Agentic AI studio · Australia & New Zealand

Find the work your business shouldn't be doing.

Rybox builds AI agents that take repetitive work off your team. It starts with a 15m audit that shows you where the hours go, what they cost, and what it takes to get them back.

2 min · We audit a limited number of businesses each month

The problem

Most of it isn't a technology problem. It's a repetition problem.

Every business runs a handful of processes that a person does the same way, dozens of times a week, because nobody ever had the time to fix it. That is where the money sits.

Accounts payable
Invoices keyed by hand, matched to POs by eye, chased over email.
4 to 9 min per invoice
Quote to cash
Quotes rebuilt from scratch each time. Follow-ups forgotten. Deals go quiet.
30 to 50% never followed up
Customer support
The same twenty questions answered hundreds of times a month.
60 to 80% repeat volume
Reporting
Data copied between three systems and a spreadsheet to produce one number.
1 to 3 days per cycle
Onboarding and compliance
Documents collected, checked, re-keyed, then checked again by someone senior.
2 to 5 days per file
Reconciliation
Statements matched line by line, exceptions handled in a side spreadsheet.
85 to 95% auto-matchable
The Rybox audit · 15m

Fifteen minutes to know exactly what your admin costs you.

No discovery workshop. No six-week consulting engagement. One structured conversation that maps how work actually moves through your business, and prices it. We run a limited number each month, so we check fit first.

STEP 01

You answer

We walk through your functions one at a time. Volumes, who touches what, where things get stuck. Plain questions, no jargon, nothing to prepare.

STEP 02

The audit scores

Every process is scored on volume, hours, error rate and rework, then converted to an annual dollar cost using your own loaded labour rates.

STEP 03

You get the report

Your three biggest drains, a recovery figure against each, and what it would take to fix them. Ranked by payback, not by what is easiest to sell you.

The audit runs in your own Rybox workspace at app.rybox.com.au. Two minutes on the fit check opens it. You can stop and resume, and the report stays in your portal.
What we build

Agents that do the job, not chatbots that talk about it.

An agent reads, decides and acts inside the systems you already run. It works to your rules, shows its reasoning, and escalates anything it isn't sure about.

Invoice agent

Reads the invoice, matches it to the PO and receipt, codes it, flags the mismatch and routes the approval.

Typical: 80% touchless, same-day close

Quote and follow-up agent

Builds the quote from your price book, sends it, then follows up on a schedule until the customer replies.

Typical: 2x follow-up coverage

Support agent

Answers the repeat questions from your own documentation, resolves what it can, and hands the rest over with context attached.

Typical: 60% first-contact resolution

Reconciliation agent

Matches statements to ledger lines, clears the clean ones, and puts only the genuine exceptions in front of a person.

Typical: 90% auto-matched

Reporting agent

Pulls from every system on a schedule, builds the pack, and writes the commentary a reader actually needs.

Typical: 3 days down to 20 minutes

Onboarding agent

Collects documents, verifies identity and entity details, checks them against your policy and builds the file.

Typical: days down to minutes
Our work

We don't just build this for clients. We run our own businesses on it.

Rybox came out of building and operating finance and software companies in Australia. Three of them run on the agent stack we would put into your business. That is the proof: we carry the risk of our own decisions.

Equipment finance · Live
Oxyan
oxyan.com.au ↗
The problem

IT resellers were losing deals at the checkout. A customer ready to buy $40,000 of hardware would ask about finance, wait three days for a credit decision, and buy somewhere else in the meantime. The friction was not the rate. It was the wait.

What we built

Two embedded surfaces, Oxyan Checkout at the merchant cart and Oxyan SalesDesk for finance links generated live during a sales call. Behind both sits Forge Run, an automated decisioning engine with a twenty-point verification and enrichment layer. Agents read ABN and entity data, banking behaviour, tax position and digital footprint, score the application against a three-tier assessment ladder, and route only genuine edge cases to a human credit officer.

Decision in minutes, not days 3-tier assessment ladder Two channel partners live
Non-bank lending · Live
Zool Capital
zoolcapital.com.au ↗
The problem

A licensed lender where credit analysts were spending most of their week reading bank statements line by line, chasing entity documents, and hand-assembling credit memos. Every hour on data entry was an hour not spent on judgement, which is the only part of the job a person is actually better at.

What we built

An assessment layer that ingests raw statements, classifies transactions, surfaces ATO debt, dishonours and undisclosed liabilities, and drafts the credit memo before an analyst opens the file. Borrower onboarding, entity verification and document collection run as agents. Every decision carries a full audit trail, which matters when you hold a licence.

