Six & Flow Ltd has held ISO/IEC 27001 certification since February 2023. This page sets out what the certificate covers, how our controls work day to day, and how your security team can get the evidence it needs.
Annex A controls adopted. The 7 exclusions are justified in our Statement of Applicability
0
Security incidents or personal data breaches in the past three years
£2m
Network security and privacy liability insurance
Jun 2026
Most recent business continuity exercise, run against a full HubSpot outage
01
Certification scope
What the certificate covers
A certificate is only as useful as its scope, so here it is in full, exactly as it appears on the certificate issued by QAS International.
Certified scope
The creation of digitally led systems to accelerate revenue growth through marketing and sales performance, from CRM to marketing campaigns, design and development and revenue operations, in accordance with our Statement of Applicability v3.
Certified entity
Six & Flow Ltd, Swan Building, Swan Street, Manchester M4 5JW
Other Group companies
The certificate does not currently cover other Six & Flow Group companies, including our teams in Ireland, the Netherlands, South Africa and Canada.
02
How we protect data
The controls behind the certificate
Each area below lists what we actually do, the ISO/IEC 27001 Annex A controls it maps to, and the internal policy that governs it.
Access
Every person has a named account with role-based, least-privilege permissions. Multi-factor authentication is enforced on all critical systems and single sign-on is used wherever a platform supports it. Administrator rights sit with a small number of named people, never on shared accounts, and are reviewed against a privileged access register.
A.5.15A.8.2A.8.5ISP15 · ISP29
Encryption
Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256 inside the platforms we use. Every company laptop has full-disk encryption enforced centrally, and client data is never kept on removable media.
A.8.24A.8.1A.7.10ISP06
Devices
Laptops are enrolled in Jamf device management with endpoint detection and response, DNS filtering and enforced screen lock. Security patches are pushed automatically, and a lost or stolen device is locked or wiped within 24 hours of being reported.
A.8.1A.8.7A.8.9ISP06
Testing and email defence
Our IT partner, DARE, runs ongoing vulnerability assessments and penetration testing across our corporate estate and applications, with no open findings. Staff face phishing simulations every year, and our domain is protected by SPF, DKIM, DMARC and Google Workspace data loss prevention.
A.8.8A.8.12A.8.23ISP06 · ISP16
Backup and recovery
Google Workspace is backed up daily by CloudAlly with point-in-time restore. CRM and project data are protected by HubSpot and ClickUp platform backups, and all source code is version controlled in private GitHub repositories. Continuity plans are tested every year: the June 2026 exercise restored service after a simulated HubSpot outage in under three hours.
A.8.13A.5.29A.5.30ISP20 · ISP28 · ISP32
Incident response
Every security event is logged, investigated and closed out against an incident register, with lessons fed back into the risk assessment. If personal data is involved we assess the risk to individuals, report notifiable breaches to the ICO within 72 hours and tell affected clients without undue delay.
A.5.24A.5.26A.5.27ISP19 · ISP30
People
Every hire is reference checked, with basic DBS checks where a role needs one. New starters complete security training before they get system access, everyone refreshes it every year, and everyone signs a confidentiality agreement. Access and equipment are recovered on the day someone leaves.
A.6.1A.6.3A.6.6ISP22 · ISP38
Suppliers
Suppliers are ranked by how critical they are to client delivery and checked before onboarding, including their certifications and data processing terms. Data processing agreements are in place with every sub-processor, and transfers outside the UK and EEA rely on adequacy decisions or Standard Contractual Clauses.
A.5.19A.5.20A.5.22ISP18 · ISP31 · ISP34
Governance
The CEO is accountable for the management system. Information security is a standing item at the weekly management meeting, risks are assessed and treated on a defined method, and an internal audit and formal management review run every year ahead of the external audit.
A.5.1A.5.35A.5.36ISP03 · ISP04 · ISP09 · ISP10
Premises
Our Manchester office is open to staff only, through keypad entry with an individual code per person. Physical security is risk assessed every year. We hold no paper records: client information lives in managed cloud platforms, and retired equipment is securely wiped before disposal.
A.7.1A.7.2A.7.14ISP35
03
Document library
Evidence for your review
Public documents download straight away. Detailed policies are released to verified reviewers once a mutual NDA is in place, usually within one working day.
Risk registers, asset inventories and access logs stay internal. We walk reviewers through them on a call when needed.
04
Sub-processors
The platforms we run on
The services that may store, process or give access to client information.
