Skip to content

Vendor & Sub-processor Register

Purpose. The single list of every third party Soon relies on, what data each one touches, and what agreement governs it. Satisfies A.5.19–A.5.23 (supplier relationships, security in agreements, ICT supply chain, monitoring and review) and SOC 2 CC9.2 (vendor risk management) / CC3.2.

It also answers the three questions Soon gets asked repeatedly: who are your sub-processors? (customers), do you have DPAs? (auditors), what happens to our data? (prospects).

Status: DRAFT — confirmed with the owner on 2026-08-22 and cross-checked against the application source code on the same date. This register supersedes the supplier list in Information Asset Inventory §D, which now points here.

1. The three categories — and why the distinction matters

Not every vendor is a sub-processor, and not every sub-processor applies to every customer. Blurring these makes the customer-facing list either misleadingly long or dishonestly short.

Category Definition Consequence
A. Core sub-processors Process customer personal data for every tenant. Unavoidable. Must appear in the public sub-processor list; a DPA is required; customers must be notified of changes.
B. Per-tenant integrations Connected only when a customer switches them on. A tenant with no calendar integration never touches Google or Microsoft. Disclosed per contract, not in the blanket list. The customer is the one choosing the integration.
C. Internal business tools Soon's own operations. Handle Soon's data (and Soon employees' data), not customer workforce data. No customer DPA needed; still assessed for Soon's own risk.

Category B is Soon's normal model for integrations — the platform's value is connecting to whatever a customer already runs, so the integration list grows over time. Every new integration is added here and disclosed to the tenant that enables it, not retro-fitted into everyone's contract.

2. Category A — core sub-processors (all customers)

Vendor Purpose Personal data processed Region Criticality Agreement
Amazon Web Services All production hosting: ECS/Fargate, RDS MySQL, S3, Lambda, SES, CloudWatch All customer data (INF-01, INF-02, INF-03) eu-west-1 (Ireland) Critical AWS GDPR Data Processing Addendum (in Service Terms) — file a copy
Amazon SES Transactional email (invitations, notifications, password resets) Names, email addresses eu-west-1 Critical Covered by the AWS DPA
Cloudflare DNS, CDN and hosting for the web front end and website; Cloudflare Access for the ISMS site Traffic metadata, IP addresses Global edge, EU config Critical Cloudflare DPA (standard terms) — file a copy
Stripe Subscription billing and payments Billing contact details. Soon stores no card numbers — Stripe is PCI DSS Level 1 EU / US (SCCs) Critical Stripe DPA (standard terms) — file a copy
WorkOS Enterprise SSO / SAML Authentication identifiers (email, directory attributes) US (SCCs) Important WorkOS DPA — file a copy
PostHog Product analytics Behavioural/usage events tied to user identifiers EU Cloud (eu.i.posthog.com, verified in code 2026-08-22) Important PostHog DPA (standard terms) — file a copy
Sentry Application error tracking Potentially personal data inside stack traces and request context EU or US — confirm the project region Important Sentry DPA — file a copy. See the PII-scrubbing action in §7.
Intercom In-app support and messaging Support contact details and conversation content US / EU (SCCs) Important Intercom DPA — file a copy
Cloudinary Image and media hosting (avatars, uploaded media) Profile images EU/US Important Cloudinary DPA — file a copy
OpenAI AI features in the product Depends on the feature — must be scoped (see §7) US (SCCs) Important OpenAI API DPA + zero-retention / no-training terms for API usage — file a copy
Google Maps Platform Address lookup and geometry in the front end (places, geometry libraries) Location and address input where a customer uses location features Global Low Google Cloud DPA — file a copy
Google Workspace Internal identity, email, and the Drive holding contracts, DPAs and HR records Soon employee data; customer contract documents EU data region (verify setting) Critical Google Workspace DPA — file a copy

Anthropic is a planned addition for AI features. It is not in use today and must be added to this register, and disclosed to customers, before it goes live.

3. Category B — per-tenant integrations (only when a customer enables them)

Connected on a tenant-by-tenant basis. A customer who does not enable an integration has no data flow to that vendor at all.

