Make monday.com work with Microsoft 365 & SharePoint →
Dashboard Hub for monday.com logo

Dashboard Hub for monday.com

Appfire Security badge

2.7 (10)

3,082 installs, since April 20, 2023.   114 installs/month.   Updated June 5, 2025.

14 days trial Touch
Gallery image Gallery image Gallery image Gallery image Gallery image Gallery image Gallery image

Centralize data into powerful, custom, shareable dashboards

Dashboard Hub lets you centralize data from your monday accounts, workspaces, and any external tool like Jira. Easily overcome reporting limitations by creating custom data cards with formulas, building powerful charts with dropdowns (even at subitem level), and securely sharing dashboards with password protection.


Interactive demo dashboards:

📊 Create custom charts and data cards with formulas

🌐 Centralize data across products (such as Jira)

🔒 Share password-protected dashboards


Dashboard Hub features

  • Create custom charts with view types such as Tables plus use Statistics, Segment customization, and more
  • Use calculations to gain specific data insights with Formula Cards
  • 15+ product integrations including monday CRM, dev, and Jira
  • Integrate and represent data from any source with REST APIs (Custom Reports)
  • Connect any number of boards from multiple accounts and workspaces
  • Password-protected links to share dashboards and boards externally
  • Secure and Enterprise-ready: multi-account data, product integrations, advanced permissions, secure external reporting, and more


Additional resources:

🚀 Difference with monday.com dashboards


See the full range of app functionality and contact our support team with any questions. 


Access our Trust Center if you have any security questions or concerns.


Appfire features dozens of top-selling apps that help teams solve big challenges.

Security & Compliance

Security

Does the developer periodically perform penetration testing?

Yes
Once in a year

Does the developer have a dedicated security and privacy point of contact for such issues or questions?

Yes

Does the app restrict redirects and forwards only to approved destinations, or show a warning when redirecting to potentially untrusted content?

Yes
As our app is executed inside Iframes we are restricted to that context, so we are not able to enforce redirects and forwarding actions that can take our users out of Monday's scope.

Does the app protect against mass parameter assignment attacks?

Yes
We use DTO's when it comes to create any new entity in our database, so the data that arrives to our backend is first enforced to be translated to our DTO before creating the new entity.

Does the app perform encoding and sanitization on all user supplied parameters to protect against Cross-Site Scripting?

Yes
In our frontend we use React as part of our stack and it escapes all values embedded inside any JSX expression. We don't rely only in this mechanism, we also have some means in place to sanitize the user input before it arrives to our backend. Finally, we rely on an ORM to abstract our access to the persistence layer, at this point we use a sanitization tool as a way to ensure that we preprocess the data before adding it to its final storage. This mechanism is also applied when we retrieve the data from the database. References: JSX Sanitization: https://legacy.reactjs.org/docs/introducing-jsx.html#jsx-prevents-injection-attacks

Does the developer protect all state-changing actions against Cross-Site Request Forgery (CSRF)?

Yes
On the first hand we implement a signed double cookie pattern storing cryptographic secret on our server side. On the other hand our backend servers only accept "application/json" content types which enforces the use of CORS mechanisms. References: * https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html#use-built-in-or-existing-csrf-implementations-for-csrf-protection

Does the developer have mechanisms to notify monday.com in case of a security breach?

Yes
Appfire Infosec to be notified of a security incident through internal ticketing system and Slack. Infosec will analyze the issue and notify monday within 24 hours. It is part of our incident handling ISO process

Does this developer have a process for installing application-level updates and security patches for the service (such as software packages and databases)?

Yes
Once we notice any kind of vulnerability by our own means or through our active bug bounty programs, we generate a security issue in our project and after triage process we try to confirm the severity. If severity is high or critical we try to attend the vulnerability as soon as possible and generate a fix. Once the mitigation is tested by part of our team we proceed to promote the patch to production. This publication process depends on the severity of the vulnerability. Critical vulnerabilities usually are published as hot fixes while lower severity vulnerabilities are programmed inside our releases planning.

Compliance

Is the app certified with the information security standard ISO/IEC 27001:2022?

Not answered

Is the app compliant with the Health Insurance Portability and Accountability Act (HIPAA)?

No

Is the app certified with System and Organization Controls (SOC 2 or SOC 3)?

Yes

Is the app compliant with the General Data Protection Regulation (GDPR)?

Yes

Data

Does the app send any data outside of monday.com? If yes, indicate whether the data is customer-submitted (e.g., board names, item names, doc content) or non-customer-submitted (e.g., account ID, board ID, user ID).

Not answered

Where does the app store logs data?

Not answered

Where does the app store the app data?

Not answered

Does the developer ensure application logs do not contain secrets or personally-identifiable information (PII)?

Yes
Every addition to our code base is reviewed at least by one team member not directly involved in the new code. Every pull request requires approval by other team members. In fact, we are trying to improve all our error logging mechanism continuously. Other tools used to register user interactions for analytics purposes are also explicitly sanitized not only at UI logging level, but also at request level.

Is customer data segregated from the data of other customers (for example logically or physically)?

Yes
All data is segregated logically by what we call account ID, that is an unique identifier related with Monday's user identification. We also encrypt the gadgets and gadget's configurations before persisting them in our database, so even if a malicious user manages to gain access to our database, he still won't be able to read our customer's data. We only store app related data so, the only Monday's data that we store is the Account ID.

Privacy

Does the developer enforce multi-factor authentication on employees access to systems which may process customer data?

Yes
All our infrastructure implements 2FA, both our servers and our persistence providers require its use.

Does the developer protect access to customer data based on the principle of least privilege?

Yes
Only part of our developers team have direct access to our production databases and this access is restricted to support tickets management. Database contents are encrypted, so we can't access directly to the dashboard's definitions or the gadget's configurations Addittionaly, our persistence provider also encrypts the data on disk so we apply two different encryption layers.

Reviews

October 26, 2024

C: This app you cannot even filter by Day, week or month. Completely misses a huge component of KPI reporting.

July 26, 2024

KM: Ability to send dashboards to clients with a password is great, but the functionality of the gadgets is very rudimentary. Can't display more than one column, can't filter by more than one item/column, can't display items from "last week"/"last month".

November 6, 2023

LD: Love the visualisation, privdes flexability to carry out more complex calcualtions too.

September 14, 2023

SD: Muy compleja, nada amigable

August 7, 2023

S: can't figure out how to get permission accesses set up :(

June 7, 2023

M: Cannot work with the boards i really want them to work on.

Installation history

We have data for December 28, 2024 onwards only. Collected sometime after 00:00 UTC daily.

ID: 10000200App ID: 10060376Listing updated: January 20, 2025