Skip to content
Open the app

HECVAT and vendor security reviews

The HECVATHigher Education Community Vendor Assessment Toolkit. The security questionnaire many universities run on a new vendor. is how most universities assess a new vendor's security. Rather than ask you to send a blank questionnaire and wait, we keep a pre-filled HECVAT-Lite self-assessment that reflects the current state of First Six.

It records what is and isn't in place. Where a control isn't there yet, the response says so and gives the plan, rather than an optimistic "yes" that a pen test would later contradict.

The short version

First Six meets or exceeds the technical controls a standard HECVAT looks for. The open items are independent attestation and process maturity: the kind of thing that takes an external audit or time as a company, not an engineering change. We propose those as milestones for a pilot rather than blockers.

Headline answers

AreaStatus
Data residency (Australia, AWS Sydney)Yes
Encryption in transit and at restYes
Single sign-on with institution-enforced MFAYes
Row-level tenant isolationYes
Append-only audit loggingYes
Data minimisation with small-cell suppressionYes
Student data used to train AINo
Automated crisis detection (disclosed, with limits and duty-of-care boundary)Yes
Documented change managementYes
Separate prod / non-prod environmentsYes, enforced in code (a non-production deployment pointed at the production database refuses to start, so a misconfigured preview fails rather than reading real data)
Accessibility (WCAG 2.1 AA, VPAT 2.5 self-assessed)Partial: ACR published 3 August 2026, external validation ahead
SOC 2 / ISO 27001On the roadmap (ISO 27001 is documented end to end; the operating records and attestation are what remain)
Third-party penetration testPlanned
Data Processing AgreementYes: a signable template, current as at 13 August 2026, shared with the pack

The full response set walks the standard HECVAT sections: company and documentation, data handling and privacy, authentication and access control, application and infrastructure security, and hosting and business continuity.

The vendor entity named in the company-and-documentation section is First Six Technologies Pty Ltd (ACN 699 938 817, ABN 19 699 938 817), registered in Queensland, Australia, trading as First Six.

What is still outstanding

Five items, and you would find all of them in a review anyway:

  • SOC 2 / ISO 27001: not yet certified. The ISO 27001 documentation set (scope, statement of applicability across all 93 Annex A controls, objectives, audit programme) exists end to end; what is missing is operating records over time and the external attestation, and that distinction is exactly how we would put it to your auditor too.
  • Third-party penetration test: planned, and we're happy to make it a contractual condition of a pilot. (Five vendor-run adversarial assessments ran between late June and the end of July 2026: 129 verified findings, four critical, all closed and re-verified against production on 2 August 2026, summarised in the security testing summary we share.)
  • Business continuity: the early-stage-vendor question, and the honest answer is mitigations rather than a certificate: your data exports on demand, an escrow option, and a defined support contact. Ask us to put those in the agreement.
  • Cyber insurance: to be obtained before production at scale.
  • Prod / non-prod separation: done, and enforced rather than agreed. A separate non-production database was stood up in July 2026 and is kept in sync, so schema changes are verified there first. Since 11 August 2026 preview and development builds connect to it and not to production, and the rule is enforced in code: a deployment that is not production refuses to build if it is pointed at the production database. Each build says in its own log which database it accepted, so the separation is checkable after the fact rather than assumed. The residual we still name: both are separate projects inside one cloud organisation, so this is environment separation, not account separation. See how we change the platform safely.
The risk register is shared, not summarised

We keep a live risk register and share it as it stands, including the entries that are still open. A questionnaire with no gaps in it takes you longer, because every answer then has to be tested.

Using it in your review

  1. Ask for the responses

    Request the HECVAT-Lite self-assessment through your First Six contact or procurement. We share it under NDA, along with our security overview, subprocessor list, and incident-response summary.

  2. Map it to your checklist

    The responses are organised by the standard HECVAT sections, so they line up with whatever internal checklist your team runs.

  3. Read the gaps, not just the ticks

    Each item is marked Yes, Partial, Planned, or No, with a note explaining it. The notes are where the real picture is.

  4. Set milestones for a pilot

    Where an item is still in progress, we can write it into the agreement as a milestone rather than treat it as a blocker.

Common questions

Do you have a completed HECVAT we can use?

Yes. We maintain pre-filled HECVAT-Lite responses that reflect the current state of the product, so your review can start straight away rather than waiting on us to fill in a blank form.

Are you SOC 2 or ISO 27001 certified?

Not yet, and we won't imply otherwise. Both are on the roadmap. The technical controls those frameworks look for are largely in place today; the independent attestation is what's still ahead.

Will you complete our own questionnaire instead?

Yes. If your institution has its own security questionnaire, we'll complete it as part of the assessment.

Where is student data stored?

In Australia, in the AWS Sydney region, isolated per tenant by row-level security. A small set of disclosed subprocessors handle diagnostic-only, scrubbed data.

How do you handle the change-management and secure-SDLC questions?

We keep a documented change-management standard covering authorisation, non-production testing, security review, reversibility, and logging, mapped to SOC 2 CC8. See how we change the platform safely.

Was this helpful?
Need more help?

The fastest answer is usually one question away.

Contact us
Edit this page on GitHub