- Share your Ideas: Got an app request? We’d love to hear your suggestions.
Security & Compliance
Security
Does the developer periodically perform penetration testing?
Not answered
Does the developer have a dedicated security and privacy point of contact for such issues or questions?
Yes
support@fortimus.co
Does the app restrict redirects and forwards only to approved destinations, or show a warning when redirecting to potentially untrusted content?
Yes
We verify and allow redirects only to approved destinations
Does the app protect against mass parameter assignment attacks?
Yes
The app protects against mass parameter assignment attacks by explicitly permitting only trusted parameters through strong parameter filtering, ensuring that only intended attributes can be set
Does the app perform encoding and sanitization on all user supplied parameters to protect against Cross-Site Scripting?
Yes
The app performs encoding and sanitization on all user-supplied parameters to protect against Cross-Site Scripting (XSS), ensuring that any malicious scripts are neutralized before rendering
Does the developer protect all state-changing actions against Cross-Site Request Forgery (CSRF)?
Yes
The app protects all state-changing actions against Cross-Site Request Forgery (CSRF) by using token-based authentication and validating request origins and domains, ensuring that only trusted sources can perform operations
Does the developer have mechanisms to notify monday.com in case of a security breach?
Yes
We immediately notify monday.com via raising a ticket, emailing necessary personnel, and also via slack. Apart from this, we also take additional steps on our side to deactivate all user tokens
Does this developer have a process for installing application-level updates and security patches for the service (such as software packages and databases)?
Yes
We have a defined process to regularly apply application updates and security patches, including monitoring for vulnerabilities, assessing impact, testing in staging, and validating before deployment.
Compliance
Is the app certified with the information security standard ISO/IEC 27001:2022?
Not answered
Is the app compliant with the Health Insurance Portability and Accountability Act (HIPAA)?
Not answered
Is the app certified with System and Organization Controls (SOC 2 or SOC 3)?
Not answered
Is the app compliant with the General Data Protection Regulation (GDPR)?
Yes
Our app is hosted on monday code which complies with enterprise-grade security standards, including GDPR, HIPAA, ISO 27001, and SOC 2.
Data
Does the app send any data outside of monday.com? If yes, indicate whether the data is customer-submitted (e.g., board names, item names, doc content) or non-customer-submitted (e.g., account ID, board ID, user ID).
No
The app is deployed using monday code, and all data is securely stored on fully compliant monday.com servers
Where does the app store logs data?
monday
Where does the app store the app data?
monday
Does the developer ensure application logs do not contain secrets or personally-identifiable information (PII)?
Yes
We ensure that application logs are free from secrets and personally identifiable information (PII). We only log account ID and automation ID for debugging purposes
Is customer data segregated from the data of other customers (for example logically or physically)?
Yes
We use monday.com's secure storage, where all data is logically separated by account, region, and compartmentalized to ensure strong data isolation and security
Privacy
Does the developer enforce multi-factor authentication on employees access to systems which may process customer data?
Yes
We enforce multi-factor authentication (MFA) for all employee access to systems that process customer data
Does the developer protect access to customer data based on the principle of least privilege?
Yes
We enforce the principle of least privilege, ensuring access to customer data is limited to only those who need it for their role
Reviews
No reviews yet.
Historical data
Installation history
We have data for December 28, 2024 onwards only. Collected sometime after 00:00 UTC daily.
Total number of installs
Change in total number of installs in last 7 days
Compares the number of installs on each date with 7 days previously:
Max
Min
Current
Change in total number of installs in last 30 days
Compares the number of installs on each date with 30 days previously:
Max
Min
Current
Change in total number of installs in last 90 days
Compares the number of installs on each date with 90 days previously:
Max
Min
Current
Ratings history
Categories history
Each of the following is a yes/no answer, so the graphs show 1 for yes, and 0 for no.