Statement analysis in minutes Audit trail on every decision Analyst time moved to judgement
Trades software · In build
Cobbo
Australian trades OS
The problem

Australian tradies run a real business from the front seat of a ute. Quotes get promised and never sent, follow-ups never happen, invoices go out late, and the work that would grow the business always loses to the work that is on today.

What we built

An operating system built around three engines, GROW for winning work, RUN for delivering it and FUND for getting paid. The centre of it is Pilot, a coachable autonomy agent. It starts by drafting and asking. As the owner corrects it, it learns how they want things done and takes on more without asking. The owner decides how much rope it gets.

Quote, chase, schedule, invoice Coachable autonomy Owner sets the limits
How we engage

Prove it on one process before you commit to ten.

Nobody should sign a transformation programme on a slide deck. We start small, in production, on a fixed fee, and let the result make the argument.

15m · qualified businesses

Audit

We map and price the work in your Rybox portal. You get a ranked report with a recovery figure against each finding, saved to your account.

30 days · fixed fee

Pilot

We build one agent for the highest-payback process and run it live against real volume. Measured against a baseline you agreed up front.

Ongoing

Scale

Once the pilot holds, we work down the list. You own the agents, the rules and the data. No lock-in.

Who it's for

We turn work down. Here is how we decide.

An audit takes real hours from our side, so we run a limited number each month and put them where there is something worth finding. Read the two lists before you book. If you are on the right-hand side, we would rather tell you now than waste your quarter.

Worth a conversation
Five or more people spending real hours each week on repeatable admin.
The work follows rules you could write down, even if nobody ever has.
Your data lives in systems with an export or an API, not only in people's heads.
Someone senior can make the call and wants something running this quarter.
You have a budget line for it, or the authority to create one.
Not us, not yet
×Under five staff and the admin adds up to an hour a day. The maths won't work.
×You want a chatbot on the website and nothing behind it.
×Nobody internally owns the process you want fixed.
×You are collecting quotes for a board paper with no budget behind it.
×The process changes every month and nobody can say how it works today.
Rough numbers

See roughly what repetitive work is costing you.

Move the sliders to match your team. This is the back of an envelope, not a quote. The audit does it properly, function by function.

8
12 hrs
$55

Indicative only. Assumes 46 working weeks and that around 60% of repeatable task time is addressable by an agent. It is a planning estimate to start a conversation, not an offer or a guarantee of savings. Your real number comes out of the audit.

Addressable cost, per year
$146,000

Before the cost of building and running the agents.

Hours returned 2,650 / yr
Equivalent to 1.4 FTE
Get started →
Before you ask

The questions everyone asks on the first call.

Answered here so you do not have to spend the audit on them.

Do you need access to our systems?

Not for the audit. That is a conversation, nothing more. For a pilot we need scoped access to the one system the agent works in, using credentials you issue and can revoke at any time. We never ask for blanket admin.

Do we have to replace our software?

No, and we would talk you out of it. Agents sit on top of what you already run, through an API or an export. Your team keeps working in the same systems. The difference is that the repetitive part is already done when they open it.

What happens when it gets something wrong?

Every agent runs to a confidence threshold you set. Below that line it stops and escalates to a person with its reasoning attached, rather than guessing. We design for the exception, because the exceptions are what make or break trust in the first month.

Is this going to cost us jobs?

In our own businesses it moved people off data entry and onto judgement, exceptions and customers. That is usually where the value is anyway. What it does reliably kill is the need to hire the next three admin roles as volume grows.

Who owns what you build?

You do. The agents, the rules, the prompts, the data and the logic are yours, and you keep them if you stop working with us. We do not hold your business hostage inside a platform you cannot leave.

How fast is something actually live?

Thirty days from the pilot starting, on one process, on a fixed fee, measured against a baseline you agree before we begin. If it does not clear the baseline, you have lost a month rather than a transformation budget.

Fit check · 2 min

Four questions. Then we both know.

Answer these and we will tell you straight away whether an audit is worth booking. If it isn't, we will say so and tell you what would change that.

Question 1 of 4
How many people spend real hours each week on repeatable admin?
Question 2 of 4
Where does it hurt most?
Question 3 of 4
When would you want something running live?
Question 4 of 4
Is there budget behind it, or the authority to create one?
✓ Fit confirmed

Worth the fifteen minutes.

On what you have told us there is enough volume, enough structure and enough intent for the audit to find something real. Leave your details and we will send two times that suit, plus the short list of questions we will walk through.

The audit runs in your Rybox portal at app.rybox.com.au. Your answers so far carry across, so you pick up where you left off. Takes about fifteen minutes and you can stop and resume.

