Information Asset Inventory¶
Purpose. Identifies the information and associated assets within the ISMS scope, their owners, classification and criticality (ISO/IEC 27001:2022 A.5.9). This inventory is the input to the Risk Assessment (ISMS-DOC-06-2/06-3): risks are assessed against these assets.
Status: DRAFT. Assets are drawn from Soon's real environment. Several owners and a few vendor/residency details are marked
TODO(owner)and must be confirmed before approval. Review quarterly and on any significant infrastructure change.
Classification scale: Public · Internal · Confidential · Restricted. Criticality (C/I/A): H = high, M = medium, L = low for Confidentiality / Integrity / Availability.
⚠️ Flags for the owner to resolve (important)¶
- Decision 2026-08-13: consolidate onto AWS. The estate currently spans AWS
(production), Azure (a legacy dev environment) and GCP (Compute, Storage and
Secret Manager). The agreed direction is to migrate off Azure and GCP onto AWS,
leaving a single provider to assess, secure and explain in every security review.
The migration is nearly complete (as at 2026-08-13); until it is finished, any remaining Azure/GCP resources stay in scope and are listed below.
TODO(owner: Thomas/Melvin): plan the migration (dev already runs on AWS asrds-soon-soon-dev; the substantive item is moving secrets out of GCP Secret Manager) and confirm that neither holds customer personal data in the meantime — the customer-facing statement that the platform and customer data run on AWS depends on it. - Customer data outside prod?
TODO(owner): confirm dev/test on Azure/GCP use masked/synthetic data only (links to A.8.11 Data Masking, A.8.33 Test information). If real customer data touches dev, residency and access change. -
AI tooling processes source code. Cursor, Claude Code, ChatGPT, Gemini and Grok are all in routine use (confirmed by the owner 2026-08-22). Source code sent to these is a confidentiality concern on INF-06, governed by the AI section of the Acceptable Use Policy: no secrets and no customer personal data in AI tools. In the product, only OpenAI is used; Anthropic is planned but not yet live. Unused DeepSeek / Mistral / xAI API keys remain in the production environment and must be revoked (register §7, action V-1).
-
BYOD / privately-owned hardware is the endpoint reality (laptops, phones, home internet). Central risk for a remote company — driven by the BYOD, Mobile Device and Remote Working policies.
- Former dedicated tenant (Knab) decommissioned. The customer relationship ended 2026-07-01 and the dedicated RDS instance no longer exists (verified in AWS 2026-08-08). Residual AWS/DNS teardown is tracked in Linear S-354.
A. Information / data assets¶
| ID | Asset | Description | Owner | Class. | C/I/A |
|---|---|---|---|---|---|
| INF-01 | Customer workforce & PII | Employee names, emails, schedules, leave, remote-work & optional location data processed for customers (Soon = data processor) | Olaf Jacobson | Restricted | H/H/H |
| INF-02 | Scheduling & forecasting data | Operational planning, auto-scheduling, forecasting datasets | Thomas Picauly | Confidential | M/H/H |
| INF-03 | Customer account & config data | Tenant settings, roles, integrations config | Thomas Picauly | Confidential | M/H/M |
| INF-04 | Authentication & secrets | Credentials, API keys, tokens, signing keys (in GCP Secret Manager / AWS) | Thomas Picauly | Restricted | H/H/H |
| INF-05 | Payment & billing data | Subscription/billing records; card data handled by Stripe (Soon stores no PAN) | Olaf Jacobson | Restricted | H/H/M |
| INF-06 | Source code & IaC | Soon application + infrastructure code (GitHub / Bitbucket) | Thomas Picauly | Confidential | H/H/M |
| INF-07 | Business & financial records | Contracts, finance, HR records | Olaf Jacobson | Confidential | M/M/M |
| INF-08 | ISMS documentation & records | This repo; policies, risk, audit, evidence references | Olaf Jacobson | Protected | M/H/M |
| INF-09 | Logs & monitoring data | Application/infra logs (CloudWatch, Sentry) — may contain personal data | Thomas Picauly | Confidential | M/M/M |
B. Application & service assets (Soon-built)¶
| ID | Asset | Description | Owner | Class. | C/I/A |
|---|---|---|---|---|---|
| SVC-01 | soon-server (Production) | Core WFM backend (prod) | Thomas Picauly | Confidential | H/H/H |
| SVC-03 | frontend | Customer-facing web app (hosted on Cloudflare) | Thomas Picauly | Internal | M/H/H |
| SVC-04 | soon-integrations | Integration services to third-party platforms | Thomas Picauly | Confidential | M/H/M |
| SVC-05 | soon-connect | Connectivity service | Thomas Picauly | Confidential | M/H/M |
| SVC-06 | solver / soon-intrasolver | Auto-scheduling / optimisation engines | Thomas Picauly | Confidential | M/H/M |
| SVC-07 | serverless-subscription | Subscription/billing logic (serverless) | Thomas Picauly | Confidential | M/H/M |
| SVC-08 | intercron | Scheduled job runner | Thomas Picauly | Internal | L/M/M |
| SVC-09 | redis | Cache / queue | Melvin Jacobson | Internal | M/M/M |
| SVC-10 | soondb (production) | Application database | Melvin Jacobson | Restricted | H/H/H |
C. Infrastructure & cloud assets¶
| ID | Asset | Description | Owner | Class. | C/I/A |
|---|---|---|---|---|---|
| CLD-01 | AWS account (eu-west-1) | Primary production cloud: Fargate, ECS, ECR, Lambda, S3, SES, CloudWatch | Melvin Jacobson | Restricted | H/H/H |
| CLD-02 | AWS RDS MySQL | rds-soon-soon-prod (production) · rds-soon-soon-dev (development) — verified in AWS 2026-08-08 |
Melvin Jacobson | Restricted | H/H/H |
| CLD-03 | Azure | Legacy development environment — being decommissioned; expected gone before the audit (owner, 2026-08-22) | Melvin Jacobson | Confidential | M/M/M |
| CLD-04 | GCP | Retained only for Google Maps Platform and remaining Secret Manager entries — not a general compute platform (owner, 2026-08-22) | Melvin Jacobson | Restricted | H/H/M |
| CLD-05 | Cloudflare | Front-end and website hosting/CDN, DNS, and Access for the ISMS site. Supersedes Netlify (owner, 2026-08-22) | Thomas Picauly | Internal | L/M/H |
D. Third-party services & sub-processors¶
This list now lives in the Vendor & Sub-processor Register (ISMS-FORM-A05-19-1), which records every vendor, the data it processes, its region and the agreement in place — confirmed with the owner and cross-checked against the source code on 2026-08-22. Summarised here for asset-inventory purposes only.
