Business systems and technology for Australian businesses

Call 1300 540 271
HPCR home
HPCR home
Case study: software product

Cleverer: a compliance evidence platform conceived and built by HPCR

A platform designed to help organisations collect and maintain evidence of the reasonable steps they are taking to protect customer data. Conceived, designed, built and operated by HPCR as a product in its own right.
Product
Cleverer, at cleverer.au
Category
Cyber compliance evidence and education platform
Origin
Conceived, designed and built by HPCR Technology
Scope
Compliance controls, evidence records, policy workflows, integrated training, reporting
BUILT BY HPCR
CLEVERER DEMONSTRATION TENANCY · FICTIONAL DATA
Cleverer executive dashboard summarising compliance status across the organisation, shown with demonstration data
The executive dashboard: open items, the recommended next step and the current activity score, on one page. Shown for a fictional demonstration organisation.

The compliance evidence problem

Australian organisations are increasingly asked to show their cyber security position: by insurers, by boards, by customers and by regulators. Most small and mid-sized organisations take reasonable steps but keep no organised record of them, so when the question comes, good intentions are all they can produce.
Between doing the right things and being able to show it sits unglamorous work: organising controls, collecting evidence, keeping policies current and acknowledged, training people and tracking that the training remains current. Without a system, that work falls to whoever has time, and the record decays the moment attention moves elsewhere.
THE ORIGIN
No client asked for Cleverer. HPCR saw the gap from years of cyber security work with small and mid-sized organisations and built the answer as a standalone product.

Platform overview

The platform brings compliance controls, evidence collection and maintenance, and policy and document workflows into one place, building a running, dated record of the steps the organisation takes, organised so that busy non-specialists can keep it current.
It also practises what it asks of its customers: multi-factor authentication, single sign-on and role-based access for organisations and their teams.
The compliance overview: the activity score broken down by training, governance, reviews and exposure, each figure traceable to the underlying records

Governance and evidence

Controls define what the organisation says it does; evidence records that it did it. Dated entries build a running record of the reasonable steps the organisation takes, ready when the question comes.
Cleverer compliance timeline showing policy and training events in sequence, shown with demonstration data
Actions, decisions and reminders are recorded over time, reducing the need to reconstruct activity from memory
The risk register: each risk carries ratings, a treatment, an owner and a next review date

Policies and acceptance

Policies carry the commitments: approved, kept current and acknowledged by staff, with each acceptance recorded alongside the rest of the evidence.
The governance register: policies version-controlled and review-cycled, with the platform surfacing its own overdue reviews
WORKFLOW

How evidence is created and maintained

01
Controls defined
What the organisation says it does
02
Steps taken
The work of protecting data, done in the business
03
Evidence recorded
Dated entries build a running record
04
Policies acknowledged
Approved, current and accepted by staff
05
People trained
Certificates issued, currency tracked, reminders automatic
06
Position reported
Visible to management and boards over time

Training and certification

Education is built in rather than bolted on: a Moodle learning management system sits behind single sign-on, so staff move from platform to training without a second login. Completions produce certificates, certification currency is tracked, and reminders send themselves before certifications lapse.
Team responsibilities: every person has a role path, a training status and an expiry date
Cleverer training dashboard, personal details obscured
Integrated training and certification. Details obscured.
Manager attestation: a structured sign-off, recorded as part of the evidence record

Management oversight and reporting

The owner or compliance lead maintains the organisation's controls, evidence and policies. Staff complete training and acknowledgements in the same place. Management and boards read the reporting on training status, certification currency and the organisation's position over time. One platform, one record, kept current by the people who already work there.
The evidence vault: activity recorded as it happens builds a chronological record, with reports generated from the same data
The same underlying platform data can be presented as a concise management or board report

What building Cleverer demonstrates

Conceived
by HPCR, not commissioned
Built from a gap seen in years of cyber security work with smaller organisations
One platform
controls, evidence, policies, training, reporting
A running, dated record kept current by the people who already work there
Its own product
brand, website and roadmap
Operating at cleverer.au, with HPCR the engineering capability behind it
Cleverer operates as a standalone product with its own brand, website and roadmap at cleverer.au. HPCR Technology remains the engineering capability behind it and separately provides the professional services organisations often need around it: implementation, supporting infrastructure, integrations and onboarding assistance.
Cleverer carries its own product roadmap, shaped by what organisations need to evidence and how those expectations evolve. For the platform itself, visit cleverer.au.
RELATED

Have a platform of your own in mind?

Cleverer started as a problem statement, not a specification. If your industry has a gap that software should fill, we can take it from idea to operating product.