SOC2C

Is this your company? Buyers are checking Yasoon UG here. Claim yasoon.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Yasoon UG logo

Yasoon UG

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Yasoon UG is SOC 2 Type II compliant. Yasoon UG also holds ISO 27001.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

More than 10.000 customers trust in yasoon to make their digital work smarter. For nearly 10 years yasoon is making award-winning apps that connect Atlassian's products to Microsoft 365. In this trust report you get an overview of yasoon’s security measures, regarding infrastructure, organization, products, data, privacy, and overall internal security. We continuously review our core systems, cloud infrastructure, endpoints, corporate procedures, enterprise risk, and employee accounts. This page gives you an always up-to-date status. To learn more on our privacy and security topics visit our [

Compliance & infrastructure

Hosting
AWS
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information

Documents

6

Subprocessors

7
  • A
    Amazon Web Services · Hosting service
    Germany
  • M
    Microsoft 365 · Customer communication
    Germany
  • L
    LogRocket · Debugging
    USA
  • S
    Sentry · Error logging
    USA
  • M
    Mailchimp · Newsletters
    USA
  • J
    Jira · Support
    Europe
  • V
    Vanta · Security
    USA

Compliance leadership

The person who leads Yasoon UG's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Yasoon UG's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Updated legal documentsAug 2024

We are pleased to announce that we 're changing the End User License Agreements (EULAs) for all of yasoon’s apps to the Marketplace Bonterms Standard Agreement on September 1st 2024. The Bonterms EULA simplifies the purchasing process by providing uniform terms, eliminating the need for customers to go through various vendor EULAs. Beyond the standard EULA, we've also addressed requests for vendor-specific amendments as follows: - Amendments for Atlassian Data Center and complementary Microsoft AppSource apps - Included our Data Processing Agreement (DPA), now enhanced with region-specific terms as CCPA, in response to customer requests - Included standard Bonterms Acceptable Use Policy (AUP) - Included our unchanged Service-Level Agreement (SLA) - Minor updates to our Privacy Policy for enhanced clarity Your continued use of our apps after September 1st 2024 will be considered acceptance of these updated terms. We thank you for your trust in our products and look forward to improving your processes. You can review all our legal documentation in yasoon’s Trust Docs.

Achieved SOC 2 certificationMay 2024

yasoon successfully gained it's SOC 2 Type II certification in May 2024. The report can be downloaded upon request here in our trust center.

Changed ISO27001 to latest ISO27001:2022 standardMar 2024

We are happy to announce that we have successfully finished our ISO27001:2022 certification.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Yasoon UG SOC 2 compliant?
Yasoon UG is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Yasoon UG ISO 27001 certified?
According to Yasoon UG's public trust center, Yasoon UG is ISO 27001 certified. On SOC2C this listing is Listed.
Is Yasoon UG SOC 2 Type I or Type II?
Yasoon UG is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Yasoon UG's SOC 2 for a vendor risk assessment?
Yes. Yasoon UG's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Yasoon UG penetration tested?
Yes — Yasoon UG undergoes third-party penetration testing as part of its security program. The pentest vendor is listed on its SOC2C profile.

Answers published by Yasoon UG

Reproduced from Yasoon UG's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Where are your servers located (data residency)?
Our apps are hosted in our infrastructure in Frankfurt, Germany (AWS). Data residency with world-wide locations is coming soon. Learn more: Data residency
Which data are stored and processed by Microsoft 365 for Jira?
Data storage We only store content that has been explicitly created by our apps. Most common data we store are: - User / instance settings - Metadata mappings between Atlassian & Microsoft objects - User login tokens retrieved by OAuth login We do not store Jira content (like Jira issues, comments, etc.) or Microsoft content (like chat content) on our servers. In some cases, we do store PII and / or OII data, in conformance with the GDPR. Data process We process data from your Jira, Microsoft 365 as well as our own data in our infrastructure in Frankfurt. This can be divided in data where the user directly interact and non user-interaction data. Examples for user interactions are: - Sending an email from Jira - Starting a Microsoft Teams chat from Jira - Creating a new Jira issue from Microsoft Teams Examples for non user-interactions are: - A Jira issue is updated and a Teams notification should be sent. - A Jira issue card is posted in a Microsoft Teams channel and the Teams bot links the issue to the conversation. - A task in Microsoft To Do is completed and a Jira issue should change it’s status. Find more information in our documentation: Data storage and processing
Do you have a DPA?
You'll find our Data Processing Agreement (DPA) here: Data Processing Addendum
Are there any differences between your Cloud and Data Center apps regarding security and legal?
Our data flows are almost identical regardless of the hosting option. This means that Jira Cloud and Jira Data Center have similar data storage and processing guidelines. To set up our Microsoft 365 for Jira, you need to make sure that your self-hosted version of Jira is publicly reachable. For more details, please refer to our documentation: Jira Data Center Fundamentals As for legal differences, we do have a Data Center specific amendment in our EULA, see here: EULA (yasoon.com)
Do you encrypt data at rest?
Data transferred from and to our services are encrypted with TLS 1.2. The implementation of TLS enforces the use of strong ciphers and key-lengths where supported by the browser. All customer data that are stored in our environment are encrypted on data drive level. Additionally there are data we consider sensitive (e.g. access tokens) not even our support staff should have access to. These data are additionally encrypted within the database with AES-256.