Does the app restrict redirects and forwards only to approved destinations, or show a warning when redirecting to potentially untrusted content?
Yes
The only forward is done for Klaviyo log in and it is processed in scope of Klaviyo OAuth with the URL stored in env parameters.
Does the app protect against mass parameter assignment attacks?
Yes
Does the app perform encoding and sanitization on all user supplied parameters to protect against Cross-Site Scripting?
Yes
This app does not accept user input, it is only the automation. We however use security headers and URL sanitization to assure only the authorized requests.
Does the developer protect all state-changing actions against Cross-Site Request Forgery (CSRF)?
Yes
Does the developer have mechanisms to notify monday.com in case of a security breach?
Yes
The notification will Initial notification would be an email to [email protected].
Does this developer have a process for installing application-level updates and security patches for the service (such as software packages and databases)?
Yes
Our security bugfix policies including patching times are published here:https://getreport.ai/bugfix-policy
Compliance
Is the app certified with the information security standard ISO/IEC 27001:2022?
Not answered
Is the app compliant with the Health Insurance Portability and Accountability Act (HIPAA)?
Yes
Is the app certified with System and Organization Controls (SOC 2 or SOC 3)?
No
Is the app compliant with the General Data Protection Regulation (GDPR)?
Yes
Data
Does the app send any data outside of monday.com? If yes, indicate whether the data is customer-submitted (e.g., board names, item names, doc content) or non-customer-submitted (e.g., account ID, board ID, user ID).
Not answered
Where does the app store logs data?
Not answered
Where does the app store the app data?
Not answered
Does the developer ensure application logs do not contain secrets or personally-identifiable information (PII)?
Yes
Only logs collected are access logs (which contain no secrets or PII) and analytics (we ensure that no secrets or PII are sent to analytics).
Is customer data segregated from the data of other customers (for example logically or physically)?
Yes
Only customer name and email is stored by us. All data is stored in separate database that is solely dedicated to Klaviyo integration.
Privacy
Does the developer enforce multi-factor authentication on employees access to systems which may process customer data?
Yes
We use MS Azure to process/hold all data. 2FA is strictly enforced for Azure access and access managed my MS Entra. The DB is only avaibale in a subnet to the app and all credentials are stored in a Azure keyvault.
Does the developer protect access to customer data based on the principle of least privilege?
Yes
The only data we store here is a mapping of a monday user to klaviyo user. Only CTO&CEO have access to the keywault and production DB.
Reviews
No reviews yet.
Installation history
We have data for December 28, 2024 onwards only. Collected sometime after 00:00 UTC daily.