Compliance Matrix
Last updated: September 12, 2026
This matrix provides an overview of how Boon's security controls align with key regulatory frameworks and industry standards. This alignment helps our customers understand how our security program supports their compliance requirements.
Detailed Control Mapping
GDPR Requirements
GDPR Requirement | Boon Controls | Implementation Status |
|---|---|---|
Records of Processing Activities | Data inventory, processing registers | Partially implemented |
Data Transfers | Standard contractual clauses, transfer impact assessments | Partially implemented |
CCPA Requirements
CCPA Requirement | Boon Controls | Implementation Status |
|---|---|---|
Right to Know | Data inventory, user request workflows | Implemented |
Right to Delete | Deletion procedures, third-party notification | Implemented |
Right to Opt-Out | Consent management, data sharing controls | Implemented |
Right to Non-Discrimination | Policy enforcement, training and awareness | Implemented |
Privacy Notice | Privacy policy, collection notice | Implemented |
Reasonable Security | Security framework, regular assessments | Partially implemented |
Current Compliance Status
Boon takes a pragmatic approach to security certifications and compliance:
Infrastructure Certifications: We build on AWS and Heroku infrastructure, which maintain formal SOC 2, ISO 27001, and other certifications
Security Controls: We've implemented controls mapped to SOC 2 and ISO 27001 frameworks
Security Testing: We conduct regular third-party security assessments including penetration tests and vulnerability scans
Privacy Compliance: We've conducted self-assessments against GDPR and CCPA requirements and implemented appropriate controls
Documentation: We maintain comprehensive security documentation available to customers under NDA
This approach provides substantive security protections while allowing us to focus resources on continuous security improvements rather than certification overhead. Assessment reports are available to customers under NDA to support their vendor due diligence processes.
For questions about our compliance program or to request detailed documentation, please contact us at compliance@goboon.co
Last updated: April 20, 2026
This matrix is provided for informational purposes only and does not constitute legal advice.