evidence behind the product's claims

Experience
Built around the daily workflow of firms managing company registers, annual reviews, solvency resolutions, ASIC debts, signing packs, and client evidence trails.
Expertise
Every form and register change is checked by the system itself against ASIC's rules — not just by the screen you type into.
Authoritativeness
The system exposes the official-source boundary and keeps ASIC, security, and production-readiness claims traceable.
Trustworthiness
Trust controls are visible: tenancy boundaries, auditability, single sign-on, retention, provider credential handling, and explicit human-review warnings.

Evidence model

What a professional firm can verify

Experience

Built around the daily workflow of firms managing company registers, annual reviews, solvency resolutions, ASIC debts, signing packs, and client evidence trails.

  • Practice dashboard, annual-review queue, calendar, debt ledger, lodgement register, document generation, signing requests, and audit log are first-class workflows.
  • CAS 360, NowInfinity, and generic CSV onboarding flows are represented so firms can migrate real portfolios instead of entering one company at a time.
  • Public and authenticated signing routes preserve evidence such as token hashes, IP address, user agent, and signing timestamps.

Expertise

Every form and register change is checked by the system itself against ASIC's rules — not just by the screen you type into.

  • ACN, ABN, officer, member, share-transaction, registered-office, annual-review, ASIC-debt, and workflow checks are service-validated.
  • Share transactions are immutable ledger entries; current holdings are calculated rather than manually overwritten.
  • Lodgement capability claims are kept separate from live approval status so the product does not imply certification it has not received.

Authoritativeness

The system exposes the official-source boundary and keeps ASIC, security, and production-readiness claims traceable.

  • ASIC obligations and API scope are linked to official ASIC pages instead of unsourced marketing copy.
  • Public API documentation and OpenAPI schema are available when the application service is deployed and configured.
  • Operational docs separate code readiness from external approvals that only ASIC can grant.

Trustworthiness

Trust controls are visible: tenancy boundaries, auditability, single sign-on, retention, provider credential handling, and explicit human-review warnings.

  • Firm isolation, role-based access, Microsoft Entra SSO configuration, retention policies, and audit logs that cannot be edited are product surfaces.
  • Provider credentials are handled through secure integration vault flows rather than browser-only storage.
  • The product is framed as professional decision-support and workflow software, not autonomous legal advice.

Security and operations

Controls that support trust

High-trust professional software needs controls that users can see and audit, not just claims in a sales page.

Firm-isolated records and role-bound access control

Microsoft Entra single sign-on support

Audit logs that cannot be edited, with evidence certificates

Share registers that preserve full transaction history

Retention-policy and security settings

Document-generation and signing evidence trails

Production readiness

What is ready, what must be operated, and what remains externally gated

Open runbook

Packaging and pricing

Software-ready

Starter, Growth, and Firm subscription packages, Stripe Checkout, Customer Portal, entitlement limits, and payment-recovery states are implemented in billing services and Settings.

Configure live Stripe Prices, signed webhooks, and run the billing readiness verifier before paid production access.

Deployment and smoke checks

Operator action

The repository documents the Vercel deployment shape, same-origin API routing, Australian region placement, and deployment smoke script.

Run the production smoke against the actual deployment URL after every auth, routing, or environment change.

Security and audit posture

Software-ready

Firm isolation, role-based access, company-level access, single sign-on support, tamper-proof signing records, retention controls, and audit verification are product surfaces.

Rotate secrets per environment, enforce edge security controls, and complete a penetration test before real client data.

ASIC and provider production access

External gate

The product keeps manual lodgement as the default and separates software readiness from approvals that only ASIC can grant.

Retain ASIC/provider approval evidence and credentials before claiming live production lodgement capability.

Buyer proof and rollout evidence

Operator action

The scoreboard records browser, build, unit, and backend workflow evidence for the current repository state.

Add real practitioner pilot timing, signed feedback, support terms, and data-processing agreements before claiming market parity.

Official source register

Where the public claims come from

Responsible operator

Cassandra ASIC Agent OS is developed and maintained by Cassandra Research Pty Ltd, an Australian company. Client compliance decisions remain with the licensed professional firm using the system.

Software transparency

The application source is available for review at github.com/Cassandra-Research/asic, and compliance claims are tied to code, tests and official-source references rather than unverifiable marketing statements.

Human review boundary

Workflow findings, warnings, and generated checklists are professional decision-support outputs. They do not replace review by an ASIC registered agent, accountant, solicitor, or other qualified adviser.

ASIC approval boundary

The code can prepare and track ASIC-agent workflows, but live ASIC production lodgement requires the firm/provider to hold the necessary credentials, approvals, and operating arrangements.