With Formula Automations in monday.com, you can streamline data management by automatically updating values with complex calculations. You can read Formula Columns inside subitems, enabling seamless data tracking across different levels of your boards. Additionally, Formula Columns can incorporate Mirror Columns, allowing you to pull in data from other boards for enhanced integration and more efficient workflows. This flexibility improves your ability to manage and analyze data effectively.
Security & Compliance
Security
Does the developer periodically perform penetration testing?
No
Does the developer have a dedicated security and privacy point of contact for such issues or questions?
Does the app restrict redirects and forwards only to approved destinations, or show a warning when redirecting to potentially untrusted content?
Yes
As an app without UI we only need to re-direct the user to monday.com for authentication purposes.
Does the app protect against mass parameter assignment attacks?
Yes
We leverage GraphQL with robustly typed models to modify data, ensuring anything sent to the strongly typed attributes is disregarded. Additionally, we employ DTOs (Data Transfer Objects) for efficient data management.
Does the app perform encoding and sanitization on all user supplied parameters to protect against Cross-Site Scripting?
Yes
Yes, our app employs encoding and sanitization on all user-supplied parameters to protect against Cross-Site Scripting (XSS) attacks. Using Node.js with the Express framework as our backend, we utilize the mongo-sanitize package to sanitize all incoming requests. This approach ensures that any potentially malicious input is appropriately filtered and encoded to prevent XSS vulnerabilities. By incorporating this sanitization step in our request handling process, we provide a secure environment and minimize the risk of XSS attacks, thereby safeguarding both our application and user data.
Does the developer protect all state-changing actions against Cross-Site Request Forgery (CSRF)?
No
Not relevant
Does the developer have mechanisms to notify monday.com in case of a security breach?
Yes
Our app is hosted in AWS, includes an alarm and monitoring system designed to alert the development team in the event of a security breach. The system continuously monitors our application and infrastructure, and if it detects any suspicious activity or potential breach, it triggers an alarm to notify the team immediately. Once alerted, the development team can quickly investigate the issue, take corrective action, and inform monday.com of the breach if necessary. This proactive approach helps ensure that potential threats are addressed swiftly to minimize impact on our service and customers.
Does this developer have a process for installing application-level updates and security patches for the service (such as software packages and databases)?
Yes
Our service utilizes Dependabot to manage application-level updates and security patches for our software packages and databases. Dependabot automatically checks for updates and generates pull requests for package dependencies, including both application-level updates and security patches. For critical and high-severity updates, we prioritize immediate action. Once Dependabot identifies these updates, our team promptly reviews and applies them to maintain the security and stability of our service. For other, lower-priority updates, we manage them on a scheduled basis. Our team reviews and applies these updates at regular intervals to ensure that the service remains up-to-date while balancing resource allocation and operational continuity.
Compliance
Is the app certified with the information security standard ISO/IEC 27001:2022?
Yes
Is the app compliant with the Health Insurance Portability and Accountability Act (HIPAA)?
Yes
We are not compliant with HIPAA as we do not store private
Is the app certified with System and Organization Controls (SOC 2 or SOC 3)?
No
Is the app compliant with the General Data Protection Regulation (GDPR)?
Yes
Data
Does the app send any data outside of monday.com? If yes, indicate whether the data is customer-submitted (e.g., board names, item names, doc content) or non-customer-submitted (e.g., account ID, board ID, user ID).
Not answered
Where does the app store logs data?
Not answered
Where does the app store the app data?
Not answered
Does the developer ensure application logs do not contain secrets or personally-identifiable information (PII)?
Yes
All code Pull Requests undergo an approval process that includes examining the log content. The team also uses methods to obscure any data that might contain confidential details.
Is customer data segregated from the data of other customers (for example logically or physically)?
Yes
We separate data by including an account id field in all entities and applying filters based on it for all requests
Privacy
Does the developer enforce multi-factor authentication on employees access to systems which may process customer data?
Yes
multi-factor authentication is enforced on employees on all the systems which processes/hold customer data (Mongo DB, AWS)
Does the developer protect access to customer data based on the principle of least privilege?
Yes
Only the Support and Development team leads have restricted access to customer data.
Reviews
January 23, 2025
HV: This app changed my life!
Installation history
We have data for December 28, 2024 onwards only. Collected sometime after 00:00 UTC daily.