Firmus Sovereign Cloud Profile

IRAP-aligned Australian-owned cloud platform for government, defence, and regulated industries — Official Neocloud Provider.

AttributeValue
Provider typeSovereign Neocloud
Legal entityFirmus Pty Ltd
HeadquartersMelbourne, Victoria, Australia 🇦🇺
Ownership jurisdictionAustralia (100% Australian-owned)
Data residencyAustralian data centres only
Official websitefirmus.co

About Firmus

Firmus is an Australian-owned cloud platform delivering sovereign infrastructure to government agencies, defence contractors, healthcare providers, and financial institutions across Australia. The company combines decades of telecommunications expertise with modern cloud-native architecture.

All Firmus infrastructure operates within Australian borders and is managed exclusively by Australian-based staff. This complete domestic control chain ensures that no foreign jurisdiction can access customer data — a critical requirement for Australian Government Information Manual (AGIM) and Protected classification workloads.

Firmus is registered on the Office of Cyber Security’s Official Neocloud Provider (ONP) list, making it eligible for government procurement under the National Cloud Strategy.

Sovereignty & Compliance Profile

AttributeValue
Regulatory frameworkACSG Cloud Security Principles v4.0, IG Standards, Privacy Act
CertificationsIRAP Assessable, SOC 2, ISO 27001
Neocloud statusYes — ONP-listed sovereign provider

Key Services

ServiceDescription
VPC & NetworkingFully isolated virtual private clouds with Australian-only peering and transit gateways
ComputeBare-metal and virtual machines sized for government workloads, from web servers to HPC clusters
Managed DatabasesPostgreSQL, MySQL, and Oracle-compatible databases with point-in-time recovery
Identity & Access ManagementSSO integration with Australian identity providers and multi-factor authentication
IRAP Assessment SupportPre-assessed baseline components to accelerate agency ASCD submissions

Operating in Australia

Australia has an active national strategy for sovereign cloud adoption through the National Cloud Strategy, which includes an Official Neocloud Provider (ONP) list curated by the Office of Cyber Security and the Department of Home Affairs.

Relevant regulatory frameworks include:

  • ACSG Cloud Security Principles v4.0: Mandatory security controls for government cloud adoption
  • Privacy Act 1988 (Cth): Australian Privacy Principles governing personal data handling
  • Protective Security Policy Framework (PSPF): Requirements for government personnel and facility security

Alternatives in Australia

ProviderTypeSpecialty
Sharon AISovereign NeocloudAI-first, governance tools
AUCloudSovereign NeocloudAustralian infrastructure, SME-focused
Amazon Web ServicesHyperscalerGovCloud-AU regions, global reach
Microsoft AzureHyperscalerGovernment zones, enterprise depth