Trust & Security
Last updated: September 2026
Soon helps organisations plan and manage their workforce. That means handling your employees’ data, so we have built security into how the product and the company operate. This page explains how we protect your information.
Anything not answered here? Email security@soon.works.
At a glance
- Hosting: primary database and backups on AWS, EU (Ireland)
- Encryption: TLS 1.2+ in transit, AES-256 at rest
- Access: least privilege, MFA on administrative access, periodic reviews based on risk and changes in access needs
- Monitoring: continuous logging, alerting and automated threat detection
- Your role: Soon is a GDPR data processor; you remain the controller
Compliance and independent assurance
We are completing formal, independently assessed security programmes:
| Programme | Status |
|---|---|
| SOC 2 Type 1 (Security) | Examination in progress with an independent auditor |
| ISO/IEC 27001:2022 | Certification in progress |
| Independent penetration test | Part of the same programme |
| AWS (our infrastructure provider) | ISO 27001, SOC 1/2/3 and PCI DSS certified |
We will publish the SOC 2 report and ISO certificate here as soon as they are issued. Until then we do not describe ourselves as certified — you will only ever see accurate status from us.
How we protect your data
Primary hosting in the EU
The platform database and backups are hosted on Amazon Web Services in eu-west-1 (Ireland). Sub-processors may also store or process personal data outside the EU, as described in our Data Processing Agreement.
Encryption everywhere
All data is encrypted in transit with TLS 1.2 or higher, and at rest with AES-256 using AWS-managed keys.
Strict access control
We work on a least-privilege basis, multi-factor authentication is required for administrative access to production, and we review access periodically based on risk and when responsibilities or access needs materially change. People joining and leaving follow a documented process.
Always-on monitoring
We run centralised logging, application error monitoring and continuous automated threat detection, with alerts going straight to our security team.
Secure by development
Production changes follow documented change-control procedures with review and testing proportionate to risk. Emergency changes may follow an expedited process, with review and documentation as soon as reasonably practicable afterward. Development, staging and production are kept separate.
Backups and resilience
Your data is backed up automatically to encrypted, retained snapshots, and the production database runs across multiple availability zones with automatic failover.
Prepared for incidents
We maintain a documented incident-response process. As a GDPR processor, if a personal-data breach affects you we notify you without undue delay so you can meet your own 72-hour obligation.
A security-minded team
Everyone at Soon is bound by confidentiality agreements, completes security-awareness training with quarterly refreshers, and works under documented policies. We are fully remote with no offices; everything runs in the cloud.
Signing in to Soon
Soon supports enterprise single sign-on (SAML) with Microsoft Entra ID, Okta and Google Workspace, as well as Google and Microsoft social login.
For accounts that use an email and password, a built-in second factor is not available yet. If you require MFA today, use SSO or social login, which apply your own identity provider’s policies. Native MFA for email and password sign-in is on our roadmap.
Sub-processors
Intercom and Sentry currently process data in the United States. We plan to migrate these services to EU hosting, but no migration date is committed. Their current regions are listed below.
We rely on a small set of vetted providers to run the service:
| Provider | Purpose | Region |
|---|---|---|
| Amazon Web Services | Infrastructure and hosting | EU (Ireland) |
| Stripe | Payments and billing | Global (PCI DSS) |
| WorkOS | Enterprise single sign-on | US |
| Intercom | Customer support | US |
| Sentry | Error monitoring | US |
| Google Workspace | Internal collaboration | EU / global |
| Netlify, Cloudflare | Web hosting and delivery | Global edge |
We tell customers about material changes to this list, and current data-processing agreements are available on request.
Your data, your control
We keep your data for as long as your contract runs, and delete it within 90 days after it ends; backup copies then expire on their normal cycle. You can request an export or deletion of your data at any time, in line with your agreement and the GDPR.
See also our Terms of Service, Privacy Policy and Data Processing Agreement.
Found a security issue?
We welcome reports from security researchers. Email security@soon.works — we investigate every report and will acknowledge yours. Please give us reasonable time to fix an issue before disclosing it publicly, and do not access or change data that is not yours while testing.
Need more detail?
Evaluating Soon for your organisation? Under a mutual NDA we can share our Security Overview, specific policies, our sub-processor list and data-processing agreements, and — once issued — our SOC 2 report. Email security@soon.works and we will set you up.