| ID | Asset | Purpose | Personal data? | Class. |
|---|---|---|---|---|
| SUP-01 | AWS (incl. SES) | Production hosting and transactional email | All customer data | Restricted |
| SUP-02 | Cloudflare | DNS, CDN, front-end and website hosting, Access | Traffic metadata | Confidential |
| SUP-03 | Stripe | Payments / subscriptions (PCI DSS) | Billing PII (no card numbers held) | Confidential |
| SUP-04 | WorkOS | Enterprise SSO/SAML | Auth identifiers | Confidential |
| SUP-05 | PostHog | Product analytics — EU Cloud (eu.i.posthog.com) |
Behavioural, identified | Confidential |
| SUP-06 | Sentry | Error tracking | Possibly, in stack traces | Confidential |
| SUP-07 | Intercom | Customer support / messaging | Yes | Confidential |
| SUP-08 | Cloudinary | Image/media hosting | Profile images | Internal |
| SUP-09 | OpenAI | AI features in product | Scope to be confirmed (register §7, V-4) | Confidential |
| SUP-10 | Google Maps Platform | Address lookup and geometry in the front end | Location/address input | Internal |
| SUP-11 | Google Workspace | Internal identity, email, Drive (contracts, DPAs, HR records) | Yes | Confidential |
| SUP-12 | Calendar integrations (Google, Outlook) | Per-tenant — only where a customer enables them | Yes, when enabled | Confidential |
| SUP-13 | Unexus / Genesys / Evolve | Per-tenant contact-centre / telephony integrations | Customer-dependent | Confidential |
| SUP-14 | GitHub | Source control + CI/CD | Source code | Confidential |
| SUP-15 | Slack · Linear · Attio · Enpass | Internal comms, issue/incident tracking, CRM, password manager | Internal + credentials | Confidential |
| SUP-16 | Aikido | Vulnerability and dependency scanning | No | Internal |
| SUP-17 | AI development assistants (Cursor, Claude Code, ChatGPT, Gemini, Grok) | Used routinely on source code | Source code — see Acceptable Use Policy | Confidential |
| SUP-18 | Revolut Business · Employes · external accountant | Banking, payroll, and bookkeeping. Soon runs no accounting software of its own — records go to the accountant, who works in their own system | Soon employee & financial data | Confidential |
No longer used: Zendesk, Databox, Hex, Microsoft Clarity, Airtable, Bitbucket, Epsagon, Mailgun, and the DeepSeek / Mistral / xAI AI providers. Netlify is dormant and empty, and is to be closed — see register §6.
E. End-user / endpoint assets¶
| ID | Asset | Description | Owner | Class. | C/I/A |
|---|---|---|---|---|---|
| END-01 | Laptops / desktops | Privately-owned (BYOD); used for all work | Each user | Confidential | M/M/M |
| END-02 | Mobile devices | Privately-owned phones/tablets (MFA, mail, Slack) | Each user | Confidential | M/M/M |
| END-03 | Home internet connections | Personal ISPs used for remote work | Each user | n/a | L/L/M |
| END-04 | MFA / authenticators | Google Authenticator etc. for account protection | Each user | Restricted | H/M/M |
F. People & knowledge¶
| ID | Asset | Description | Class. |
|---|---|---|---|
| PPL-01 | Team members / contractors | Founders, engineers, contractors (ZZP) — hold knowledge & access | Internal |
| PPL-02 | Andrea Cardinali (external) | Security consultant (CyberSquad) with repo access | Internal |
| PPL-03 | Key-person knowledge | Undocumented operational know-how (single points of knowledge) | Confidential |
Related documents¶
- Vendor & Sub-processor Register (ISMS-FORM-A05-19-1) — the authoritative supplier list
- Asset Management Policy (ISMS-DOC-A05-9-1)
- Acceptable Use Policy (ISMS-DOC-A05-10-1)
- Statement of Applicability (ISMS-FORM-06-2)
- Risk Assessment and Treatment Process (ISMS-DOC-06-2) — to create; consumes this inventory
- Context & Scope — supply-chain overview
- Source: reference asset list
Change log¶
| Version | Date | Author | Comments |
|---|---|---|---|
| 0.1 | 2026-06-25 | Andrea Cardinali / ISMS | First draft from Soon's real asset list; owners and several vendor/residency details flagged TODO(owner). |
| 0.2 | 2026-08-22 | ISMS | Supplier list confirmed with the owner and cross-checked against the source code; §D now summarises the new Vendor & Sub-processor Register. Netlify replaced by Cloudflare; Azure and GCP positions clarified; AI tooling flag updated (OpenAI only in product, five assistants used internally). |