Trust, shown with evidence
First Six holds welfare data about students, so security is the boundary the whole platform is built around, not a feature bolted on at the end. This page shares the program behind that claim: the policies we hold ourselves to, the controls we operate, the standards they map to, and the documents that prove it. Where an independent attestation is not in hand yet, this page says what stands in its place today and names precisely what is missing.
Assessments and attestations
6What is in place, and what is not yet
2Some things a security review asks for cannot be answered with a certificate. Each one below says what is genuinely operating today, then states the limitation in the words you would use yourself. The limitation is never the shorter half.
- An ISO 27001 and SOC 2 programme, running and mapped control by controlThe policies, the controls with their stated cadences, the audit programme, the register of times a control was not working, and the management review all exist and are on this site. Each control is mapped to the specific ISO 27001 Annex A control and SOC 2 Common Criteria it serves, and that mapping goes to your security team on request.Neither standard has been externally audited, so there is no certificate to send you and we will not imply one with a badge. What you can check is the mapping and the evidence behind each control.
- Adversarial testing that runs against this platform continuouslyWe run structured adversarial assessments and remediate what they find, and a daily automated sweep checks the database's access controls and fails loudly rather than quietly. The testing summary goes to your security team with the security pack.That testing has been ours rather than a third party's, which is weaker assurance than an external test, and we would rather say so than let the word testing imply otherwise. An independent penetration test is on the roadmap.
Governance
Data security and privacy
Application security
Infrastructure security
A green dot means the control is operating and reviewed on its stated frequency. An amber dot means it is documented and scheduled but has not run yet — we mark those rather than hide them.
Applications · 7
Data · 10
- Encryption in transit
- Encryption at rest
- Australian data residency, disclosed cross-border flows
- Data classification and retention schedule
- Student self-service erasure
- Bounded backup retention (30-day age-out)
- Off-site encrypted backup
- Automated demo and visitor-data purges
- Small-cell suppression on analytics
- Data portability by construction
Identity and access control · 9
- SSO-only authentication
- Row-level security tenant isolation
- Role-based access with least privilege
- Staff scope confinement
- Server-side session revocation
- Staff leaver deactivation
- No standing provider access (break-glass only)
- Privileged function gating with anonymous-surface ratchet
- Quarterly access review
Cloud infrastructure · 8
Monitoring · 11
- Daily database security sweep
- Append-only immutable audit log
- Sensitive-record read auditing
- AI-assisted change attribution
- Sending-domain authentication (SPF, DKIM, DMARC)
- Staff anomaly detection
- Uptime monitoring and public status page
- Crisis-failure alerting
- PII-scrubbed error monitoring
- External heartbeat on the security sweep
- Log access restriction
People · 3
Business operations · 10
- Governed information security policy suite
- Quarterly management review
- Measurable security objectives
- Living, procurement-shared risk register
- Nonconformity and corrective-action register
- Evidence index and CI evidence ledger
- Incident response and breach notification
- Quarterly restore drills
- Business continuity and wind-down commitments
- Annual tabletop incident exercise
Product delivery · 7
Customers · 6
Subprocessors
Every third party that touches data — who they are, what they carry, and where they run — is published as a single canonical register, with 30 days’ notice of changes. We deliberately keep one copy rather than restating it here, so the list you read is never a stale duplicate.
Request access and we can share the full policy set, the assessment reports, and completed questionnaires — or answer yours directly. Procurement teams can also start from the pre-answered pack in the knowledge base.