Skip to content

Information Asset Inventory

Purpose. Identifies the information and associated assets within the ISMS scope, their owners, classification and criticality (ISO/IEC 27001:2022 A.5.9). This inventory is the input to the Risk Assessment (ISMS-DOC-06-2/06-3): risks are assessed against these assets.

Status: DRAFT. Assets are drawn from Soon's real environment. Several owners and a few vendor/residency details are marked TODO(owner) and must be confirmed before approval. Review quarterly and on any significant infrastructure change.

Classification scale: Public · Internal · Confidential · Restricted. Criticality (C/I/A): H = high, M = medium, L = low for Confidentiality / Integrity / Availability.


⚠️ Flags for the owner to resolve (important)

  1. Decision 2026-08-13: consolidate onto AWS. The estate currently spans AWS (production), Azure (a legacy dev environment) and GCP (Compute, Storage and Secret Manager). The agreed direction is to migrate off Azure and GCP onto AWS, leaving a single provider to assess, secure and explain in every security review. The migration is nearly complete (as at 2026-08-13); until it is finished, any remaining Azure/GCP resources stay in scope and are listed below. TODO(owner: Thomas/Melvin): plan the migration (dev already runs on AWS as rds-soon-soon-dev; the substantive item is moving secrets out of GCP Secret Manager) and confirm that neither holds customer personal data in the meantime — the customer-facing statement that the platform and customer data run on AWS depends on it.
  2. Customer data outside prod? TODO(owner): confirm dev/test on Azure/GCP use masked/synthetic data only (links to A.8.11 Data Masking, A.8.33 Test information). If real customer data touches dev, residency and access change.
  3. AI tooling processes source code. Cursor, Claude Code, ChatGPT, Gemini and Grok are all in routine use (confirmed by the owner 2026-08-22). Source code sent to these is a confidentiality concern on INF-06, governed by the AI section of the Acceptable Use Policy: no secrets and no customer personal data in AI tools. In the product, only OpenAI is used; Anthropic is planned but not yet live. Unused DeepSeek / Mistral / xAI API keys remain in the production environment and must be revoked (register §7, action V-1).

  4. BYOD / privately-owned hardware is the endpoint reality (laptops, phones, home internet). Central risk for a remote company — driven by the BYOD, Mobile Device and Remote Working policies.

  5. Former dedicated tenant (Knab) decommissioned. The customer relationship ended 2026-07-01 and the dedicated RDS instance no longer exists (verified in AWS 2026-08-08). Residual AWS/DNS teardown is tracked in Linear S-354.

A. Information / data assets

ID Asset Description Owner Class. C/I/A
INF-01 Customer workforce & PII Employee names, emails, schedules, leave, remote-work & optional location data processed for customers (Soon = data processor) Olaf Jacobson Restricted H/H/H
INF-02 Scheduling & forecasting data Operational planning, auto-scheduling, forecasting datasets Thomas Picauly Confidential M/H/H
INF-03 Customer account & config data Tenant settings, roles, integrations config Thomas Picauly Confidential M/H/M
INF-04 Authentication & secrets Credentials, API keys, tokens, signing keys (in GCP Secret Manager / AWS) Thomas Picauly Restricted H/H/H
INF-05 Payment & billing data Subscription/billing records; card data handled by Stripe (Soon stores no PAN) Olaf Jacobson Restricted H/H/M
INF-06 Source code & IaC Soon application + infrastructure code (GitHub / Bitbucket) Thomas Picauly Confidential H/H/M
INF-07 Business & financial records Contracts, finance, HR records Olaf Jacobson Confidential M/M/M
INF-08 ISMS documentation & records This repo; policies, risk, audit, evidence references Olaf Jacobson Protected M/H/M
INF-09 Logs & monitoring data Application/infra logs (CloudWatch, Sentry) — may contain personal data Thomas Picauly Confidential M/M/M

B. Application & service assets (Soon-built)

ID Asset Description Owner Class. C/I/A
SVC-01 soon-server (Production) Core WFM backend (prod) Thomas Picauly Confidential H/H/H
SVC-03 frontend Customer-facing web app (hosted on Cloudflare) Thomas Picauly Internal M/H/H
SVC-04 soon-integrations Integration services to third-party platforms Thomas Picauly Confidential M/H/M
SVC-05 soon-connect Connectivity service Thomas Picauly Confidential M/H/M
SVC-06 solver / soon-intrasolver Auto-scheduling / optimisation engines Thomas Picauly Confidential M/H/M
SVC-07 serverless-subscription Subscription/billing logic (serverless) Thomas Picauly Confidential M/H/M
SVC-08 intercron Scheduled job runner Thomas Picauly Internal L/M/M
SVC-09 redis Cache / queue Melvin Jacobson Internal M/M/M
SVC-10 soondb (production) Application database Melvin Jacobson Restricted H/H/H

