Skip to main content

Infrastructure & Compliance

We take steps to securely develop and test against security threats to ensure the safety of our customer data. We maintain a Secure Development Lifecycle, in which training our developers and performing design and code reviews takes a primary role. In addition, Xoxoday employs third-party security experts to perform detailed penetration tests on different applications. In addition to the security components provided by our top-level cloud providers AWS, Xoxoday maintains its own dedicated controls by following the industry best practices. These controls cover DDoS attacks, DB protection and a dedicated web application firewall, as well as network firewall fine-grained rules configured using the highest industry standards.
We provide Software as a Service (SaaS).
SaaS.
Admins can control the application and will have access to alerts and security events.
Xoxoday application is an API-driven digital rewards platform that automates rewards, incentives and gifting. The storefront has a global catalogue of 20,000+ options with 5,000+ experiences, 2,000+ gift cards and 10,000+ perks. The platform offers reward distribution modes like sending bulk vouchers via emails and generation of bulk voucher codes.
No. We are cloud hosted only.
We will share this as an attachment upon request.
Cloud hosted, microservice-based, highly scalable, High Availability.
NA — We are cloud hosted. Users need to have internet access.
Yes. The solution is available as part of SAP SuccessFactors solution on web, as well as the SuccessFactors native mobile app for both iOS and Android.
It’s accessible in a mobile browser and can be accessed via an Android or iOS device.
Our applications are compatible with desktops, tablets, and mobiles. No additional components are required.
Our applications are compatible with desktops, tablets, and mobiles. No additional components are required.
AWS / Kubernetes — React — Node/GraphQL — MySQL/MongoDB.
We have deployed our application on Amazon Web Services (AWS) cloud platform. We are using MySQL, Salt stack, Node.js and MongoDB technology.
Yes. We are using the latest language frameworks like MySQL, JavaScript, Node.js and MongoDB.
Yes. These are approved during the code review process wherein the reviewer checks the utility and security of the libraries.
We have deployed our application on AWS Cloud virtual platform. The backup data center is in Singapore.
The data centers are hosted completely in isolation so that access is limited and controlled. Load balancer allows shifting incremental load and can auto scale based on data load. Each instance (EC2) under a fortified VPC network is a conglomeration of Docker Container Web Services and APIs and application layer running on top. Amazon CloudWatch is implemented to enable monitoring. The data is encrypted using 256-encryption-based SSL certificate. Xoxoday plans a quarterly VAPT-based security audit.
Plum by Xoxoday is a cloud-based SaaS platform hosted on VPC infrastructure of AWS. The data centers are hosted in complete isolation. The architecture allows adding more location-specific data centers for latency and data security. Load balancers allow auto-scaling. Each EC2 instance under fortified VPC network is a conglomeration of Docker Container Web Services and APIs. Amazon CloudWatch is implemented for monitoring. Data is encrypted using TLS 1.3 in transit and AES-256 at rest.

Backup, Recovery & Business Continuity

Data backups are done daily and in a secured way in AWS.
We use AWS Virtual platform cloud. We have created an Amazon CloudWatch alarm that monitors Amazon EC2 instances and automatically recovers them if impaired. EBS Snapshot functionality allows us to capture and restore virtual machine images at any time.
Yes, the infrastructure environment solution includes software/provider independent restore and recovery capabilities.
Yes. Data backups are automated and done daily in a secured way on AWS. We test the backup or redundancy mechanisms at least annually.
Our RTO and RPO is 60 minutes.
Yes. Data backups are done daily and in a secured way in AWS.
Data backups are done on a daily basis and in a secured way on AWS.
We take automated backups on a regular basis.
Yes. We take a backup of all data before making any major changes to hardware and software.
We have implemented the Backup Recovery Procedure.
We have Business Continuity Policy and Business Continuity Management Procedure in place, tested periodically. Our policies are reviewed and audited annually. We test the BCP every 12 months, reviewed as part of internal and external audits.
Yes. Data backups are done on a daily basis in a secured way in AWS.
Yes. It is tested annually.
Yes. All data backup is encrypted.
Yes. It can be recovered.
We have implemented the Business Continuity Management Policy and test the BCM plan annually. The BCM policy is attached for reference.
We have implemented policies and procedures with regard to DR. Since we have deployed our application on AWS cloud, they provide DR services.
The application network architecture diagram is attached upon request.

Application Development & SDLC

We have an SDLC Policy as per ISMS requirements and follow General Coding Practice. We conduct data validation on a trusted system, use cryptographic functions to protect secrets, and perform code reviews, vulnerability assessments, and penetration testing. We follow a blue-green deployment strategy that introduces new changes without downtime and provides rollback capability.
Yes. Changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates.
We have implemented the SDLC Procedure and standards of quality are met for all software development.
We have not outsourced software development activities. Our code reviews and analysis run through stringent automated technologies as well as manual source code overviews to cover any security loopholes prior to the production phase.
Yes. All debugging and test code elements are removed from released software versions.
Yes. We use an automated source code analysis tool.
We are proactively embedding privacy into the design and operation of IT systems, networked infrastructure, and business practices.
We focus on security while producing software. SDLC procedures are attached for reference.
Yes. All environments are separate.
No. We do not use production data in test environments.
Yes. Both are kept separate.
Yes.
Any applications and software are implemented after security testing by our IT team. All logs are monitored. We maintain an approved software/application register, audited during internal and external audits. Users are disallowed from installing software on their workstations.
Yes. We have static code analysis.
We have an SDLC Policy per ISMS requirements and follow General Coding Practice including data validation on a trusted system, cryptographic functions to protect secrets, and least privilege — restricting users to only the functionality, data, and system information required for their tasks.
More than 50% of our production code is covered by automated tests.
We do not use staging for building artifacts.
We conduct application security testing with the help of industry-approved third-party vendors every six months. Any observations found are addressed by our team. The primary objective is to identify and eliminate problems that could lead to a breach of confidentiality, availability, or integrity of Xoxoday data resources.
Yes. Our code reviews run through stringent automated technologies and manual source code overviews. Vulnerability scanning gives deep insight for quick identification of non-compliant systems. Xoxoday also employs third-party security experts to perform VAPT.
Yes. Code reviews and analysis run through stringent automated technologies as well as manual source code review. Multiple security checks including code reviews, web vulnerability reviews, and advanced security tests are performed in every build.
Yes. Code is reviewed both internally and externally. We engage third-party vendors for security testing every six months.
All software development procedures are supervised and monitored by Xoxoday to include: security requirements, independent security review of the environment, code reviews, quality monitoring, evaluation, and acceptance criteria for information systems.
Our QA department reviews and tests our code base. Dedicated application security engineers identify, test, and triage security vulnerabilities. We also conduct code reviews and VAPT with the help of a third-party vendor. VAPT Certificate is attached.
Yes. This is part of the code review process wherein the reviewer checks the utility and security of the 3rd party library.
Compliant. The application is developed based on secure coding guidelines and code reviews are conducted per compliance requirements.
Compliant.
Compliant. Yes, we follow all technical guidelines for development that come under the Open Web Application Security Project.
Compliant. We have implemented DLP techniques and there are no possibilities of data leakage or loss.
Compliant. The application uses HTTPS.
We cannot impose file upload frequency restrictions. However, the application has technical and organizational measures to prevent attacks through WAF, log monitoring, AWS GuardDuty, Amazon CloudWatch, IDS/IPS, etc.

