Trust, security, privacy, and responsible AI across MISIXS brands.
This Trust Center shows you how MISIXS, LLC handles security and privacy, who we work with to deliver our services, and how brands like RuleFirst keep your data protected. Everything expands right here on the page, so you won't hit any dead ends.
Trust Center sections
Use this as your internal and external navigation. Every section is written in plain language while still meeting enterprise review standards.
How to read this page
MISIXS sets baseline trust controls for all our brands. RuleFirst and other brands use these same controls, and we only highlight differences when something meaningful changes about the data we process, what we commit to, or what features we offer.
What MISIXS means by "Trust Center"
A Trust Center is a public record of how we think and operate. It's not a marketing page. It explains what we do, why we do it, and how accountability works across our ecosystem.
About downloadable PDFs
You can download a PDF of each policy section when one's available.
Last reviewed: [01/02/2026] · Website Review Owner: [Security Archecture & GRC]
Trust Overview
MISIXS, LLC operates multiple brands, products, and services, including the RuleFirst platform. We manage security, privacy, and responsible technology use through centralized governance so customers get consistency, even as our offerings evolve.
Scope
This Trust Center covers MISIXS-owned and operated brands and systems, including customer-facing platforms and internal operations that support them. Brand notes appear below and expand right here
Accountability
We assign clear ownership for security and privacy decisions. When operational tasks are delegated, accountability stays centralized so standards don't fragment across brands.
Security Program
Our security program implements reasonable administrative, technical, and organizational measures to protect data and maintain reliable operations. We focus on prevention, detection, and response while balancing usability and business needs.
Governance and risk management
Security decisions are driven by risk. We document security requirements, review changes that impact exposure, and maintain a consistent approval process for material changes, subprocessors, and new capabilities.
Access control and identity
We design systems around least privilege, strong authentication, and controlled administrative access. We review and adjust access as roles change, and we restrict and monitor privileged actions.
Secure development and change control
We integrate security into how we build and maintain systems. We review and validate changes before release, and production access and deployments follow controlled workflows.
Monitoring and operational resilience
We maintain logging and monitoring appropriate to the systems we operate. We investigate suspicious activity, track reliability signals, and continuously improve controls to reduce operational risk.
Policy and Usage
Everything expands right here so you can read it immediately. PDFs are available for download where published.
Data Processing Agreement (DPA)
This DPA governs how MISIXS processes personal data on your behalf when you use our services. It covers pilot activities, demonstrations, proofs of concept, testing, and production services. This DPA operates as our baseline processor agreement and doesn't change the commercial terms in your service agreement unless expressly incorporated. All MISIXS brands, including RuleFirst, use this Data Processing Agreement unless we tell you otherwise.
Read the DPA language
Terms of Service and Use
These terms govern your access to and use of MISIXS services, including the RuleFirst platform and all other MISIXS brands, covering acceptable use, account responsibilities, and any service-specific terms.
Read the Terms language
Privacy Policy
This policy explains what information is collected, why it is collected, how it is used, and what choices may be available depending on context.
Read the Privacy language
Encryption Policy
This policy describes encryption expectations and requirements.
Read the Encryption Policy language
Information Security Policy
This policy describes information security governance and baseline controls.
Read the Information Security Policy language
Incident Management Policy
This policy describes incident handling, escalation, and communication expectations.
Read the Incident Management Policy language
Business Continuity and Recovery Policy
This policy describes continuity planning and recovery expectations.
Read the Business Continuity and Recovery Policy language
AI and Automation Responsibility
MISIXS uses artificial intelligence, machine learning, and automation technologies to provide certain features and functionality. We don't use customer data to train public foundation models or proprietary AI models unless expressly agreed in writing. Where public model APIs are used, we leverage zero retention or no training configurations where available.
Human oversight
Automation supports work, but it doesn't remove responsibility. We design workflows so material decisions can be reviewed, audited, and corrected.
Data handling in AI enabled features
We apply the same data minimization and access control standards to AI-enabled features as we do to the rest of our systems. Customer data processed through AI features is governed by our Data Processing Agreement and Privacy Policy. Brand notes below disclose additional AI-related processing only when it differs from the MISIXS baseline.
Safety boundaries
We aim to reduce misuse through guardrails, monitoring, and policy enforcement that fit the context of each product and brand.
Compliance and Framework Alignment
We align our practices with recognized security and privacy frameworks. When customers need specific mappings or evidence, we provide controlled disclosures that fit the engagement.
Framework alignment
Our program aligns with principles found in common frameworks such as ISO 27001 and NIST guidance. We focus on consistent governance, access control, change control, monitoring, and incident preparedness.
Customer due diligence
If you need a security questionnaire, a vendor review packet, or a discussion with a trust contact, use the contact section below and include your timeline, scope, and any required forms.
Incident Response Philosophy
We prepare for incidents so we can respond quickly, contain impact, and communicate responsibly. Our goal is to protect customers, restore normal operations, and learn from every event.
Detection and triage
We investigate events that indicate potential compromise, data exposure, or service disruption. We prioritize containment and evidence preservation while maintaining operational continuity where possible.
Communication
When notification is required by contract or law, we communicate through appropriate channels with clear facts and practical guidance.
