Skip to content

For security reviewers

You've asked to evaluate Soon's security as part of a purchase or vendor review. This page tells you what we can share and how to get it. If you're already under NDA with us, skip to "What you can request".

Thanks for doing the diligence — we'd rather answer your questions directly than have you guess. Most enterprise security reviews of Soon can be completed from the materials below.

Start with the summary

Almost everything a first-pass review needs is on our Security at Soon page: hosting and data residency, encryption, access control, monitoring, secure development, sub-processors, breach notification, and data retention. Please read that first — it may answer most of your questionnaire on its own.

What you can request (under NDA)

Once a mutual NDA is in place, we can share:

Document What it covers
Security Overview A fuller, structured description of our security programme and controls
Sub-processor list & DPAs Every provider that touches customer data, their purpose and region, with data-processing agreements
Named policies Specific policies relevant to your review (e.g. access control, incident response, encryption, backup)
SOC 2 Type 1 report As soon as it is issued by our independent auditor
ISO/IEC 27001 certificate On issue
Penetration test summary An executive summary of our most recent independent test

We share documents as PDFs (watermarked where sensitive). We don't share raw evidence, credentials, customer data, or our internal risk and incident records — if your review needs assurance on those, our SOC 2 report is the right instrument, since an independent auditor has examined them on your behalf.

How to request

Email security@soon.works with:

  1. Your organisation and your role in the review;
  2. Whether an NDA is already in place (if not, we'll send ours or sign yours);
  3. The specific documents or questions you need.

We aim to respond within two business days.

If you use a questionnaire (SIG, CAIQ, custom)

Send it over — we'll complete it against the materials above. To speed things up, point us at the sections your standard already maps to security controls, and we'll answer directly rather than in prose.

Reporting a vulnerability

If your review turns up a security issue, please tell us at security@soon.works before disclosing it, and don't access data that isn't yours while testing. We'll acknowledge and work with you on it.


Contact: security@soon.works