Access Control & Authentication

We have a role-based access system to make sure that only authorized individuals have access to the required information.
We don’t provide multi-factor authentication as a default. As of now, there’s OAuth 2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins.
No, we don’t provide multi-factor authentication as a default. As of now, there’s OAuth 2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins.
It can be configured with Active Directory.
Access to data and systems is based on the principles of least privilege. All information systems and data are classified and segregated to support role-based access requirements. We use MFA, Firewall, VPN, Active Directory, etc. for maximum security.
The password needs to be a minimum of 8 characters long and contain at least one capital letter, special characters among ’# $ % * &’ and 1 digit. These are reviewed monthly.
We store passwords hashed. We have SHA-512 hash with unique salt for every password.
We store passwords hashed. We have SHA-512 hash with unique salt for every password.
Yes. Our password requirements comply with all factors to ensure strong passwords: minimum length, special characters, capitalized letters, and alpha-numeric combinations. Passwords are stored after encryption.
Yes.
Yes.
The solution does not allow login using credentials that have not been used. Admins can create and delete user accounts.
It’s a SaaS solution. Users can log in from multiple locations.
No. Users need to login with user ID and password. However, we have integrations with Zoho CRM, HubSpot, DarwinBox, SurveyMonkey, Freshdesk, etc.
Since it’s a SaaS product, session timeout can be set with the help of Active Directory. For example — 15 min or 20 mins as per requirements.
The account will get automatically locked after 5 unsuccessful login attempts.
Users will get a reset password link and can unlock their account through that.
User accounts will be created by the admin and linked with the email ID of the users. Please refer to the admin guide: https://xoxoday.gitbook.io/plum/user-guide/for-admins-1
Yes.
Yes. Two-factor authentication is enabled. MFA devices like Google Authenticator are available for OTP/Codes/Passwords.
Yes.
We have procedures for Roles, Responsibilities & Authorities at Xoxoday. Per the access control policy, access to data is provided only to authorized and appropriate individuals.
Password policy: Must contain at least 8 characters, numbers and letters, uppercase (A-Z), lowercase (a-z), digits (0-9), and non-alphabetic characters (e.g., !, $, #, %). Password must be changed every 90 days. Passwords are shared through secure, encrypted channels.
Yes. Policies and procedures enforce two-factor authentication for privileged account management while accessing tenant data/systems. An IAM solution manages user access through role-based access profiles based on the need-to-know principle and segregation of duties.
By default, Xoxoday will not have access to service data. Access control is managed by the admin from the customer end. If we require access for troubleshooting, we request temporary access, and the customer decides. Access to our production environment is allowed only via the Xoxoday corporate network to authorized individuals.
Yes. Access has been restricted and monitored for security reasons.
Yes. We have complexity and length requirements for passwords.
We review user access on a periodical basis, validated during internal and external audits.

Network Security & Firewall

Yes. We have captured this information in our architecture and data flow diagrams.
Yes, we have a firewall.
Yes, we have the network architecture diagram.
Yes, we have configured secure internet access.
Yes, we have configured these.
Yes. We have IDS and IPS implemented and receive alerts for unauthorised network access.
Yes. It’s reviewed on a monthly basis.
Yes.
Yes.
Yes. All are configured according to security standards as part of the build process.
We have implemented IDS/IPS to facilitate timely detection, investigation by root cause analysis, and response to incidents.
Wireless access is allowed and handled with high-quality routers, password protection and restriction on internet usage.
Yes. We have installed firewalls for maximum security and configured them to restrict unauthorised traffic.
All data is collected only through the Xoxoday Platform.
We use a Web Application Firewall (WAF).
We harden the operating systems and restrict access to all ports, applications, and software, monitored on a regular basis.
We have implemented policies and mechanisms to protect the wireless network environment. We use a cloud-hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and linked with SSO/Active Directory.
Yes. It’s logically and physically segregated. We have deployed our application on AWS Cloud platform.
We do not provide external access.
We have implemented IDS/IPS, Endpoint security, Firewall, DLP, Antispoofing, VPN, Active Directory and other security solutions for maximum security.
Yes. With multiple layered firewalls configured with deny-all mode allowing only specific rules required for business, network traffic is regulated. We have implemented intrusion detection and prevention system tools for timely detection and investigation.
Yes. As part of WAF, rate limiters are installed to block multiple requests from specific IPs to prevent DDoS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats.
All our network components and computers are password protected to ensure compliance with integrity, availability, and confidentiality principles of Information Security.
Yes.
We have Network Access Control and Security Procedure in place. Network resources must be on a need-to-know basis and authorizations must be obtained from appropriate authorities. Networks are logically or physically divided based on the criticality of the information stored.
We have WAF, IDS/IPS, AWS GuardDuty, Cloudflare, and data encryption. We conduct code reviews and VAPT annually with a third-party vendor. We are equipped to detect and mitigate DDoS attacks, session hijacks, login spoofs, or any other data extraction strategies.
We use Cloudflare Web Application Firewall (WAF) and IDS/IPS for maximum security.
Yes. We have implemented the Web Application Firewall (WAF).
We have a web application firewall, IDS/IPS, SQL injection protection. We use Cloudflare for the same.
Yes. Our network communication is encrypted with highly restricted protocols to ensure maximum security. We use TLS 1.2 encryption for data in transit.
We use HTTPS and our network communication is encrypted with highly restricted protocols to ensure maximum security.
We do not provide support for IP address range restriction. Our restrictions/security are based on our OAuth process and do not restrict to specific IPs.

