HECVAT and vendor security reviews
The HECVATHigher Education Community Vendor Assessment Toolkit. The security questionnaire many universities run on a new vendor. is how most universities assess a new vendor's security. Rather than ask you to send a blank questionnaire and wait, we keep a pre-filled HECVAT-Lite self-assessment that reflects the current state of First Six.
It records what is and isn't in place. Where a control isn't there yet, the response says so and gives the plan, rather than an optimistic "yes" that a pen test would later contradict.
The short version
First Six meets or exceeds the technical controls a standard HECVAT looks for. The open items are independent attestation and process maturity: the kind of thing that takes an external audit or time as a company, not an engineering change. We propose those as milestones for a pilot rather than blockers.
Headline answers
| Area | Status |
|---|---|
| Data residency (Australia, AWS Sydney) | Yes |
| Encryption in transit and at rest | Yes |
| Single sign-on with institution-enforced MFA | Yes |
| Row-level tenant isolation | Yes |
| Append-only audit logging | Yes |
| Data minimisation with small-cell suppression | Yes |
| Student data used to train AI | No |
| Automated crisis detection (disclosed, with limits and duty-of-care boundary) | Yes |
| Documented change management | Yes |
| Separate prod / non-prod environments | Yes, enforced in code (a non-production deployment pointed at the production database refuses to start, so a misconfigured preview fails rather than reading real data) |
| Accessibility (WCAG 2.1 AA, VPAT 2.5 self-assessed) | Partial: ACR published 3 August 2026, external validation ahead |
| SOC 2 / ISO 27001 | On the roadmap (ISO 27001 is documented end to end; the operating records and attestation are what remain) |
| Third-party penetration test | Planned |
| Data Processing Agreement | Yes: a signable template, current as at 13 August 2026, shared with the pack |
The full response set walks the standard HECVAT sections: company and documentation, data handling and privacy, authentication and access control, application and infrastructure security, and hosting and business continuity.
The vendor entity named in the company-and-documentation section is First Six Technologies Pty Ltd (ACN 699 938 817, ABN 19 699 938 817), registered in Queensland, Australia, trading as First Six.
What is still outstanding
Five items, and you would find all of them in a review anyway:
- SOC 2 / ISO 27001: not yet certified. The ISO 27001 documentation set (scope, statement of applicability across all 93 Annex A controls, objectives, audit programme) exists end to end; what is missing is operating records over time and the external attestation, and that distinction is exactly how we would put it to your auditor too.
- Third-party penetration test: planned, and we're happy to make it a contractual condition of a pilot. (Five vendor-run adversarial assessments ran between late June and the end of July 2026: 129 verified findings, four critical, all closed and re-verified against production on 2 August 2026, summarised in the security testing summary we share.)
- Business continuity: the early-stage-vendor question, and the honest answer is mitigations rather than a certificate: your data exports on demand, an escrow option, and a defined support contact. Ask us to put those in the agreement.
- Cyber insurance: to be obtained before production at scale.
- Prod / non-prod separation: done, and enforced rather than agreed. A separate non-production database was stood up in July 2026 and is kept in sync, so schema changes are verified there first. Since 11 August 2026 preview and development builds connect to it and not to production, and the rule is enforced in code: a deployment that is not production refuses to build if it is pointed at the production database. Each build says in its own log which database it accepted, so the separation is checkable after the fact rather than assumed. The residual we still name: both are separate projects inside one cloud organisation, so this is environment separation, not account separation. See how we change the platform safely.
We keep a live risk register and share it as it stands, including the entries that are still open. A questionnaire with no gaps in it takes you longer, because every answer then has to be tested.
Using it in your review
- Ask for the responses
Request the HECVAT-Lite self-assessment through your First Six contact or procurement. We share it under NDA, along with our security overview, subprocessor list, and incident-response summary.
- Map it to your checklist
The responses are organised by the standard HECVAT sections, so they line up with whatever internal checklist your team runs.
- Read the gaps, not just the ticks
Each item is marked Yes, Partial, Planned, or No, with a note explaining it. The notes are where the real picture is.
- Set milestones for a pilot
Where an item is still in progress, we can write it into the agreement as a milestone rather than treat it as a blocker.
Common questions
Do you have a completed HECVAT we can use?
Yes. We maintain pre-filled HECVAT-Lite responses that reflect the current state of the product, so your review can start straight away rather than waiting on us to fill in a blank form.
Are you SOC 2 or ISO 27001 certified?
Not yet, and we won't imply otherwise. Both are on the roadmap. The technical controls those frameworks look for are largely in place today; the independent attestation is what's still ahead.
Will you complete our own questionnaire instead?
Yes. If your institution has its own security questionnaire, we'll complete it as part of the assessment.
Where is student data stored?
In Australia, in the AWS Sydney region, isolated per tenant by row-level security. A small set of disclosed subprocessors handle diagnostic-only, scrubbed data.
How do you handle the change-management and secure-SDLC questions?
We keep a documented change-management standard covering authorisation, non-production testing, security review, reversibility, and logging, mapped to SOC 2 CC8. See how we change the platform safely.
Related
The fastest answer is usually one question away.