Security Program Executive Summary

Last updated: September 12, 2026

Introduction

At Boon, security is foundational to everything we do. As a referral hiring platform, we understand the sensitivity of the data entrusted to us and maintain comprehensive security controls to protect this information. This executive summary provides an overview of our security program, designed to give you confidence in our commitment to protecting your data.

Security Program Overview

Boon's security program is built on industry best practices and designed to align with key frameworks including SOC 2, ISO 27001, GDPR, CCPA, and the NIST Cybersecurity Framework. Our security approach encompasses:

Strong Governance

  • Clear security roles and responsibilities

  • Comprehensive security policies and procedures

  • Regular independent security assessments

  • Continuous monitoring and improvement

Data Protection

  • AES-256 encryption for all data at rest

  • TLS 1.2+ encryption for all data in transit

  • Strict access controls based on least privilege

  • Regular data backup and recovery testing

Infrastructure Security

  • Cloud security best practices across AWS and Heroku environments

  • Regular vulnerability scanning and remediation

  • Network security controls and monitoring

  • Continuous configuration management

Application Security

  • Secure development lifecycle practices

  • Regular security testing including penetration tests

  • API security controls including authentication and rate limiting

  • Input validation and output encoding

Operational Security

  • 24/7 security monitoring

  • Comprehensive incident response capabilities

  • Regular security awareness training

  • Formal change management processes

Security Program Maturity

At Boon, we've adopted a pragmatic approach to security that prioritizes effective protection over checkbox compliance. Our security program has evolved significantly since our founding, with our focus on implementing strong security controls that directly protect our customers' data.

While we haven't pursued formal certifications like SOC 2 or ISO 27001 at this stage, we've intentionally built our security program to align with these frameworks. Our infrastructure leverages AWS and Heroku's certified environments while our own security controls are designed with these standards in mind.

Our security roadmap includes continued maturation of our controls, with plans to undergo formal readiness assessments as we scale. This approach allows us to direct our resources toward security improvements that deliver the most value to our customers rather than pursuing certifications prematurely.

We believe in transparency about our security posture and welcome customer discussions about specific security requirements. Many of our enterprise customers have completed their own security assessments of our platform, providing additional validation of our security controls.

Key Security Metrics

  • Recovery Objectives: RTO: 4 hours, RPO: 1 hour

  • Latest Penetration Test: February 2025 with zero medium or high findings

  • Vulnerability Management: Mean time to remediate critical issues: 24 hours

  • Security Testing: Annual third-party penetration testing, with continuous automated scanning

  • Business Continuity: BC/DR plan reviewed and tested at least annually

Recent Security Enhancements

  • Full policy set refreshed across 23 policies, including a complete ISMS suite (May 2026)

  • Business continuity and disaster recovery plan reviewed and updated (May 2026)

  • Sub-processor directory reviewed and expanded to 15 service providers (August 2026)

  • Incident response tabletop exercise completed and remediations applied (January 2026)

  • Static API keys replaced with workload identity, and automated secret scanning enabled (January 2026)

Compliance Approach

Boon leverages certified infrastructure while maintaining a pragmatic approach to formal organizational certifications:

  • Infrastructure Certifications: Our platform is built on AWS and Heroku, which maintain SOC 2, ISO 27001, and other certifications

  • Security Controls: We've implemented controls aligned with SOC 2 principles and ISO 27001 requirements

  • Regulatory Compliance: Our policies and procedures address GDPR and CCPA/CPRA requirements

  • Independent Validation: Regular third-party security assessments validate our security controls

  • Documentation: Comprehensive security documentation available for client due diligence processes

This approach allows us to maintain robust security while focusing resources on continuous security improvements and client-specific requirements.

Business Continuity and Disaster Recovery

Boon maintains a robust business continuity and disaster recovery program, including:

  • Comprehensive incident response capabilities

  • Regular BC/DR testing (most recent: September 2025)

  • Multi-region redundancy for critical systems

  • Regular data backups with encryption

  • Recovery objectives consistently met in testing

Security Assurance

We provide multiple forms of security assurance:

  • Regular customer security reviews

  • Comprehensive security documentation

  • Penetration test and vulnerability scan summaries

  • BC/DR test reports

  • Security program updates

Security Roadmap Highlights

Our continuous security improvement roadmap includes:

  • Continued ISMS control implementation and evidence collection

  • Automated secret scanning across repositories and public-facing assets

  • Least-privilege IAM enforcement across all production service accounts

  • Annual third-party penetration testing and full policy review

  • For roadmap detail relevant to your organization, contact security@goboon.co

Engaging with Our Security Team

We welcome dialogue about our security program:

  • Schedule a security review meeting

  • Request security documentation

  • Discuss specific security requirements

  • Report security concerns

Security Posture Overview

Current Security Status: Strong

  • Last policy review: May 2026

  • All Critical and High vulnerabilities: Remediated

  • Current Focus: Continuous Improvement

Recent Security Updates

  • August 28, 2026: Sub-processor directory reviewed and expanded to 15 service providers

  • May 13, 2026: Business Continuity and Disaster Recovery Plan updated

  • May 7, 2026: Full policy set refreshed — 23 policies including the ISMS suite

  • April 21, 2026: Resiliency Plan updated

  • April 20, 2026: Data Privacy & Compliance Summary and Compliance Matrix updated

  • January 3, 2026: Incident response tabletop exercise completed

Security At-A-Glance

  • Data Encryption: AES-256 for data at rest, TLS 1.2+ for data in transit

  • Authentication: Multi-factor authentication required for all staff

  • Recovery Objectives: RTO: 4 hours, RPO: 1 hour (consistently exceeded in testing)

  • Monitoring: 24/7 automated monitoring with real-time alerts

At Boon, we don't view security as a checkbox exercise but as a foundational element of our business. Our security program is designed to protect our clients' data, maintain trust, and continuously improve our security posture in the face of evolving threats.

— Dakota Younger, CEO, Boon

This summary is reviewed quarterly. Last updated: September 11, 2026

Need Help?

Contact us at security@goboon.co.