Security & Compliance FAQ

Last updated: September 12, 2026

General Security Questions

How does Boon protect my data?

Boon implements multiple layers of security protection including:

  • AES-256 encryption for all data at rest

  • TLS 1.2+ encryption for all data in transit

  • Role-based access controls with least privilege principles

  • Multi-factor authentication for all users

  • Regular security assessments and penetration testing

  • Continuous monitoring and alerting systems

What certifications or compliance frameworks does Boon follow?

While Boon does not currently hold formal SOC 2 or ISO 27001 certifications, our platform is built on infrastructure providers (AWS, Heroku) that maintain these certifications. Our security program is designed with these frameworks in mind:

  • SOC 2: Our security controls are aligned with SOC 2 principles

  • ISO 27001: Our policies follow ISO 27001 control objectives

  • NIST Cybersecurity Framework: Used as a guiding framework for our security program

  • GDPR: Self-assessment completed with implemented controls

  • CCPA: Self-assessment completed with implemented controls

We conduct regular third-party security assessments, including penetration tests and vulnerability scans, to validate our security controls and demonstrate our commitment to security. We're happy to provide these assessment reports under NDA to support your compliance requirements.

Boon is actively progressing toward formal certification and maintains a complete policy set of 23 policies, including a full ISMS suite. Evidence of our certification readiness work is available on request.

How often does Boon perform security assessments?

We maintain a rigorous schedule of security assessments:

  • Penetration tests: annually, by an independent third party

  • Vulnerability scans: quarterly

  • Automated security scanning: continuous, with bi-weekly review

  • BC/DR exercises: at least annually

Data Protection Questions

Where is my data stored?

Customer production data is stored in the United States, in AWS data centers that maintain SOC 2 and ISO 27001 certification, with redundancy across multiple availability zones. Certain sub-processors may process limited data in the EU; where that occurs, transfers are governed by the EU–U.S. Data Privacy Framework, the UK Extension, and/or Standard Contractual Clauses. See Sub-processors & Data Transfers for the full list.

How is my data backed up?

We implement incremental backups every 25 minutes, with full backups performed daily. All backups are encrypted using AES-256 encryption and stored securely with strict access controls.

What is your data retention policy?

We retain customer data for the duration of your service agreement plus 30 days, unless otherwise specified by contractual agreements or regulatory requirements.

Does Boon share my data with third parties?

We do not sell, rent, or trade customer data. We only share data with third-party service providers necessary to deliver our services (such as cloud infrastructure providers), all of whom are bound by strict data protection agreements.

Access and Authentication Questions

How does Boon secure user access?

We implement multiple security controls including:

  • Strong password requirements (minimum 8 characters with complexity requirements)

  • Mandatory multi-factor authentication for all users

  • Role-based access controls with regular reviews

  • Session timeouts after 1 hour of inactivity

  • Automatic account lockout after multiple failed login attempts

Can I customize security settings for my organization?

Yes, enterprise customers can customize certain security settings including:

  • Password policy requirements

  • Session timeout duration

  • IP address restrictions

  • Custom role definitions

Incident Response Questions

What happens if there is a security incident?

We maintain a comprehensive incident response plan that includes:

  • 24/7 monitoring and alerting systems

  • A dedicated incident response team

  • Clear communication protocols for notifying affected customers

  • Detailed procedures for containment, eradication, and recovery

  • Post-incident review and improvement processes

How quickly will I be notified if there is an incident affecting my data?

We commit to notifying affected customers within 24 hours of confirming an incident that impacts your data, with initial notifications often occurring much sooner.

Business Continuity Questions

What is your uptime guarantee?

We maintain a 99.9% uptime SLA for our platform (excluding scheduled maintenance windows).

How quickly can you recover from a disaster?

Our disaster recovery plan is designed to meet the following objectives:

  • Recovery Time Objective (RTO): 4 hours

  • Recovery Point Objective (RPO): 1 hour

In our most recent BC/DR tests, we consistently exceeded these targets, achieving recovery in under 3 hours with data loss of less than 45 minutes.

How often do you test your disaster recovery capabilities?

We conduct BC/DR exercises at least annually, with additional targeted tests when we make material changes to our infrastructure or provider dependencies. Our most recent exercises were completed in October 2024 (full failover simulation) and September 2025 (plan review and walkthrough). Reports are published in the Business Continuity section of this knowledge base.

Additional Questions

How can I report a security concern?

Security concerns can be reported directly to our security staff at security@goboon.co or through your account manager. We review and respond to all security reports promptly.

Can I receive a copy of your security documentation for my own compliance needs?

Yes, we provide security documentation to customers under NDA for their compliance and risk assessment purposes. Please contact your account representative to request this information.

How do you manage security for your third-party vendors?

We maintain a comprehensive vendor risk management program that includes:

  • Initial security assessments before engagement

  • Regular security reviews of critical vendors

  • Contractual security and privacy requirements

  • Continuous monitoring of vendor security posture

How can I stay updated on your security enhancements?

We publish quarterly security bulletins to all customers and maintain an up-to-date security changelog in our Security & Compliance Portal. Enterprise customers also receive direct notifications about significant security updates.