Trust centre
Documents
The paper trail. Public documents link straight through; the rest are shared on request to security@firstsix.com.au, generally under NDA.
Public
6Privacy policyThe binding student-facing policy, counsel-reviewed. Where any page and the policy differ, the policy governs.9 Aug 2026Public
Terms of serviceThe platform terms, including the availability clause and the wellbeing and emergency disclaimer.12 July 2026Public
Data processing agreement (reference terms)The reference DPA terms — export and deletion windows, backup age-out, subprocessor change notice. The signed agreement governs.2 Aug 2026Public
HECVAT posture summaryThe pre-answered vendor-security posture for university procurement, honest about the outstanding items.6 Aug 2026Public
Procurement packThe single entry point for a procurement or cyber review: what is in the assessment bundle and how to get it.9 Aug 2026Public
Accessibility conformance report (VPAT 2.5)The published accessibility commitment and the ACR posture: self-assessed, partially conformant, caveats stated.6 Aug 2026Public
Available on request
6Security testing summaryClass-level summary of the security assessments we have run: what each covered, the severity profile, and how remediation was verified. States plainly that none of the testing was independent.2 Aug 2026Request
Internal red-team penetration test reportThe internal, authorised, read-only assessment of production, with finding-level detail and remediation status. Shared under NDA so remediation detail never becomes an attack map.22 July 2026Request
White-box security assessmentAn authorised white-box application security assessment against a pinned commit, with per-finding remediation status. Shared under NDA.31 July 2026Request
Risk registerThe living register of 200-plus assessed risks, with the methodology and the acceptance criteria. Routinely shared with procurement so gaps are managed rather than hidden.11 Aug 2026Request
Statement of ApplicabilityThe honest self-assessed status of all 93 ISO/IEC 27001:2022 Annex A controls, with evidence pointers.13 July 2026Request
Pilot signing packSecurity and data handling summary, vendor security assessment answers, pilot charter and terms, and the counsel-approved DPA template, ready to sign.9 Aug 2026Request
Need one of the restricted documents?
Tell us which document and the institution you're assessing for. Reports that name findings, hosts, or third parties are shared under NDA so remediation detail never becomes an attack map.