Information security

How we look after the data you trust us with

Six & Flow Ltd has held ISO/IEC 27001 certification since February 2023. This page sets out what the certificate covers, how our controls work day to day, and how your security team can get the evidence it needs.

Certificate of registration
ISO/IEC 27001:2022
Information Security Management System
Valid
Certificate no.
IT1324
Certification body
QAS International
First certified
6 February 2023
Valid until
6 February 2027
86 / 93
Annex A controls adopted. The 7 exclusions are justified in our Statement of Applicability
0
Security incidents or personal data breaches in the past three years
£2m
Network security and privacy liability insurance
Jun 2026
Most recent business continuity exercise, run against a full HubSpot outage
01
Certification scope

What the certificate covers

A certificate is only as useful as its scope, so here it is in full, exactly as it appears on the certificate issued by QAS International.

Certified scope
The creation of digitally led systems to accelerate revenue growth through marketing and sales performance, from CRM to marketing campaigns, design and development and revenue operations, in accordance with our Statement of Applicability v3.

Certified entity

Six & Flow Ltd, Swan Building, Swan Street, Manchester M4 5JW

Other Group companies

The certificate does not currently cover other Six & Flow Group companies, including our teams in Ireland, the Netherlands, South Africa and Canada.

02
How we protect data

The controls behind the certificate

Each area below lists what we actually do, the ISO/IEC 27001 Annex A controls it maps to, and the internal policy that governs it.

Access

Every person has a named account with role-based, least-privilege permissions. Multi-factor authentication is enforced on all critical systems and single sign-on is used wherever a platform supports it. Administrator rights sit with a small number of named people, never on shared accounts, and are reviewed against a privileged access register.

A.5.15A.8.2A.8.5ISP15 · ISP29

Encryption

Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256 inside the platforms we use. Every company laptop has full-disk encryption enforced centrally, and client data is never kept on removable media.

A.8.24A.8.1A.7.10ISP06

Devices

Laptops are enrolled in Jamf device management with endpoint detection and response, DNS filtering and enforced screen lock. Security patches are pushed automatically, and a lost or stolen device is locked or wiped within 24 hours of being reported.

A.8.1A.8.7A.8.9ISP06

Testing and email defence

Our IT partner, DARE, runs ongoing vulnerability assessments and penetration testing across our corporate estate and applications, with no open findings. Staff face phishing simulations every year, and our domain is protected by SPF, DKIM, DMARC and Google Workspace data loss prevention.

A.8.8A.8.12A.8.23ISP06 · ISP16

Backup and recovery

Google Workspace is backed up daily by CloudAlly with point-in-time restore. CRM and project data are protected by HubSpot and ClickUp platform backups, and all source code is version controlled in private GitHub repositories. Continuity plans are tested every year: the June 2026 exercise restored service after a simulated HubSpot outage in under three hours.

A.8.13A.5.29A.5.30ISP20 · ISP28 · ISP32

Incident response

Every security event is logged, investigated and closed out against an incident register, with lessons fed back into the risk assessment. If personal data is involved we assess the risk to individuals, report notifiable breaches to the ICO within 72 hours and tell affected clients without undue delay.

A.5.24A.5.26A.5.27ISP19 · ISP30

People

Every hire is reference checked, with basic DBS checks where a role needs one. New starters complete security training before they get system access, everyone refreshes it every year, and everyone signs a confidentiality agreement. Access and equipment are recovered on the day someone leaves.

A.6.1A.6.3A.6.6ISP22 · ISP38

Suppliers

Suppliers are ranked by how critical they are to client delivery and checked before onboarding, including their certifications and data processing terms. Data processing agreements are in place with every sub-processor, and transfers outside the UK and EEA rely on adequacy decisions or Standard Contractual Clauses.

A.5.19A.5.20A.5.22ISP18 · ISP31 · ISP34

Governance

The CEO is accountable for the management system. Information security is a standing item at the weekly management meeting, risks are assessed and treated on a defined method, and an internal audit and formal management review run every year ahead of the external audit.