Logging, Monitoring & Audit

Yes. We monitor the logs. Application and infrastructure logs are centrally collected and backed up in a secure manner for internal development and audit-related concerns.
Yes. We maintain the records.
Yes. Since we record Services and Server logs at the level of virtual machine, and Audit and Access logs at the level of AWS, all these are covered.
Monthly.
Yes. Only authorised individuals can do this.
Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. We provide logs to the customer on a need and approval basis.
We maintain logs and monitor for security and audit purposes.
Yes. System clocks of all relevant information processing systems are synchronized to facilitate tracing and reconstitution of activity timelines.
Yes.
We maintain logs for at least 180 days. Only the CTO and Production Head will have access to these logs. There will be no modification to these logs.
Only authorised individuals have access to the security logs — e.g., CTO, DevOps Head, Production Head.
At least 180 days.
Yes. Only authorised individuals have access.
Yes. We have a SIEM in place for monitoring and maintaining logs over security incidents from various components.
Yes, SIEM has been implemented. Our event management systems merge data sources to maintain log data within the SIEM. This helps in proper analysis and driving out alerts in case of contingency. Audit logs are reviewed and recorded automatically. These logs are integrated with security operations/SIEM solutions.
We have implemented the Security Operations Center to monitor, prevent, detect, investigate, and respond to cyber threats around the clock.
Cyber security incidents are analyzed with network intrusion detection (IDS) tools. The incident response team is immediately notified for counter-actions and defense mechanisms. We have a Security incident management process to classify and handle incidents and security breaches.
Yes.
No. Logs are automatically audited but are not integrated with tenant’s security ops. In case the tenant requests logs, they can be shared when asked by the clients.
No. We do not have such a service. The key admin actions are present in the application reports. Our support team can help with a deep dive into a specific incident with the help of audit logs.
Yes. Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
All infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. The audit logs are reviewed and recorded automatically. These logs are integrated with security operations/SIEM solutions.
Yes. Our event management systems merge data sources to maintain log data within the SIEM. This helps in proper analysis and driving out alerts if needed.
We monitor logs on a regular basis. Infrastructure logs are collected using AWS Audit Trail. Application related logs are collected in our Elastic Search server and retained in long-term cloud storage.
We use a cloud-hosted VPN with strict access controls. We have implemented intrusion detection tools for timely detection and investigation. File integrity and network intrusion detection (IDS) tools are implemented. We also have Endpoint security software for all computers.
We perform internal and external audits annually. We also conduct security assessments and testing like VAPT every six months. We communicate these assessment results to clients on a yearly basis.
Yes. We conduct audits on our Information Security Management System. The last audit date was 16th June 2021.
Yes.
Yes. Administrative logs are part of the Cloud Dashboard and are regularly reviewed.
We use Bitdefender Endpoint security software to prevent malware and protect data. Additionally, we have AWS GuardDuty threat detection service that continuously monitors for malicious activity and unauthorised behaviour. We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails.
We have an intrusion detection/monitoring application that alerts on unauthorized access. We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails.
Infrastructure logs are collected using AWS Audit Trail. Application related logs are collected in our Elastic Search server and retained in long-term cloud storage.
Yes. All audit logs are monitored as a best practice.
Yes. Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage.
Yes. Our event management systems merge the data sources to maintain a log data within the SIEM. This helps in proper analysis and driving out alerts if needed in case of contingency.
At Xoxoday, the following are recorded in audit logs: 1. Infrastructure logs — collected using AWS Audit Trail. 2. Application related logs — collected in our Elastic Search server and retained in long-term cloud storage.

Data Protection & Encryption

Yes. We can freeze data from a specific time without freezing other data if needed.
We have a data loss prevention solution in place and data will not be lost.
Personal data will be processed only for rewards and redemption purposes.
Yes. We can provide the data flow diagram.
We use technologies like DLP, Data encryption, access control, and log monitoring.
All data is collected only through the Xoxoday Platform.
Yes. The data is segregated with a client-specific key for proper handling and representation. Physical segregation is done for production and non-production environments.
We use a split key mechanism to ensure that every client’s key is unique. It’s generated automatically from our end.
We have WAF, IDS/IPS, AWS GuardDuty, Cloudflare, and encrypted data. We conduct code reviews per compliance requirements and VAPT annually with a third-party vendor. We are equipped to detect and mitigate threats, DDoS attacks, session hijacks, login spoofs, or any other data extraction strategies.
Yes. We do testing before deploying in the production environment.
All data is collected only through the Xoxoday Platform.
We do not transfer any data externally. However, we have implemented encryption, VPN, Firewall, IDS/IPS, and monitoring systems.
We have disabled all ports and users do not have access to USB, CD-ROM, Disks, tapes, or Hard drives. All data including backups has been encrypted. We use TLS 1.2 for data in transit and AES-256 for data at rest.
All customer data including backup data is stored on AWS virtual platform cloud and does not store anything locally. We use TLS 1.2 for data in transit and AES-256 for data at rest. We have also implemented the Media handling procedure.
Yes.
Our web application, email records, and endpoints are sealed with data loss prevention techniques. We have the capability to respond immediately.
We logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant’s data.
All security mechanisms and policies are established to prevent data leaks in transit as well as at rest. Exhaustive VAPT has been conducted along with business logic testing based on the OWASP framework, which incorporates 120+ test cases.
No. We use logical data isolation with the help of company-specific encryption keys.
Yes. We have implemented Data Loss Prevention techniques on AWS.
We have implemented data loss prevention techniques to make sure that the data is not lost permanently.
It’s a part of our data loss prevention techniques.
Our web assets, email records, and endpoints are sealed with data loss prevention techniques even when the endpoint is disconnected from the corporate network.
Each tenant’s data is uniquely encrypted using a client-specific key. We use AES-256 bit encryption for data at rest. Our network communication is encrypted with highly restricted protocols. The cryptographic keys, including data encryption and SSL certificates, are managed by Xoxoday for optimal security.
We use a split key mechanism to ensure that every client’s key is unique. We perform annual key rotation. Keys are generated using KMS service whenever needed. We store keys in KMS.
We use a split key mechanism to ensure that every client’s key is unique. We perform annual key rotation. Keys are generated using KMS service whenever needed. We store keys in KMS.
We use logical data isolation with the help of company-specific encryption keys.
Password can be reset by employees. We do not send the password in plain text. We use TLS 1.2 for data in transit and AES-256 for data at rest.
We store passwords hashed. We have SHA-512 hash with unique salt for every password.
Only our product engineering team members have access as per their job functions and role-based logical access. We do not provide access to any third parties and all development and testing is done by internal employees.
Yes. We use TLS 1.2 for data in transit and AES-256 for data at rest. All data including backups is encrypted.
Our data cleaning process goes through an organized purge. Once the data is purged, it’s purged from all places.
Yes. Per our policies and procedures, we ensure secure disposal and removal of data from every storage media. The data cannot be recovered by any computer forensic means. We assure secure data disposal when storage is decommissioned or when the contract comes to an end.
The only user data stored within the system is personal information — names, emails, and contact numbers. This data is not put to any use by Xoxoday and resides within the system. The data can be deleted upon the tenant’s request.
We have implemented the Data Retention and Disposal Policy.

