Vendor & Sub-processor Register¶
Purpose. The single list of every third party Soon relies on, what data each one touches, and what agreement governs it. Satisfies A.5.19–A.5.23 (supplier relationships, security in agreements, ICT supply chain, monitoring and review) and SOC 2 CC9.2 (vendor risk management) / CC3.2.
It also answers the three questions Soon gets asked repeatedly: who are your sub-processors? (customers), do you have DPAs? (auditors), what happens to our data? (prospects).
Status: DRAFT — confirmed with the owner on 2026-08-22 and cross-checked against the application source code on the same date. This register supersedes the supplier list in Information Asset Inventory §D, which now points here.
1. The three categories — and why the distinction matters¶
Not every vendor is a sub-processor, and not every sub-processor applies to every customer. Blurring these makes the customer-facing list either misleadingly long or dishonestly short.
| Category | Definition | Consequence |
|---|---|---|
| A. Core sub-processors | Process customer personal data for every tenant. Unavoidable. | Must appear in the public sub-processor list; a DPA is required; customers must be notified of changes. |
| B. Per-tenant integrations | Connected only when a customer switches them on. A tenant with no calendar integration never touches Google or Microsoft. | Disclosed per contract, not in the blanket list. The customer is the one choosing the integration. |
| C. Internal business tools | Soon's own operations. Handle Soon's data (and Soon employees' data), not customer workforce data. | No customer DPA needed; still assessed for Soon's own risk. |
Category B is Soon's normal model for integrations — the platform's value is connecting to whatever a customer already runs, so the integration list grows over time. Every new integration is added here and disclosed to the tenant that enables it, not retro-fitted into everyone's contract.
2. Category A — core sub-processors (all customers)¶
| Vendor | Purpose | Personal data processed | Region | Criticality | Agreement |
|---|---|---|---|---|---|
| Amazon Web Services | All production hosting: ECS/Fargate, RDS MySQL, S3, Lambda, SES, CloudWatch | All customer data (INF-01, INF-02, INF-03) | eu-west-1 (Ireland) | Critical | AWS GDPR Data Processing Addendum (in Service Terms) — file a copy |
| Amazon SES | Transactional email (invitations, notifications, password resets) | Names, email addresses | eu-west-1 | Critical | Covered by the AWS DPA |
| Cloudflare | DNS, CDN and hosting for the web front end and website; Cloudflare Access for the ISMS site | Traffic metadata, IP addresses | Global edge, EU config | Critical | Cloudflare DPA (standard terms) — file a copy |
| Stripe | Subscription billing and payments | Billing contact details. Soon stores no card numbers — Stripe is PCI DSS Level 1 | EU / US (SCCs) | Critical | Stripe DPA (standard terms) — file a copy |
| WorkOS | Enterprise SSO / SAML | Authentication identifiers (email, directory attributes) | US (SCCs) | Important | WorkOS DPA — file a copy |
| PostHog | Product analytics | Behavioural/usage events tied to user identifiers | EU Cloud (eu.i.posthog.com, verified in code 2026-08-22) |
Important | PostHog DPA (standard terms) — file a copy |
| Sentry | Application error tracking | Potentially personal data inside stack traces and request context | EU or US — confirm the project region | Important | Sentry DPA — file a copy. See the PII-scrubbing action in §7. |
| Intercom | In-app support and messaging | Support contact details and conversation content | US / EU (SCCs) | Important | Intercom DPA — file a copy |
| Cloudinary | Image and media hosting (avatars, uploaded media) | Profile images | EU/US | Important | Cloudinary DPA — file a copy |
| OpenAI | AI features in the product | Depends on the feature — must be scoped (see §7) | US (SCCs) | Important | OpenAI API DPA + zero-retention / no-training terms for API usage — file a copy |
| Google Maps Platform | Address lookup and geometry in the front end (places, geometry libraries) |
Location and address input where a customer uses location features | Global | Low | Google Cloud DPA — file a copy |
| Google Workspace | Internal identity, email, and the Drive holding contracts, DPAs and HR records | Soon employee data; customer contract documents | EU data region (verify setting) | Critical | Google Workspace DPA — file a copy |
Anthropic is a planned addition for AI features. It is not in use today and must be added to this register, and disclosed to customers, before it goes live.
