Skip to content
Reviewed Jul 2026Knowledge base

Tenant exit and export

Operating, reviewed on its stated cadence

On exit, whether the customer's or ours, each institution receives its full machine-readable export before anything is deleted, ending with hard deletion and, on request, a certificate of destruction. The tooling exists and has been exercised rather than described: a scratch tenant was provisioned, exported across every table, dry-run, then torn down end to end, with the dry-run counts matching the real run exactly and the certificate-of-destruction record written to an append-only log that survives the deletion. Legal holds are enforced by the database rather than by the operator remembering: a student under an unreleased hold aborts the whole teardown. Two steps do stay manual and are named rather than implied: sweeping stored files, which the teardown does not touch, and preserving records under the mandatory-reporting retention floor, which nothing yet enforces.

Category
Customers
Owner
Founder
Last verified
25 July 2026
Evaluation frequency
Event-driven

Standards mappings

This control maps to the following standards and frameworks. Each entry states our real relationship with the standard, and the specific requirements this control helps satisfy.

HECVAT (Higher Education Community Vendor Assessment Toolkit)Higher educationSelf-assessed

A full HECVAT answer pack is maintained and kept current for university procurement, deliberately honest about gaps (no SOC 2 or ISO attestation, no independent penetration test, PITR not enabled). It is a vendor self-assessment, not an externally validated response, backed by a full internal HECVAT-aligned self-audit.

  • ExitVendor viability and data exit

Everything mapped to this standard

Australian Privacy Act 1988 (APPs, incl. the NDB scheme)PrivacyApplicable law

The primary legal regime. APP 8 drives the residency objective and every disclosed cross-border flow, APP 11 drives retention and erasure, and the Notifiable Data Breaches scheme's assessment clock is built into the incident runbook with OAIC contacts documented. The privacy policy, terms, and DPA template are reviewed and approved in-house; First Six has no external counsel engaged.

  • APP 11.2Destruction and de-identification

Everything mapped to this standard

Policy mapping

The written standard this control enforces:

Need the detail behind this page?

Request access and we can share the full policy set, assessment reports, and completed questionnaires under NDA — or answer your security questionnaire directly.