Summary
- Cloud Registry Pty Ltd is an Australian proprietary company based in Sydney (ACN 137 160 975) that presents itself as a new gTLD back-end registry operator and hosted TLD platform provider; it has never been the .au registry operator. [8]
- On 20 July 2012 Cloud Registry submitted to auDA's Industry Advisory Panel, in a document signed by its then chief executive Ruud Verstijnen, arguing for a full public tender of the .au registry rather than renegotiation with the incumbent, and stating the company's interest in tendering for the .au second-level registries. [9]
- auDA's public record shows the .au registry is operated by Identity Digital Australia, a third party contracted by auDA, appointed after a 2017 global tender and reappointed after the 2023 tender. [2]
- The 2023 tender opened in May 2023, closed on 26 June 2023, and the successful tenderer was announced on 27 August 2023, with evaluation overseen by an independent probity advisor. [3]
- The resulting Registry Services Agreement is dated 22 August 2023 and runs for an initial four years from 1 July 2024, with an auDA option to extend by two further years; the agreement itself was made available only to qualified tenderers on request and has not been published. [4] [5] [7]
- auDA's own contract recitals describe its delegation of authority as an exercise of public rights that is not property and cannot be assigned except by the Australian Government and ICANN — while the operational contract that implements that delegation remains confidential. [5]
The registry of record, and who is not on it
Start with the fact that gives this article its subject. The .au country-code top-level domain — the namespace under which Australia's internet identity is registered — is not operated by Cloud Registry Pty Ltd. auDA, the .au Domain Administration body, states plainly that the registry is operated by Identity Digital Australia, described as the .au registry operator and as a third party contracted by auDA to deliver registry services, first appointed following a global tender process in 2017 and reappointed following a subsequent global tender in 2023. [2]
Cloud Registry Pty Ltd, by contrast, is an Australian proprietary company with an ACN of 137 160 975, headquartered at Suite 32, Seabridge House, 377 Kent Street, Sydney. Its own corporate page describes it as a new gTLD back-end registry operator offering a hosted or licensed platform for the operation of top-level domains — a vendor in the market for generic top-level domain registry services, not the operator of Australia's ccTLD. [8] In the language of registry governance, it is a supplier adjacent to the .au system, not a participant in it.
So why does Cloud Registry merit a governance analysis at all? Because its public record — thin as it is — happens to sit at exactly the point where the legitimacy questions of delegated ccTLD authority become visible. Companies that win contracts teach you about contracts. Companies that never win them, but keep arguing for the process that would let them, teach you about the structure of access itself.
The delegation auDA holds — and what its own documents say it is
The 2025 Registrar Agreement, the standard contract auDA executes with accredited registrars, contains recitals that are unusual in how explicitly they characterise auDA's authority. They record that auDA is endorsed and recognised as the holder of the delegation of authority by ICANN for the administrative authority of the .au ccTLD, and that auDA holds that delegation by virtue of the Australian Government's Endorsement and the ICANN Sponsorship Agreement. [5]
The same recitals then do something that national domain authorities rarely say in writing: they state that the Endorsement and Delegation are "the exercise of public rights", that they are not property, and that they cannot be assigned except by the Australian Government and ICANN. [5] This is a legal architecture in three sentences. The authority over .au is public in origin; it is held, not owned; and it cannot be sold, transferred or mortgaged by the holder. Whatever auDA does with .au, it does on behalf of a public entitlement that exists upstream of it.
The recitals also perform a governance transfer. They record that auDA appointed Identity Digital Australia Pty Ltd as the Registry Operator under a Registry Services Agreement dated 22 August 2023, and that registrars must be Registry Operator Accredited as well as auDA Accredited to access the registry and registry data, with the Registry Operator able to require a registrar to enter a Registry-Registrar Agreement as a condition of access.
[5] In other words, the registrar-facing layer of .au governance is contractually interposed through the operator: access to the registry of record is mediated by the operator's own accreditation and agreement requirements, sitting on top of auDA's accreditation.
The instruments also carry a security designation. The registry database, the public WHOIS service, the .au top-level authoritative DNS name servers and the listed second-level DNS name servers are declared critical infrastructure assets under the Security of Critical Infrastructure Act 2018 (Cth). [5] [6] That declaration matters for this analysis because it marks the perimeter that the Australian Parliament has decided must be defended — and, by implication, the perimeter within which a contracted operator exercises delegated control.
What the tender reveals about the terms of competition
If the delegation is public in character, the mechanism for conferring operational authority is competitive tender. The record of the 2023 tender shows a structured process: tenders were sought from May 2023 and closed on 26 June 2023; evaluation was conducted by a committee with external expertise and overseen by an independent probity advisor; and the successful tender was announced on 27 August 2023.
