For security reviewers¶
You've asked to evaluate Soon's security as part of a purchase or vendor review. This page tells you what we can share and how to get it. If you're already under NDA with us, skip to "What you can request".
Thanks for doing the diligence — we'd rather answer your questions directly than have you guess. Most enterprise security reviews of Soon can be completed from the materials below.
Start with the summary¶
Almost everything a first-pass review needs is on our Security at Soon page: hosting and data residency, encryption, access control, monitoring, secure development, sub-processors, breach notification, and data retention. Please read that first — it may answer most of your questionnaire on its own.
What you can request (under NDA)¶
Once a mutual NDA is in place, we can share:
| Document | What it covers |
|---|---|
| Security Overview | A fuller, structured description of our security programme and controls |
| Sub-processor list & DPAs | Every provider that touches customer data, their purpose and region, with data-processing agreements |
| Named policies | Specific policies relevant to your review (e.g. access control, incident response, encryption, backup) |
| SOC 2 Type 1 report | As soon as it is issued by our independent auditor |
| ISO/IEC 27001 certificate | On issue |
| Penetration test summary | An executive summary of our most recent independent test |
We share documents as PDFs (watermarked where sensitive). We don't share raw evidence, credentials, customer data, or our internal risk and incident records — if your review needs assurance on those, our SOC 2 report is the right instrument, since an independent auditor has examined them on your behalf.
How to request¶
Email security@soon.works with:
- Your organisation and your role in the review;
- Whether an NDA is already in place (if not, we'll send ours or sign yours);
- The specific documents or questions you need.
We aim to respond within two business days.
If you use a questionnaire (SIG, CAIQ, custom)¶
Send it over — we'll complete it against the materials above. To speed things up, point us at the sections your standard already maps to security controls, and we'll answer directly rather than in prose.
Reporting a vulnerability¶
If your review turns up a security issue, please tell us at security@soon.works before disclosing it, and don't access data that isn't yours while testing. We'll acknowledge and work with you on it.
Contact: security@soon.works