Patch Management

We update patches on a routine basis.
We update patches on a routine basis for servers as well.
We test patches before implementation in the production environment.
Patches are updated regularly.
Security patches are rated as Critical, High, Medium, and Low.
Critical patches will be deployed immediately. High patches will be deployed within 5 days. Medium patches within 15 days. Low within 25 days. Patch Management Procedure is attached.
Yes. We update patches periodically for our operating systems, software, servers, and network infrastructure.
Yes. We test the patches on the testing environment and deploy to production upon validation.
Yes. Security patches are regularly monitored and applied to the network security devices. All critical patches will be deployed immediately.
We update patches periodically. See Patch Management Procedure attached.
Yes. We regularly update our instance and make sure we follow security best practices. There is a process in place for regularly updating the servers and monitoring for latest updates across the entire stack.
We have implemented the Patch Management Procedure.
We follow the Change Management process to implement the compensatory control.
We follow the Change Management process.
Patches are updated on time.
Critical patches will be deployed immediately. High patches within 5 days. Medium patches within 15 days. Low within 25 days. Patch Management Procedure is attached.
Yes. We test patches before deploying in the production environment.

Change Management

We have implemented the Change Management Procedure. All IT changes take place as per the Change Management Procedure.
Yes. Changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates.
Yes. Change management procedures are attached. We are compliant.
Yes. We have implemented the change management procedures, and this applies to all Xoxoday assets, infrastructure, processes, software, and third-party activities. The procedure also applies to employees, vendors, and all other individuals who have access to, or are responsible for Xoxoday information processing facilities.
Yes. Our production team and QA team test all new releases or changes made to the existing product.
Yes. We will notify the customer if there are any major changes.
Yes. Our customer support team will communicate.

Antivirus & Endpoint Security

We have installed antivirus on all workstations and servers.
Yes. We have the controls in place. We have blocked connecting Hard disk, USB, CD-ROM, etc. to computers and all devices are centrally managed.
We use Bitdefender Endpoint security software to prevent malware and protect data. Additionally, we have AWS GuardDuty that continuously monitors for malicious activity and unauthorised behaviour. We use a cloud-hosted VPN with strict access controls linked with SSO/Active Directory.
We use endpoint security for prevention.
We have an alerting system in place and we perform scanning immediately to reduce the risk.
We have all required security controls for protecting endpoints — VPN, Firewall, IDS/IPS, Anti-Virus software, Audit log monitoring, Active Directory, etc.
We maintain up-to-date endpoint security to safeguard from attack scripts, viruses, worms, Trojan horses, backdoors, and malicious active content.
We are using Linux operating systems and following security best practices. We are monitoring using Prometheus/Grafana.
We have installed endpoint security in servers and PCs of all our employees as per compliance requirements.
We have all required security controls for protecting endpoints — VPN, Firewall, IDS/IPS, Anti-Virus software, Audit log monitoring, Active Directory, etc. We use a cloud-hosted VPN with strict access controls linked with SSO/Active Directory.

SSO, Authentication & Integration

Yes. Our partnerships with a wide array of integration partners ensure existing customer-based SSO capability for all users to seamlessly use Xoxoday’s products. With an easy DIY setup, your SSO solution would be plugged in and ready to go. Please refer to our list of integrations: https://xoxoday.gitbook.io/plum/developer-resources/integrations
Please click here to know more about API integration: https://www.empuls.io/integrations
The application enables user account management through API-based integration with the customer’s HR management system. These APIs are used to access employee data to ensure users’ accounts are created, updated, and disabled securely.
We have implemented WAF, IDS/IPS, and Amazon GuardDuty for maximum security. OAuth 2.0 is used to authorize all API requests. We also conduct code reviews to make sure that the APIs are secure.
Yes. It supports SSO.
Our partnerships with a wide array of integration partners ensure existing customer-based SSO capability for all users to seamlessly use Xoxoday’s products. With an easy DIY setup, your SSO solution would be plugged in and ready to go.
It’s a web and mobile application.
Our partnerships ensure existing customer-based SSO capability for all users. Our identity federation standards include SAML 2.0, SPML, WS-Federation, and more as means of authenticating and authorizing users with airtight security protocol. Please visit: xoxoday.com/integrations
Yes. The application has robust authentication methods. We have integrated SAML 2.0 with SAP SuccessFactors and support OAuth 2.0 and Azure AD for seamless authentication.
We have an option to integrate with SSO and HRMS. For more info, please visit the link: https://www.application.io/integrations
Two standard reports are available for admins on SuccessFactors at the program level — Budget and Spot Award Nomination. Using People Analytics, customers can create their own reports and dashboards combining Spot Awards data from Recognition with data from across SuccessFactors. Admins can also access similar data via a Xoxoday logon.
Yes. Customers can extract data from SuccessFactors via Integration Center and integrate it with other third parties.
Somewhat. We have a Spot Award Approved event available via Intelligent Service Center on SuccessFactors which customers can use to build custom extensions.
User provisioning for SAP SuccessFactors — Reward and Recognition is handled the same way as the rest of SuccessFactors. For employees redeeming points via Xoxoday, user provisioning is done on the fly at the time of redeeming the awards.

Third Party & Vendor Management

We make sure that they have adequate controls in place and meet the security standard.
We are managing the platform end to end.
Yes. Incident reporting obligations are passed on to all 3rd parties as well. All contracts and agreements are reviewed by the Legal Department.
We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. Administrative logs are part of the Cloud Dashboard and are regularly reviewed.