[3] The new Registry Services Agreement commences on 1 July 2024, for an initial four-year term, with an option for auDA to extend by a further two years; auDA also retains the right to require the Registry Operator to comply with the agreement for up to 12 months following expiry or termination, a wind-down provision for continuity. [4] [7]
A four-year term with a two-year extension is a meaningful constraint on any operator: it converts incumbency into a recurring contest. Independent probity oversight adds a second accountability layer. On the surface, this is the tendered competition that Cloud Registry's 2012 submission argued for, realised a decade later.
But the same RFT record contains the detail that cuts the other way. The proposed Registry Services Agreement — the instrument that would actually define the winner's rights, obligations, service levels, pricing levers and exit terms — was not published. It was made available to qualified tenderers on request, through the RFT contact officer. [7] The competition was open; the terms of the thing being competed for were not.
This is the first accountability gap this article identifies, and it is structural rather than behavioural. A delegation described in auDA's own contract recitals as an exercise of public rights is implemented through a private contract whose full text is withheld from the public on whose behalf the delegation is said to be exercised. Independent probity advisors observe the fairness of the process between bidders; nobody outside auDA and the tenderers can read the resulting terms.
Registry Services Description documents — the 2023 release, dated 1 May 2023, is public — define the Registry Operator as the entity providing services to auDA under the Registry Services Agreement, and enumerate the services: the registry EPP interface, public WHOIS and RDAP, top-level and second-level authoritative DNS name servers, Registry Lock, Domain Drop List, and DNSSEC signing and publication. They also record that public-facing registry domain names, such as those used for WHOIS, are provided by auDA and delegated to the Registry Operator for the duration of the Registry Services Agreement.
[6] What is public, in other words, is a functional description of the services and their ownership topology; what is not public is the contract that prices them, constrains them and defines what happens when they fail.
Cloud Registry's 2012 challenge, and what it demanded
Now place the challenger on the record. On 20 July 2012, Cloud Registry Pty Ltd made a submission to auDA's Industry Advisory Panel on the future of the .au registry. It was signed by Ruud Verstijnen as the company's chief executive. Its argument was procedural and, at its core, about legitimacy: rather than renegotiating with the incumbent registry operator, auDA should run a full public tender for the .au registry.
The submission also stated, without ambiguity, that Cloud Registry would be interested in tendering for the provision of the .au 2LD registries — the second-level domains that constitute the commercial core of the Australian namespace. [9]
The submission predates the 2017 tender that produced the incumbent's first appointment, and predates by eleven years the 2023 tender that reappointed it. It is, in the record, the position of an outside challenger stated at the moment when the choice between renegotiation and competition was live. And the historical sequence is the point: auDA did subsequently adopt tendering — in 2017 and again in 2023 — which means the challenger's core procedural argument became auDA's actual practice. But neither tender produced a role for Cloud Registry.
The 2012 submission remains its most consequential public intervention on .au governance, and it was advocacy, not a contract.
Read carefully, the 2012 document also shows what tendering does not resolve. A full public tender answers who operates the registry and on what competitive footing. It does not answer what the public can know about the terms. Cloud Registry urged transparency of process; the process arrived; the terms stayed confidential. The challenger's victory was procedural, and it was incomplete.
The enclosure, precisely stated
Pull the threads together and the structure of .au authority can be stated with some precision, entirely from auDA's own instruments.
At the top sits a public delegation: the Australian Government Endorsement and the ICANN Sponsorship Agreement, exercised by auDA, characterised in auDA's own recitals as public rights, non-property, non-assignable except by the Australian Government and ICANN. [5] In the middle sits a competitive tender that decides who will hold the operational contract — 2017 and 2023 are on record, with dated milestones and probity oversight. [2] [3] At the bottom sits the Registry Services Agreement: dated 22 August 2023, commencing 1 July 2024, initial four-year term, two-year extension option, and not published. [4] [7]
The enclosure is this: the top and the middle are public, the bottom is confidential, and the bottom is where the delegable content actually lives. The registry database, the WHOIS service, the DNS name servers and the EPP interface — the assets declared SOCI-critical — are operated day to day under terms the public cannot inspect. [5] [6] The delegation is public; the delegation's implementation is not.
A governance system can survive that configuration, but it cannot be called fully accountable while it persists, because the mechanism that translates public authority into operational control is precisely the mechanism the public is not permitted to read.
Three features sharpen the point. First, the term structure. A four-year initial term ending 30 June 2028, extensible to 2030, means the next competitive moment is on a known clock — but between tenders, the operator's authority is bounded only by the confidential contract. Second, the interposition of the operator in registrar relations. Registry access requires the operator's accreditation and the operator's Registry-Registrar Agreement, so the operator holds contractual power over every registrar's pathway to the registry, under terms that are themselves confidential. [5] Third, the security perimeter.
