Security & Compliance FAQ
Last updated: September 12, 2026
General Security Questions
How does Boon protect my data?
Boon implements multiple layers of security protection including:
AES-256 encryption for all data at rest
TLS 1.2+ encryption for all data in transit
Role-based access controls with least privilege principles
Multi-factor authentication for all users
Regular security assessments and penetration testing
Continuous monitoring and alerting systems
What certifications or compliance frameworks does Boon follow?
While Boon does not currently hold formal SOC 2 or ISO 27001 certifications, our platform is built on infrastructure providers (AWS, Heroku) that maintain these certifications. Our security program is designed with these frameworks in mind:
SOC 2: Our security controls are aligned with SOC 2 principles
ISO 27001: Our policies follow ISO 27001 control objectives
NIST Cybersecurity Framework: Used as a guiding framework for our security program
GDPR: Self-assessment completed with implemented controls
CCPA: Self-assessment completed with implemented controls
We conduct regular third-party security assessments, including penetration tests and vulnerability scans, to validate our security controls and demonstrate our commitment to security. We're happy to provide these assessment reports under NDA to support your compliance requirements.
Boon is actively progressing toward formal certification and maintains a complete policy set of 23 policies, including a full ISMS suite. Evidence of our certification readiness work is available on request.
How often does Boon perform security assessments?
We maintain a rigorous schedule of security assessments:
Penetration tests: annually, by an independent third party
Vulnerability scans: quarterly
Automated security scanning: continuous, with bi-weekly review
BC/DR exercises: at least annually
Data Protection Questions
Where is my data stored?
Customer production data is stored in the United States, in AWS data centers that maintain SOC 2 and ISO 27001 certification, with redundancy across multiple availability zones. Certain sub-processors may process limited data in the EU; where that occurs, transfers are governed by the EU–U.S. Data Privacy Framework, the UK Extension, and/or Standard Contractual Clauses. See Sub-processors & Data Transfers for the full list.
How is my data backed up?
We implement incremental backups every 25 minutes, with full backups performed daily. All backups are encrypted using AES-256 encryption and stored securely with strict access controls.
What is your data retention policy?
We retain customer data for the duration of your service agreement plus 30 days, unless otherwise specified by contractual agreements or regulatory requirements.
Does Boon share my data with third parties?
We do not sell, rent, or trade customer data. We only share data with third-party service providers necessary to deliver our services (such as cloud infrastructure providers), all of whom are bound by strict data protection agreements.
Access and Authentication Questions
How does Boon secure user access?
We implement multiple security controls including:
Strong password requirements (minimum 8 characters with complexity requirements)
Mandatory multi-factor authentication for all users
Role-based access controls with regular reviews
Session timeouts after 1 hour of inactivity
Automatic account lockout after multiple failed login attempts
Can I customize security settings for my organization?
Yes, enterprise customers can customize certain security settings including:
Password policy requirements
Session timeout duration
IP address restrictions
Custom role definitions
Incident Response Questions
What happens if there is a security incident?
We maintain a comprehensive incident response plan that includes:
24/7 monitoring and alerting systems
A dedicated incident response team
Clear communication protocols for notifying affected customers
Detailed procedures for containment, eradication, and recovery
Post-incident review and improvement processes
How quickly will I be notified if there is an incident affecting my data?
We commit to notifying affected customers within 24 hours of confirming an incident that impacts your data, with initial notifications often occurring much sooner.
Business Continuity Questions
What is your uptime guarantee?
We maintain a 99.9% uptime SLA for our platform (excluding scheduled maintenance windows).
How quickly can you recover from a disaster?
Our disaster recovery plan is designed to meet the following objectives:
Recovery Time Objective (RTO): 4 hours
Recovery Point Objective (RPO): 1 hour
In our most recent BC/DR tests, we consistently exceeded these targets, achieving recovery in under 3 hours with data loss of less than 45 minutes.
How often do you test your disaster recovery capabilities?
We conduct BC/DR exercises at least annually, with additional targeted tests when we make material changes to our infrastructure or provider dependencies. Our most recent exercises were completed in October 2024 (full failover simulation) and September 2025 (plan review and walkthrough). Reports are published in the Business Continuity section of this knowledge base.
Additional Questions
How can I report a security concern?
Security concerns can be reported directly to our security staff at security@goboon.co or through your account manager. We review and respond to all security reports promptly.
Can I receive a copy of your security documentation for my own compliance needs?
Yes, we provide security documentation to customers under NDA for their compliance and risk assessment purposes. Please contact your account representative to request this information.
How do you manage security for your third-party vendors?
We maintain a comprehensive vendor risk management program that includes:
Initial security assessments before engagement
Regular security reviews of critical vendors
Contractual security and privacy requirements
Continuous monitoring of vendor security posture
How can I stay updated on your security enhancements?
We publish quarterly security bulletins to all customers and maintain an up-to-date security changelog in our Security & Compliance Portal. Enterprise customers also receive direct notifications about significant security updates.