Integration Purpose Data shared when enabled
Google Calendar Two-way schedule sync Shift times, employee calendar identifiers
Microsoft Outlook / 365 Calendar Two-way schedule sync Shift times, employee calendar identifiers
Unexus Contact-centre / telephony integration Agent identifiers, activity data
Genesys Contact-centre platform integration Agent identifiers, activity and volume data
Evolve Contact-centre platform integration Agent identifiers, activity data
Zoom Used only where a customer's own process requires it (Soon's own default is Google Meet) Meeting metadata

Rule for adding an integration. Any new integration is (1) added to this register before it ships, (2) named in the enabling tenant's agreement or integration consent, and (3) risk- assessed if it processes personal data. It does not become a blanket sub-processor for every customer.

4. Category C — internal business tools

Vendor Purpose Soon data held Criticality
GitHub Source control, CI/CD, code review Source code and IaC (INF-06) Critical
Slack Internal communication Internal discussion Important
Linear Issue tracking and the incident record system Security issues, incident records Important
Attio CRM Prospect and customer contact data Important
Enpass Company password manager — the only permitted location for credentials All shared credentials (INF-04) Critical
Google Meet Default video conferencing Meeting content Low
Loom Async video (used frequently) Recorded screen content — must not show production data Low
Aikido Vulnerability and dependency scanning on the GitHub organisation Source code metadata, findings Important
Cursor · Claude Code · ChatGPT · Gemini · Grok AI development assistants, used routinely on source code Source code (INF-06) — governed by the AI section of the Acceptable Use Policy Important
Revolut Business Business banking Financial records Critical
Employes Payroll Employee payroll data Important
External accountant Bookkeeping and statutory accounts. Soon runs no accounting software of its own — records are sent to the accountant, who works in their own system (currently AFAS, which they could change). The accountant is the vendor here; AFAS is their tool. Financial records; payroll-related employee data Important
CyberSquad (Andrea Cardinali) External security consultancy: ISMS advisory and the independent internal audit. Holds read access to the whole ISMS, including the risk register and findings — the one outsider with standing access to Internal and Protected material ISMS documentation, risk and audit records Important
Figma Design — retained but not actively used Design assets Low
Miro Whiteboarding — retained but not actively used Diagrams Low

Employment contracts and signed agreements are held in Google Drive, not in a dedicated HR system — see Records Retention & Protection Policy.

Soon operates no finance or accounting system of its own. Banking is Revolut Business, payroll is Employes, and everything else goes to the external accountant. This keeps the in-scope estate smaller, but it means the accountant is a third party holding Soon's confidential records and is managed as a vendor accordingly (action V-8).

5. Marketing website (soon.works) — analytics and advertising

These run on the public marketing site only, never inside the application, and load only after cookie consent (CookieConsent.astro gates them via Google Consent Mode).

Vendor Purpose
Google Analytics (via Google Tag Manager) Website analytics
Meta / Facebook Pixel Advertising conversion measurement
PostHog Website product analytics

No analytics or advertising tags run in the customer-facing application. The only external script the application front end loads is Google Maps (verified 2026-08-22).

6. Not in use — decommissioned or never adopted

Recorded deliberately: earlier ISMS drafts, the CSP allowlist and old dependencies name these, and an auditor who finds the reference needs an answer.

Vendor Position
Zendesk Never adopted — support runs on Intercom
Databox, Hex, Microsoft Clarity, Airtable, Bitbucket No longer used
Epsagon Discontinued (vendor shut down). The legacy EpsagonMonitoringTrail CloudTrail is being replaced — see the close-out plan, task 5
Mailgun Not used. Code path exists in mailer.js; SES is the production sender
DeepSeek, Mistral, xAI (Grok API) Not used in the product. API keys are still present in the production environment — remove and revoke (§7)
Azure Legacy development environment; to be gone before the audit
GCP Retained only for Google Maps and remaining Secret Manager entries; not a general compute platform
Netlify Superseded by Cloudflare for front-end hosting. The account still exists but holds nothing (owner, 2026-08-22) — close it (action V-7)
Segment · Datadog · Mutiny · Sprig · Cohere · HubSpot Not used. Present only as stale entries in the application's CSP allowlist — see §7

