Create secure Client Portals directly on monday.com
Client Portal Builder lets you easily build, manage, and publish custom Client Portals directly on monday. Securely share board items, files, and more in password-protected Client Portals. Watch the ↗️ Getting Started video to see the app in action.
Does the app restrict redirects and forwards only to approved destinations, or show a warning when redirecting to potentially untrusted content?
Not answered
Does the app protect against mass parameter assignment attacks?
Yes
We use Zod to validate user input.
Does the app perform encoding and sanitization on all user supplied parameters to protect against Cross-Site Scripting?
Yes
We use react in the front end, which provides a protection layer against XSS attacks. In the backend, we use Zod to validate user input.
Does the developer protect all state-changing actions against Cross-Site Request Forgery (CSRF)?
Not answered
Does the developer have mechanisms to notify monday.com in case of a security breach?
Yes
We would notify them through a support request if we got evidence that a third party had access to critical app data.
Does this developer have a process for installing application-level updates and security patches for the service (such as software packages and databases)?
Not answered
Compliance
Is the app certified with the information security standard ISO/IEC 27001:2022?
Not answered
Is the app compliant with the Health Insurance Portability and Accountability Act (HIPAA)?
Not answered
Is the app certified with System and Organization Controls (SOC 2 or SOC 3)?
Not answered
Is the app compliant with the General Data Protection Regulation (GDPR)?
Yes
Data
Does the app send any data outside of monday.com? If yes, indicate whether the data is customer-submitted (e.g., board names, item names, doc content) or non-customer-submitted (e.g., account ID, board ID, user ID).
Not answered
Where does the app store logs data?
monday
Where does the app store the app data?
monday
Does the developer ensure application logs do not contain secrets or personally-identifiable information (PII)?
Not answered
Is customer data segregated from the data of other customers (for example logically or physically)?
Yes
We are using monday storage: Customer data gets stored in their monday.com account.
Privacy
Does the developer enforce multi-factor authentication on employees access to systems which may process customer data?
Not answered
Does the developer protect access to customer data based on the principle of least privilege?
Yes
We are a small company, so we don't have non-classified company employees in the first place.
Reviews
June 4, 2025
TK: The team is the best at support and helping get things solved. Highly recommend
Installation history
We have data for December 28, 2024 onwards only. Collected sometime after 00:00 UTC daily.