C. Infrastructure & cloud assets

ID Asset Description Owner Class. C/I/A
CLD-01 AWS account (eu-west-1) Primary production cloud: Fargate, ECS, ECR, Lambda, S3, SES, CloudWatch Melvin Jacobson Restricted H/H/H
CLD-02 AWS RDS MySQL rds-soon-soon-prod (production) · rds-soon-soon-dev (development) — verified in AWS 2026-08-08 Melvin Jacobson Restricted H/H/H
CLD-03 Azure Legacy development environment — being decommissioned; expected gone before the audit (owner, 2026-08-22) Melvin Jacobson Confidential M/M/M
CLD-04 GCP Retained only for Google Maps Platform and remaining Secret Manager entries — not a general compute platform (owner, 2026-08-22) Melvin Jacobson Restricted H/H/M
CLD-05 Cloudflare Front-end and website hosting/CDN, DNS, and Access for the ISMS site. Supersedes Netlify (owner, 2026-08-22) Thomas Picauly Internal L/M/H

D. Third-party services & sub-processors

This list now lives in the Vendor & Sub-processor Register (ISMS-FORM-A05-19-1), which records every vendor, the data it processes, its region and the agreement in place — confirmed with the owner and cross-checked against the source code on 2026-08-22. Summarised here for asset-inventory purposes only.

ID Asset Purpose Personal data? Class.
SUP-01 AWS (incl. SES) Production hosting and transactional email All customer data Restricted
SUP-02 Cloudflare DNS, CDN, front-end and website hosting, Access Traffic metadata Confidential
SUP-03 Stripe Payments / subscriptions (PCI DSS) Billing PII (no card numbers held) Confidential
SUP-04 WorkOS Enterprise SSO/SAML Auth identifiers Confidential
SUP-05 PostHog Product analytics — EU Cloud (eu.i.posthog.com) Behavioural, identified Confidential
SUP-06 Sentry Error tracking Possibly, in stack traces Confidential
SUP-07 Intercom Customer support / messaging Yes Confidential
SUP-08 Cloudinary Image/media hosting Profile images Internal
SUP-09 OpenAI AI features in product Scope to be confirmed (register §7, V-4) Confidential
SUP-10 Google Maps Platform Address lookup and geometry in the front end Location/address input Internal
SUP-11 Google Workspace Internal identity, email, Drive (contracts, DPAs, HR records) Yes Confidential
SUP-12 Calendar integrations (Google, Outlook) Per-tenant — only where a customer enables them Yes, when enabled Confidential
SUP-13 Unexus / Genesys / Evolve Per-tenant contact-centre / telephony integrations Customer-dependent Confidential
SUP-14 GitHub Source control + CI/CD Source code Confidential
SUP-15 Slack · Linear · Attio · Enpass Internal comms, issue/incident tracking, CRM, password manager Internal + credentials Confidential
SUP-16 Aikido Vulnerability and dependency scanning No Internal
SUP-17 AI development assistants (Cursor, Claude Code, ChatGPT, Gemini, Grok) Used routinely on source code Source code — see Acceptable Use Policy Confidential
SUP-18 Revolut Business · Employes · external accountant Banking, payroll, and bookkeeping. Soon runs no accounting software of its own — records go to the accountant, who works in their own system Soon employee & financial data Confidential

No longer used: Zendesk, Databox, Hex, Microsoft Clarity, Airtable, Bitbucket, Epsagon, Mailgun, and the DeepSeek / Mistral / xAI AI providers. Netlify is dormant and empty, and is to be closed — see register §6.

E. End-user / endpoint assets

ID Asset Description Owner Class. C/I/A
END-01 Laptops / desktops Privately-owned (BYOD); used for all work Each user Confidential M/M/M
END-02 Mobile devices Privately-owned phones/tablets (MFA, mail, Slack) Each user Confidential M/M/M
END-03 Home internet connections Personal ISPs used for remote work Each user n/a L/L/M
END-04 MFA / authenticators Google Authenticator etc. for account protection Each user Restricted H/M/M

F. People & knowledge

ID Asset Description Class.
PPL-01 Team members / contractors Founders, engineers, contractors (ZZP) — hold knowledge & access Internal
PPL-02 Andrea Cardinali (external) Security consultant (CyberSquad) with repo access Internal
PPL-03 Key-person knowledge Undocumented operational know-how (single points of knowledge) Confidential

Change log

Version Date Author Comments
0.1 2026-06-25 Andrea Cardinali / ISMS First draft from Soon's real asset list; owners and several vendor/residency details flagged TODO(owner).
0.2 2026-08-22 ISMS Supplier list confirmed with the owner and cross-checked against the source code; §D now summarises the new Vendor & Sub-processor Register. Netlify replaced by Cloudflare; Azure and GCP positions clarified; AI tooling flag updated (OpenAI only in product, five assistants used internally).