Where a provider offers UK or EU hosting, data for UK and EU clients stays in that region. Where a provider offers Canadian hosting, Canadian client data stays in Canada. Otherwise data is processed in the United States under UK adequacy regulations or EU Standard Contractual Clauses. Every provider is assessed against our Supplier Security Policy (ISP18) before onboarding and is covered by a data processing agreement.
Cloud CRM and marketing automation platform. System of record for client contact, company, deal and service data. Six & Flow configures and administers client portals on the client's documented instructions.
Contact and company records
deals and tickets
email and web engagement
marketing consent
EU (Germany)Outside client's regionRegion is fixed when a portal is created. Client-owned portals follow the client's own choice.
EU (Germany)Outside client's regionRegion is fixed when a portal is created. Client-owned portals follow the client's own choice.
CanadaOutside client's regionRegion is fixed when a portal is created. Client-owned portals follow the client's own choice.
USOutside client's regionRegion is fixed when a portal is created. Client-owned portals follow the client's own choice.
Group integration company acting as sub-processor. Designs, builds and operates integrations between client systems under a written sub-processor agreement with Six & Flow Ltd.
Client records in transit between systems
integration and error logs
UKOutside client's regionIntegration runtimes run on the hosting providers listed on this page and follow their regions.
UKOutside client's regionIntegration runtimes run on the hosting providers listed on this page and follow their regions.
UKOutside client's regionIntegration runtimes run on the hosting providers listed on this page and follow their regions.
UKOutside client's regionIntegration runtimes run on the hosting providers listed on this page and follow their regions.
AI model provider (Claude) used in client solutions and internal tools. Inputs and outputs under commercial terms are not used to train models.
Prompts, documents and outputs submitted for processing
USOutside client's regionDirect API processing is US-based. EU processing is possible by calling Claude through AWS Bedrock or Google Vertex AI in an EU region.
USOutside client's regionDirect API processing is US-based. EU processing is possible by calling Claude through AWS Bedrock or Google Vertex AI in an EU region.
USOutside client's regionDirect API processing is US-based. EU processing is possible by calling Claude through AWS Bedrock or Google Vertex AI in an EU region.
USOutside client's regionDirect API processing is US-based. EU processing is possible by calling Claude through AWS Bedrock or Google Vertex AI in an EU region.
AI model provider used in FlowLM, our internal knowledge tool, and in client solutions. API inputs and outputs are not used to train models by default.
Prompts, documents and outputs submitted for processing
EU (data residency)Outside client's regionEU data residency applies only to projects created with it enabled.
EU (data residency)Outside client's regionEU data residency applies only to projects created with it enabled.
USOutside client's regionEU data residency applies only to projects created with it enabled.
USOutside client's regionEU data residency applies only to projects created with it enabled.
A.5.19A.5.20A.5.22A.5.23
AircallClient-provisionedMedium criticality
Cloud telephony platform. Call metadata and recordings feed FlowLM.
Call metadata
call recordings
contact numbers
USOutside client's regionConfirm whether the Six & Flow account uses EU storage.
USOutside client's regionConfirm whether the Six & Flow account uses EU storage.
USOutside client's regionConfirm whether the Six & Flow account uses EU storage.
USOutside client's regionConfirm whether the Six & Flow account uses EU storage.
A.5.19A.5.20A.5.22A.5.23
Collaboration and sales
Collaboration and sales sub-processors
Provider
Processing activity
Data categories
Data region
UK and EU
Canada
United States
Controls
Google WorkspaceSix & Flow tenantCritical criticality
Productivity suite for email, calendars, documents and file storage, including files shared with clients.
Email content
documents and files
calendar entries
user directory
EUOutside client's regionSingle Six & Flow tenant. EU location applies only if a data regions policy is set; otherwise data is stored globally.
EUOutside client's regionSingle Six & Flow tenant. EU location applies only if a data regions policy is set; otherwise data is stored globally.
EUOutside client's regionSingle Six & Flow tenant. EU location applies only if a data regions policy is set; otherwise data is stored globally.
EUOutside client's regionSingle Six & Flow tenant. EU location applies only if a data regions policy is set; otherwise data is stored globally.
A.5.19A.5.20A.5.22A.5.23
Microsoft 365Six & Flow tenantHigh criticality
Productivity suite used by some teams for email, documents and collaboration with clients who work in Microsoft.
Email content
documents and files
user directory
UKOutside client's regionTenant data location follows the country the tenant was created in. Group entities with their own tenants follow their own location.
