Compliance posture
An honest self-assessment of where First Six stands against the frameworks universities check in procurement — HECVAT, SOC 2, ISO 27001, the Privacy Act and GDPR, FERPA, and WCAG — maintained to speed up vendor-security questionnaires, not as a certification.
What this policy commits us to
- SOC 2: not started — controls documented and self-assessed, not audited.
- ISO 27001: documented, with operating records accruing; the missing pieces are an independent auditor and months of records before a certification audit.
- Privacy Act / GDPR: privacy policy, terms, and DPA counsel-reviewed and approved, with the audit-trail erasure carve-out disclosed.
- WCAG 2.1 AA: VPAT published, partially conformant, pending third-party verification.
Controls mapped to this policy
Mapping controls to the policy is how we check adherence. A green dot marks a control that is operating and traceable to evidence; an amber dot marks one that is documented and scheduled but has not run yet.
Standards mappings
Through its controls, this policy maps to the following standards and frameworks. Each entry states our real relationship with the standard.
ISO/IEC 27001:2022InfoSec complianceSelf-assessed
A full 93-control Annex A Statement of Applicability is maintained and honestly dispositioned, and the ISMS went live on 26 July 2026 with its first completed management review. Not certified: no external audit has occurred, the clause 9.2 internal audit is openly unmet, and the certification trigger (a named tender, funding, or first hire) was formally decided at the first management review.
- A.8.29Security testing in development and acceptance
- 6.1Actions to address risks and opportunities
- 8.2Information security risk assessment
SOC 2 (AICPA Trust Services Criteria)InfoSec complianceAligned
Controls are explicitly mapped to the criteria — change management to CC8, logging and monitoring to CC7, access control to CC6 — but no SOC 2 attestation of any type exists. Independent attestation is a tracked roadmap item, offered as a contractual milestone for a pilot.
- CC3Risk assessment
HECVAT (Higher Education Community Vendor Assessment Toolkit)Higher educationSelf-assessed
A full HECVAT answer pack is maintained and kept current for university procurement, deliberately honest about gaps (no SOC 2 or ISO attestation, no independent penetration test, PITR not enabled). It is a vendor self-assessment, not an externally validated response, backed by a full internal HECVAT-aligned self-audit.
- Pen testingThird-party penetration testing — answered honestly: not independently, yet
Request access and we can share the full policy set, assessment reports, and completed questionnaires under NDA — or answer your security questionnaire directly.