Arjun is a read-only ISM assessment tool that installs into your own Azure or AWS tenant and generates a System Security Plan and its Annex.
ARJUN
ISM assessment & IRAP evidence — in your own tenant.
read-only · no egress · yours to run
$ curl -sL https://arjunsec.run/install.sh | bash -s -- --region australiaeast
$ curl -sL https://arjunsec.run/install-aws.sh | bash -s -- --region ap-southeast-2
Copy a line and paste it into your cloud's browser shell — it runs the same from Windows, macOS or Linux. One command lands the whole app in a single resource group / stack you can delete as a unit. Read the docs →
// what it does
The whole ISM, answerable — and the documents to prove it.
full ISM coverage
Every control applicable at your classification becomes an answerable question — all ~1,000, not a curated subset. Nothing is left as a silent gap.
attestations
Record each control's implementation status with a justification and supporting-evidence references. Re-checked for currency against every ISM release.
multiple systems
Assess several authorisation boundaries from one deployment — each with its own classification, answers and SSP. A control can be Effective for one system and Inherited for another.
control inheritance
Mark controls inherited from a CSP's IRAP-assessed platform or a parent system. The SSP cites the source and its assessment and reports inherited controls distinctly — the way an assessor expects.
ssp + annex
Generate a formatted System Security Plan and its control-implementation Annex as real Office documents, ready for an assessor.
report branding
Apply your agency's logo and header/footer to the output. The protective marking stays on every page — a document obligation, not a style choice.
honest coverage
Controls you haven't answered are reported as not assessed, with the reason — never assumed compliant. An assessor can trust the gaps.
any cloud
Runs on Azure, AWS, or any host. One tool, one SSP, whichever cloud your system lives in.
// how it runs
In your cloud. Read-only. Nothing leaves.
read-only
Reader on Azure, ReadOnlyAccess on AWS — and nothing more. Arjun reads configuration to assess it and changes nothing in your tenant.
no egress
Your configuration and attestations stay in your own tenant. Nothing is sent to us, cached by us, or seen by us.
your cloud
Installs into your own subscription or account. You own the deployment, the database, and every document it produces.
small footprint
One container, one managed database, sign-in through your own identity provider. Approvable by a security architect in an afternoon.
Security audits welcome. Arjun runs inside your own tenant and holds read-only access — so don’t take our word for it, audit it. The install templates and the exact permissions it requests are public, and the full source code is available to security teams for review on request. Responsible disclosure and source-access requests — security@arjunsec.run.
// the winrar model
One price. Nothing gated.
No feature gates. No licence keys. No nagware. Every feature — the questionnaire, the attestations, the SSP and Annex — is on for everyone, forever. If Arjun is useful to your agency, licence it.
Your subscription keeps the ISM controls current: as ASD revises the ISM, updated releases carry the new catalog, and Arjun tells you in-app when one is available. Upgrading is one command and preserves your attestations.