Skip to content
Reviewed Jul 2026Knowledge base
First Six Trust Centre

Trust, shown with evidence

First Six holds welfare data about students, so security is the boundary the whole platform is built around, not a feature bolted on at the end. This page shares the program behind that claim: the policies we hold ourselves to, the controls we operate, the standards they map to, and the documents that prove it. Where an independent attestation is not in hand yet, this page says what stands in its place today and names precisely what is missing.

Assessments and attestations

6

What is in place, and what is not yet

2

Some things a security review asks for cannot be answered with a certificate. Each one below says what is genuinely operating today, then states the limitation in the words you would use yourself. The limitation is never the shorter half.

  • An ISO 27001 and SOC 2 programme, running and mapped control by controlThe policies, the controls with their stated cadences, the audit programme, the register of times a control was not working, and the management review all exist and are on this site. Each control is mapped to the specific ISO 27001 Annex A control and SOC 2 Common Criteria it serves, and that mapping goes to your security team on request.Neither standard has been externally audited, so there is no certificate to send you and we will not imply one with a badge. What you can check is the mapping and the evidence behind each control.
  • Adversarial testing that runs against this platform continuouslyWe run structured adversarial assessments and remediate what they find, and a daily automated sweep checks the database's access controls and fails loudly rather than quietly. The testing summary goes to your security team with the security pack.That testing has been ours rather than a third party's, which is weaker assurance than an external test, and we would rather say so than let the word testing imply otherwise. An independent penetration test is on the roadmap.

Policies

18All policies

Controls, with their cadences

76All controls

A green dot means the control is operating and reviewed on its stated frequency. An amber dot means it is documented and scheduled but has not run yet — we mark those rather than hide them.

Documents

12All documents
Privacy policyThe binding student-facing policy, reviewed in-house rather than by external counsel. Where any page and the policy differ, the policy governs.9 Aug 2026Public
Terms of serviceThe platform terms, including the availability clause and the wellbeing and emergency disclaimer.12 July 2026Public
Data processing agreement (reference terms)The reference DPA terms — export and deletion windows, backup age-out, subprocessor change notice. The signed agreement governs.2 Aug 2026Public
HECVAT posture summaryThe pre-answered vendor-security posture for university procurement, honest about the outstanding items.6 Aug 2026Public

Subprocessors

Every third party that touches data — who they are, what they carry, and where they run — is published as a single canonical register, with 30 days’ notice of changes. We deliberately keep one copy rather than restating it here, so the list you read is never a stale duplicate.

The subprocessor register — why each one, in detail

Interested in learning more?

Request access and we can share the full policy set, the assessment reports, and completed questionnaires — or answer yours directly. Procurement teams can also start from the pre-answered pack in the knowledge base.