Service, Support & Upgrades

It will be the responsibility of Xoxoday.
The process for upgrades is automated using Continuous Integration and Deployment. Since our services are delivered via the web, upgrades and updates are seamless and usually do not involve any actions from end-users.
Xoxoday’s architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows.
The process for upgrades is automated using CI/CD. We try to release product hotfixes once every week and major features once every month.
The process for upgrades is automated using CI/CD. Upgrades and updates are seamless. We try to release hotfixes once every week and major features once every month.
Product updates and feature enhancements are done periodically by the application team. These updates are available to all customers by default. The customer need not do anything from their end to update the product version as the application is hosted on AWS Cloud.
The time of support ranges between two to forty-eight hours. This depends on the level of service and the gravity of incidents.
We have Email Support and an application help center for helping users.
We will be providing training for the admin and the end user and also provide extensive support through our customer support team.
Yes. We have an Information security team and group of people with responsibility for security within the organization.
Yes. We fix the issues found at no cost. We understand that consumer data protection is a high priority. We have implemented a Bug Bounty Program and encourage the reporting of security issues. If any outsiders or customers report security-related issues, we fix them free of cost.
We have deployed our application on Amazon Web Services (AWS) cloud platform. We are using MySQL, Salt stack, Node.js, and MongoDB technology.
See the application high-level diagram of CI/CD attached.
See the following policies attached — Infrastructure Change Control Procedure, Patch Management Procedure, Information System Acquisition Development and Maintenance Procedure, SDLC Procedure, Threat and Vulnerability Management.
Please click here for more details: https://help.empuls.io/
Payments are redirected to PayU gateway or PayPal websites to complete purchases securely. We are also implementing PCI DSS compliance controls and will provide the certification as soon as possible.
Approximately 2 weeks.
No installation. We are an out-of-the-box SaaS solution.
We have a multi-layered network architecture with role-based access control. All confidential/PII data is encrypted at rest with a split key mechanism to ensure that every client’s key is unique. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.
Yes.
Yes.
Yes. We have deployed our application on AWS Virtual platform cloud. We use WAF, IDS/IPS, AWS Audit Trail, Amazon GuardDuty, etc.
Yes. Segregation is done for production and non-production environments.
The production center location will be Bangalore.

Compliance Statements

Xoxoday would act as liaison partner between customer and merchants. We process the budgets which are approved by the customer. Xoxoday application is a SaaS Product.
The logs are automatically audited, but are not integrated with tenant’s security ops. In case the tenant requests logs, they can be shared when asked by the clients.
It’s a multi-tenant system. We use logical data isolation with the help of company-specific encryption keys and it is isolated from other customers’ data.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. We provide these logs on a need and approval basis for forensic investigation. We can freeze data from a specific time without freezing other data if needed.
We are compliant. We have implemented the password management policy and follow the concept of least privilege. Only a limited number of approved users have privileged access. All access will be provided on a need and approval basis. We maintain a ticketing system to make sure that the appropriate process is followed.
We have implemented the Password Management Policy for maximum security of data.
We are compliant. The password will be changed every 90 days.
These are integrated with security operations/SIEM solutions.
We have a secure log-on process and are compliant with these requirements.
We have a secure log-off process and are compliant with these requirements.
Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
We review architecture diagrams and data flow diagrams on a periodical basis. This is also validated during our internal and external independent audits.
We logically segregate the tenant’s data, and it is segregated with a client-specific key for proper handling and security reasons.
We do not use any unsecured protocols.
All critical applications are reviewed and tested before deployment.
We have a separate test and production environment.
We monitor systems and network utilization.
We have implemented file integrity (host) and network intrusion detection (IDS) tools to help facilitate timely detection and investigation.
We make sure that we follow industry best practices, the PDCA cycle, and standards in order to safeguard the Information Security System.
All critical patches are applied rapidly.
We are a multi-tenant SaaS system and all our logs will contain data of all customers. We will have our own log monitoring and security analysis.
Yes. All critical patches will be deployed immediately. We ensure that our infrastructure is always using up-to-date systems.
We have the ability to logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant’s data.
Compliant. We have deployed our application and database on separate servers.
Since the application is a SaaS Platform, this would not be applicable.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. Administrative logs are part of the Cloud Dashboard and are regularly reviewed.
Yes. We logically segregate the tenant’s data and the application.
WAF and rate limiters are installed to block multiple requests from specific IPs to prevent DDoS-type attacks.
Once the user logs out from the application, all pages, forms, and pop-ups will get closed.
We maintain logs and monitor on a regular basis for security reasons.
Compliant. We have resources to meet these requirements.

Infrastructure & Compliance

We take steps to securely develop and test against security threats to ensure the safety of our customer data. We maintain a Secure Development Lifecycle, in which training our developers and performing design and code reviews takes a primary role. In addition, Xoxoday employs third-party security experts to perform detailed penetration tests on different applications. In addition to the security components provided by our top-level cloud providers AWS, Xoxoday maintains its own dedicated controls by following the industry best practices. These controls cover DDoS attacks, DB protection and a dedicated web application firewall, as well as network firewall fine-grained rules configured using the highest industry standards.
We provide Software as a Service (SaaS).
SaaS.
Admins can control the application and will have access to alerts and security events.
Xoxoday application is an API-driven digital rewards platform that automates rewards, incentives and gifting. The storefront has a global catalogue of 20,000+ options with 5,000+ experiences, 2,000+ gift cards and 10,000+ perks. The platform offers reward distribution modes like sending bulk vouchers via emails and generation of bulk voucher codes.
No. We are cloud hosted only.
We will share this as an attachment upon request.
Cloud hosted, microservice-based, highly scalable, High Availability.
NA — We are cloud hosted. Users need to have internet access.
Yes. The solution is available as part of SAP SuccessFactors solution on web, as well as the SuccessFactors native mobile app for both iOS and Android.
It’s accessible in a mobile browser and can be accessed via an Android or iOS device.
Our applications are compatible with desktops, tablets, and mobiles. No additional components are required.
Our applications are compatible with desktops, tablets, and mobiles. No additional components are required.
AWS / Kubernetes — React — Node/GraphQL — MySQL/MongoDB.
We have deployed our application on Amazon Web Services (AWS) cloud platform. We are using MySQL, Salt stack, Node.js and MongoDB technology.
Yes. We are using the latest language frameworks like MySQL, JavaScript, Node.js and MongoDB.
Yes. These are approved during the code review process wherein the reviewer checks the utility and security of the libraries.
We have deployed our application on AWS Cloud virtual platform. The backup data center is in Singapore.
The data centers are hosted completely in isolation so that access is limited and controlled. Load balancer allows shifting incremental load and can auto scale based on data load. Each instance (EC2) under a fortified VPC network is a conglomeration of Docker Container Web Services and APIs and application layer running on top. Amazon CloudWatch is implemented to enable monitoring. The data is encrypted using 256-encryption-based SSL certificate. Xoxoday plans a quarterly VAPT-based security audit.
Plum by Xoxoday is a cloud-based SaaS platform hosted on VPC infrastructure of AWS. The data centers are hosted in complete isolation. The architecture allows adding more location-specific data centers for latency and data security. Load balancers allow auto-scaling. Each EC2 instance under fortified VPC network is a conglomeration of Docker Container Web Services and APIs. Amazon CloudWatch is implemented for monitoring. Data is encrypted using TLS 1.3 in transit and AES-256 at rest.

