Security Program Executive Summary
Last updated: September 12, 2026
Introduction
At Boon, security is foundational to everything we do. As a referral hiring platform, we understand the sensitivity of the data entrusted to us and maintain comprehensive security controls to protect this information. This executive summary provides an overview of our security program, designed to give you confidence in our commitment to protecting your data.
Security Program Overview
Boon's security program is built on industry best practices and designed to align with key frameworks including SOC 2, ISO 27001, GDPR, CCPA, and the NIST Cybersecurity Framework. Our security approach encompasses:
Strong Governance
Clear security roles and responsibilities
Comprehensive security policies and procedures
Regular independent security assessments
Continuous monitoring and improvement
Data Protection
AES-256 encryption for all data at rest
TLS 1.2+ encryption for all data in transit
Strict access controls based on least privilege
Regular data backup and recovery testing
Infrastructure Security
Cloud security best practices across AWS and Heroku environments
Regular vulnerability scanning and remediation
Network security controls and monitoring
Continuous configuration management
Application Security
Secure development lifecycle practices
Regular security testing including penetration tests
API security controls including authentication and rate limiting
Input validation and output encoding
Operational Security
24/7 security monitoring
Comprehensive incident response capabilities
Regular security awareness training
Formal change management processes
Security Program Maturity
At Boon, we've adopted a pragmatic approach to security that prioritizes effective protection over checkbox compliance. Our security program has evolved significantly since our founding, with our focus on implementing strong security controls that directly protect our customers' data.
While we haven't pursued formal certifications like SOC 2 or ISO 27001 at this stage, we've intentionally built our security program to align with these frameworks. Our infrastructure leverages AWS and Heroku's certified environments while our own security controls are designed with these standards in mind.
Our security roadmap includes continued maturation of our controls, with plans to undergo formal readiness assessments as we scale. This approach allows us to direct our resources toward security improvements that deliver the most value to our customers rather than pursuing certifications prematurely.
We believe in transparency about our security posture and welcome customer discussions about specific security requirements. Many of our enterprise customers have completed their own security assessments of our platform, providing additional validation of our security controls.
Key Security Metrics
Recovery Objectives: RTO: 4 hours, RPO: 1 hour
Latest Penetration Test: February 2025 with zero medium or high findings
Vulnerability Management: Mean time to remediate critical issues: 24 hours
Security Testing: Annual third-party penetration testing, with continuous automated scanning
Business Continuity: BC/DR plan reviewed and tested at least annually
Recent Security Enhancements
Full policy set refreshed across 23 policies, including a complete ISMS suite (May 2026)
Business continuity and disaster recovery plan reviewed and updated (May 2026)
Sub-processor directory reviewed and expanded to 15 service providers (August 2026)
Incident response tabletop exercise completed and remediations applied (January 2026)
Static API keys replaced with workload identity, and automated secret scanning enabled (January 2026)
Compliance Approach
Boon leverages certified infrastructure while maintaining a pragmatic approach to formal organizational certifications:
Infrastructure Certifications: Our platform is built on AWS and Heroku, which maintain SOC 2, ISO 27001, and other certifications
Security Controls: We've implemented controls aligned with SOC 2 principles and ISO 27001 requirements
Regulatory Compliance: Our policies and procedures address GDPR and CCPA/CPRA requirements
Independent Validation: Regular third-party security assessments validate our security controls
Documentation: Comprehensive security documentation available for client due diligence processes
This approach allows us to maintain robust security while focusing resources on continuous security improvements and client-specific requirements.
Business Continuity and Disaster Recovery
Boon maintains a robust business continuity and disaster recovery program, including:
Comprehensive incident response capabilities
Regular BC/DR testing (most recent: September 2025)
Multi-region redundancy for critical systems
Regular data backups with encryption
Recovery objectives consistently met in testing
Security Assurance
We provide multiple forms of security assurance:
Regular customer security reviews
Comprehensive security documentation
Penetration test and vulnerability scan summaries
BC/DR test reports
Security program updates
Security Roadmap Highlights
Our continuous security improvement roadmap includes:
Continued ISMS control implementation and evidence collection
Automated secret scanning across repositories and public-facing assets
Least-privilege IAM enforcement across all production service accounts
Annual third-party penetration testing and full policy review
For roadmap detail relevant to your organization, contact security@goboon.co
Engaging with Our Security Team
We welcome dialogue about our security program:
Schedule a security review meeting
Request security documentation
Discuss specific security requirements
Report security concerns
Security Posture Overview
Current Security Status: Strong
Last policy review: May 2026
All Critical and High vulnerabilities: Remediated
Current Focus: Continuous Improvement
Recent Security Updates
August 28, 2026: Sub-processor directory reviewed and expanded to 15 service providers
May 13, 2026: Business Continuity and Disaster Recovery Plan updated
May 7, 2026: Full policy set refreshed — 23 policies including the ISMS suite
April 21, 2026: Resiliency Plan updated
April 20, 2026: Data Privacy & Compliance Summary and Compliance Matrix updated
January 3, 2026: Incident response tabletop exercise completed
Security At-A-Glance
Data Encryption: AES-256 for data at rest, TLS 1.2+ for data in transit
Authentication: Multi-factor authentication required for all staff
Recovery Objectives: RTO: 4 hours, RPO: 1 hour (consistently exceeded in testing)
Monitoring: 24/7 automated monitoring with real-time alerts
At Boon, we don't view security as a checkbox exercise but as a foundational element of our business. Our security program is designed to protect our clients' data, maintain trust, and continuously improve our security posture in the face of evolving threats.
— Dakota Younger, CEO, Boon
This summary is reviewed quarterly. Last updated: September 11, 2026
Need Help?
Contact us at security@goboon.co.