3. Category B — per-tenant integrations (only when a customer enables them)¶
Connected on a tenant-by-tenant basis. A customer who does not enable an integration has no data flow to that vendor at all.
| Integration | Purpose | Data shared when enabled |
|---|---|---|
| Google Calendar | Two-way schedule sync | Shift times, employee calendar identifiers |
| Microsoft Outlook / 365 Calendar | Two-way schedule sync | Shift times, employee calendar identifiers |
| Unexus | Contact-centre / telephony integration | Agent identifiers, activity data |
| Genesys | Contact-centre platform integration | Agent identifiers, activity and volume data |
| Evolve | Contact-centre platform integration | Agent identifiers, activity data |
| Zoom | Used only where a customer's own process requires it (Soon's own default is Google Meet) | Meeting metadata |
Rule for adding an integration. Any new integration is (1) added to this register before it ships, (2) named in the enabling tenant's agreement or integration consent, and (3) risk- assessed if it processes personal data. It does not become a blanket sub-processor for every customer.
4. Category C — internal business tools¶
| Vendor | Purpose | Soon data held | Criticality |
|---|---|---|---|
| GitHub | Source control, CI/CD, code review | Source code and IaC (INF-06) | Critical |
| Slack | Internal communication | Internal discussion | Important |
| Linear | Issue tracking and the incident record system | Security issues, incident records | Important |
| Attio | CRM | Prospect and customer contact data | Important |
| Enpass | Company password manager — the only permitted location for credentials | All shared credentials (INF-04) | Critical |
| Google Meet | Default video conferencing | Meeting content | Low |
| Loom | Async video (used frequently) | Recorded screen content — must not show production data | Low |
| Aikido | Vulnerability and dependency scanning on the GitHub organisation | Source code metadata, findings | Important |
| Cursor · Claude Code · ChatGPT · Gemini · Grok | AI development assistants, used routinely on source code | Source code (INF-06) — governed by the AI section of the Acceptable Use Policy | Important |
| Revolut Business | Business banking | Financial records | Critical |
| Employes | Payroll | Employee payroll data | Important |
| External accountant | Bookkeeping and statutory accounts. Soon runs no accounting software of its own — records are sent to the accountant, who works in their own system (currently AFAS, which they could change). The accountant is the vendor here; AFAS is their tool. | Financial records; payroll-related employee data | Important |
| CyberSquad (Andrea Cardinali) | External security consultancy: ISMS advisory and the independent internal audit. Holds read access to the whole ISMS, including the risk register and findings — the one outsider with standing access to Internal and Protected material | ISMS documentation, risk and audit records | Important |
| Figma | Design — retained but not actively used | Design assets | Low |
| Miro | Whiteboarding — retained but not actively used | Diagrams | Low |
Employment contracts and signed agreements are held in Google Drive, not in a dedicated HR system — see Records Retention & Protection Policy.
Soon operates no finance or accounting system of its own. Banking is Revolut Business, payroll is Employes, and everything else goes to the external accountant. This keeps the in-scope estate smaller, but it means the accountant is a third party holding Soon's confidential records and is managed as a vendor accordingly (action V-8).
5. Marketing website (soon.works) — analytics and advertising¶
These run on the public marketing site only, never inside the application, and load
only after cookie consent (CookieConsent.astro gates them via Google Consent Mode).
| Vendor | Purpose |
|---|---|
| Google Analytics (via Google Tag Manager) | Website analytics |
| Meta / Facebook Pixel | Advertising conversion measurement |
| PostHog | Website product analytics |
No analytics or advertising tags run in the customer-facing application. The only external script the application front end loads is Google Maps (verified 2026-08-22).
6. Not in use — decommissioned or never adopted¶
Recorded deliberately: earlier ISMS drafts, the CSP allowlist and old dependencies name these, and an auditor who finds the reference needs an answer.
