Skip to content

Supplier Relationships Security Policy

Purpose. Soon runs entirely on third-party services — AWS, GitHub, Stripe, Intercom, Sentry, PostHog, Netlify and others. This policy defines how suppliers are vetted before onboarding, bound by agreements, tracked, reviewed and offboarded, so that customer and company data stays protected in the supply chain.

1. Scope

Applies to every third party that processes, stores or can access Soon or customer data, or that is critical to delivering the Soon service. This includes cloud and SaaS providers, sub-processors under customer DPAs, and contractors' tooling. It does not cover suppliers with no access to Soon data or systems (e.g. one-off purchases of goods).

2. Policy

2.1 Due diligence before onboarding

Before a new supplier is given Soon or customer data, the requester must, in proportion to the sensitivity of the data involved:

  • Review the supplier's security posture — independent assurance where available (SOC 2 report, ISO/IEC 27001 certificate, published security documentation).
  • Confirm where data will be stored and processed. For customer personal data, EU hosting/residency is required unless a valid GDPR transfer mechanism is in place.
  • Sign a Data Processing Agreement (DPA) whenever the supplier processes personal data on Soon's behalf, and confirm the supplier can be added to Soon's sub-processor list where customer DPAs require it.
  • Obtain approval per the Cloud Services Policy.

2.2 Security requirements in agreements

Agreements with suppliers that handle Soon or customer data must cover: confidentiality, security measures appropriate to the data classification, breach/incident notification, use of sub-contractors, and return or deletion of data at contract end. For standard SaaS this is normally met by the vendor's terms plus DPA; deviations must be assessed before signing.

2.3 Supplier register

Soon maintains a register of suppliers recording: supplier name, service provided, data processed and its classification, DPA status, assurance evidence held, internal owner and next review date. The Information Asset Inventory lists supplier services as assets. The supplier register is held in Google Drive (Soon shared drive). (Formerly asked for the location of the dedicated supplier register (or that the asset inventory serves as it).

2.4 Ongoing review

  • Each supplier in the register is reviewed annually or on contract renewal, whichever comes first: re-check assurance reports, incidents, changes to sub-processors and data locations.
  • Critical suppliers (AWS, Stripe, GitHub) are also reviewed when they announce material changes (e.g. new sub-processors or terms).
  • Significant changes to a supplier service that affect security must be risk assessed before adoption.

2.5 Offboarding

When a supplier relationship ends, the internal owner must: revoke Soon accounts and integrations (API keys, OAuth grants, webhooks), obtain return or deletion of Soon/customer data per the agreement, update the supplier register and the sub-processor list, and record the offboarding.

3. Roles & responsibilities

  • Supplier owner (the person accountable internally for each supplier) — performs due diligence, keeps register entries current, runs reviews and offboarding.
  • Policy owner (Olaf Jacobson, ISM) — maintains this policy and the supplier register, approves onboarding of suppliers handling Confidential/Restricted data.

Change log

Version Date Author Comments
0.1 2023-10-23 Olaf Jacobson First draft document
0.2 2026-07-18 Andrea Cardinali Rewritten lean and Soon-specific (ISMS overhaul) — grounded in the real supplier set; dropped enterprise contract lifecycle and CFO dispute escalation