Post incident improvements
We track root causes, corrective actions, and process improvements so that the same class of incident becomes less likely over time.
Vendor and Subprocessor Management
We evaluate vendors based on risk and business necessity. We prefer vendors that support strong security practices, clear contractual terms and reliable operations.
Risk based evaluation
We review vendors based on what they do, what data they may access, and the operational impact they introduce. We re evaluate when scope changes or when new risk signals appear.
Subprocessors
If a subprocessor list is required for a specific product, it will be disclosed within that product's trust notes in the Trust by Brand section below.
Customer requests
If your organization requires advance notice of vendor changes, share the requirement during contracting so we can determine feasibility and document the process.
Trust by Brand
Each brand inherits the MISIXS Trust Center baseline. Brand notes highlight meaningful differences in data handling, feature maturity, and usage context, and they open in place below.
Rule First CRM | AI and Automation Platform
Customer operations platform with automation and AI enabled workflows.
Open trust notesRule First Media
Media and content workflows, including production and distribution.
Open trust notesSixcess Brands
Consumer lifestyle brands focused on performance, energy, and experience.
Open trust notesRule First Adventures
Creative, maker, and enthusiast brands spanning media, products, and community.
Open trust notesRule First trust notes
Rule First is a customer operations platform with automation and AI enabled workflows.
If you are participating in a proof of concept or pilot that includes custom code, configuration, or fine tuning, our Data Processing Agreement applies unless the applicable statement of work or written agreement expressly states otherwise.
During these engagements, additional service providers may be used to support the approved solution design. If any of those providers qualify as subprocessors for your use case, we will disclose them as part of the engagement documentation or updated solution record.
Secret AI Labs trust notes
Secret AI Labs is a research and development brand focused on experimentation in AI, cybersecurity, and emerging technology.
Some experiences may be provided as demonstrations, prototypes, or experimental tools that can change or be discontinued without notice. We apply reasonable safeguards and security minded practices; however, features offered under Secret AI Labs may not be production grade and should not be relied upon for critical operations or safety decisions.
By using Secret AI Labs experiences, you agree to use them lawfully and responsibly, including not using any tools, outputs, or guidance to compromise systems, violate rights, or cause harm.
FutureProofWithSix trust notes
This brand operates under the MISIXS Trust Center baseline and does not introduce additional data processing or security obligations beyond those described elsewhere on this page.
Rule First Media trust notes
This brand operates under the MISIXS Trust Center baseline and does not introduce additional data processing or security obligations beyond those described elsewhere on this page.
Sixcess Brands trust notes
Sixcess Brands includes consumer focused products and experiences such as Drink Sixcess and Drive Sixcess. These brands do not operate customer accounts or platforms and do not process regulated personal data.
Data collection, where applicable, is limited to basic marketing interactions such as email signups, event participation, or voluntary feedback. No customer data is sold or shared beyond service providers necessary to operate marketing and fulfillment workflows.
Included brands: Drink Sixcess, Drive Sixcess.
Rule First Adventures trust notes
Rule First Adventures is a creative and enthusiast-focused brand group that operates independently from MISIXS customer-facing software platforms and enterprise SaaS offerings. The brands under Rule First Adventures focus on product design, media, storytelling, community engagement, and hobby-based commerce rather than providing software as a service to the public.
Included brands may feature entertainment content, media experiences, community interactions, and informational tools related to hobbies and creative pursuits. Any driving, RC, or real world activity content is presented for entertainment and storytelling purposes only. It is not intended as instruction, professional guidance, or encouragement to replicate conduct. Participants and viewers are responsible for operating safely, complying with applicable laws, and exercising appropriate judgment and precautions.
Rule First Adventures brands do not offer SaaS products, do not provide regulated digital services, and do not perform automated decision making, profiling, or behavioral analysis of individuals. AI enabled experiences, where present, are informational in nature and are not used to make decisions about individuals or to train proprietary models.
Customer and community information collected by Rule First Adventures brands is limited to basic transactional, communication, and engagement data necessary to fulfill orders, respond to inquiries, manage communities, and operate the business. Aggregated analytics may be used to understand general site usage and improve experiences, but such data is not used for individual profiling or targeted advertising across unrelated brands.
Operational data for Rule First Adventures brands may be managed within MISIXS operated internal systems, such as customer relationship management and communications tooling, for legitimate internal business purposes. This use is administrative and operational in nature and does not convert Rule First Adventures brands into SaaS platforms or customer-facing software services.
Each Rule First Adventures brand maintains its own privacy policy and terms of service, which govern interactions on that brand's website and experiences. The MISIXS Trust Center exists to clarify scope, boundaries, and operational posture and does not replace or override brand-specific policies where no SaaS or enterprise services are being provided.
For specific details regarding data collection, usage, and user rights related to a Rule First Adventures brand, visitors should refer to the privacy policy and terms of service published on that brand's website.
Included brands: Mr. Bones Co., Half Alive Co., Bobby & Timmy RC, Custom 3D Prints.
Contact Us
For trust, privacy, and security inquiries, contact MISIXS using the channel below. If you are submitting a due diligence request, include your timeline, scope, and any required forms.
Trust and security contact
Email: [email protected] (replace as needed)
General contact
Email: [email protected] (replace as needed)