Make monday.com work with Microsoft 365 & SharePoint →
Mirror Magic: Numbers logo

Mirror Magic: Numbers

Monday Man LLC

5 (9)

1,089 installs, since January 19, 2023.   36 installs/month.   Updated January 27, 2025.

Free plan available No touch
Gallery image Gallery image Gallery image

Powerful copying of number mirror values

Mirror Magic: Numbers — Write summarized number mirror column values to local and other mirror columns using simple recipes. No formulas needed.


Watch the instant demo here: Mirror Magic: Numbers


Summarize number mirrors with any of the following functions: Sum, Average, Median, Min, Max, Count, Count Positive, Count Negative, Count Zero


The first step of your journey to amazing mirror functionality. A collection of powerful, easy-to-use recipes that will give you the power to magically make your Mondays better.


Magic is power. Please wield it wisely.

Security & Compliance

Security

Does the developer periodically perform penetration testing?

Yes
AWS managed services is routinely testing its platform. AWS provides the only access to our platform.

Does the developer have a dedicated security and privacy point of contact for such issues or questions?

No

Does the app restrict redirects and forwards only to approved destinations, or show a warning when redirecting to potentially untrusted content?

Yes
The app is an integration app, there are no browser based components, and no ability for the user to interact directly with the service. Redirects are not enabled.

Does the app protect against mass parameter assignment attacks?

Yes
All inputs are strongly typed and parsed prior to utilization ensuring only expected parameters and values are used and anything unexpected is discarded.

Does the app perform encoding and sanitization on all user supplied parameters to protect against Cross-Site Scripting?

Yes
All inputs are parsed, validated, and sanitized when received from the monday.com servers. There are no user supplied parameters - except those provided in a recipe configuration or through monday board data.

Does the developer protect all state-changing actions against Cross-Site Request Forgery (CSRF)?

Yes
All app requests come from the monday.com integration servers, and requests are authenticated with a monday.com JWT. CSRF protection is not relevant in this circumstance.

Does the developer have mechanisms to notify monday.com in case of a security breach?

Yes
We will notify monday.com through the app developer support channels of any breach where customer data was exposed, or possibility of code tampering as soon as we become aware.

Does this developer have a process for installing application-level updates and security patches for the service (such as software packages and databases)?

Yes
AWS Managed Services are used exclusively for infrastructure. The professionals at AWS manage all patches and updates. We are responsible for ensuring any code dependencies are up-to-date.

Compliance

Is the app certified with the information security standard ISO/IEC 27001:2022?

Not answered

Is the app compliant with the Health Insurance Portability and Accountability Act (HIPAA)?

No

Is the app certified with System and Organization Controls (SOC 2 or SOC 3)?

No

Is the app compliant with the General Data Protection Regulation (GDPR)?

Yes
For purposes of GDPR we are a data processor, not controller. We do not store PII within our own systems. We use third-party tools such as a help-desk platform which do collect data such as email addresses and communications.

Data

Does the app send any data outside of monday.com? If yes, indicate whether the data is customer-submitted (e.g., board names, item names, doc content) or non-customer-submitted (e.g., account ID, board ID, user ID).

Not answered

Where does the app store logs data?

Not answered

Where does the app store the app data?

Not answered

Does the developer ensure application logs do not contain secrets or personally-identifiable information (PII)?

Yes
Logging of payloads and queries is restricted to our dev environment to prevent storing any PII. Secrets are stored in a manner that automatically obfuscates them if an object is logged, and code is reviewed to ensure they are not manually logged.

Is customer data segregated from the data of other customers (for example logically or physically)?

Yes
The account ID and app ID are in every record key, as a result, only records for the current account and app are accessible.

Privacy

Does the developer enforce multi-factor authentication on employees access to systems which may process customer data?

Yes
All systems utilize two-factor authentication. A very limited number of people, developers and support staff have the ability to access production servers, which only process but do not store customer board data.

Does the developer protect access to customer data based on the principle of least privilege?

Yes
We do not store customer board data. Only classified employees have access to metadata, user’s name, and email address.

Reviews

No reviews yet.

Installation history

We have data for December 28, 2024 onwards only. Collected sometime after 00:00 UTC daily.

ID: 10000158App ID: 10037460Listing updated: December 25, 2024