Compliance Matrix

Last updated: September 12, 2026

This matrix provides an overview of how Boon's security controls align with key regulatory frameworks and industry standards. This alignment helps our customers understand how our security program supports their compliance requirements.

Detailed Control Mapping

GDPR Requirements

GDPR Requirement

Boon Controls

Implementation Status

Records of Processing Activities

Data inventory, processing registers

Partially implemented

Data Transfers

Standard contractual clauses, transfer impact assessments

Partially implemented

CCPA Requirements

CCPA Requirement

Boon Controls

Implementation Status

Right to Know

Data inventory, user request workflows

Implemented

Right to Delete

Deletion procedures, third-party notification

Implemented

Right to Opt-Out

Consent management, data sharing controls

Implemented

Right to Non-Discrimination

Policy enforcement, training and awareness

Implemented

Privacy Notice

Privacy policy, collection notice

Implemented

Reasonable Security

Security framework, regular assessments

Partially implemented

Current Compliance Status

Boon takes a pragmatic approach to security certifications and compliance:

  • Infrastructure Certifications: We build on AWS and Heroku infrastructure, which maintain formal SOC 2, ISO 27001, and other certifications

  • Security Controls: We've implemented controls mapped to SOC 2 and ISO 27001 frameworks

  • Security Testing: We conduct regular third-party security assessments including penetration tests and vulnerability scans

  • Privacy Compliance: We've conducted self-assessments against GDPR and CCPA requirements and implemented appropriate controls

  • Documentation: We maintain comprehensive security documentation available to customers under NDA

This approach provides substantive security protections while allowing us to focus resources on continuous security improvements rather than certification overhead. Assessment reports are available to customers under NDA to support their vendor due diligence processes.

For questions about our compliance program or to request detailed documentation, please contact us at compliance@goboon.co

Last updated: April 20, 2026

This matrix is provided for informational purposes only and does not constitute legal advice.