A.5.1A.5.35A.5.36ISP03 · ISP04 · ISP09 · ISP10

Premises

Our Manchester office is open to staff only, through keypad entry with an individual code per person. Physical security is risk assessed every year. We hold no paper records: client information lives in managed cloud platforms, and retired equipment is securely wiped before disposal.

A.7.1A.7.2A.7.14ISP35
03
Document library

Evidence for your review

Public documents download straight away. Detailed policies are released to verified reviewers once a mutual NDA is in place, usually within one working day.

DocumentRefLast reviewedAccessAction
ISO/IEC 27001:2022 certificate
QAS International, certificate IT1324
IT1324 Feb 2026 Public Request ISO/IEC 27001:2022 certificate
Information Security Policy
Our policy statement and security objectives
ISP03 v4 Jan 2026 Public Request Information Security Policy
Scope of the ISMS
How the certification boundary was set
ISP02 v2 Jul 2025 Public Request Scope of the ISMS
Data Protection Policy
Processing, retention and breach handling
ISP30 v2 Jan 2026 On request Request Data Protection Policy
Cyber liability insurance certificate
Network security and privacy liability, £2m limit
Insurance [Policy year] On request Request Cyber liability insurance certificate
Data processing agreement
Our standard terms as your processor
DPA [Date] On request Request Data processing agreement
Statement of Applicability
All 93 Annex A controls with status and evidence
SoA v3 Feb 2026 Under NDA Request Statement of Applicability
Access Control Policy
User registration, privileges and reviews
ISP15 v3 Jan 2026 Under NDA Request Access Control Policy
Technology Control and MDM Policy
Encryption, patching and device compliance
ISP06 v1 Oct 2025 Under NDA Request Technology Control and MDM Policy
Backup Procedure
What is backed up, where and how often
ISP28 v1 Jul 2025 Under NDA Request Backup Procedure
Business Continuity Procedure
Keeping client delivery running
ISP20 v3 Feb 2026 Under NDA Request Business Continuity Procedure
Business continuity exercise report
Simulated HubSpot outage, timeline and review
BC test Jun 2026 Under NDA Request Business continuity exercise report
Disaster Recovery Policy
Recovery scenarios and responsibilities
ISP32 v2 Jan 2026 Under NDA Request Disaster Recovery Policy
Incident Management Control
Detection, response and lessons learned
ISP19 v2 Oct 2025 Under NDA Request Incident Management Control
Supplier Security Policy
Assessing and monitoring third parties
ISP18 v2 Jan 2026 Under NDA Request Supplier Security Policy
Human Resource Security
Screening, onboarding and leavers
ISP22 v3 Jan 2026 Under NDA Request Human Resource Security
Secure System Engineering Principles
How we build and change systems
ISP17 v2 Oct 2025 Under NDA Request Secure System Engineering Principles

Risk registers, asset inventories and access logs stay internal. We walk reviewers through them on a call when needed.

04
Sub-processors

The platforms we run on

The services that may store, process or give access to client information.

Where a provider offers UK or EU hosting, data for UK and EU clients stays in that region. Where a provider offers Canadian hosting, Canadian client data stays in Canada. Otherwise data is processed in the United States under UK adequacy regulations or EU Standard Contractual Clauses. Every provider is assessed against our Supplier Security Policy (ISP18) before onboarding and is covered by a data processing agreement.

Show regions for organisations in:

Client delivery

Client delivery sub-processors
ProviderProcessing activityData categoriesData regionUK and EUCanadaUnited StatesControls
HubSpotClient-provisionedSix & Flow tenantCritical criticality

Cloud CRM and marketing automation platform. System of record for client contact, company, deal and service data. Six & Flow configures and administers client portals on the client's documented instructions.

EU (Germany)Region is fixed when a portal is created. Client-owned portals follow the client's own choice. EU (Germany)Region is fixed when a portal is created. Client-owned portals follow the client's own choice.CanadaRegion is fixed when a portal is created. Client-owned portals follow the client's own choice.USRegion is fixed when a portal is created. Client-owned portals follow the client's own choice.
A.5.19A.5.20A.5.22A.5.23
FlowConnect LtdClient-provisionedCritical criticality

Group integration company acting as sub-processor. Designs, builds and operates integrations between client systems under a written sub-processor agreement with Six & Flow Ltd.