The SOCI declaration brings government attention to the assets, but a security designation is not a transparency mechanism: an asset can be defended more closely and still be governed less openly. [5] [6]
What Cloud Registry's record does and does not show
It is worth being precise about the limits of the evidence, because the challenger's own footprint is small. The company's self-description as a gTLD back-end provider comes from its own corporate page. [8] Its 2012 submission is a position document, not proof of capability; auDA hosted it because the Industry Advisory Panel solicited stakeholder views, not because Cloud Registry had any standing in the .au system.
Nothing in the located public record shows Cloud Registry participating in the 2017 or 2023 tenders, and nothing shows it was excluded from them — the tender processes themselves are documented only at the level of dates, evaluation structure and announcement. [3] [7] The claim that Cloud Registry "lost" any tender would exceed the evidence; what the record shows is advocacy followed by absence.
That absence is itself informative. The 2023 RFT's process for obtaining the proposed Registry Services Agreement — qualified tenderers only, on request [7] — means that the public record of who was willing and able to bid on the confidential terms is also partial. When the terms of a public-rights delegation are available only to insiders, the pool of visible participants shrinks to the insiders, and challenges like Cloud Registry's 2012 argument become structurally harder to sustain: a challenger must commit to bidding without knowing what it is bidding on, or stay outside.
The enclosure does not just hide terms; it shapes who remains in the field.
Where accountability remains incomplete
Three gaps follow from the record, stated as gaps rather than allegations.
First, the confidentiality of the Registry Services Agreement leaves the terms under which a public-rights delegation is operationally exercised outside public view. The RFT record establishes this fact directly: the proposed RSA was provided to qualified tenderers on request rather than published. [7] Whether any of its terms would embarrass auDA if published is unknown — that is the nature of confidentiality — but the accountability question is not whether the terms are bad; it is that the public cannot check.
Second, the operator's interposed power over registrars — accreditation plus Registry-Registrar Agreement as conditions of access [5] — operates under the same confidentiality. Registrars, the segment of the industry closest to registrants, face contractual constraints set by a third party whose primary contract with auDA they cannot read either.
Third, the challenger channel is procedural but not consequential. Cloud Registry's 2012 submission shows that auDA's advisory structures receive outside arguments for competition [9], and the subsequent adoption of tendering in 2017 and 2023 shows those arguments can shape process. But there is no located mechanism by which an unsuccessful or outside party's substantive concerns — about terms, transparency or incumbent advantage — convert into public visibility. The advisory panel heard the argument for tendering; no instrument in the public record shows the argument for publishing the RSA being put, answered, or refused.
The delegation's own characterisation cuts both ways here. Because the Endorsement and Delegation are public rights, not property [5], the public has a standing argument that it should be able to see how its rights are exercised — a stronger normative footing than a mere consumer interest in a private contract. Because the assets are declared critical infrastructure [5] [6], Parliament has already asserted a public stake in the registry's security. What has not yet followed, on the public record, is an instrument making the implementation contract consistent with the public character of the authority it implements.
The clock
Governance arguments about delegated authority resolve on timetables, and this one has one. The Registry Services Agreement commenced on 1 July 2024 for four years, with a two-year extension option. [4] [7] That places the end of the initial term at 30 June 2028 and the outer edge of the extended term at mid-2030. At some point before the initial term ends, auDA must decide whether to extend or tender again. Each of those decisions will be taken under the same architecture documented here: public delegation, competitive process, confidential contract.
Whether the third element remains unchanged is the observable question the record leaves open.
For its part, Cloud Registry Pty Ltd remains what the record shows it to be: a Sydney-based gTLD platform vendor [8] whose 2012 submission [9] correctly anticipated the competitive turn auDA would take, and whose continued presence on the outside of the .au system marks the distance between competition over who operates a registry and transparency about how the operation is governed. The challenger did not win the contract. The more durable fact is that the system it challenged now runs its competition in the open and its terms behind closed doors — and that both facts are documented by the delegating authority's own instruments.
Sources and evidence boundaries
The factual claims in this article are drawn from auDA's public instruments and statements, from the 2023 tender record, and from Cloud Registry's own corporate and submission documents; each material claim is cited inline to the exact source. Two pages consulted during research — the auDA registry service providers page and the auDA registry agreements page — could not be confirmed as reachable at their published paths and no factual claim in this article rests on them; they are listed here only as pointers for readers tracing auDA's document structure.
[0] [1] The full text of the Registry Services Agreement has not been published; statements about its term and access conditions are drawn from the RFT and Registrar Agreement records, not from the agreement itself. [4] [5] [7]
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
