Does the developer periodically perform penetration testing?
Yes
Does the developer have a dedicated security and privacy point of contact for such issues or questions?
Yes
security@capablekoala.co
Does the app restrict redirects and forwards only to approved destinations, or show a warning when redirecting to potentially untrusted content?
No
Does the app protect against mass parameter assignment attacks?
No
Does the app perform encoding and sanitization on all user supplied parameters to protect against Cross-Site Scripting?
Yes
Does the developer protect all state-changing actions against Cross-Site Request Forgery (CSRF)?
Yes
The monday SDK is used for all state changes, and the SDK handles all server interactions.
Does the developer have mechanisms to notify monday.com in case of a security breach?
Yes
Monday would be contacted by the new support ticket mechanism (https://developer.monday.com/apps/changelog/attention-new-support-form-to-open-technical-tickets) upon discovery of a breach.
Does this developer have a process for installing application-level updates and security patches for the service (such as software packages and databases)?
Yes
Vulnerabilities are monitored with github's dependabot and security vulnerabilities will be updated within 48 hours for critical, and 1 week for High or below.
Compliance
Is the app certified with the information security standard ISO/IEC 27001:2022?
Not answered
Is the app compliant with the Health Insurance Portability and Accountability Act (HIPAA)?
Not answered
Is the app certified with System and Organization Controls (SOC 2 or SOC 3)?
Not answered
Is the app compliant with the General Data Protection Regulation (GDPR)?
Yes
Data
Does the app send any data outside of monday.com? If yes, indicate whether the data is customer-submitted (e.g., board names, item names, doc content) or non-customer-submitted (e.g., account ID, board ID, user ID).
No
Where does the app store logs data?
monday
Where does the app store the app data?
monday
Does the developer ensure application logs do not contain secrets or personally-identifiable information (PII)?
Yes
No logs are collected routinely. Sentry tracks minimal data and has PII scrubbers enabled
Is customer data segregated from the data of other customers (for example logically or physically)?
Yes
The app is front-end only, so all data is stored in their monday.com account. The board view settings is used to store some settings An upcoming feature will also use the storage from the JS SDK.
Privacy
Does the developer enforce multi-factor authentication on employees access to systems which may process customer data?
Yes
Company policy is that all accounts for the company have MFA when supported.
Does the developer protect access to customer data based on the principle of least privilege?
Yes
Nobody at the company can access customer data other than via any information which is reported to our error event system, sentry.
Reviews
February 22, 2026
SM: Awesome org charts even for complex charts. Easy to use with monday.com. Great customer service. Very responsive and they fix any issues quickly and communicate promptly. Highly recommend.
June 19, 2025
AS: Great customer service :) I'm still building my org chart and I like it so far :)
June 11, 2025
AM: Had an issue with the org charts generating vertically so contacted the team and this was resolved straight away in a very simple and straight forward manner. This app is very intuitive and easy to use, highly recommend!
December 10, 2024
BH: Great app
December 10, 2024
MD: Just the app you need to handle external users of monday.com.
March 4, 2024
AM: It's the best and most complete in terms of configuration options (I've tested ALL the others so far). The final layout of the cards needs to be improved a little, as they still "truncate" texts that aren't even that long.
Historical data
Installation history
We have data for December 28, 2024 onwards only. Collected sometime after 00:00 UTC daily.
Total number of installs
Change in total number of installs in last 1 day(s)
Compares the number of installs on each date with 1 days previously:
Max
Min
Current
Change in total number of installs in last 7 day(s)
Compares the number of installs on each date with 7 days previously:
Max
Min
Current
Change in total number of installs in last 30 day(s)
Compares the number of installs on each date with 30 days previously:
Max
Min
Current
Change in total number of installs in last 90 day(s)
Compares the number of installs on each date with 90 days previously:
Max
Min
Current
Change in total number of installs in last 180 day(s)
Compares the number of installs on each date with 180 days previously:
Max
Min
Current
Ratings history
Categories history
Each of the following is a yes/no answer, so the graphs show 1 for yes, and 0 for no.