UKIntegration runtimes run on the hosting providers listed on this page and follow their regions. UKIntegration runtimes run on the hosting providers listed on this page and follow their regions.UKOutside client's regionIntegration runtimes run on the hosting providers listed on this page and follow their regions.UKOutside client's regionIntegration runtimes run on the hosting providers listed on this page and follow their regions.
A.5.19A.5.20A.5.22
n8nClient-provisionedSix & Flow tenantHigh criticality

Workflow automation platform that orchestrates and transforms data flows between client systems.

EU (Germany)n8n Cloud is hosted in the EU only. Self-hosted instances follow their hosting provider's region. EU (Germany)n8n Cloud is hosted in the EU only. Self-hosted instances follow their hosting provider's region.EU (Germany)Outside client's regionn8n Cloud is hosted in the EU only. Self-hosted instances follow their hosting provider's region.EU (Germany)Outside client's regionn8n Cloud is hosted in the EU only. Self-hosted instances follow their hosting provider's region.
A.5.19A.5.20A.5.22A.5.23
ClickUpSix & Flow tenantHigh criticality

Work management platform for project plans, tasks and collaboration with clients on delivery.

EUSingle Six & Flow workspace. EU hosting depends on plan; workspaces are US-hosted by default. EUSingle Six & Flow workspace. EU hosting depends on plan; workspaces are US-hosted by default.EUOutside client's regionSingle Six & Flow workspace. EU hosting depends on plan; workspaces are US-hosted by default.EUOutside client's regionSingle Six & Flow workspace. EU hosting depends on plan; workspaces are US-hosted by default.
A.5.19A.5.20A.5.22A.5.23

Hosting, data and AI

Hosting, data and AI sub-processors
ProviderProcessing activityData categoriesData regionUK and EUCanadaUnited StatesControls
TalkdeskClient-provisionedSix & Flow tenantHigh criticality

Cloud contact-centre platform. We build and support integrations between client Talkdesk instances and their CRM and service systems.

EUInstances are usually client-owned, so the region follows the client's Talkdesk contract. EUInstances are usually client-owned, so the region follows the client's Talkdesk contract.CanadaInstances are usually client-owned, so the region follows the client's Talkdesk contract.USInstances are usually client-owned, so the region follows the client's Talkdesk contract.
A.5.19A.5.20A.5.22A.5.23
Google Cloud PlatformClient-provisionedSix & Flow tenantCritical criticality

Infrastructure as a service for hosting applications, databases, file storage and nightly backups.

UK (London)Region is selected per project when resources are created. UK (London)Region is selected per project when resources are created.Canada (Montréal)Region is selected per project when resources are created.USRegion is selected per project when resources are created.
A.5.19A.5.20A.5.22A.5.23A.8.13
Amazon Web ServicesClient-provisionedSix & Flow tenantCritical criticality

Infrastructure as a service for hosting applications, databases and file storage.

UK (London)Region is selected per account and resource when created. UK (London)Region is selected per account and resource when created.Canada (Central)Region is selected per account and resource when created.USRegion is selected per account and resource when created.
A.5.19A.5.20A.5.22A.5.23A.8.13
SupabaseClient-provisionedSix & Flow tenantHigh criticality

Managed Postgres database, authentication and file storage for applications we build and operate.

UK (London)Region is selected per project and cannot be changed afterwards. UK (London)Region is selected per project and cannot be changed afterwards.Canada (Central)Region is selected per project and cannot be changed afterwards.USRegion is selected per project and cannot be changed afterwards.
A.5.19A.5.20A.5.22A.5.23
MongoDB AtlasClient-provisionedSix & Flow tenantHigh criticality

Managed document database for applications we build and operate.

UK (London)Region is selected per cluster. UK (London)Region is selected per cluster.CanadaRegion is selected per cluster.USRegion is selected per cluster.
A.5.19A.5.20A.5.22A.5.23
PineconeClient-provisionedSix & Flow tenantHigh criticality

Managed vector database storing embeddings for AI search and retrieval.

