Make monday.com work with Microsoft 365 & SharePoint →
CloudTalk logo

CloudTalk

CloudTalk

128 installs, since April 21, 2026.   42 installs/month.   App updated April 8, 2026. Listing updated May 13, 2026.

Not paid No touch

AI calling & call logging for teams using monday.com

App long description:

Connect CloudTalk to monday.com CRM to centralize your communication workflows, synchronize contact data, and access customer intelligence directly within your existing boards.

Why teams love CloudTalk + monday.com CRM?

  • Global Reach, Local Presence: Expand your business instantly with local numbers in 160+ countries. Manage international teams and reach customers anywhere without leaving your monday.com workspace.
  • AI-Powered Call Insights: Don't just log calls—understand them. Every conversation automatically includes an AI Call SummarySentiment Analysis, and Extracted Topics directly in the item update. Spot customer mood trends without listening to hours of recordings.
  • Native "Recipe" Automation: We use monday.com's native recipe-based logic. Trigger specific workflows (like "Create a new lead" or "Update deal stage") automatically when a call ends or a contact is updated,.
  • Bi-Directional Sync: Keep your CRM clean. Using our Event-based sync, a column change in monday.comupdates the contact in CloudTalk instantly, and vice-versa.
  • Deep Timeline Integration: View recordings, notes, and tags right where you manage your work. Call data is logged to the Timeline or specific destination columns, keeping your interface clean and organized.

👉 Book a demo with our team to see the AI integration in action.

Security & Compliance

Security

Does the developer periodically perform penetration testing?

Yes
Yes. We conduct periodic penetration testing performed by accredited external third-party suppliers. Penetration tests are conducted at least annually, in addition to ongoing internal security audits. Testing is performed in a staging or isolated environment to protect production systems, with findings tracked and remediated according to our Vulnerability Management Policy SLAs. Penetration test reports and executive summaries are available at trust.cloudtalk.io.

Does the developer have a dedicated security and privacy point of contact for such issues or questions?

Yes
Yes. We have a dedicated security and privacy point of contact: Security / Compliance: security@cloudtalk.io Privacy / Data Protection: privacy@cloudtalk.io External Data Protection Officer (DPO): privacy@cloudtalk.io For security vulnerability reports, we also operate a responsible disclosure programme. All security and privacy inquiries are handled by our Security team, which is responsible for enforcing policies, managing incidents, and coordinating with our external DPO and legal team.

Does the app restrict redirects and forwards only to approved destinations, or show a warning when redirecting to potentially untrusted content?

Yes
Yes. We restrict redirects and forwards to approved destinations only. Our secure development practices follow OWASP principles, which include unvalidated redirect and forward prevention as a standard control. Any redirect to an external or potentially untrusted URL is subject to validation against an approved allowlist. This control is verified through our SAST/DAST checks and external penetration tests.

Does the app protect against mass parameter assignment attacks?

Yes
Yes. We protect against mass parameter assignment (also known as mass assignment or over-posting) attacks. Our secure development practices follow OWASP guidelines, which include preventing mass assignment vulnerabilities as part of input validation and API security controls. These protections are validated through SAST/DAST scanning in our CI/CD pipeline and through periodic penetration testing.

Does the app perform encoding and sanitization on all user supplied parameters to protect against Cross-Site Scripting?

Yes
Yes. We perform input encoding and sanitization on all user-supplied parameters to protect against Cross-Site Scripting (XSS). Our secure development practices apply OWASP Secure Coding Principles, which include output encoding and input validation as mandatory controls. XSS vulnerabilities are explicitly identified in our Vulnerability Management Policy as code vulnerabilities to prevent. These controls are validated through SAST/DAST testing integrated into our CI/CD pipeline, as well as during periodic external penetration tests.

Does the developer protect all state-changing actions against Cross-Site Request Forgery (CSRF)?

Yes
Yes. We implement CSRF protection on all state-changing actions. Our secure development practices follow OWASP principles, which include CSRF mitigation as a standard security requirement. CSRF protection is validated during security testing (SAST/DAST) and through our periodic penetration tests. Security requirements including protection against CSRF are incorporated into development from the design stage in line with our privacy-by-design approach.