Backup, Recovery & Business Continuity

Data backups are done daily and in a secured way in AWS.
We use AWS Virtual platform cloud. We have created an Amazon CloudWatch alarm that monitors Amazon EC2 instances and automatically recovers them if impaired. EBS Snapshot functionality allows us to capture and restore virtual machine images at any time.
Yes, the infrastructure environment solution includes software/provider independent restore and recovery capabilities.
Yes. Data backups are automated and done daily in a secured way on AWS. We test the backup or redundancy mechanisms at least annually.
Our RTO and RPO is 60 minutes.
Yes. Data backups are done daily and in a secured way in AWS.
Data backups are done on a daily basis and in a secured way on AWS.
We take automated backups on a regular basis.
Yes. We take a backup of all data before making any major changes to hardware and software.
We have implemented the Backup Recovery Procedure.
We have Business Continuity Policy and Business Continuity Management Procedure in place, tested periodically. Our policies are reviewed and audited annually. We test the BCP every 12 months, reviewed as part of internal and external audits.
Yes. Data backups are done on a daily basis in a secured way in AWS.
Yes. It is tested annually.
Yes. All data backup is encrypted.
Yes. It can be recovered.
We have implemented the Business Continuity Management Policy and test the BCM plan annually. The BCM policy is attached for reference.
We have implemented policies and procedures with regard to DR. Since we have deployed our application on AWS cloud, they provide DR services.
The application network architecture diagram is attached upon request.

Application Development & SDLC

We have an SDLC Policy as per ISMS requirements and follow General Coding Practice. We conduct data validation on a trusted system, use cryptographic functions to protect secrets, and perform code reviews, vulnerability assessments, and penetration testing. We follow a blue-green deployment strategy that introduces new changes without downtime and provides rollback capability.
Yes. Changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates.
We have implemented the SDLC Procedure and standards of quality are met for all software development.
We have not outsourced software development activities. Our code reviews and analysis run through stringent automated technologies as well as manual source code overviews to cover any security loopholes prior to the production phase.
Yes. All debugging and test code elements are removed from released software versions.
Yes. We use an automated source code analysis tool.
We are proactively embedding privacy into the design and operation of IT systems, networked infrastructure, and business practices.
We focus on security while producing software. SDLC procedures are attached for reference.
Yes. All environments are separate.
No. We do not use production data in test environments.
Yes. Both are kept separate.
Yes.
Any applications and software are implemented after security testing by our IT team. All logs are monitored. We maintain an approved software/application register, audited during internal and external audits. Users are disallowed from installing software on their workstations.
Yes. We have static code analysis.
We have an SDLC Policy per ISMS requirements and follow General Coding Practice including data validation on a trusted system, cryptographic functions to protect secrets, and least privilege — restricting users to only the functionality, data, and system information required for their tasks.
More than 50% of our production code is covered by automated tests.
We do not use staging for building artifacts.
We conduct application security testing with the help of industry-approved third-party vendors every six months. Any observations found are addressed by our team. The primary objective is to identify and eliminate problems that could lead to a breach of confidentiality, availability, or integrity of Xoxoday data resources.
Yes. Our code reviews run through stringent automated technologies and manual source code overviews. Vulnerability scanning gives deep insight for quick identification of non-compliant systems. Xoxoday also employs third-party security experts to perform VAPT.
Yes. Code reviews and analysis run through stringent automated technologies as well as manual source code review. Multiple security checks including code reviews, web vulnerability reviews, and advanced security tests are performed in every build.
Yes. Code is reviewed both internally and externally. We engage third-party vendors for security testing every six months.
All software development procedures are supervised and monitored by Xoxoday to include: security requirements, independent security review of the environment, code reviews, quality monitoring, evaluation, and acceptance criteria for information systems.
Our QA department reviews and tests our code base. Dedicated application security engineers identify, test, and triage security vulnerabilities. We also conduct code reviews and VAPT with the help of a third-party vendor. VAPT Certificate is attached.
Yes. This is part of the code review process wherein the reviewer checks the utility and security of the 3rd party library.
Compliant. The application is developed based on secure coding guidelines and code reviews are conducted per compliance requirements.
Compliant.
Compliant. Yes, we follow all technical guidelines for development that come under the Open Web Application Security Project.
Compliant. We have implemented DLP techniques and there are no possibilities of data leakage or loss.
Compliant. The application uses HTTPS.
We cannot impose file upload frequency restrictions. However, the application has technical and organizational measures to prevent attacks through WAF, log monitoring, AWS GuardDuty, Amazon CloudWatch, IDS/IPS, etc.

