Industry

Government web development that is accessible, secure and auditable

Public digital services have no opt out audience. Whoever cannot use the service still needs the service, and usually has fewer alternatives than a commercial customer would.

What does High10 build for government?

Government web development is the design and delivery of websites, services and consultation tools for Australian councils, state agencies and public bodies. It is built to WCAG 2.2 AA, aligned to the Digital Service Standard, hosted in Australian regions, and documented to the evidence standard that public procurement and security assessment require.

Get a fixed written quote
Typical timeline
8 to 20 weeks
What drives cost
The number of services being digitised, the accessibility and assurance requirements, and how many existing systems have to be integrated.
Best for
Local councils, state agencies, statutory bodies and public sector programs
You own
The code, the content, the data and every hosting account
Built with
WCAG 2.2 AA, Australian data residency, documented security controls
How it stacks upAccessible front endForms and paymentsContent governanceOnshore secure hosting
Built to WCAG 2.2 AA and tested with assistive technology before public release.

Your handover

What is actually broken in public sector digital delivery

The failures are rarely technical. A council site carries fifteen years of accumulated content, most of it published by a team that no longer exists, structured around the organisational chart rather than around what a resident is trying to do. Someone looking to report a damaged footpath has to know which directorate owns footpaths. Forms are PDFs that must be printed, signed and posted, which excludes anyone without a printer and creates a manual re entry job for staff.

  1. 01Task based information architecture from resident research
  2. 02Accessible website or service built to WCAG 2.2 AA
  3. 03Accessibility conformance statement with manual test results
  4. 04Online forms replacing printable PDFs, with validation and save progress
  5. 05Consultation tools with multiple participation levels
  6. 06Security and data flow documentation for assessment
  • Content governance model and publishing roles
  • Integration with records, payment or case management systems
  • Handover pack with training recordings and an access register
The second failure is fragmentation

The second failure is fragmentation. A program launches with its own microsite, its own login and its own supplier, and five years later the agency runs eleven separate systems that cannot tell whether the person using them is the same person. Every one of them was a reasonable decision at the time. Together they produce a public experience where the burden of understanding government structure sits with the citizen, and an internal cost that nobody has ever added up.

The standards a government project has to meet

Accessibility is the hard floor. WCAG 2.2 AA is the working benchmark across Australian government, and it is a testable requirement rather than an aspiration. We design and build to it from the first wireframe and test with a keyboard and a screen reader, because automated scanners pass pages that are unusable in practice. The Digital Service Standard shapes the delivery approach as well, with expectations around user research, iterative delivery, plain language and measuring performance in the open.

Security and sovereignty follow

Security and sovereignty follow. Public sector projects generally require data held in Australian regions, alignment with the Information Security Manual and the Essential Eight mitigation strategies, and hosting arrangements that satisfy the agency's certification requirements. Privacy obligations come from the Privacy Act 1988 for Commonwealth entities and from the equivalent state legislation elsewhere, and records created by the service are usually public records with retention obligations under an archives or state records act. The Australian Government Style Manual governs how the content is written. None of this is optional and all of it is easier when it is designed in from the beginning.

  • WCAG 2.2 AA verified by manual keyboard and screen reader testing
  • Content written to the Australian Government Style Manual
  • Data resident in Australian regions with the arrangement documented
  • Security controls mapped to the Information Security Manual and Essential Eight
  • Records retention aligned to the applicable archives legislation
  • Accessibility and security evidence supplied as procurement ready documents

How the engagement runs

How we make a project procurement ready

Public buyers cannot accept a supplier's word for anything, and they should not have to. The evidence has to exist as documents that survive an internal review, an audit and a change of staff. We produce it as part of delivery rather than assembling it at the end when memory has faded.

  1. 01Stage 1Accessibility conformance statement with the manual testing method and results recorded
  2. 02Stage 2Security documentation covering controls, data flows, hosting location and third parties
  3. 03Stage 3Privacy impact considerations documented against the applicable legislation
  4. 04Stage 4Content governance model naming who may publish what and who reviews it
  5. 05Stage 5Performance budgets and measured results, so speed claims are checkable
  6. 06Stage 6Records and retention mapping for material the service creates
  7. 07Handover packRepository, environment documentation, training recordings and an access register
DiscoverDesignBuildTestHandover
Two decisions on your side that keep the project moving

This is also what makes the difference for small agencies without a large digital team. When the person who ran the project moves on, the next person inherits a documented system rather than a mystery, which is the single most common reason public sector sites decay.

What we build for agencies and councils

Most of the work falls into three groups. Public websites restructured around tasks rather than around the organisation, with content consolidated and the dead material actually removed rather than archived into a subfolder nobody visits. Transactional services that replace a printable PDF with a form that validates, saves progress, accepts attachments and lands in the system that processes it. And consultation platforms that let a community respond in ways other than attending a Tuesday evening meeting in a hall.

