Skip to content
Reviewed Jul 2026Knowledge base

ISMS scope statement

Adherence evidenced by 2 mapped controls

Defines exactly what the security program covers: First Six Technologies Pty Ltd, the platform's applications, the production and non-production database projects, the deployments, the repository and CI, the listed subprocessors, and the data categories processed.

Group
Governance
Owner
Founder
Last reviewed
13 July 2026

Request the full policy

What this policy commits us to

  • All application data at rest lives in Australia (AWS ap-southeast-2, Sydney) for both database projects.
  • Not collected: passwords (authentication is delegated to the institution's IdP via SSO), payment or card data, or health records beyond self-reported wellbeing.
  • Welfare and crisis data is named as the platform's most sensitive category and drives the strongest controls.
  • Physical and environmental controls are inherited in full from cloud providers, each holding its own SOC 2 / ISO attestation.
  • The institution's IdP and directory are explicitly out of scope as the institution's own systems.

Controls mapped to this policy

Mapping controls to the policy is how we check adherence. A green dot marks a control that is operating and traceable to evidence; an amber dot marks one that is documented and scheduled but has not run yet.

Standards mappings

Through its controls, this policy maps to the following standards and frameworks. Each entry states our real relationship with the standard.

ISO/IEC 27001:2022InfoSec complianceSelf-assessed

A full 93-control Annex A Statement of Applicability is maintained and honestly dispositioned, and the ISMS went live on 26 July 2026 with its first completed management review. Not certified: no external audit has occurred, the clause 9.2 internal audit is openly unmet, and the certification trigger (a named tender, funding, or first hire) was formally decided at the first management review.

  • A.7Physical controls (inherited from cloud providers)
  • A.5.23Security for use of cloud services

Everything mapped to this standard

Need the detail behind this page?

Request access and we can share the full policy set, assessment reports, and completed questionnaires under NDA — or answer your security questionnaire directly.