Skip to content

Trust & Security

Last updated: August 2026

Soon helps organisations plan and manage their workforce. That means handling your employees’ data, so we have built security into how the product and the company operate. This page explains how we protect your information.

Anything not answered here? Email [email protected].

At a glance

  • Hosting: AWS, EU (Ireland) — your data stays in the European Union
  • Encryption: TLS 1.2+ in transit, AES-256 at rest
  • Access: least privilege, MFA on administrative access, quarterly reviews
  • Monitoring: continuous logging, alerting and automated threat detection
  • Your role: Soon is a GDPR data processor; you remain the controller

Compliance and independent assurance

We are completing formal, independently assessed security programmes:

ProgrammeStatus
SOC 2 Type 1 (Security)Examination in progress with an independent auditor
ISO/IEC 27001:2022Certification in progress
Independent penetration testPart of the same programme
AWS (our infrastructure provider)ISO 27001, SOC 1/2/3 and PCI DSS certified

We will publish the SOC 2 report and ISO certificate here as soon as they are issued. Until then we do not describe ourselves as certified — you will only ever see accurate status from us.

How we protect your data

Your data stays in the EU

The platform runs on Amazon Web Services in eu-west-1 (Ireland) and your data is stored in the European Union. One exception is listed under sub-processors below, and we are closing it.

Encryption everywhere

All data is encrypted in transit with TLS 1.2 or higher, and at rest with AES-256 using AWS-managed keys.

Strict access control

We work on a least-privilege basis, multi-factor authentication is required for administrative access to production, and we review who has access every quarter. People joining and leaving follow a documented process.

Always-on monitoring

We run centralised logging, application error monitoring and continuous automated threat detection, with alerts going straight to our security team.

Secure by development

Every change is peer-reviewed and passes automated security testing, including dependency and secret scanning, before it can reach production. Development, staging and production are kept separate.

Backups and resilience

Your data is backed up automatically to encrypted, retained snapshots, and the production database runs across multiple availability zones with automatic failover.

Prepared for incidents

We maintain a documented incident-response process. As a GDPR processor, if a personal-data breach affects you we notify you without undue delay so you can meet your own 72-hour obligation.

A security-minded team

Everyone at Soon is bound by confidentiality agreements, completes security-awareness training with quarterly refreshers, and works under documented policies. We are fully remote with no offices; everything runs in the cloud.

Signing in to Soon

Soon supports enterprise single sign-on (SAML) with Microsoft Entra ID, Okta and Google Workspace, as well as Google and Microsoft social login.

For accounts that use an email and password, a built-in second factor is not available yet. If you require MFA today, use SSO or social login, which apply your own identity provider’s policies. Native MFA for email and password sign-in is on our roadmap.

Sub-processors

We rely on a small set of vetted providers to run the service:

ProviderPurposeRegion
Amazon Web ServicesInfrastructure and hostingEU (Ireland)
StripePayments and billingGlobal (PCI DSS)
WorkOSEnterprise single sign-onUS
IntercomCustomer supportUS โ€” moving to EU hosting
SentryError monitoringPer current agreement
Google WorkspaceInternal collaborationEU / global
Netlify, CloudflareWeb hosting and deliveryGlobal edge

We tell customers about material changes to this list, and current data-processing agreements are available on request.

Your data, your control

We keep your data for as long as your contract runs, and delete it within 90 days after it ends; backup copies then expire on their normal cycle. You can request an export or deletion of your data at any time, in line with your agreement and the GDPR.

See also our Terms of Service, Privacy Policy and Data Processing Agreement.

Found a security issue?

We welcome reports from security researchers. Email [email protected] — we investigate every report and will acknowledge yours. Please give us reasonable time to fix an issue before disclosing it publicly, and do not access or change data that is not yours while testing.

Need more detail?

Evaluating Soon for your organisation? Under a mutual NDA we can share our Security Overview, specific policies, our sub-processor list and data-processing agreements, and — once issued — our SOC 2 report. Email [email protected] and we will set you up.