Trust & Security
Last updated: August 2026
Soon helps organisations plan and manage their workforce. That means handling your employees’ data, so we have built security into how the product and the company operate. This page explains how we protect your information.
Anything not answered here? Email [email protected].
At a glance
- Hosting: AWS, EU (Ireland) — your data stays in the European Union
- Encryption: TLS 1.2+ in transit, AES-256 at rest
- Access: least privilege, MFA on administrative access, quarterly reviews
- Monitoring: continuous logging, alerting and automated threat detection
- Your role: Soon is a GDPR data processor; you remain the controller
Compliance and independent assurance
We are completing formal, independently assessed security programmes:
| Programme | Status |
|---|---|
| SOC 2 Type 1 (Security) | Examination in progress with an independent auditor |
| ISO/IEC 27001:2022 | Certification in progress |
| Independent penetration test | Part of the same programme |
| AWS (our infrastructure provider) | ISO 27001, SOC 1/2/3 and PCI DSS certified |
We will publish the SOC 2 report and ISO certificate here as soon as they are issued. Until then we do not describe ourselves as certified — you will only ever see accurate status from us.
How we protect your data
Your data stays in the EU
The platform runs on Amazon Web Services in eu-west-1 (Ireland) and your data is stored in the European Union. One exception is listed under sub-processors below, and we are closing it.
Encryption everywhere
All data is encrypted in transit with TLS 1.2 or higher, and at rest with AES-256 using AWS-managed keys.
Strict access control
We work on a least-privilege basis, multi-factor authentication is required for administrative access to production, and we review who has access every quarter. People joining and leaving follow a documented process.
Always-on monitoring
We run centralised logging, application error monitoring and continuous automated threat detection, with alerts going straight to our security team.
Secure by development
Every change is peer-reviewed and passes automated security testing, including dependency and secret scanning, before it can reach production. Development, staging and production are kept separate.
Backups and resilience
Your data is backed up automatically to encrypted, retained snapshots, and the production database runs across multiple availability zones with automatic failover.
Prepared for incidents
We maintain a documented incident-response process. As a GDPR processor, if a personal-data breach affects you we notify you without undue delay so you can meet your own 72-hour obligation.
A security-minded team
Everyone at Soon is bound by confidentiality agreements, completes security-awareness training with quarterly refreshers, and works under documented policies. We are fully remote with no offices; everything runs in the cloud.
Signing in to Soon
Soon supports enterprise single sign-on (SAML) with Microsoft Entra ID, Okta and Google Workspace, as well as Google and Microsoft social login.
For accounts that use an email and password, a built-in second factor is not available yet. If you require MFA today, use SSO or social login, which apply your own identity provider’s policies. Native MFA for email and password sign-in is on our roadmap.
Sub-processors
We rely on a small set of vetted providers to run the service:
| Provider | Purpose | Region |
|---|---|---|
| Amazon Web Services | Infrastructure and hosting | EU (Ireland) |
| Stripe | Payments and billing | Global (PCI DSS) |
| WorkOS | Enterprise single sign-on | US |
| Intercom | Customer support | US โ moving to EU hosting |
| Sentry | Error monitoring | Per current agreement |
| Google Workspace | Internal collaboration | EU / global |
| Netlify, Cloudflare | Web hosting and delivery | Global edge |
We tell customers about material changes to this list, and current data-processing agreements are available on request.
Your data, your control
We keep your data for as long as your contract runs, and delete it within 90 days after it ends; backup copies then expire on their normal cycle. You can request an export or deletion of your data at any time, in line with your agreement and the GDPR.
See also our Terms of Service, Privacy Policy and Data Processing Agreement.
Found a security issue?
We welcome reports from security researchers. Email [email protected] — we investigate every report and will acknowledge yours. Please give us reasonable time to fix an issue before disclosing it publicly, and do not access or change data that is not yours while testing.
Need more detail?
Evaluating Soon for your organisation? Under a mutual NDA we can share our Security Overview, specific policies, our sub-processor list and data-processing agreements, and — once issued — our SOC 2 report. Email [email protected] and we will set you up.