UKOutside client's regionTenant data location follows the country the tenant was created in. Group entities with their own tenants follow their own location.
UKOutside client's regionTenant data location follows the country the tenant was created in. Group entities with their own tenants follow their own location.
UKOutside client's regionTenant data location follows the country the tenant was created in. Group entities with their own tenants follow their own location.
A.5.19A.5.20A.5.22A.5.23
SlackSix & Flow tenantHigh criticality
Messaging platform for internal channels and shared channels with clients.
Messages
shared files
user profiles
UKOutside client's regionUK data residency needs a Business+ or Enterprise plan; otherwise data is stored in the US.
UKOutside client's regionUK data residency needs a Business+ or Enterprise plan; otherwise data is stored in the US.
UKOutside client's regionUK data residency needs a Business+ or Enterprise plan; otherwise data is stored in the US.
UKOutside client's regionUK data residency needs a Business+ or Enterprise plan; otherwise data is stored in the US.
A.5.19A.5.20A.5.22A.5.23
VidyardSix & Flow tenantMedium criticality
Video hosting platform for recorded walkthroughs, demos and training shared with clients.
Video recordings
viewer names, email addresses and engagement data
CanadaOutside client's regionVidyard is Canada-based and hosting is assumed to be in Canada.
CanadaOutside client's regionVidyard is Canada-based and hosting is assumed to be in Canada.
CanadaOutside client's regionVidyard is Canada-based and hosting is assumed to be in Canada.
CanadaOutside client's regionVidyard is Canada-based and hosting is assumed to be in Canada.
A.5.19A.5.20A.5.22A.5.23
Apollo.ioSix & Flow tenantMedium criticality
Sales intelligence platform for prospect research and business contact enrichment.
Business contact details
company firmographics
email engagement
USOutside client's regionUS-hosted only.
USOutside client's regionUS-hosted only.
USOutside client's regionUS-hosted only.
USOutside client's regionUS-hosted only.
A.5.19A.5.20A.5.22A.5.23
Security, backup and operations
Security, backup and operations sub-processors
Provider
Processing activity
Data categories
Data region
UK and EU
Canada
United States
Controls
CloudAllySix & Flow tenantHigh criticality
Backup as a service providing daily, point-in-time recoverable backups of Google Workspace.
Copies of email, documents and calendar data
UKOutside client's regionBackup storage region is chosen when the account is set up.
UKOutside client's regionBackup storage region is chosen when the account is set up.
UKOutside client's regionBackup storage region is chosen when the account is set up.
UKOutside client's regionBackup storage region is chosen when the account is set up.
A.5.19A.5.20A.5.22A.5.23A.8.13
GitHubSix & Flow tenantHigh criticality
Source code hosting and version control for software we build, with access through named accounts.
Source code
configuration files
commit history
No sensitive client data
USOutside client's regionEU hosting needs GitHub Enterprise Cloud with data residency.
USOutside client's regionEU hosting needs GitHub Enterprise Cloud with data residency.
USOutside client's regionEU hosting needs GitHub Enterprise Cloud with data residency.
USOutside client's regionEU hosting needs GitHub Enterprise Cloud with data residency.
A.5.19A.5.20A.5.22A.5.23A.8.4
LastPassSix & Flow tenantHigh criticality
Enterprise password manager for storing and sharing credentials on a least-privilege basis.
Encrypted credentials
vault metadata
No sensitive client data
EUOutside client's regionData centre region is set when the account is created.
EUOutside client's regionData centre region is set when the account is created.
EUOutside client's regionData centre region is set when the account is created.
EUOutside client's regionData centre region is set when the account is created.
A.5.19A.5.20A.5.22A.5.23A.5.17
JamfSix & Flow tenantHigh criticality
Device management and endpoint protection for company laptops: encryption, patching, configuration and remote lock or wipe.
Device identifiers
user names
device compliance and security telemetry
No sensitive client data
EU (Germany)Outside client's regionConfirm the Jamf Cloud instance region.
EU (Germany)Outside client's regionConfirm the Jamf Cloud instance region.
EU (Germany)Outside client's regionConfirm the Jamf Cloud instance region.
EU (Germany)Outside client's regionConfirm the Jamf Cloud instance region.
A.5.19A.5.20A.5.22A.5.23A.8.1A.8.7
DARESix & Flow tenantHigh criticality
Managed IT service provider delivering IT support, vulnerability assessments and penetration testing.