Set up in minutes. Keep it updated. Mitigate effectively. Perfect for project managers, risk officers, and compliance teams.
Capable Risk Register is a comprehensive risk management solution for monday.com. It provides a means to setup auto-updating risk columns so that you can get validated, correct risk level calculation. The app comes with templates for use and setup videos to help you get going in no time too.
Why Capable Risk Register?
📋 Comprehensive Risk Management: Instantly create a clear, professional risk register to track and mitigate potential issues.
⚙️ Fully Customizable Solution: Tailor everything from impact and probability levels to risk categories, ensuring the tool fits your specific project needs.
👥 Collaborative Approach: Empower every team member to contribute, ensuring a comprehensive view of potential risks.
📊 Visualize with Ease: User-friendly risk matrix, pie charts, and bar charts provide a visual snapshot of all your risks.
🔐 Governance & Compliance: Support for ISO14971, IEC60812, ISO27001, ISO 31000, PCI, and many more GRC programs requiring a risk register!
How It Works
Add your risks to our template, link mitigations and tasks as needed.
Capable Risk Register will validate and compute impact + auto-create your visual risk matrix.
Customize your view with risk categories and priorities.
Track and update risks throughout your project lifecycle—done!
Does the developer periodically perform penetration testing?
Not answered
Does the developer have a dedicated security and privacy point of contact for such issues or questions?
Yes
security@capablekoala.co
Does the app restrict redirects and forwards only to approved destinations, or show a warning when redirecting to potentially untrusted content?
Yes
Does the app protect against mass parameter assignment attacks?
Yes
Does the app perform encoding and sanitization on all user supplied parameters to protect against Cross-Site Scripting?
Yes
Does the developer protect all state-changing actions against Cross-Site Request Forgery (CSRF)?
Yes
Does the developer have mechanisms to notify monday.com in case of a security breach?
Yes
Monday would be contacted by the new support ticket mechanism upon discovery of a breach.
Does this developer have a process for installing application-level updates and security patches for the service (such as software packages and databases)?
Yes
Vulnerabilities are monitored with github's dependabot and security vulnerabilities will be updated within 48 hours for critical, and 1 week for High or below.
Compliance
Is the app certified with the information security standard ISO/IEC 27001:2022?
Not answered
Is the app compliant with the Health Insurance Portability and Accountability Act (HIPAA)?
Not answered
Is the app certified with System and Organization Controls (SOC 2 or SOC 3)?
Not answered
Is the app compliant with the General Data Protection Regulation (GDPR)?
Yes
Data
Does the app send any data outside of monday.com? If yes, indicate whether the data is customer-submitted (e.g., board names, item names, doc content) or non-customer-submitted (e.g., account ID, board ID, user ID).
Yes
Non-customer-submitted data may be sent to monitoring systems to track application errors.
Where does the app store logs data?
monday
Where does the app store the app data?
monday
Does the developer ensure application logs do not contain secrets or personally-identifiable information (PII)?
Yes
Only the customer account ID, board id and item ids being used for logging. Sentry tracks minimal data and has PII scrubbers enabled.
Is customer data segregated from the data of other customers (for example logically or physically)?
Yes
All data is stored using monday.com provided key/value storage (which is segregated by customer by default), or in the customer's monday.com boards.
Privacy
Does the developer enforce multi-factor authentication on employees access to systems which may process customer data?
Yes
Company policy is that all accounts for the company have MFA when supported.
Does the developer protect access to customer data based on the principle of least privilege?
Yes
Customer data is only available to senior level employees who have been approved by the company directors.
Reviews
No reviews yet.
Historical data
Installation history
We have data for December 28, 2024 onwards only. Collected sometime after 00:00 UTC daily.
Total number of installs
Change in total number of installs in last 7 days
Compares the number of installs on each date with 7 days previously:
Max
Min
Current
Change in total number of installs in last 30 days
Compares the number of installs on each date with 30 days previously:
Max
Min
Current
Change in total number of installs in last 90 days
Compares the number of installs on each date with 90 days previously:
Max
Min
Current
Ratings history
Categories history
Each of the following is a yes/no answer, so the graphs show 1 for yes, and 0 for no.