EU (Ireland)No Canadian region is offered, so Canadian client data is processed in the US. EU (Ireland)No Canadian region is offered, so Canadian client data is processed in the US.USOutside client's regionNo Canadian region is offered, so Canadian client data is processed in the US.USNo Canadian region is offered, so Canadian client data is processed in the US.
A.5.19A.5.20A.5.22A.5.23
AnthropicClient-provisionedSix & Flow tenantHigh criticality

AI model provider (Claude) used in client solutions and internal tools. Inputs and outputs under commercial terms are not used to train models.

USDirect API processing is US-based. EU processing is possible by calling Claude through AWS Bedrock or Google Vertex AI in an EU region. USOutside client's regionDirect API processing is US-based. EU processing is possible by calling Claude through AWS Bedrock or Google Vertex AI in an EU region.USOutside client's regionDirect API processing is US-based. EU processing is possible by calling Claude through AWS Bedrock or Google Vertex AI in an EU region.USDirect API processing is US-based. EU processing is possible by calling Claude through AWS Bedrock or Google Vertex AI in an EU region.
A.5.19A.5.20A.5.22A.5.23
OpenAIClient-provisionedSix & Flow tenantHigh criticality

AI model provider used in FlowLM, our internal knowledge tool, and in client solutions. API inputs and outputs are not used to train models by default.

EU (data residency)EU data residency applies only to projects created with it enabled. EU (data residency)EU data residency applies only to projects created with it enabled.USOutside client's regionEU data residency applies only to projects created with it enabled.USEU data residency applies only to projects created with it enabled.
A.5.19A.5.20A.5.22A.5.23
AircallClient-provisionedMedium criticality

Cloud telephony platform. Call metadata and recordings feed FlowLM.

USConfirm whether the Six & Flow account uses EU storage. USOutside client's regionConfirm whether the Six & Flow account uses EU storage.USOutside client's regionConfirm whether the Six & Flow account uses EU storage.USConfirm whether the Six & Flow account uses EU storage.
A.5.19A.5.20A.5.22A.5.23

Collaboration and sales

Collaboration and sales sub-processors
ProviderProcessing activityData categoriesData regionUK and EUCanadaUnited StatesControls
Google WorkspaceSix & Flow tenantCritical criticality

Productivity suite for email, calendars, documents and file storage, including files shared with clients.

EUSingle Six & Flow tenant. EU location applies only if a data regions policy is set; otherwise data is stored globally. EUSingle Six & Flow tenant. EU location applies only if a data regions policy is set; otherwise data is stored globally.EUOutside client's regionSingle Six & Flow tenant. EU location applies only if a data regions policy is set; otherwise data is stored globally.EUOutside client's regionSingle Six & Flow tenant. EU location applies only if a data regions policy is set; otherwise data is stored globally.
A.5.19A.5.20A.5.22A.5.23
Microsoft 365Six & Flow tenantHigh criticality

Productivity suite used by some teams for email, documents and collaboration with clients who work in Microsoft.

UKTenant data location follows the country the tenant was created in. Group entities with their own tenants follow their own location. UKTenant data location follows the country the tenant was created in. Group entities with their own tenants follow their own location.UKOutside client's regionTenant data location follows the country the tenant was created in. Group entities with their own tenants follow their own location.UKOutside client's regionTenant data location follows the country the tenant was created in. Group entities with their own tenants follow their own location.
A.5.19A.5.20A.5.22A.5.23
SlackSix & Flow tenantHigh criticality

Messaging platform for internal channels and shared channels with clients.

UKUK data residency needs a Business+ or Enterprise plan; otherwise data is stored in the US. UKUK data residency needs a Business+ or Enterprise plan; otherwise data is stored in the US.UKOutside client's regionUK data residency needs a Business+ or Enterprise plan; otherwise data is stored in the US.UKOutside client's regionUK data residency needs a Business+ or Enterprise plan; otherwise data is stored in the US.
A.5.19A.5.20A.5.22A.5.23
VidyardSix & Flow tenantMedium criticality

Video hosting platform for recorded walkthroughs, demos and training shared with clients.