Worth a look

Close, but we want to check one thing.

There is probably something here. Before we book fifteen minutes we would rather spend five on the phone working out whether the timing or the scope stacks up. Leave your details and we will call.

Five minutes, no deck. If it isn't there we will tell you on the call.

Not yet

An audit wouldn't pay for itself right now.

On these answers the volume or the timing isn't there, and we would be taking your fifteen minutes for a report you couldn't act on. That usually changes when the team doing the manual work grows past five, or when a specific process starts costing you deadlines. Come back when it does.

In the meantime, the estimator further up the page will give you a rough number to work with, and it costs you nothing.

Got it. We will be in touch.

You will hear from us within one business day.

HQ
Level 1, 413/417 New South Head Rd, Double Bay NSW 2028
Serving Australia and New Zealand
Legal

Privacy Policy

How we collect, hold, use and disclose personal information, and what you can do about it.

Effective 5 August 2026
Version 1.0
ABN 95 687 610 840
SECTION 01

Who we are

In this policy, Rybox, we, us and our means the entity trading as Rybox, ABN 95 687 610 840, of Level 1, 413/417 New South Head Rd, Double Bay NSW 2028.

We are an agentic AI studio. We audit business processes and design, build and operate AI agents for businesses in Australia and New Zealand.

We are committed to protecting your privacy and we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where we handle personal information of individuals in New Zealand, we also have regard to the New Zealand Privacy Act 2020.

This policy covers our website, our fit check and audit process, and our dealings with clients, prospective clients, suppliers and job applicants.

SECTION 02

What personal information we collect

The kinds of personal information we collect depend on how you deal with us. They generally include:

  • Identity and contact details such as your name, business name, role, work email address and phone number.
  • Fit check and audit responses such as approximate headcount, which business functions you want to improve, your intended timeframe and whether budget is allocated.
  • Business process information gathered during an audit, such as transaction volumes, how work moves between people and systems, and indicative labour costs. This is mostly business information, but it can include personal information about your staff.
  • Engagement records such as correspondence, meeting notes, proposals, contracts, invoices and payment details.
  • Technical information such as your IP address, browser type, device type, pages viewed and the date and time of your visit.
  • Recruitment information if you apply to work with us, including your CV, work history and references.

We do not seek to collect sensitive information as defined in the Privacy Act. If you provide it to us unprompted, we will only use it for the purpose for which you provided it.

You can browse our website without telling us who you are. You can also deal with us anonymously or under a pseudonym where it is lawful and practicable, though this may limit what we can do for you. We cannot, for example, deliver an audit report without a way to send it to you.

SECTION 03

How we collect it

We collect personal information directly from you wherever we can, including when you complete the fit check on our website, contact us by phone or email, take part in an audit or a scoping conversation, engage us for a project, or apply for a role.

We may also collect information from third parties or publicly available sources, such as your organisation's website, business registers including ASIC and the Australian Business Register, or professional networking platforms. We do this to confirm business details and to understand the context of an enquiry.

If we receive personal information about you from someone else and we did not need it, we will destroy or de-identify it where the law requires us to.

SECTION 04

Why we collect and use it

We collect, hold and use personal information to:

  • assess whether an audit is likely to be worthwhile for your business, and tell you if it is not;
  • schedule, run and deliver audits and produce audit reports;
  • scope, quote, build, deploy and support AI agents and related software;
  • communicate with you, respond to enquiries and provide support;
  • administer our contracts, invoicing and accounts;
  • improve our services, our website and our own internal processes;
  • meet our legal, regulatory, tax and record-keeping obligations; and
  • consider applicants for employment or contracting roles.

Where we use your information for a purpose other than the one we collected it for, we will only do so where you would reasonably expect it, where you have consented, or where the law permits or requires it.

SECTION 05

Client data in agent builds

When we build or operate an AI agent for a client, that agent may process data held in the client's own systems. That data can include personal information about the client's customers, suppliers or staff.

In that context the client is the entity responsible for that personal information and decides how it is used. We act on the client's instructions as a service provider. Our handling of that data is governed by the written agreement between us and the client, which sets out permitted purposes, security requirements, confidentiality, retention and deletion on termination.

We work to the principle of least privilege. We ask for scoped access to the specific systems an agent needs, using credentials the client issues and can revoke at any time. We do not ask for blanket administrator access.

If you are a customer or employee of one of our clients and you want to know how your personal information is handled, contact that organisation directly in the first instance. We will assist them in responding to you.

SECTION 06

AI processing and model providers

Our work involves large language models and related AI services. Depending on the engagement, data may be processed by third party model providers under contract to us or to our client.

