6clicks' Approach to Security, Data Privacy and Responsible AI
Understand the principles, approach and leadership behind the 6clicks information security, data privacy and AI governance program
6clicks operates a single, integrated management system that brings information security and responsible AI governance together. Our program is independently certified to ISO/IEC 27001:2022 (Information Security Management System) and ISO/IEC 42001:2023 (AI Management System), and is supported by a range of additional external assessments. This page explains the principles we work to, the approach we take, the controls we operate, and how we govern the responsible use of AI across the platform.
What principles underpin the 6clicks security, privacy and AI governance program?
The following principles underpin the program:
- Build on strong foundations – We build the 6clicks application on top of strong foundations, primarily Microsoft Azure. Azure is well credentialed for security, and we take advantage of its rich, serverless feature set to secure our infrastructure.
- Involve everybody – The executive team sets the tone from the top with clear accountability for security and AI governance. A nominated CISO leads the function, policies are communicated across the business, and program performance is monitored internally and through engagement with independent advisors, testers, customers and regulators.
- Maintain persistence – 6clicks operates an integrated management system that triggers security and AI governance activities on an ongoing basis. We perform continuous real-time monitoring, daily and weekly vulnerability scanning, regular penetration testing, and ongoing training.
- Govern AI responsibly – We manage the development and use of AI to the same disciplined standard as information security. AI risks – such as bias, transparency, data quality and misuse – are assessed, controlled and continually improved under our ISO/IEC 42001-certified AI Management System.
- Be transparent – Our philosophy is to be as transparent about our security and AI arrangements as is sensible, and we share detailed information under confidentiality arrangements. We do not pretend to be perfect, and we are happy to share updates on projects in progress.
What approach does 6clicks take to information security and data privacy?
- 6clicks takes a security-first approach to maintain the high cybersecurity standards of our commercial partners and to ensure relevant data always remains secure.
- Security, privacy and responsible AI practices are established as part of our certified management system, spanning both our ISO/IEC 27001:2022 ISMS and our ISO/IEC 42001:2023 AI Management System.
- 6clicks has partnered with Microsoft to leverage Microsoft Azure for hosting of the primary 6clicks SaaS platform. For customers with sovereignty or data-residency requirements, 6clicks also offers sovereign cloud and on-premise deployment options, with additional hosting arrangements considered based on demand.
- 6clicks maintains an external ASD IRAP assessment focused on our 6clicks for Government (Australia) environment, hosted in Microsoft Azure Australia Central (Canberra Data Centres).
- 6clicks encrypts data in transit using Transport Layer Security (TLS/HTTPS) and data at rest using AES-256.
- 6clicks performs regular monitoring, vulnerability scanning and penetration testing, and adapts its countermeasures accordingly.
What certifications and independent assurance does 6clicks hold?
6clicks maintains a broad set of independent certifications and assessments covering information security, AI governance and government-grade assurance:
| Certification / Assessment | Scope | Status |
| ISO/IEC 27001:2022 | Information Security Management System (ISMS) | Certified |
| ISO/IEC 42001:2023 | AI Management System (AIMS) | Certified |
| ASD IRAP Assessment | Independent assessment of the 6clicks for Government (Australia) environment against the Australian Government Information Security Manual (ISM) | Assessed |
| UK Cyber Essentials Plus | UK government-backed baseline cyber security controls, including external technical verification | Assessed |
| Australian Defence Industry Security Program (DISP) | Membership supporting protective and personnel security expectations within Defence industry supply chains | Member |
| Dubai Electronic Security Center (DESC) – CSP Security Standard | Cloud Service Provider security requirements for Dubai government, semi-government and critical information infrastructure entities | Assessed |
Current certificates, audit reports and validity dates are available in the 6clicks Trust Portal and the Certification Audits and Reports repository, provided under confidentiality arrangements on request.
How does 6clicks govern the responsible use of AI?
