Make monday.com work with Microsoft 365 & SharePoint →
Recur logo

Recur

Mind Pollution, LLC

49 installs, since July 8, 2024.   4 installs/month.   Updated August 13, 2024.

14 days trial No touch
Gallery image Gallery image Gallery image

Recur makes recurring tasks easy.

Recur makes recurring tasks easy. With granular controls over the frequency of your recurring tasks, you can ensure your tasks meet your workflow. Choose between immediate creation of your recurring tasks or schedule them to appear on your board.


Get a 14-day free trial and start using Recur today, or [contact for more details and a demo.](mailto:[email protected])

Security & Compliance

Security

Does the developer periodically perform penetration testing?

No

Does the developer have a dedicated security and privacy point of contact for such issues or questions?

Yes

Does the app restrict redirects and forwards only to approved destinations, or show a warning when redirecting to potentially untrusted content?

Yes
The only redirect allowed by the app is during the OAuth flow and that is scoped to the defined Redirect URI in the monday developer portal.

Does the app protect against mass parameter assignment attacks?

Yes
The app does not have any freeform user inputs to enable this.

Does the app perform encoding and sanitization on all user supplied parameters to protect against Cross-Site Scripting?

Yes
There are no user freeform inputs to sanitize.

Does the developer protect all state-changing actions against Cross-Site Request Forgery (CSRF)?

Yes
The monday app is an iframed sandbox app with no direct access to the parent window. This helps prevent any state-changing actions via CSRF. The iframe communicates directly with a backend server and that is it.

Does the developer have mechanisms to notify monday.com in case of a security breach?

Yes
In the event of a security breach, monday will be notified via email immediately.

Does this developer have a process for installing application-level updates and security patches for the service (such as software packages and databases)?

Yes
Application-level updates and patches are handled via a continuous integration pipeline. When an update is needed, the code change is applied and pushed to a repository on Github. For the server, the push results in an new deployment of the backend server. For the iframe app, a zip file is created and uploaded.

Compliance

Is the app certified with the information security standard ISO/IEC 27001:2022?

Not answered

Is the app compliant with the Health Insurance Portability and Accountability Act (HIPAA)?

No

Is the app certified with System and Organization Controls (SOC 2 or SOC 3)?

No

Is the app compliant with the General Data Protection Regulation (GDPR)?

Yes

Data

Does the app send any data outside of monday.com? If yes, indicate whether the data is customer-submitted (e.g., board names, item names, doc content) or non-customer-submitted (e.g., account ID, board ID, user ID).

Not answered

Where does the app store logs data?

Not answered

Where does the app store the app data?

Not answered

Does the developer ensure application logs do not contain secrets or personally-identifiable information (PII)?

Yes
The backend logging is done through Cloudflare Logpush which allows fine-grained control of the logs sent. The app removes any PII as part of the logging. https://developers.cloudflare.com/workers/observability/logging/logpush/

Is customer data segregated from the data of other customers (for example logically or physically)?

Yes
Customer data is segregated using a PostgreSQL database (through Supabase) and tables within that database. Requests to access this data are validated using the authenticated monday.com user's session token then routed to the appropriate table and row in the table. Here's more on how Supabase handles customer data: https://supabase.com/docs/guides/database/secure-data

Privacy

Does the developer enforce multi-factor authentication on employees access to systems which may process customer data?

Yes
This is a solo business, and I have MFA enabled for all resources.

Does the developer protect access to customer data based on the principle of least privilege?

Yes
This is a solo business, and I am the only employee.

Reviews

July 31, 2024

GH: Only works on simple dates, not for timeline date fields. What a bummer...

Installation history

We have data for December 28, 2024 onwards only. Collected sometime after 00:00 UTC daily.

ID: 10000523App ID: 10147043Listing updated: July 15, 2024