| Vendor | Position |
|---|---|
| Zendesk | Never adopted — support runs on Intercom |
| Databox, Hex, Microsoft Clarity, Airtable, Bitbucket | No longer used |
| Epsagon | Discontinued (vendor shut down). The legacy EpsagonMonitoringTrail CloudTrail is being replaced — see the close-out plan, task 5 |
| Mailgun | Not used. Code path exists in mailer.js; SES is the production sender |
| DeepSeek, Mistral, xAI (Grok API) | Not used in the product. API keys are still present in the production environment — remove and revoke (§7) |
| Azure | Legacy development environment; to be gone before the audit |
| GCP | Retained only for Google Maps and remaining Secret Manager entries; not a general compute platform |
| Netlify | Superseded by Cloudflare for front-end hosting. The account still exists but holds nothing (owner, 2026-08-22) — close it (action V-7) |
| Segment · Datadog · Mutiny · Sprig · Cohere · HubSpot | Not used. Present only as stale entries in the application's CSP allowlist — see §7 |
7. Actions arising¶
| # | Action | Why | Owner |
|---|---|---|---|
| V-1 | Remove and revoke the DeepSeek, Mistral and xAI API keys from the production environment | Unused live credentials are pure liability; an auditor reading the environment config will ask what they are | Thomas |
| V-2 | Prune the CSP allowlist in soon-server/src/server/cspConfig.js — drop Segment, Datadog, Mutiny, Sprig, Cohere, HubSpot, Facebook, DoubleClick, Clarity and Google Analytics from the application policy |
Every allowed domain is a permitted exfiltration route. The application loads none of them | Thomas |
| V-3 | Confirm Sentry PII scrubbing is enabled (sendDefaultPii: false, data-scrubbing on) and record the project's data region |
Sentry is the most likely accidental route for customer personal data to leave the EU | Thomas |
| V-4 | Scope what the OpenAI integration sends — which fields, whether any customer personal data is included, and confirm zero-retention API terms | Required for an honest sub-processor disclosure and for GXO-style questionnaires | Thomas |
| V-5 | Collect the DPAs for every Category A vendor into Drive → Legal → Vendors | Closes SOC 2 #67 and #68 | Olaf |
| V-6 | Publish the Category A list as the sub-processor list on the Trust Center | Prospects ask for it in every security review | Olaf |
| V-7 | Close the dormant Netlify account | An unused hosting account with live DNS is a classic audit finding — stale deploys and dangling subdomains outlive the team's memory of them | Thomas |
| V-8 | Confirm the accountant's engagement letter carries confidentiality terms, and file it | Required for SOC 2 #68; the accountant holds Soon's financial and payroll-related employee data | Olaf |
| V-9 | Put the CyberSquad engagement on a signed footing — a consultancy agreement plus a completed NDA, and record the ISMS access grant in the external access register | Andrea reads the risk register and the findings — the most sensitive material we hold. A.5.19–A.5.21 apply to him exactly as they do to a SaaS vendor, and #68 wants the confidentiality terms in writing. Olaf signs for Soon; Alessandro must not, as Andrea is his brother (related-party note, ISMS-DOC-05-2 §1.7) | Olaf |
8. How vendors are managed¶
- Before adoption. Any vendor that will process customer personal data, hold credentials or receive source code is assessed against the Supplier Relationships Policy and added here before it goes live.
- Assurance. For Category A, obtain the provider's SOC 2 Type 2 or ISO 27001 certificate and its DPA. File both in Drive → Legal → Vendors.
- Review. This register is reviewed annually, and immediately on any change to the Category A list. Category A changes are notified to customers per the DPA.
- Exit. On termination, confirm data deletion or return per the Records Retention & Protection Policy and move the vendor to §6 with the date.
9. Roles¶
- ISM (Olaf Jacobson) — owns this register, collects DPAs, approves new vendors, runs the annual review.
- Engineering lead (Thomas Picauly) — confirms what each integration actually sends; owns V-1 to V-4.
- Infrastructure (Melvin Jacobson) — cloud provider configuration and region settings.
Related documents¶
- Supplier Relationships Policy (A.5.19–A.5.23)
- Information Asset Inventory — §D now points here
- Privacy and Personal Data Protection Policy · Records Retention & Protection Policy
- Cloud Service Policy · Acceptable Use Policy — AI tooling rules
- System Description · SOC 2 Readiness — controls #67, #68
Change log¶
| Version | Date | Author | Comments |
|---|---|---|---|
| 0.3 | 2026-08-22 | ISMS | Added CyberSquad (Andrea Cardinali) as an internal-tools vendor — an omission found in pre-audit review: he is the one external party with read access to the whole ISMS, so the supplier controls apply to him. Raised action V-9. |
| 0.2 | 2026-08-22 | ISMS | Owner confirmations applied: Soon runs no accounting system of its own — the external accountant is the vendor (AFAS is their tool), so a confidentiality-terms check was added (V-8); the dormant Netlify account is empty and is to be closed (V-7). |
| 0.1 | 2026-08-22 | ISMS | First version. Vendor list confirmed with the owner and cross-checked against the application source code; split into core sub-processors, per-tenant integrations and internal tools; decommissioned vendors recorded; six actions raised (unused AI API keys, stale CSP allowlist, Sentry PII scrubbing, OpenAI data scope, DPA collection, Trust Center publication). |