

SOSAFE
By SoSafe
Here's the typical implementation process for SoSafe software in a brief, bullet-point format:
Initial Setup: Choose the services and features you need from SoSafe's offerings.
User Data Sync: Integrate SoSafe with your existing systems to sync user data.
Customization: Tailor the platform to your organization's needs and branding.
Phishing Simulation Setup: If selected, integrate the phishing simulation with your email system.
Training Content: Customize and set up the training modules for your employees.
Technical Implementation: Follow SoSafe's technical documentation to ensure proper setup.
User Onboarding: Get all employees registered and familiar with the platform.
Testing: Conduct initial tests to ensure everything is working as expected.
Launch: Roll out the platform to your entire organization.
Personalized Security Awareness Training: The platform reduces the time investment per user by 60% through personalized training modules, which suggests a high degree of customization to meet individual user needs.
Integration with Leading Providers: SoSafe works with leading market providers to continuously improve the platform and offer a comprehensive overview of security measures, indicating that it can be tailored to integrate with existing systems and workflows.
SoSafe offers comprehensive training and support to new users to ensure they can effectively utilize the platform:
Implementation and Onboarding: SoSafe provides a fast implementation process, typically taking around 20 days, with minimal effort required from the client’s side. A dedicated Customer Success Manager assists throughout the onboarding process, including the kick-off phase.
Training Programs: SoSafe’s training measures are aimed at all employees and include interactive awareness training with learning modules, short videos, examples from everyday work, and short quizzes. The training covers essential topics such as password use, malware detection, and data misuse, and includes simulated phishing emails to help employees recognize and respond to phishing attacks.
Personalized Learning: SoSafe offers a personalized learning platform that tailors content to each user’s unique risk profile, ensuring a deeper understanding and engagement with cybersecurity concepts. The platform uses data-driven personalization to deliver targeted content, saving up to 30% of the time investment compared to traditional methods.
Data Encryption: Customer data is encrypted in transit over public networks using at least TLS 1.2, and all systems and data drives use full-disk AES encryption at rest.
Access Controls: Only authorized SoSafe employees have access to customer data, and all access is restricted to privileged groups unless specifically requested and reviewed for validity. Unauthorized or inappropriate access to customer data is treated as a security incident and managed through an incident management process.
Endpoint Security: All endpoints are secured with endpoint protection, and SoSafe employees use company-managed mobile devices with enforced security measures, including antivirus systems and mobile device management software.
Monthly Release Notes: SoSafe publishes monthly release notes that detail new features, enhancements, and bug fixes. These updates include improvements to the user interface, new functionalities, and fixes for any identified issues.
Continuous Improvement: The platform is continuously updated to stay aligned with the latest security regulations and standards, ensuring that it remains effective and compliant. SoSafe’s development team actively works on enhancing the platform’s features and addressing any bugs to provide a seamless user experience.
Data Ownership: SoSafe collects personal data only as necessary to provide its services and processes this data exclusively for the purposes described. The company has strict controls in place to manage access to customer data, ensuring that only authorized employees can access this data, and all access is restricted to privileged groups. Data ownership policies are designed to ensure that data is handled securely and in compliance with GDPR and other relevant regulations.
Scaling Up: Scaling up typically involves enhancing the capacity of existing resources to handle increased demand. This might include adding more hardware or upgrading existing systems to improve performance and support more concurrent users. SoSafe’s infrastructure, hosted on AWS cloud, supports vertical scaling, allowing organizations to increase their resource allocation as their needs grow.
Scaling Down: Scaling down involves reducing resources when demand decreases, which can help organizations manage costs more effectively. This might include deactivating or removing unnecessary resources. SoSafe’s cloud-based infrastructure allows for easy scaling down, ensuring that organizations can adjust their resource usage without significant downtime or disruption.
Contract Renewal
Automatic Renewal: SoSafe subscriptions automatically renew each month unless the business notifies SoSafe 15 days in advance or the service is canceled by SoSafe. This automatic renewal ensures continuity of service unless explicitly canceled by the user.
Notification for non-renewal: To avoid automatic renewal, businesses must provide advance notice to SoSafe at least 15 days before the renewal date. This allows time for contract review, usage analysis, and negotiation of better terms if necessary.
Fee Adjustments: SoSafe reserves the right to adjust subscription fees and other charges at its sole discretion. Any fee changes will become effective at the end of the current billing cycle unless the subscription is canceled. Prior notice of any fee changes will be provided, and continued use of the service after the fee change constitutes acceptance of the new fees.
Contract Renewal Process: The renewal process involves either continuing under existing terms or renegotiating and amending the terms to suit current business needs. Renewal discussions can also be an opportunity to introduce clients to newer features, additional services, or upgraded offerings.
Contract Cancellation
Cancellation Notice: To cancel the SoSafe service, businesses must contact SoSafe 15 days prior to the desired cancellation date. This notice period allows for the orderly termination of services and return of any proprietary equipment provided by SoSafe.
Return of Equipment: If an account is terminated or canceled, all equipment provided by SoSafe must be returned within 15 days of termination. Failure to return equipment may result in a replacement fee.
Refunds: Refunds for subscription fees may be considered on a case-by-case basis and are provided at the sole discretion of SoSafe and its parent company, Traction Health. Variable check-in charges are not eligible for refunds.
Mid-Subscription Cancellation: If a cancellation is requested mid-subscription, the subscription will run until the next renewal date. For example, if the renewal date is June 28 and cancellation is requested on June 1, the subscription will continue until June 28.
ISO 27001: SoSafe is ISO 27001-certified, which is a widely recognized international standard for information security management. The certification was achieved on December 20, 2022, and the company undergoes yearly performance surveillance audits to maintain this certification.
GDPR (General Data Protection Regulation): SoSafe is fully compliant with GDPR, ensuring that all personal data is processed in accordance with the stringent data protection regulations set by the European Union.
TISAX (Trusted Information Security Assessment Exchange): SoSafe participates in TISAX, which is a standard for information security in the automotive industry, facilitated by the ENX Association on behalf of the German Association of the Automotive Industry (VDA).
HIPAA (Health Insurance Portability and Accountability Act): SoSafe’s platform is designed to support compliance with HIPAA, which is crucial for handling sensitive healthcare information securely.