For auditors and assessors¶
You've been given time-boxed, read-only access to Soon's full Information Security Management System. This page orients you so you can find what you need quickly. Unlike the public Security at Soon page, what you can see here is the complete, unedited ISMS — including our risk register, open items and internal notes.
Welcome, and thank you for the engagement. We've deliberately given you the whole thing, warts and all — where we have gaps or open remediation, you'll find them stated plainly rather than hidden. We'd rather you assess the reality.
Where to start¶
| You're looking for | Go to |
|---|---|
| What's in scope, and the system boundary | System Description and Context & Scope |
| Every control and its status | Document Register · Status dashboard |
| SOC 2 readiness (all 68 CC controls) | SOC 2 section — status, our narrative, and the evidence for each |
| Which policy meets which criterion | Policies SOC 2 expects |
| How risk drives control selection | Risk Assessment Report · Statement of Applicability |
| How we collect and store evidence | Evidence Register · Evidence procedure |
| What we know is open, and the plan | Two-week close-out plan and §7 of the System Description |
How to read this ISMS¶
- It's a version-controlled document set — every document carries its owner, status, version and control mappings in its front-matter, and every change has an author and date in git history. If you want to see when a control was documented or a decision made, the history is authoritative.
- Only
approveddocuments count for certification; many are currentlydraftand say so. The register and dashboard show the live status. - Evidence lives separately from the policies. Policy documents describe the control; the artefacts that prove it operate are held in our evidence store and indexed in the Evidence Register. Ask us for any artefact by its control reference.
- Automation: a number of technical controls are checked continuously by our own
monitoring (
soon-grc) rather than by point-in-time screenshots — see Continuous Control Monitoring. We're happy to run a live check during the engagement.
About your access¶
- Your access is read-only and time-boxed to the engagement; it's recorded in our external access register and revoked on completion.
- Sign-ins are logged (Cloudflare Access), which is itself part of how we demonstrate the access control working — feel free to ask to see it.
- If you need an artefact, a walkthrough, or a live control demonstration, contact your Soon point of contact or security@soon.works and we'll arrange it.
Requesting evidence and interviews¶
Tell us the control references you want to sample and we'll provide the artefacts and the control owner. Owners for each area are named in the risk report and the individual procedures (ISM: Olaf Jacobson; platform/access: Thomas Picauly; infrastructure/backups: Melvin Jacobson; independent internal audit: Andrea Cardinali, CyberSquad).
Point of contact: security@soon.works