Make monday.com work with Microsoft 365 & SharePoint →
Sketch Designs logo

Sketch Designs

42nd

146 installs, since August 1, 2022.   4 installs/month.   Updated March 24, 2024.

14 days trial Existing legacy
Gallery image Gallery image Gallery image

Easily share Sketch files across your organization.

Sketch Designs makes it super easy to share both public & private Sketch files across your organization. Great for documentation, design systems, digital assets and more.


Don’t worry about synchronization, constantly uploading exports of your latest version or confusing interfaces. Simply copy a Sketch shareable link of the file you wish to add and click save.

Security & Compliance

Security

Does the developer periodically perform penetration testing?

No
The app does not have servers.

Does the developer have a dedicated security and privacy point of contact for such issues or questions?

Yes

Does the app restrict redirects and forwards only to approved destinations, or show a warning when redirecting to potentially untrusted content?

Yes
The app does not allow linking in any way.

Does the app protect against mass parameter assignment attacks?

No
The app has no servers, and posts no data.

Does the app perform encoding and sanitization on all user supplied parameters to protect against Cross-Site Scripting?

Yes
Santization is done as best on the client side when reaching out to monday's our APIs and Sketch server, but this process is done by third parties (monday and Sketch).

Does the developer protect all state-changing actions against Cross-Site Request Forgery (CSRF)?

No
The app does not store data on its own, nor does it have any servers running code.

Does the developer have mechanisms to notify monday.com in case of a security breach?

Yes
We would notify monday via email if anything should happen. But since our app is static, and storage is done on monday itself, this is not a valid vector for concern.

Does this developer have a process for installing application-level updates and security patches for the service (such as software packages and databases)?

Yes
Application is 100% static, served via Google Cloud CDN. Update process is to update packages via npm update and deploy a new build to the cloud.

Compliance

Is the app certified with the information security standard ISO/IEC 27001:2022?

Not answered

Is the app compliant with the Health Insurance Portability and Accountability Act (HIPAA)?

No
No employees of the company in the USA.

Is the app certified with System and Organization Controls (SOC 2 or SOC 3)?

No

Is the app compliant with the General Data Protection Regulation (GDPR)?

Yes
The app does not store any data on its own.

Data

Does the app send any data outside of monday.com? If yes, indicate whether the data is customer-submitted (e.g., board names, item names, doc content) or non-customer-submitted (e.g., account ID, board ID, user ID).

Not answered

Where does the app store logs data?

other
no logs

Where does the app store the app data?

monday

Does the developer ensure application logs do not contain secrets or personally-identifiable information (PII)?

Yes
There are no logs.

Is customer data segregated from the data of other customers (for example logically or physically)?

Yes
All data storage is done via the monday js SDK

Privacy

Does the developer enforce multi-factor authentication on employees access to systems which may process customer data?

No
The app does not store anything outside monday.

Does the developer protect access to customer data based on the principle of least privilege?

Yes
Nobody has access to customer data. The app does not store anything outside monday.

Reviews

No reviews yet.

Installation history

We have data for December 28, 2024 onwards only. Collected sometime after 00:00 UTC daily.

ID: 10000091App ID: 10032584Listing updated: September 24, 2024