Make monday.com work with Microsoft 365 & SharePoint →
Notes logo

Notes

Barefoot Australia Pty Ltd

7,169 installs, since December 31, 2020.   130 installs/month.   Updated March 24, 2024.

14 days trial Existing legacy
Gallery image Gallery image Gallery image

Notes provides a dedicated board view oriented to note keeping and oriented around a calendar organization experience. Notes allows users to record and view information relevant to a board, not just board items. Notes includes templates to make note takin

Notes is supplementary to monday.com's updates. The updates feature of monday.com is great for collaborating on individual items. Often, however, you may simply need to log information so that you have a record of it for later recall. For example, summaries of phone calls and meetings can be logged in Notes to share with your team members and to remind yourself when you later re-visit the item. And whilst recording notes against board items is great, sometimes there are events that may apply to multiple items on the board. This is why Notes allows you to log details about activities such as campaigns against special categories that are not item-specific.


Notes includes templates to make note-taking faster and more consistent. When creating a new note, choose the most applicable template and then just fill in the details.


The templates provided so far include:

  • Call
  • Campaign
  • Email
  • Event
  • Feedback
  • Project check-in

Security & Compliance

Security

Does the developer periodically perform penetration testing?

Not answered

Does the developer have a dedicated security and privacy point of contact for such issues or questions?

Not answered

Does the app restrict redirects and forwards only to approved destinations, or show a warning when redirecting to potentially untrusted content?

Yes
The Notes app does not have a HTTP server.

Does the app protect against mass parameter assignment attacks?

Yes
The Notes app does not have a HTTP server.

Does the app perform encoding and sanitization on all user supplied parameters to protect against Cross-Site Scripting?

Yes
The Notes app is implemented using React which provides XSS protection.

Does the developer protect all state-changing actions against Cross-Site Request Forgery (CSRF)?

Yes
The Notes app does not have a backend so there sessions/cookies/tokens to protect. All invocations of the monday.com API are made using the monday.com SDK.

Does the developer have mechanisms to notify monday.com in case of a security breach?

Yes
Whilst it hasn't happened, I would contact monday.com using a private channel such as not to publicly disclose the breach. At that point, we would work together to resolve the issue which would also involve agreeing on the communications necessary.

Does this developer have a process for installing application-level updates and security patches for the service (such as software packages and databases)?

Yes
The Notes app is a static fontend app so it just uses https://www.npmjs.com/package/renovate to ensure the latest versions of imported libraries are used, thus minimising the chance of vulnerabilities in the codebase. It should be mentioned, however, that the running of https://www.npmjs.com/package/renovate is ad-hoc at this time.

Compliance

Is the app certified with the information security standard ISO/IEC 27001:2022?

Not answered

Is the app compliant with the Health Insurance Portability and Accountability Act (HIPAA)?

Not answered

Is the app certified with System and Organization Controls (SOC 2 or SOC 3)?

Not answered

Is the app compliant with the General Data Protection Regulation (GDPR)?

Not answered

Data

Does the app send any data outside of monday.com? If yes, indicate whether the data is customer-submitted (e.g., board names, item names, doc content) or non-customer-submitted (e.g., account ID, board ID, user ID).

Not answered

Where does the app store logs data?

Not answered

Where does the app store the app data?

Not answered

Does the developer ensure application logs do not contain secrets or personally-identifiable information (PII)?

Yes
Notes does not access PII nor does it need access to any form of secrets.

Is customer data segregated from the data of other customers (for example logically or physically)?

Yes
The Notes app only comprises the board view and no customer data is egressed outside of the Notes iframe apart from back to monday.com using the storage API. Each board view is segregated from other board views and consequently other customers.

Privacy

Does the developer enforce multi-factor authentication on employees access to systems which may process customer data?

Yes
No one has access to customer data since it is not egressed in any way.

Does the developer protect access to customer data based on the principle of least privilege?

Yes
No customer data is egressed so this is not applicable.

Reviews

April 7, 2023

RR: great app, can track everything

Installation history

We have data for December 28, 2024 onwards only. Collected sometime after 00:00 UTC daily.

ID: 88App ID: 25218Listing updated: October 13, 2024