Does the developer have mechanisms to notify monday.com in case of a security breach?

Yes
Yes. We have a documented Incident Management Policy and Data Breach Response Policy. In the event of a confirmed security breach affecting customer data, we notify affected customers (acting as controller) without undue delay targeting within 24 hours of becoming aware. Our dedicated Data Breach Response Team, led by our Privacy Officer, coordinates notification. For GDPR purposes, supervisory authorities are notified within 72 hours. Customers can also monitor real-time status at status.cloudtalk.io and subscribe to incident notifications. Security issues can be reported to security@cloudtalk.io.

Does this developer have a process for installing application-level updates and security patches for the service (such as software packages and databases)?

Yes
Yes. We maintain a documented Vulnerability Management Policy covering the full lifecycle of vulnerabilities: identification, prioritisation, remediation, and verification. Our CI/CD pipeline includes automated security checks (SAST/DAST) that detect vulnerabilities before deployment. Patch SLAs are risk-based: Critical vulnerabilities must be fixed within the current sprint (max 2 weeks); High within the following sprint (~4 weeks); Medium within 4 sprints (~2 months); Low within 8 sprints (~3 months). Security patches for software packages and databases are applied continuously as part of our standard release process.

Compliance

Is the app certified with the information security standard ISO/IEC 27001:2022?

Yes
Yes. CloudTalk s.r.o. holds a current ISO/IEC 27001:2022 certification for its Information Security Management System (ISMS). The certification was awarded following an independent audit by an accredited certification body and is renewed annually. Our ISO 27001 certificate is available for download at trust.cloudtalk.io.

Is the app compliant with the Health Insurance Portability and Accountability Act (HIPAA)?

Yes
Yes. CloudTalk supports HIPAA-compliant use cases for customers in the healthcare sector. We sign Business Associate Agreements (BAAs) with customers who process Protected Health Information (PHI).

Is the app certified with System and Organization Controls (SOC 2 or SOC 3)?

Yes
. The audit was conducted by an accredited independent third-party auditor. Our SOC 2 Type II report is available at trust.cloudtalk.io (NDA may be required for the full report). We renew our SOC 2 audit annually.

Is the app compliant with the General Data Protection Regulation (GDPR)?

Yes
Yes. CloudTalk is fully compliant with the General Data Protection Regulation (GDPR). We act as a data processor on behalf of our customers (controllers) when processing their data. Our compliance is supported by: a comprehensive Privacy Management System; a dedicated Privacy Officer and external Data Protection Officer (DPO privacy@cloudtalk.io ); Standard Contractual Clauses (SCCs) integrated into our standard DPA; Transfer Impact Assessments (TIAs) for all third-country transfers; participation in the EU–U.S. Data Privacy Framework (CloudTalk.io Inc.); and compliance audited under ISO 27001 and SOC 2 Type II. Our Privacy Notice and DPA are available at cloudtalk.io/privacy and trust.cloudtalk.io.

Data

Does the app send any data outside of monday.com? If yes, indicate whether the data is customer-submitted (e.g., board names, item names, doc content) or non-customer-submitted (e.g., account ID, board ID, user ID).

Yes
Yes. When integrated with monday.com, data may flow as follows: • Non-customer-submitted data (e.g., account ID, board ID, user ID): Used for authentication, integration configuration, and activity logging within CloudTalk. • Customer-submitted data (e.g., contact names, phone numbers, email addresses, board/item data used to trigger calls or populate contact records): May be transferred to CloudTalk for call processing and CRM functionality. All data transferred outside monday.com to CloudTalk is processed in accordance with our DPA, Privacy Notice, and applicable data protection laws. Data is transmitted exclusively over encrypted channels (TLS 1.2+). Our full sub-processor list is available at cloudtalk.io/sub-processors.

Where does the app store logs data?

aws
Logs are stored in EU-based AWS systems and can be retained for up to 2 years. All logs are protected against tampering and unauthorised access, and system administrators cannot delete their own activity logs.