The research does not have to be elaborate

We also do the unglamorous integration work that determines whether any of it holds up: connecting to records systems, payment gateways and case management platforms so a submission becomes a case rather than an email. That is integration and web application work, usually alongside user experience design grounded in research with actual residents rather than with internal stakeholders describing residents. The research does not have to be elaborate. Eight conversations with people who have recently tried to use the service will tell you most of what needs to change.

Consultation that produces usable input

Community consultation tends to produce two failure modes. Either almost nobody responds, so the agency concludes there is no interest, or a determined minority dominates and the result is unrepresentative. Both are usually caused by the method rather than the community. A twelve page PDF submission form after 6pm at a community centre selects for people with time, confidence and transport.

More on consultation that produces usable input

Better consultation offers several ways in at different levels of effort: a two question response, a map based comment on a specific location, a short survey and a full submission, all recorded against the same project. It says plainly what is actually open for decision and what is not, which prevents the resentment that follows a consultation on a decision already made. Then it closes the loop by publishing what was heard and what changed. We build these as accessible tools with plain language throughout, and we instrument them properly through analytics so participation can be reported by channel and by demographic reach rather than by raw submission count.

When we are the wrong supplier

We are the wrong choice for classified or protected environments requiring an IRAP assessed platform and cleared personnel. We are also the wrong choice for very large multi year transformation programs that need a systems integrator with a standing team of dozens. We are a specialist delivery partner suited to defined projects with a real scope, and we would rather say so at the briefing stage than be the smallest name on a consortium.

The rest of the answer

If your immediate problem is that a site fails accessibility testing, that is a remediation engagement rather than a rebuild, and it is usually far cheaper. If the content is unusable but the platform is fine, the answer is content strategy and rewriting, not a new build. Agencies procuring for a specific service should also consider whether the need is really a portal rather than a website, because the two are procured and priced quite differently.

Everything included

The handover checklist

The practical artefacts your team or your development partner receives when this phase is complete.

  • Task based information architecture from resident research
  • Accessible website or service built to WCAG 2.2 AA
  • Accessibility conformance statement with manual test results
  • Online forms replacing printable PDFs, with validation and save progress
  • Consultation tools with multiple participation levels
  • Security and data flow documentation for assessment
  • Content governance model and publishing roles
  • Integration with records, payment or case management systems
  • Handover pack with training recordings and an access register

Not sure which level you need?

A 45 minute call, no cost, no obligation. You leave with a scope, an honest timeline and a fixed written quote.

Book a strategy call

Questions buyers usually ask

Frequently asked questions

Working with us

Can you prove WCAG 2.2 AA conformance?

We provide a conformance statement describing the testing method, the assistive technologies used, the results and any known exceptions with remediation timing. Testing is manual with a keyboard and a screen reader as well as automated, because scanners detect only part of the problem. If you require independent verification by a third party auditor, we support that and build the schedule around it.

Do you work with councils as well as state agencies?

Yes, and councils are often a better fit for the way we work, because the scope is defined and the outcome is visible to residents quickly. Common projects include restructuring a site around resident tasks, replacing printable forms with online services, and building consultation tools for planning and infrastructure programs.

Detail and edge cases

How long does a government digital project take?

Typically 8 to 20 weeks depending on scope and approval cycles. A service redesign with research, build and testing sits mid range. Content consolidation across a large council site can extend it considerably, since decisions about what to remove need owners who are often busy. We plan around approval gates from the start rather than treating them as interruptions.

How do you handle procurement and quoting?

We respond to the process you use, whether that is a panel arrangement, a quotation request or an open tender, and we supply the evidence documents public buyers need rather than marketing material. Pricing is provided as a fixed written quote against a defined scope, with any variation mechanism stated. We are happy to be assessed on documentation quality, since that is where many suppliers are thin.

Where is the data hosted?

In Australian regions, with the specific region, provider and any subprocessors documented so your assessment team can review them. We do not use offshore hosting for public sector work. Where an agency has a mandated hosting arrangement or an existing certified provider, we deploy into that environment rather than proposing our own.

What happens if our staff turn over after the project?

That is the scenario we document for. Handover includes the repository, environment documentation, a content governance model naming roles rather than individuals, training recordings per task and an access register. A new officer should be able to run the site from the documentation alone. We are also available for support, but the arrangement should be a choice rather than a dependency.

Talk to us before the specification is locked

Send us the brief or the draft scope. We reply within one business day with a practical assessment and, where it is a fit, a fixed written quote with the evidence documents listed.