Where we use third party model providers, we seek arrangements under which submitted data is not used to train that provider's publicly available models, and is retained only for the period necessary to deliver the service. The specific providers, hosting regions and retention terms applying to an engagement are set out in the agreement for that engagement.

Automated processing may inform decisions in systems we build. Where an agent produces an outcome that materially affects an individual, we design for a human review path and an audit trail, and we work with our clients to make sure the responsible person in their organisation can review and override the outcome.

We do not use the content of your fit check responses, audit conversations or client data to train publicly available AI models.

SECTION 07

Who we disclose it to

We may disclose personal information to:

  • our personnel and contractors who need it to do their job;
  • service providers who support our business, including cloud hosting, email, customer relationship management, scheduling, e-signature, accounting and payment providers;
  • AI and model providers as described above;
  • our professional advisers, including lawyers, accountants and insurers;
  • a purchaser or prospective purchaser in connection with a sale or restructure of our business; and
  • government agencies, regulators, courts or law enforcement where required or authorised by law.

We do not sell personal information, and we do not disclose it to third parties for their own marketing purposes.

SECTION 08

Overseas disclosure

Some of our service providers store or process data outside Australia. This is most likely to include the United States, the European Union, New Zealand and Singapore, depending on the provider.

Before disclosing personal information overseas we take steps that are reasonable in the circumstances to ensure the recipient handles it in a way consistent with the Australian Privacy Principles, including through contractual commitments.

Where an engagement requires data to remain in Australia, we will say so in the agreement for that engagement and select providers accordingly.

SECTION 09

Cookies and analytics

Our website may use cookies and similar technologies to make the site work, remember your preferences and understand how the site is used in aggregate.

Most browsers let you refuse or delete cookies. If you do, some parts of the site may not work as intended.

Where we use analytics or advertising technologies, they may collect information about your device and browsing activity. We use this to understand which pages are useful and where people get stuck, not to identify you personally.

SECTION 10

How we keep it secure

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These steps include access controls and least-privilege permissions, encryption of data in transit, restricting access to personnel who need it, confidentiality obligations on our people and contractors, and reviewing our providers' security arrangements.

No system is completely secure. While we work hard to protect your information, we cannot guarantee the security of information transmitted to us over the internet.

SECTION 11

How long we keep it

We keep personal information only for as long as we need it for the purposes described in this policy, or for as long as the law requires us to keep it. Some records, including financial records, must be kept for a minimum of seven years under Australian law.

Where we no longer need personal information and we are not required to retain it, we destroy it or de-identify it.

Client data processed during an engagement is retained and deleted in accordance with the agreement for that engagement.

SECTION 12

Accessing and correcting your information

You can ask us for access to the personal information we hold about you, and you can ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading.

To make a request, contact us using the details in section 17. We may need to verify your identity first. We will respond within a reasonable period, normally within 30 days.

We do not charge for making a request. We may charge a reasonable fee for the cost of giving access where a request is substantial, and we will tell you before we do.

If we refuse access or refuse to correct information, we will tell you why in writing and explain how you can complain.

SECTION 13

Direct marketing

We may send you information about our services where you have asked us to, where you are a client, or where you would reasonably expect it. Every marketing message includes a way to opt out, and you can opt out at any time by contacting us or using the unsubscribe link.

If you ask us to stop, we will. We will still send you messages necessary to deliver a service you have engaged us for.

SECTION 14

Data breaches

We maintain a data breach response process. If we suffer a data breach that is likely to result in serious harm to an individual whose personal information we hold, we will assess it promptly and, where the Notifiable Data Breaches scheme applies, notify affected individuals and the Office of the Australian Information Commissioner as required.

If the breach involves client data, we will notify the client without undue delay so they can meet their own obligations.

SECTION 15

Complaints

If you think we have breached the Australian Privacy Principles or mishandled your personal information, contact us first using the details in section 17. Tell us what happened and how you would like it resolved.

We will acknowledge your complaint promptly, investigate it, and respond in writing, normally within 30 days.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992. If you are in New Zealand, you can complain to the Office of the Privacy Commissioner at privacy.org.nz.

SECTION 16

Changes to this policy

We may update this policy from time to time to reflect changes in our practices, our services or the law. The current version is always available on our website, with the effective date shown at the top of this page.

Where a change is significant, we will take reasonable steps to notify you.

SECTION 17

Contact us

For any privacy question, request or complaint, contact our Privacy Officer:

ENTITY
Rybox · ABN 95 687 610 840
POST
Level 1, 413/417 New South Head Rd,
Double Bay NSW 2028