Trust, shown with evidence
First Six holds welfare data about students, so security is the boundary the whole platform is built around, not a feature bolted on at the end. This page shares the program behind that claim: the policies we hold ourselves to, the controls we operate, the standards they map to, and the documents that prove it. Where an independent attestation is not in hand yet, this page says what stands in its place today and names precisely what is missing.
Assessments and attestations
6What is in place, and what is not yet
4Four things a security review asks for that we cannot answer with a certificate. Each one says what is actually operating today, then states the limitation in the terms you would use yourself. The second half is never the smaller half.
- An ISO 27001 and SOC 2 programme, running and mapped control by controlThe policies, the controls with their stated cadences, the audit programme, the register of times a control was not working, and the management review all exist and are on this site. Each control is mapped to the specific ISO 27001 Annex A control and SOC 2 Common Criteria it serves, and that mapping goes to your security team on request.Neither standard has been externally audited, so there is no certificate to send you and we will not imply one with a badge. What you can check is the mapping and the evidence behind each control.
- Adversarial testing that runs against this platform continuouslyWe run structured adversarial assessments and remediate what they find, and a daily automated sweep checks the database's access controls and fails loudly rather than quietly. The testing summary goes to your security team with the security pack.That testing has been ours rather than a third party's, which is weaker assurance than an external test, and we would rather say so than let the word testing imply otherwise. An independent penetration test is on the roadmap.
- Cyber insurance bound before any of your students are in the systemQuotes are in progress, and the trigger is written into the Pilot Terms rather than promised in a conversation: certificates of currency are provided before the first pilot with real students begins.No policy is in force today.
- Backups that have been restored, not just takenDaily managed snapshots, plus a daily off-site backup encrypted to a key held offline and ageing out within 30 days. It is drilled rather than assumed: a full end-to-end restore on 27 July 2026 came back complete and reconciled row for row against production.Recovery to an arbitrary moment, point-in-time recovery, is a paid database tier we have not taken yet, so today's worst-case recovery point is the last daily backup rather than the last few minutes. It is enabled at the first paying engagement.
Governance
Data security and privacy
Application security
Infrastructure security
A green dot means the control is operating and reviewed on its stated frequency. An amber dot means it is documented and scheduled but has not run yet — we mark those rather than hide them.
Applications · 7
Data · 10
- Encryption in transit
- Encryption at rest
- Australian data residency, disclosed cross-border flows
- Data classification and retention schedule
- Student self-service erasure
- Bounded backup retention (30-day age-out)
- Off-site encrypted backup
- Automated demo and visitor-data purges
- Small-cell suppression on analytics
- Data portability by construction
Identity and access control · 9
- SSO-only authentication
- Row-level security tenant isolation
- Role-based access with least privilege
- Staff scope confinement
- Server-side session revocation
- Staff leaver deactivation
- No standing provider access (break-glass only)
- Privileged function gating with anonymous-surface ratchet
- Quarterly access review
Cloud infrastructure · 8
Monitoring · 11
- Daily database security sweep
- Append-only immutable audit log
- Sensitive-record read auditing
- AI-assisted change attribution
- Sending-domain authentication (SPF, DKIM, DMARC)
- Staff anomaly detection
- Uptime monitoring and public status page
- Crisis-failure alerting
- PII-scrubbed error monitoring
- External heartbeat on the security sweep
- Log access restriction
People · 3
Business operations · 10
- Governed information security policy suite
- Quarterly management review
- Measurable security objectives
- Living, procurement-shared risk register
- Nonconformity and corrective-action register
- Evidence index and CI evidence ledger
- Incident response and breach notification
- Quarterly restore drills
- Business continuity and wind-down commitments
- Annual tabletop incident exercise
Product delivery · 7
Customers · 6
Subprocessors
Every third party that touches data — who they are, what they carry, and where they run — is published as a single canonical register, with 30 days’ notice of changes. We deliberately keep one copy rather than restating it here, so the list you read is never a stale duplicate.
Request access and we can share the full policy set, the assessment reports, and completed questionnaires — or answer yours directly. Procurement teams can also start from the pre-answered pack in the knowledge base.