7. Actions arising

# Action Why Owner
V-1 Remove and revoke the DeepSeek, Mistral and xAI API keys from the production environment Unused live credentials are pure liability; an auditor reading the environment config will ask what they are Thomas
V-2 Prune the CSP allowlist in soon-server/src/server/cspConfig.js — drop Segment, Datadog, Mutiny, Sprig, Cohere, HubSpot, Facebook, DoubleClick, Clarity and Google Analytics from the application policy Every allowed domain is a permitted exfiltration route. The application loads none of them Thomas
V-3 Confirm Sentry PII scrubbing is enabled (sendDefaultPii: false, data-scrubbing on) and record the project's data region Sentry is the most likely accidental route for customer personal data to leave the EU Thomas
V-4 Scope what the OpenAI integration sends — which fields, whether any customer personal data is included, and confirm zero-retention API terms Required for an honest sub-processor disclosure and for GXO-style questionnaires Thomas
V-5 Collect the DPAs for every Category A vendor into Drive → Legal → Vendors Closes SOC 2 #67 and #68 Olaf
V-6 Publish the Category A list as the sub-processor list on the Trust Center Prospects ask for it in every security review Olaf
V-7 Close the dormant Netlify account An unused hosting account with live DNS is a classic audit finding — stale deploys and dangling subdomains outlive the team's memory of them Thomas
V-8 Confirm the accountant's engagement letter carries confidentiality terms, and file it Required for SOC 2 #68; the accountant holds Soon's financial and payroll-related employee data Olaf
V-9 Put the CyberSquad engagement on a signed footing — a consultancy agreement plus a completed NDA, and record the ISMS access grant in the external access register Andrea reads the risk register and the findings — the most sensitive material we hold. A.5.19–A.5.21 apply to him exactly as they do to a SaaS vendor, and #68 wants the confidentiality terms in writing. Olaf signs for Soon; Alessandro must not, as Andrea is his brother (related-party note, ISMS-DOC-05-2 §1.7) Olaf

8. How vendors are managed

  • Before adoption. Any vendor that will process customer personal data, hold credentials or receive source code is assessed against the Supplier Relationships Policy and added here before it goes live.
  • Assurance. For Category A, obtain the provider's SOC 2 Type 2 or ISO 27001 certificate and its DPA. File both in Drive → Legal → Vendors.
  • Review. This register is reviewed annually, and immediately on any change to the Category A list. Category A changes are notified to customers per the DPA.
  • Exit. On termination, confirm data deletion or return per the Records Retention & Protection Policy and move the vendor to §6 with the date.

9. Roles

  • ISM (Olaf Jacobson) — owns this register, collects DPAs, approves new vendors, runs the annual review.
  • Engineering lead (Thomas Picauly) — confirms what each integration actually sends; owns V-1 to V-4.
  • Infrastructure (Melvin Jacobson) — cloud provider configuration and region settings.

Change log

Version Date Author Comments
0.3 2026-08-22 ISMS Added CyberSquad (Andrea Cardinali) as an internal-tools vendor — an omission found in pre-audit review: he is the one external party with read access to the whole ISMS, so the supplier controls apply to him. Raised action V-9.
0.2 2026-08-22 ISMS Owner confirmations applied: Soon runs no accounting system of its own — the external accountant is the vendor (AFAS is their tool), so a confidentiality-terms check was added (V-8); the dormant Netlify account is empty and is to be closed (V-7).
0.1 2026-08-22 ISMS First version. Vendor list confirmed with the owner and cross-checked against the application source code; split into core sub-processors, per-tenant integrations and internal tools; decommissioned vendors recorded; six actions raised (unused AI API keys, stale CSP allowlist, Sentry PII scrubbing, OpenAI data scope, DPA collection, Trust Center publication).