Access Control & Authentication

We have a role-based access system to make sure that only authorized individuals have access to the required information.
We don’t provide multi-factor authentication as a default. As of now, there’s OAuth 2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins.
No, we don’t provide multi-factor authentication as a default. As of now, there’s OAuth 2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins.
It can be configured with Active Directory.
Access to data and systems is based on the principles of least privilege. All information systems and data are classified and segregated to support role-based access requirements. We use MFA, Firewall, VPN, Active Directory, etc. for maximum security.
The password needs to be a minimum of 8 characters long and contain at least one capital letter, special characters among ’# $ % * &’ and 1 digit. These are reviewed monthly.
We store passwords hashed. We have SHA-512 hash with unique salt for every password.
We store passwords hashed. We have SHA-512 hash with unique salt for every password.
Yes. Our password requirements comply with all factors to ensure strong passwords: minimum length, special characters, capitalized letters, and alpha-numeric combinations. Passwords are stored after encryption.
Yes.
Yes.
The solution does not allow login using credentials that have not been used. Admins can create and delete user accounts.
It’s a SaaS solution. Users can log in from multiple locations.
No. Users need to login with user ID and password. However, we have integrations with Zoho CRM, HubSpot, DarwinBox, SurveyMonkey, Freshdesk, etc.
Since it’s a SaaS product, session timeout can be set with the help of Active Directory. For example — 15 min or 20 mins as per requirements.
The account will get automatically locked after 5 unsuccessful login attempts.
Users will get a reset password link and can unlock their account through that.
User accounts will be created by the admin and linked with the email ID of the users. Please refer to the admin guide: https://xoxoday.gitbook.io/plum/user-guide/for-admins-1
Yes.
Yes. Two-factor authentication is enabled. MFA devices like Google Authenticator are available for OTP/Codes/Passwords.
Yes.
We have procedures for Roles, Responsibilities & Authorities at Xoxoday. Per the access control policy, access to data is provided only to authorized and appropriate individuals.
Password policy: Must contain at least 8 characters, numbers and letters, uppercase (A-Z), lowercase (a-z), digits (0-9), and non-alphabetic characters (e.g., !, $, #, %). Password must be changed every 90 days. Passwords are shared through secure, encrypted channels.
Yes. Policies and procedures enforce two-factor authentication for privileged account management while accessing tenant data/systems. An IAM solution manages user access through role-based access profiles based on the need-to-know principle and segregation of duties.
By default, Xoxoday will not have access to service data. Access control is managed by the admin from the customer end. If we require access for troubleshooting, we request temporary access, and the customer decides. Access to our production environment is allowed only via the Xoxoday corporate network to authorized individuals.
Yes. Access has been restricted and monitored for security reasons.
Yes. We have complexity and length requirements for passwords.
We review user access on a periodical basis, validated during internal and external audits.

Network Security & Firewall

Yes. We have captured this information in our architecture and data flow diagrams.
Yes, we have a firewall.
Yes, we have the network architecture diagram.
Yes, we have configured secure internet access.
Yes, we have configured these.
Yes. We have IDS and IPS implemented and receive alerts for unauthorised network access.
Yes. It’s reviewed on a monthly basis.
Yes.
Yes.
Yes. All are configured according to security standards as part of the build process.
We have implemented IDS/IPS to facilitate timely detection, investigation by root cause analysis, and response to incidents.
Wireless access is allowed and handled with high-quality routers, password protection and restriction on internet usage.
Yes. We have installed firewalls for maximum security and configured them to restrict unauthorised traffic.
All data is collected only through the Xoxoday Platform.
We use a Web Application Firewall (WAF).
We harden the operating systems and restrict access to all ports, applications, and software, monitored on a regular basis.
We have implemented policies and mechanisms to protect the wireless network environment. We use a cloud-hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and linked with SSO/Active Directory.
Yes. It’s logically and physically segregated. We have deployed our application on AWS Cloud platform.
We do not provide external access.
We have implemented IDS/IPS, Endpoint security, Firewall, DLP, Antispoofing, VPN, Active Directory and other security solutions for maximum security.
Yes. With multiple layered firewalls configured with deny-all mode allowing only specific rules required for business, network traffic is regulated. We have implemented intrusion detection and prevention system tools for timely detection and investigation.
Yes. As part of WAF, rate limiters are installed to block multiple requests from specific IPs to prevent DDoS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats.
All our network components and computers are password protected to ensure compliance with integrity, availability, and confidentiality principles of Information Security.
Yes.
We have Network Access Control and Security Procedure in place. Network resources must be on a need-to-know basis and authorizations must be obtained from appropriate authorities. Networks are logically or physically divided based on the criticality of the information stored.
We have WAF, IDS/IPS, AWS GuardDuty, Cloudflare, and data encryption. We conduct code reviews and VAPT annually with a third-party vendor. We are equipped to detect and mitigate DDoS attacks, session hijacks, login spoofs, or any other data extraction strategies.
We use Cloudflare Web Application Firewall (WAF) and IDS/IPS for maximum security.
Yes. We have implemented the Web Application Firewall (WAF).
We have a web application firewall, IDS/IPS, SQL injection protection. We use Cloudflare for the same.
Yes. Our network communication is encrypted with highly restricted protocols to ensure maximum security. We use TLS 1.2 encryption for data in transit.
We use HTTPS and our network communication is encrypted with highly restricted protocols to ensure maximum security.
We do not provide support for IP address range restriction. Our restrictions/security are based on our OAuth process and do not restrict to specific IPs.

Logging, Monitoring & Audit

Yes. We monitor the logs. Application and infrastructure logs are centrally collected and backed up in a secure manner for internal development and audit-related concerns.
Yes. We maintain the records.
Yes. Since we record Services and Server logs at the level of virtual machine, and Audit and Access logs at the level of AWS, all these are covered.
Monthly.
Yes. Only authorised individuals can do this.
Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. We provide logs to the customer on a need and approval basis.
We maintain logs and monitor for security and audit purposes.
Yes. System clocks of all relevant information processing systems are synchronized to facilitate tracing and reconstitution of activity timelines.
Yes.
We maintain logs for at least 180 days. Only the CTO and Production Head will have access to these logs. There will be no modification to these logs.
Only authorised individuals have access to the security logs — e.g., CTO, DevOps Head, Production Head.
At least 180 days.
Yes. Only authorised individuals have access.
Yes. We have a SIEM in place for monitoring and maintaining logs over security incidents from various components.
Yes, SIEM has been implemented. Our event management systems merge data sources to maintain log data within the SIEM. This helps in proper analysis and driving out alerts in case of contingency. Audit logs are reviewed and recorded automatically. These logs are integrated with security operations/SIEM solutions.
We have implemented the Security Operations Center to monitor, prevent, detect, investigate, and respond to cyber threats around the clock.
Cyber security incidents are analyzed with network intrusion detection (IDS) tools. The incident response team is immediately notified for counter-actions and defense mechanisms. We have a Security incident management process to classify and handle incidents and security breaches.
Yes.
No. Logs are automatically audited but are not integrated with tenant’s security ops. In case the tenant requests logs, they can be shared when asked by the clients.
No. We do not have such a service. The key admin actions are present in the application reports. Our support team can help with a deep dive into a specific incident with the help of audit logs.
Yes. Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
All infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. The audit logs are reviewed and recorded automatically. These logs are integrated with security operations/SIEM solutions.
Yes. Our event management systems merge data sources to maintain log data within the SIEM. This helps in proper analysis and driving out alerts if needed.
We monitor logs on a regular basis. Infrastructure logs are collected using AWS Audit Trail. Application related logs are collected in our Elastic Search server and retained in long-term cloud storage.
We use a cloud-hosted VPN with strict access controls. We have implemented intrusion detection tools for timely detection and investigation. File integrity and network intrusion detection (IDS) tools are implemented. We also have Endpoint security software for all computers.
We perform internal and external audits annually. We also conduct security assessments and testing like VAPT every six months. We communicate these assessment results to clients on a yearly basis.
Yes. We conduct audits on our Information Security Management System. The last audit date was 16th June 2021.
Yes.
Yes. Administrative logs are part of the Cloud Dashboard and are regularly reviewed.
We use Bitdefender Endpoint security software to prevent malware and protect data. Additionally, we have AWS GuardDuty threat detection service that continuously monitors for malicious activity and unauthorised behaviour. We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails.
We have an intrusion detection/monitoring application that alerts on unauthorized access. We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails.
Infrastructure logs are collected using AWS Audit Trail. Application related logs are collected in our Elastic Search server and retained in long-term cloud storage.
Yes. All audit logs are monitored as a best practice.
Yes. Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage.
Yes. Our event management systems merge the data sources to maintain a log data within the SIEM. This helps in proper analysis and driving out alerts if needed in case of contingency.
At Xoxoday, the following are recorded in audit logs: 1. Infrastructure logs — collected using AWS Audit Trail. 2. Application related logs — collected in our Elastic Search server and retained in long-term cloud storage.

