Security & assurance
What we are certified for, and what we are not
Our certifications cover SoftOpen’s hosting and support operations. They do not certify the open-source platforms themselves, and we will not let a procurement process pretend otherwise.
Certifications
Current, with scope and expiry
ISO/IEC 27001:2022
Managed hosting and support operations
- Issued by
- BSI
- Valid until
- 30 June 2027
ISO 9001:2015
Delivery of software deployment and configuration services
- Issued by
- BSI
- Valid until
- 12 March 2027
Cyber Essentials Plus
Corporate estate and delivery devices
- Issued by
- IASME
- Valid until
- 14 November 2026
What these certifications do not cover
They certify how SoftOpen operates — our hosting platform, our support processes, our corporate estate. They say nothing about the security of ERPNext, Grafana, Mattermost, Twenty or Umbraco themselves, which are independent projects we do not control. Any supplier telling you their ISO 27001 certificate covers a third-party open-source project is misrepresenting it.
Data residency
UK and EU regions only
Managed hosting runs in UK South or West Europe, in our AWS account or yours. Customer data does not leave the selected region.
We do not offer hosting in other regions. Not as a negotiating position — we do not operate there, so we could not meet a standard of service we would be willing to commit to. If you need US or APAC hosting, we are the wrong supplier and we will say so early.
Penetration testing
Annual, CREST-accredited, against the managed hosting platform. A summary letter is available under NDA. Findings are remediated on a severity-based schedule and re-tested.
Data processing
A standard DPA is available on request and is signed at order. We act as processor for customer data held in managed environments, and as controller only for the contact data of the people we deal with.
Sub-processors
Who else touches the data
| Provider | Purpose | Region |
|---|---|---|
| Amazon Web Services | Managed hosting infrastructure | UK South, West Europe |
| Cloudflare | Edge, DNS and DDoS protection | Global edge, EU config |
| SendGrid | Transactional email from managed platforms | EU |
| Atlassian | Support ticketing | EU |
We give 30 days’ notice before adding a sub-processor that would touch customer data, and you may object.
Data ownership and exit
You own your data and the deployed instance. There is no lock-in, and no exit fee. If you leave us and the platform is in your own cloud account, nothing moves at all — we hand over the runbooks and remove our access. If it is on our platform, we migrate it to yours as a scoped piece of work.
This is not generosity. We argue that proprietary lock-in is bad for buyers, and a supplier who says that while quietly building some of their own is not worth listening to. Your configuration and any extension we write are in your repository from the first commit.
Reporting a vulnerability
If you believe you have found a security issue in our infrastructure or in something we have deployed, email us. We will acknowledge within one working day and keep you updated until it is closed. We do not take legal action against good-faith research.
Need to complete a security questionnaire?
Send it over. We answer them in full, including the questions where the honest answer is “no”.