Trust centre
Policies
18 written policies govern how First Six is built and run. Each page summarises what the policy commits us to, the controls that enforce it, and the standards it maps to. The full documents are available on request.
Governance
8- Information security policyThe top-level statement of how First Six protects the confidentiality, integrity, and availability of the student personal, welfare, and crisis data it processes for universities — and the umbrella over a governed suite of area policies with named owners and review cadences.Reviewed 13 July 2026
- ISMS scope statementDefines exactly what the security program covers: First Six Technologies Pty Ltd, the platform's applications, the production and non-production database projects, the deployments, the repository and CI, the listed subprocessors, and the data categories processed.Reviewed 13 July 2026
- ISMS context and interested partiesThe analysis behind the program: the external and internal issues shaping it, every interested party and what each requires — with an honest 'addressed?' column — and the improvement opportunities that follow.Reviewed 26 July 2026
- Security objectives and measurementTurns the policy's five promises into measurable objectives: what is measured, the target, the source, the cadence, and a permanent append-only measurement log.Reviewed 26 July 2026
- Management review procedureA quarterly, dated, written record that the security program's evidence was examined and what was decided, committed to the repository for a tamper-evident timestamp. The first review completed on 26 July 2026 — the ISMS go-live date.Reviewed 26 July 2026
- Internal audit programmeAnnual full-scope audits by evidence sampling — with the honest statement that a single-operator company cannot satisfy the auditor-independence requirement internally and must engage an external auditor.Reviewed 26 July 2026
- Statement of ApplicabilityAn honest self-assessment of all 93 ISO/IEC 27001:2022 Annex A controls, recording for each whether it is implemented, partial, not implemented, inherited from a cloud provider, or not applicable — with evidence pointers into the repository.Reviewed 13 July 2026
- Compliance postureAn honest self-assessment of where First Six stands against the frameworks universities check in procurement — HECVAT, SOC 2, ISO 27001, the Privacy Act and GDPR, FERPA, and WCAG — maintained to speed up vendor-security questionnaires, not as a certification.Reviewed 13 July 2026
Data security and privacy
4- Access control policyHow First Six decides who can see and do what — enforced in the database itself: row-level security on every table, deny by default, least privilege for staff, and no standing First Six access to identifiable student records. A model that exists in code, not an aspiration.Reviewed 13 July 2026
- Data retention and lifecycle policyWhat personal data First Six holds, how long it is kept, and how it is deleted across the whole lifecycle — active students, leavers, cohort end, and tenant exit. States the current reality including the gaps, the committed position, and what still needs building.Reviewed 13 July 2026
- Data subject rights policyHow requests to see, correct, export, or delete personal data are handled under the Australian Privacy Principles and GDPR-equivalent rights — including the sensitive edge cases a wellbeing platform must get right.Reviewed 13 July 2026
- Crisis detection: limits and responsibilityA counsel-reviewed, plainly worded statement of what the platform's automated crisis detection is, what it is not, and where the boundary of First Six's responsibility sits relative to the institution's own duty of care.Reviewed 22 July 2026
Application security
2- Change management policyHow changes to application code, database schema, access controls, configuration, and infrastructure are authorised, tested, reviewed, deployed, logged, and documented — the single named policy for secure-SDLC reviews.Reviewed 13 July 2026
- Accessibility self-assessment (WCAG 2.1 AA)The working self-assessment against WCAG 2.1 Level AA that sits behind the published VPAT: what is verified in code, what the known gaps are, and the process that treats accessibility as a release gate.Reviewed 28 July 2026
Infrastructure security
1Security operations
3- Phishing and social engineering policyMost attacks on a company this size do not break cryptography; they ask a person to open the door. This policy says what stops that here, and it is written around the fact that First Six is one person, so the usual control (a colleague noticing the request is strange) does not exist and the technical controls compensate for its absence rather than decorating it.Reviewed 11 Aug 2026
- Logging and monitoring policyWhat First Six logs, where it lives, how long it is kept, who can read it, and how trouble is detected — consolidating verified mechanisms into one policy and stating the open items honestly.Reviewed 13 July 2026
- Business continuity and wind-down policyWhat happens to an institution's data and service if First Six the company cannot continue — insolvency, founder incapacity, acquisition, or a voluntary wind-down. Honest about the solo-operator continuity risk.Reviewed 5 July 2026
Need the detail behind this page?
Request access and we can share the full policy set, assessment reports, and completed questionnaires under NDA — or answer your security questionnaire directly.