CanadaVidyard is Canada-based and hosting is assumed to be in Canada. CanadaOutside client's regionVidyard is Canada-based and hosting is assumed to be in Canada.CanadaVidyard is Canada-based and hosting is assumed to be in Canada.CanadaOutside client's regionVidyard is Canada-based and hosting is assumed to be in Canada.
A.5.19A.5.20A.5.22A.5.23
Apollo.ioSix & Flow tenantMedium criticality

Sales intelligence platform for prospect research and business contact enrichment.

USUS-hosted only. USOutside client's regionUS-hosted only.USOutside client's regionUS-hosted only.USUS-hosted only.
A.5.19A.5.20A.5.22A.5.23

Security, backup and operations

Security, backup and operations sub-processors
ProviderProcessing activityData categoriesData regionUK and EUCanadaUnited StatesControls
CloudAllySix & Flow tenantHigh criticality

Backup as a service providing daily, point-in-time recoverable backups of Google Workspace.

UKBackup storage region is chosen when the account is set up. UKBackup storage region is chosen when the account is set up.UKOutside client's regionBackup storage region is chosen when the account is set up.UKOutside client's regionBackup storage region is chosen when the account is set up.
A.5.19A.5.20A.5.22A.5.23A.8.13
GitHubSix & Flow tenantHigh criticality

Source code hosting and version control for software we build, with access through named accounts.

USEU hosting needs GitHub Enterprise Cloud with data residency. USOutside client's regionEU hosting needs GitHub Enterprise Cloud with data residency.USOutside client's regionEU hosting needs GitHub Enterprise Cloud with data residency.USEU hosting needs GitHub Enterprise Cloud with data residency.
A.5.19A.5.20A.5.22A.5.23A.8.4
LastPassSix & Flow tenantHigh criticality

Enterprise password manager for storing and sharing credentials on a least-privilege basis.

EUData centre region is set when the account is created. EUData centre region is set when the account is created.EUOutside client's regionData centre region is set when the account is created.EUOutside client's regionData centre region is set when the account is created.
A.5.19A.5.20A.5.22A.5.23A.5.17
JamfSix & Flow tenantHigh criticality

Device management and endpoint protection for company laptops: encryption, patching, configuration and remote lock or wipe.

EU (Germany)Confirm the Jamf Cloud instance region. EU (Germany)Confirm the Jamf Cloud instance region.EU (Germany)Outside client's regionConfirm the Jamf Cloud instance region.EU (Germany)Outside client's regionConfirm the Jamf Cloud instance region.
A.5.19A.5.20A.5.22A.5.23A.8.1A.8.7
DARESix & Flow tenantHigh criticality

Managed IT service provider delivering IT support, vulnerability assessments and penetration testing.

UKUK-based managed service. UKUK-based managed service.UKOutside client's regionUK-based managed service.UKOutside client's regionUK-based managed service.
A.5.19A.5.20A.5.22A.8.8
XeroSix & Flow tenantMedium criticality

Cloud accounting platform for invoicing and financial records. Holds client billing contacts only.

USXero hosts customer data in the US. USOutside client's regionXero hosts customer data in the US.USOutside client's regionXero hosts customer data in the US.USXero hosts customer data in the US.
A.5.19A.5.20A.5.22A.5.23
DeelSix & Flow tenantMedium criticality

HR, payroll and contractor management. Holds employee data only; no client data.

USUS-hosted. USOutside client's regionUS-hosted.USOutside client's regionUS-hosted.USUS-hosted.
A.5.19A.5.20A.5.22A.5.23
05
Data protection

Privacy and personal data

Regulation

We work to UK GDPR, EU GDPR and the Data Protection Act 2018, and act as processor for client data under a written data processing agreement.

ICO registration

Six & Flow Ltd is registered with the Information Commissioner's Office, reference ZB851933.

Retention

Data not tied to a client contract or employment is kept for two years at most. Client data is deleted or returned when an engagement ends.

Your rights

Subject access requests are answered within 30 days. Where we act for a client, we pass the request to them and help them respond.

Security reviews

Have a questionnaire to complete?

Send it over with your document request. We answer most standard questionnaires within five working days.

Start a security review
Responsible disclosure

Found a vulnerability?

Tell us privately and give us a reasonable chance to fix it before you share it. We will confirm receipt within two working days.

security@sixandflow.com