Skip to content

Security & assurance

What we are certified for, and what we are not

Our certifications cover SoftOpen’s hosting and support operations. They do not certify the open-source platforms themselves, and we will not let a procurement process pretend otherwise.

Certifications

Current, with scope and expiry

ISO/IEC 27001:2022

Managed hosting and support operations

Issued by
BSI
Valid until
30 June 2027

ISO 9001:2015

Delivery of software deployment and configuration services

Issued by
BSI
Valid until
12 March 2027

Cyber Essentials Plus

Corporate estate and delivery devices

Issued by
IASME
Valid until
14 November 2026

What these certifications do not cover

They certify how SoftOpen operates — our hosting platform, our support processes, our corporate estate. They say nothing about the security of ERPNext, Grafana, Mattermost, Twenty or Umbraco themselves, which are independent projects we do not control. Any supplier telling you their ISO 27001 certificate covers a third-party open-source project is misrepresenting it.

Data residency

UK and EU regions only

Managed hosting runs in UK South or West Europe, in our AWS account or yours. Customer data does not leave the selected region.

We do not offer hosting in other regions. Not as a negotiating position — we do not operate there, so we could not meet a standard of service we would be willing to commit to. If you need US or APAC hosting, we are the wrong supplier and we will say so early.

Penetration testing

Annual, CREST-accredited, against the managed hosting platform. A summary letter is available under NDA. Findings are remediated on a severity-based schedule and re-tested.

Data processing

A standard DPA is available on request and is signed at order. We act as processor for customer data held in managed environments, and as controller only for the contact data of the people we deal with.

Sub-processors

Who else touches the data

ProviderPurposeRegion
Amazon Web ServicesManaged hosting infrastructureUK South, West Europe
CloudflareEdge, DNS and DDoS protectionGlobal edge, EU config
SendGridTransactional email from managed platformsEU
AtlassianSupport ticketingEU

We give 30 days’ notice before adding a sub-processor that would touch customer data, and you may object.

Data ownership and exit

You own your data and the deployed instance. There is no lock-in, and no exit fee. If you leave us and the platform is in your own cloud account, nothing moves at all — we hand over the runbooks and remove our access. If it is on our platform, we migrate it to yours as a scoped piece of work.

This is not generosity. We argue that proprietary lock-in is bad for buyers, and a supplier who says that while quietly building some of their own is not worth listening to. Your configuration and any extension we write are in your repository from the first commit.

Reporting a vulnerability

If you believe you have found a security issue in our infrastructure or in something we have deployed, email us. We will acknowledge within one working day and keep you updated until it is closed. We do not take legal action against good-faith research.

security@softopen.co.uk

Need to complete a security questionnaire?

Send it over. We answer them in full, including the questions where the honest answer is “no”.