Skip to content
Reviewed Jul 2026Knowledge base
First Six Trust Centre

Trust, shown with evidence

First Six holds welfare data about students, so security is the boundary the whole platform is built around, not a feature bolted on at the end. This page shares the program behind that claim: the policies we hold ourselves to, the controls we operate, the standards they map to, and the documents that prove it. Where an independent attestation is not in hand yet, this page says what stands in its place today and names precisely what is missing.

Assessments and attestations

6

What is in place, and what is not yet

4

Four things a security review asks for that we cannot answer with a certificate. Each one says what is actually operating today, then states the limitation in the terms you would use yourself. The second half is never the smaller half.

  • An ISO 27001 and SOC 2 programme, running and mapped control by controlThe policies, the controls with their stated cadences, the audit programme, the register of times a control was not working, and the management review all exist and are on this site. Each control is mapped to the specific ISO 27001 Annex A control and SOC 2 Common Criteria it serves, and that mapping goes to your security team on request.Neither standard has been externally audited, so there is no certificate to send you and we will not imply one with a badge. What you can check is the mapping and the evidence behind each control.
  • Adversarial testing that runs against this platform continuouslyWe run structured adversarial assessments and remediate what they find, and a daily automated sweep checks the database's access controls and fails loudly rather than quietly. The testing summary goes to your security team with the security pack.That testing has been ours rather than a third party's, which is weaker assurance than an external test, and we would rather say so than let the word testing imply otherwise. An independent penetration test is on the roadmap.
  • Cyber insurance bound before any of your students are in the systemQuotes are in progress, and the trigger is written into the Pilot Terms rather than promised in a conversation: certificates of currency are provided before the first pilot with real students begins.No policy is in force today.
  • Backups that have been restored, not just takenDaily managed snapshots, plus a daily off-site backup encrypted to a key held offline and ageing out within 30 days. It is drilled rather than assumed: a full end-to-end restore on 27 July 2026 came back complete and reconciled row for row against production.Recovery to an arbitrary moment, point-in-time recovery, is a paid database tier we have not taken yet, so today's worst-case recovery point is the last daily backup rather than the last few minutes. It is enabled at the first paying engagement.

Policies

18All policies

Controls, with their cadences

76All controls

A green dot means the control is operating and reviewed on its stated frequency. An amber dot means it is documented and scheduled but has not run yet — we mark those rather than hide them.

Documents

12All documents
Privacy policyThe binding student-facing policy, counsel-reviewed. Where any page and the policy differ, the policy governs.9 Aug 2026Public
Terms of serviceThe platform terms, including the availability clause and the wellbeing and emergency disclaimer.12 July 2026Public
Data processing agreement (reference terms)The reference DPA terms — export and deletion windows, backup age-out, subprocessor change notice. The signed agreement governs.2 Aug 2026Public
HECVAT posture summaryThe pre-answered vendor-security posture for university procurement, honest about the outstanding items.6 Aug 2026Public

Subprocessors

Every third party that touches data — who they are, what they carry, and where they run — is published as a single canonical register, with 30 days’ notice of changes. We deliberately keep one copy rather than restating it here, so the list you read is never a stale duplicate.

The subprocessor register — why each one, in detail

Interested in learning more?

Request access and we can share the full policy set, the assessment reports, and completed questionnaires — or answer yours directly. Procurement teams can also start from the pre-answered pack in the knowledge base.