Make monday.com work with Microsoft 365 & SharePoint →
Integration for Bitbucket® logo

Integration for Bitbucket®

Avisi Apps

457 installs, since April 25, 2021.   8 installs/month.   Updated March 24, 2024.

Free Existing legacy
Gallery image Gallery image Gallery image Gallery image

All the bitbucket integration you need to connect your business and development teams.

Activate the Integration for Bitbucket® and easily connect your Bitbucket issues with monday.com items. For example, automatically create or update an item in monday.com when pushing a commit in Bitbucket.


Avisi Apps builds apps you can trust

🔒 We have a SOC 2 declaration

🔑 We are ISO 27001:2017 certified

📋 We maintain all GDPR standards


Read more on how to get started in our documentation:

https://avisi-apps.gitbook.io/bitbucket-integration/

Security & Compliance

Security

Does the developer periodically perform penetration testing?

Yes
Yes, A penetration test is performed each year by an external party for any of their apps.

Does the developer have a dedicated security and privacy point of contact for such issues or questions?

Yes
Yes, a dedicated service portal is available through any of their app's listing on the monday.com marketplace.

Does the app restrict redirects and forwards only to approved destinations, or show a warning when redirecting to potentially untrusted content?

Yes

Does the app protect against mass parameter assignment attacks?

Yes

Does the app perform encoding and sanitization on all user supplied parameters to protect against Cross-Site Scripting?

Yes

Does the developer protect all state-changing actions against Cross-Site Request Forgery (CSRF)?

Yes

Does the developer have mechanisms to notify monday.com in case of a security breach?

Yes
Whenever we find a security incident we follow these steps: 1. Notify internal security team 2. Investigate the threat, impact, scale, and root cause 3. Determine and notify any parties involved (like monday.com) 4. Fix the issue 5. Notify customers, and parties involved on the fix and steps towards the future to prevent the same from happening again.

Does this developer have a process for installing application-level updates and security patches for the service (such as software packages and databases)?

Yes
Application level updates and security patches are following the same process: 1. All changes are managed through version control. 2. The code gets reviewed via our peer review process. 3. Via an automated CI / CD pipeline it gets deployed to our test environment. 4. The changes get tested end to end by the QA team. 5. After approval, another automated CI / CD pipeline deploys to production.

Compliance

Is the app certified with the information security standard ISO/IEC 27001:2022?

Not answered

Is the app compliant with the Health Insurance Portability and Accountability Act (HIPAA)?

Yes
https://apps.avisi.com/trust

Is the app certified with System and Organization Controls (SOC 2 or SOC 3)?

Yes
https://apps.avisi.com/trust

Is the app compliant with the General Data Protection Regulation (GDPR)?

Yes
https://apps.avisi.com/trust

Data

Does the app send any data outside of monday.com? If yes, indicate whether the data is customer-submitted (e.g., board names, item names, doc content) or non-customer-submitted (e.g., account ID, board ID, user ID).

Not answered

Where does the app store logs data?

other
Google Cloud Logging

Where does the app store the app data?

DB
Google Cloud Firestore

Does the developer ensure application logs do not contain secrets or personally-identifiable information (PII)?

Yes

Is customer data segregated from the data of other customers (for example logically or physically)?

Yes
Yes, customer data is logically segregated.

Privacy

Does the developer enforce multi-factor authentication on employees access to systems which may process customer data?

Yes

Does the developer protect access to customer data based on the principle of least privilege?

Yes
Yes, access to production data is restricted to the on-call team. Nobody is permitted to look at customer data without asking for explicit permission from the customer of which we keep record via the support request filed by the customer. Access to resources is logged to an audit log containing a record of information including the identity of the accessor and the date and time.

Reviews

No reviews yet.

Installation history

We have data for December 28, 2024 onwards only. Collected sometime after 00:00 UTC daily.

ID: 117App ID: 36172Listing updated: October 8, 2024