Where does the app store the app data?

other
App data is stored in Amazon AWS data centers. Primary storage is in Frankfurt, Germany (eu-central-1, EU), secondary regions include Northern Virginia, USA (us-east-1), Singapore (ap-southeast-1), Sao Paulo, Brazil (sa-east-1) and Sydney, Australia (ap-southeast-2). Call recordings and AI-generated data are stored exclusively in the EU (Frankfurt). All data is encrypted at rest using AES-256 (SSE-S3 for recordings; AWS KMS for all other data). Backups are also stored within AWS S3 and encrypted at rest.

Does the developer ensure application logs do not contain secrets or personally-identifiable information (PII)?

Yes
We are following our Personal Data Protection Policy requires data minimisation logs only capture what is necessary, although audit records may contain personal data. Logs are protected against tampering, and system administrators are not authorised to delete or modify their own activity records. Logging practices are reviewed during security audits and penetration tests.

Is customer data segregated from the data of other customers (for example logically or physically)?

Yes
Yes. Customer data is logically segregated at the application layer. Each customer's data is fully isolated through application-level logic, ensuring that no customer can access another customer's data. While customers share the same underlying AWS infrastructure, strict tenant isolation is enforced within the application and database layers. Data isolation is a core security requirement defined in our RND Security Policy.

Privacy

Does the developer enforce multi-factor authentication on employees access to systems which may process customer data?

Yes
Yes. Multi-factor authentication (MFA/2FA) is mandatory for all employee access to systems that may process customer data. Our Access Management Policy requires 2FA wherever supported. Employees access internal systems and infrastructure via a secured VPN with mandatory 2FA. SSO with enforced MFA is the preferred authentication mechanism. Customers can also enforce 2FA for their own users through their SSO provider.

Does the developer protect access to customer data based on the principle of least privilege?

Yes
Yes. We apply the principle of least privilege across all access to customer data, enforced through our Access Management Policy. Access is granted only when there is a clear, ongoing business need and is assigned at the minimum level required for the role. We use Role-Based Access Control (RBAC) as our preferred model. AWS IAM least-privilege policies are enforced and reviewed at least annually. Access rights are reviewed during onboarding, role changes, and off-boarding, and a full annual access review is conducted by the Security team.

Reviews

June 2, 2026

SL: Werkt voorlopig naar behoren..

May 29, 2026

EH: Really easy to use and simple app!

May 29, 2026

UV: Integrates really well with Monday and works really well for the team

May 28, 2026

MM: Very good app, very easy to use as someoene who has never used anything likr this before.

May 28, 2026

VS: Great app! I have to make several conference calls and international calls as well, and this app makes it easy to adjust and dial in. Would recommend!

May 27, 2026

AC: really helpful for managing calls

May 27, 2026

AS: CloudTalk integrates well with monday.com and is easy to set up. Working with its integrations, I’d love broader API support and more native options to enable smoother, scalable automations. Solid tool overall, definitely recommend.

May 27, 2026

AG: CloudTalk is a useful tool for organising calls and improving workflow efficiency, especially when used with Monday.com for project planning. However, increased native integration support would be beneficial to reduce reliance on third-party solutions.

May 27, 2026

JR: Good app if you are looking for an affordable and flexible phone application. Works good with monday integration

Historical data

Installation history

We have data for December 28, 2024 onwards only. Collected sometime after 00:00 UTC daily.

Total number of installs

Change in total number of installs in last 1 day(s)

Compares the number of installs on each date with 1 days previously:

Max
Min
Current

Change in total number of installs in last 7 day(s)

Compares the number of installs on each date with 7 days previously:

Max
Min
Current

Change in total number of installs in last 30 day(s)

Compares the number of installs on each date with 30 days previously:

Max
Min
Current

Change in total number of installs in last 90 day(s)

Compares the number of installs on each date with 90 days previously:

Max
Min
Current

Change in total number of installs in last 180 day(s)

Compares the number of installs on each date with 180 days previously:

Max
Min
Current

Ratings history

Categories history

Each of the following is a yes/no answer, so the graphs show 1 for yes, and 0 for no.

In "Featured" category?

In "Editor's choice" category?

In "Trending this week" category?

App metadata

ID: 10001142App ID: 10366767Listing updated: May 13, 2026