We encourage you to get a live demonstration with our team and to see firsthand how monday.com becomes a fully integrated QMS in click! Get a free demo here
The application is an out of the box eQMS (Electronic Quality Management System) which is allowing customers to manage their Regulatory and Compliance affairs in monday.com. The application will be compatible with FDA regulations in general and specifically CFR part 11 which is crucial for companies who wish to manage those processes in a digital platform. The application is mainly for managing Deviations, CAPAs, Complaints, Action Item and supporting features.
It will allow configuration and updates per specific needs of the customer.
Does the app restrict redirects and forwards only to approved destinations, or show a warning when redirecting to potentially untrusted content?
Yes
The app only redirects to `*.monday.com` addresses for authentication, never accepting user input.
Does the app protect against mass parameter assignment attacks?
Yes
The app is built using a framework which is not vulnerable to this exploit
Does the app perform encoding and sanitization on all user supplied parameters to protect against Cross-Site Scripting?
Yes
User input is sanitised and escaped before being saved to the database wherever applicable
Does the developer protect all state-changing actions against Cross-Site Request Forgery (CSRF)?
Yes
CSRF tokens are used to protect all state-changing requests
Does the developer have mechanisms to notify monday.com in case of a security breach?
Yes
monday will be contacted via their support channels to inform in the case of a data breach within 48 hours.
Does this developer have a process for installing application-level updates and security patches for the service (such as software packages and databases)?
Yes
Dependabot is used to monitor all third party software patches as they are released and all critical and high severity patches are updated within 24 hours. Other patches are rolled out within 1 week.
Compliance
Is the app certified with the information security standard ISO/IEC 27001:2022?
Not answered
Is the app compliant with the Health Insurance Portability and Accountability Act (HIPAA)?
No
Is the app certified with System and Organization Controls (SOC 2 or SOC 3)?
No
Is the app compliant with the General Data Protection Regulation (GDPR)?
Yes
Data
Does the app send any data outside of monday.com? If yes, indicate whether the data is customer-submitted (e.g., board names, item names, doc content) or non-customer-submitted (e.g., account ID, board ID, user ID).
Not answered
Where does the app store logs data?
monday
Where does the app store the app data?
monday
Does the developer ensure application logs do not contain secrets or personally-identifiable information (PII)?
Yes
Logs are constructed to only contain account ids
Is customer data segregated from the data of other customers (for example logically or physically)?
Yes
Data is stored using monday's APIs to store each account's data in completely isolated stores.
Privacy
Does the developer enforce multi-factor authentication on employees access to systems which may process customer data?
Yes
Data is held in monday and protected by MFA, as well as in google workspace.
Does the developer protect access to customer data based on the principle of least privilege?
Yes
Only senior employees with an ongoing need to access customer data as part of their duties are granted any form of access.
Reviews
No reviews yet.
Installation history
We have data for December 28, 2024 onwards only. Collected sometime after 00:00 UTC daily.