AI is core to the 6clicks platform through Hailey, our AI engine for risk and compliance work. We govern its development and use under an ISO/IEC 42001:2023-certified AI Management System (AIMS) – the international standard for the responsible, transparent and auditable use of AI. The AIMS provides independent validation that 6clicks operates a structured governance system for AI, including management of AI risks, controls, oversight and continual improvement.Our approach to AI is guided by six principles that shape how we design and operate AI capabilities:
- Transparency – being clear about how AI is used and how it reaches its outputs.
- Privacy and data security – protecting the data that AI systems access and process.
- Bias mitigation – identifying and reducing unfair or unintended bias.
- Continuous improvement – monitoring performance and improving over time.
- Human-centred design – keeping human oversight and judgement central.
- Ethical use – applying AI in ways that are lawful, fair and aligned with our values.
Because our information security and AI governance systems share the same ISO Harmonized Structure, they operate as one integrated program – risks, controls, audits and management reviews are conducted jointly rather than in parallel.
What security controls and measures does 6clicks operate?
We continually invest in enterprise-grade security features and best practices across our cloud environment.
Technical measures include: backup and recovery; cryptographic key management; capacity management; anti-malware; mobile device management; encryption of data in transit and at rest (AES-256); multi-factor authentication; privileged access management; single sign-on (SSO); logging and monitoring; code review; DDoS protection; security incident response; vulnerability management; and web application firewall (WAF).
Policies and practices include: information asset management; security risk management; policy and control management; change management; supplier security; acceptable use; system acquisition and development; business continuity; security issue management; management reviews; internal and external audit; human resource security; penetration testing; workplace health and safety; and physical and environmental security.
How does 6clicks protect data privacy?
6clicks treats the protection of personal and customer data as a core obligation of both our security and AI governance programs. Our full data handling practices are set out in two authoritative documents, which take precedence over this summary:
- 6clicks Privacy Policy – how we collect, use, disclose and protect personal data, and your privacy rights.
- 6clicks Data Processing Agreement (DPA) – the terms under which 6clicks processes customer ("User") data, including security measures (Annexure 2) and the sub-processor list (Annexure 3).
In summary:
- Encryption everywhere – data is encrypted in transit (TLS/HTTPS) and at rest (AES-256).
- Access control – access to customer data is restricted on a least-privilege basis and protected by multi-factor authentication, single sign-on and privileged access management.
- Controller and processor roles – 6clicks acts as a data controller for its website, account and marketing data, and as a data processor for the customer data our clients submit to the platform, governed by the DPA.
- Data residency and sovereignty – 6clicks offers SaaS, sovereign cloud and on-premise deployment options so that customers can meet jurisdictional data-residency requirements. Customers can confirm the hosting region applicable to their instance.
- International transfers – where personal data is transferred across borders, 6clicks relies on recognised safeguards including the EU Standard Contractual Clauses, the UK Addendum and the EU–US Data Privacy Framework.
- Privacy rights – 6clicks supports access, correction, deletion, restriction, objection, portability and consent-withdrawal rights in line with applicable privacy laws. To exercise a right or raise a privacy query, contact the 6clicks Data Protection Officer at support@6clicks.io.
Sub-processors. 6clicks engages a defined set of trusted sub-processors to deliver the platform. The current list is published in the Privacy Policy and in Annexure 3 of the Data Processing Agreement.Please refer to those documents for the authoritative, up-to-date list.
Who leads the security, privacy and AI governance function at 6clicks?
The information security, data privacy and AI governance function at 6clicks is led by Ian Hughes, Chief Information Security Officer (CISO).
Ian is accountable for the 6clicks integrated management system, which brings information security (ISO/IEC 27001) and AI governance (ISO/IEC 42001) together under a single, coordinated program. He leads 6clicks' security operations, risk management, compliance and assurance activities, and oversees the responsible use of AI across the platform. Working with the executive team, Ian ensures that security and privacy obligations are embedded in how 6clicks builds and operates its products, and that AI is deployed in line with the company's data protection commitments and ethical principles.
How can I request more information?
Detailed security, privacy and AI governance documentation – including current certificates and audit reports – is available under confidentiality arrangements.
Visit the 6clicks Trust Portal.
For anything else please contact your 6clicks representative or submit a support ticket.