SECURITY OVERVIEW Soon for enterprise security review |
|---|
Document version 1.5 (draft) · Last reviewed August 2026 · security@soon.works
Internal note (not for external distribution): this version corrects several claims found not to fully match reality during ISMS gap-checking (2026-06-25 to 2026-07-03) — hosting (multi-cloud, not "entirely AWS"), a data-residency exception (Intercom), backup specifics still being confirmed, and native customer MFA not yet built. Before sending this to any customer, confirm the corrected version replaces whatever is currently in circulation.
AT A GLANCE
| Service | Cloud-based workforce scheduling SaaS (Soon) |
|---|---|
| Hosting | Amazon Web Services (eu-west-1, Ireland) — primary; select internal services on Google Cloud (europe-west4, Belgium), also EU |
| Data residency | European Union - GDPR-aligned, with one known exception being remediated (Intercom customer support tooling — see §1) |
| Encryption | TLS 1.2+ in transit; AES-256 at rest |
| Authentication | SSO and SAML supported; MFA required for administrative access to critical production systems (risk-tiered — see Access control) |
| Infrastructure certifications | AWS: ISO/IEC 27001, SOC 1, SOC 2, PCI DSS |
| Security program | ISO/IEC 27001-aligned ISMS |
| Data Processing Agreement | Available; aligned with GDPR requirements |
1. Platform and data¶
Soon is a cloud-based workforce scheduling and operational planning platform delivered as Software-as-a-Service. Core production infrastructure runs on Amazon Web Services in the EU-West-1 (Ireland) region; a small number of internal services run on Google Cloud in europe-west4 (Belgium). Customer data is stored within the European Union to meet EU data residency requirements, with one known exception: our customer support tooling (Intercom) currently runs on Intercom's US-hosted infrastructure. We are migrating this to an EU-hosted configuration or an EU-based alternative.
The platform processes user account data, employee names and email addresses, scheduling and workforce planning data, and operational forecasting and reporting data. Soon does not require, request, or process special categories of personal data.
2. Governance and risk management¶
Information security is owned at the leadership level and operated by engineering management. Soon maintains an Information Security Management System aligned with ISO/IEC 27001, covering policies, access controls, supplier management, and incident response.
Our security program is built on three principles:
Least privilege. Access is restricted to the minimum required for each role and reviewed regularly.
Defense in depth. Multiple layers of technical and operational controls protect infrastructure, applications, and access.
Continuous risk assessment. Risks affecting customer data, infrastructure, integrations, availability, and applications are reviewed on a recurring basis and prioritised by likelihood and impact.
3. Infrastructure and cloud security¶
Soon runs on Amazon Web Services in the EU-West-1 (Ireland) region. AWS is independently certified against ISO/IEC 27001, SOC 1, SOC 2, and PCI DSS, and these attestations apply to the underlying infrastructure used by Soon. AWS compliance reports are available to customers under NDA via AWS Artifact.
Network security. Application ingress to production runs through AWS-managed load balancers with TLS termination, and workloads run inside Virtual Private Clouds governed by security group rules. The production database has no public endpoint — it accepts connections only from application workloads inside the VPC, and named engineers reach it through authenticated, logged AWS Systems Manager sessions rather than an open port. Anomalous database logins are monitored continuously by AWS GuardDuty. Remaining network hardening (removing the last public IPs and completing the infrastructure-as-code migration) continues, alongside strengthening production, staging and development separation.
Internal note. The public database endpoint was removed on 2026-08-19 (soon-server#1675). The paragraph above is now accurate and may be circulated. Evidence for it —
PubliclyAccessible: falseand the security-group export — still needs capturing; until then this is a claim we believe rather than one we can show.
Patching and vulnerability management. Operating system and platform patching at the infrastructure layer is managed by AWS. Application dependencies are monitored for known vulnerabilities, and updates are applied through our standard release process.
Backup and recovery. The production database is backed up automatically each day (7-day retention, encrypted at rest with AWS KMS), with manual backups taken in addition. Point-in-time recovery is being enabled, backup copies are being isolated to a separate account/region, and periodic restore testing is being introduced and recorded as part of our ISO 27001 / SOC 2 readiness work.
4. Access control and authentication¶
Customer authentication. Soon supports enterprise Single Sign-On via SAML with all major identity providers, including Microsoft Entra ID, Okta, and Google Workspace. For accounts using email/password login, native multi-factor authentication is not yet available — customers seeking MFA-level assurance today are encouraged to use SSO or social login (Google/Microsoft), both of which inherit the identity provider's own MFA. Native MFA for email/password accounts is on our product roadmap.
Internal access. Access to production systems is restricted to authorised engineering personnel on a least-privilege, role-based basis. Multi-factor authentication is required for the AWS console and Google Workspace; enforcement across the remaining tooling is being completed, and access is reviewed on joiner, mover, and leaver events.
Personnel security. All staff sign confidentiality agreements. Security awareness expectations are communicated to staff and reviewed periodically. Background checks are performed where legally permissible and appropriate to the role.
5. Application security and data protection¶
Secure development. All code changes go through peer review before merge. Deployments are automated and traceable. Development practices follow OWASP secure coding guidance, and the application is designed to mitigate common web application risks including the OWASP Top 10.
Encryption. All data in transit is protected with TLS 1.2 or higher. Customer data and backups are encrypted at rest using AES-256.
Data protection and GDPR. Soon acts as a data processor under GDPR. A Data Processing Agreement is available and forms part of standard customer contracting. Soon supports customer obligations for data subject rights including access, correction, and deletion. A current sub-processor list is maintained and shared on request.
6. Monitoring, logging, and incident response¶
Soon maintains centralised logging and continuous monitoring across production systems. Infrastructure metrics are collected via AWS CloudWatch and application errors are tracked via Sentry, with alerting configured for availability and error-rate anomalies.
Incident response. Security incidents are triaged by severity and handled by engineering leadership. Customers are notified without undue delay of any incident affecting their data or service, in line with GDPR and contractual commitments.
7. Business continuity¶
Soon's architecture relies on AWS managed services with multi-availability-zone redundancy for high availability. Backups, recovery procedures, and operational runbooks support restoration in the event of an infrastructure failure or data loss event.
8. Security contact¶
For security questionnaires, vendor risk reviews, or further detail on any control listed above, please contact security@soon.works. Soon participates fully in customer security reviews as part of enterprise onboarding.