Make monday.com work with Microsoft 365 & SharePoint →
BigPicture PPM logo

BigPicture PPM

Appfire Security badge

1,009 installs, since November 29, 2023.   50 installs/month.   Updated March 26, 2024.

Free Touch
Gallery image Gallery image Gallery image Gallery image Gallery image

Streamline portfolios with Gantt and resource management

BigPicture PPM is an enterprise-grade project portfolio management app that augments monday.com with an additional layer of information aggregation, visualization, and control. Manage projects, programs, and portfolios across your teams and organization.



🎦 Book a demo


What sets BigPicture apart:

  • 360° view of all work across the organization
  • Cross-board dependencies & resource management
  • Built for scale, with no limit of connected boards


Set up BigPicture to work the way you work


📊 Manage your portfolio in one place:

  • Build & manage collections of projects at or above the board level
  • Advanced structure of work items (at least 4 levels)
  • Aggregate data from across workspaces & boards


🕔 Craft informative timelines:

  • Visualize work on Gantt view at both portfolio & initiative levels
  • Aggregate data at each level of the work structure
  • Display items with or without dates


🗓️ Schedule work with outstanding accuracy:

  • Manage items across multiple boards & workspaces
  • Scheduling engine accounts for days off
  • Four types of scheduling dependencies
  • Rich data displayed in columns right next to the Gantt view


📣 Manage resources across the entire portfolio:

  • Manage workload & capacity of teams or individuals on the Resources view
  • “Find the perfect match” auto-suggests assignee based on capacity and skills
  • Easy drag & drop to re-assign tasks


Ready to manage your work at scale?


Explore app functionality via our documentation. To see what’s new, visit the Change Log!


The Appfire platform features dozens of top-selling apps that help teams worldwide solve big challenges.

Security & Compliance

Security

Does the developer periodically perform penetration testing?

Not answered

Does the developer have a dedicated security and privacy point of contact for such issues or questions?

Yes
https://trust.appfire.com/

Does the app restrict redirects and forwards only to approved destinations, or show a warning when redirecting to potentially untrusted content?

Yes
The application, written in Angular, out of the box provides security in terms of adding HTML/JS/links in inputs. Additionally, we protect ourselves with custom forms. In our application, it is not possible to add a link to an input, which means there is no possibility of redirecting to unknown sites. Our application only redirects to known sites such as: Documentation: https://appfire.atlassian.net/wiki/spaces/mBP/overview?platform=Monday Support: https://appfire.atlassian.net/servicedesk/customer/portal/32 Release notes: https://appfire.atlassian.net/wiki/spaces/DLP/pages/297994187?product=eu.softwareplant.bigpicture&utm_source=app&platform=Monday BigLab: https://bigpicture.one/lab/ - our website inviting users to participate in user research Main platform: direct link to a monday.com Subitem, Item, Group, or Board

Does the app protect against mass parameter assignment attacks?

Yes
We are using built-in Angular sanitisation methods and DOMPurify library for additional validation, and all inputs are then verified on the back end.

Does the app perform encoding and sanitization on all user supplied parameters to protect against Cross-Site Scripting?

Yes
We are using built-in Angular sanitisation methods and DOMPurify library for additional validation

Does the developer protect all state-changing actions against Cross-Site Request Forgery (CSRF)?

Yes
We use a strict refferrer policy in addition to Bearer Tokens

Does the developer have mechanisms to notify monday.com in case of a security breach?

Yes
Appfire Infosec to be notified of a security incident through internal ticketing system and Slack. Infosec will analyze the issue and notify monday within 24 hours. It is part of our incident handling ISO process.

Does this developer have a process for installing application-level updates and security patches for the service (such as software packages and databases)?

Yes
Application-level updates are done by the team, we analyze all dependencies with Snyk and install critical and high severity updates immediately. Other updates are scheduled in the team and done on regular basis. Critical: within 1 working week High: 2 weeks Medium, Low: Tech debt, planned according to team priorities and goals, up to 2 months

Compliance

Is the app certified with the information security standard ISO/IEC 27001:2022?

Not answered

Is the app compliant with the Health Insurance Portability and Accountability Act (HIPAA)?

No
HIPAA requirements do not normally apply to Appfire and its products, since we do not store or process protected health information (PHI). As such, a Business Associate Agreement (BAA) is not required.

Is the app certified with System and Organization Controls (SOC 2 or SOC 3)?

Yes
https://trust.appfire.com/?itemName=certifications&source=click

Is the app compliant with the General Data Protection Regulation (GDPR)?

Yes
https://trust.appfire.com/?itemUid=45220873-6e51-4dbb-b1b1-37d66ee9ef95&source=click

Data

Does the app send any data outside of monday.com? If yes, indicate whether the data is customer-submitted (e.g., board names, item names, doc content) or non-customer-submitted (e.g., account ID, board ID, user ID).

Not answered

Where does the app store logs data?

Not answered

Where does the app store the app data?

Not answered

Does the developer ensure application logs do not contain secrets or personally-identifiable information (PII)?

Yes
We do not log any secrets or PII. However, if someone accidentally adds some sensitive data in the logs, we overwrite the toString method in which we mask sensitive data using the * characters.

Is customer data segregated from the data of other customers (for example logically or physically)?

Yes
Logical. Schema-level isolation. Each client's data is stored in a separate schema within the same database. The application is configured to connect to the appropriate schema based on the client's identity.

Privacy

Does the developer enforce multi-factor authentication on employees access to systems which may process customer data?

Yes
All employees that have access to the AWS Console have MFA enabled. We have identity management system for manage permissions to the servers. To connect to the database user needs to be connected to the VPN which is secured with asymetric encryption.

Does the developer protect access to customer data based on the principle of least privilege?

Yes
Only DevOps administrators have access to the databases. Developers can request access to a specific tenant schema via a ticket. Developer access is granted for a limited time and for one schema only

Reviews

May 30, 2024

PG: We've had a great experience working with BigPicture to implement our use case in monday.com. The app meets our needs without being over complicated or having too many unnecessary features. The customer support team has been fantastic to work with!

Installation history

We have data for December 28, 2024 onwards only. Collected sometime after 00:00 UTC daily.

ID: 10000355App ID: 10062020Listing updated: November 6, 2024