Data Protection & Encryption

Yes. We can freeze data from a specific time without freezing other data if needed.
We have a data loss prevention solution in place and data will not be lost.
Personal data will be processed only for rewards and redemption purposes.
Yes. We can provide the data flow diagram.
We use technologies like DLP, Data encryption, access control, and log monitoring.
All data is collected only through the Xoxoday Platform.
Yes. The data is segregated with a client-specific key for proper handling and representation. Physical segregation is done for production and non-production environments.
We use a split key mechanism to ensure that every client’s key is unique. It’s generated automatically from our end.
We have WAF, IDS/IPS, AWS GuardDuty, Cloudflare, and encrypted data. We conduct code reviews per compliance requirements and VAPT annually with a third-party vendor. We are equipped to detect and mitigate threats, DDoS attacks, session hijacks, login spoofs, or any other data extraction strategies.
Yes. We do testing before deploying in the production environment.
All data is collected only through the Xoxoday Platform.
We do not transfer any data externally. However, we have implemented encryption, VPN, Firewall, IDS/IPS, and monitoring systems.
We have disabled all ports and users do not have access to USB, CD-ROM, Disks, tapes, or Hard drives. All data including backups has been encrypted. We use TLS 1.2 for data in transit and AES-256 for data at rest.
All customer data including backup data is stored on AWS virtual platform cloud and does not store anything locally. We use TLS 1.2 for data in transit and AES-256 for data at rest. We have also implemented the Media handling procedure.
Yes.
Our web application, email records, and endpoints are sealed with data loss prevention techniques. We have the capability to respond immediately.
We logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant’s data.
All security mechanisms and policies are established to prevent data leaks in transit as well as at rest. Exhaustive VAPT has been conducted along with business logic testing based on the OWASP framework, which incorporates 120+ test cases.
No. We use logical data isolation with the help of company-specific encryption keys.
Yes. We have implemented Data Loss Prevention techniques on AWS.
We have implemented data loss prevention techniques to make sure that the data is not lost permanently.
It’s a part of our data loss prevention techniques.
Our web assets, email records, and endpoints are sealed with data loss prevention techniques even when the endpoint is disconnected from the corporate network.
Each tenant’s data is uniquely encrypted using a client-specific key. We use AES-256 bit encryption for data at rest. Our network communication is encrypted with highly restricted protocols. The cryptographic keys, including data encryption and SSL certificates, are managed by Xoxoday for optimal security.
We use a split key mechanism to ensure that every client’s key is unique. We perform annual key rotation. Keys are generated using KMS service whenever needed. We store keys in KMS.
We use a split key mechanism to ensure that every client’s key is unique. We perform annual key rotation. Keys are generated using KMS service whenever needed. We store keys in KMS.
We use logical data isolation with the help of company-specific encryption keys.
Password can be reset by employees. We do not send the password in plain text. We use TLS 1.2 for data in transit and AES-256 for data at rest.
We store passwords hashed. We have SHA-512 hash with unique salt for every password.
Only our product engineering team members have access as per their job functions and role-based logical access. We do not provide access to any third parties and all development and testing is done by internal employees.
Yes. We use TLS 1.2 for data in transit and AES-256 for data at rest. All data including backups is encrypted.
Our data cleaning process goes through an organized purge. Once the data is purged, it’s purged from all places.
Yes. Per our policies and procedures, we ensure secure disposal and removal of data from every storage media. The data cannot be recovered by any computer forensic means. We assure secure data disposal when storage is decommissioned or when the contract comes to an end.
The only user data stored within the system is personal information — names, emails, and contact numbers. This data is not put to any use by Xoxoday and resides within the system. The data can be deleted upon the tenant’s request.
We have implemented the Data Retention and Disposal Policy.

Patch Management

We update patches on a routine basis.
We update patches on a routine basis for servers as well.
We test patches before implementation in the production environment.
Patches are updated regularly.
Security patches are rated as Critical, High, Medium, and Low.
Critical patches will be deployed immediately. High patches will be deployed within 5 days. Medium patches within 15 days. Low within 25 days. Patch Management Procedure is attached.
Yes. We update patches periodically for our operating systems, software, servers, and network infrastructure.
Yes. We test the patches on the testing environment and deploy to production upon validation.
Yes. Security patches are regularly monitored and applied to the network security devices. All critical patches will be deployed immediately.
We update patches periodically. See Patch Management Procedure attached.
Yes. We regularly update our instance and make sure we follow security best practices. There is a process in place for regularly updating the servers and monitoring for latest updates across the entire stack.
We have implemented the Patch Management Procedure.
We follow the Change Management process to implement the compensatory control.
We follow the Change Management process.
Patches are updated on time.
Critical patches will be deployed immediately. High patches within 5 days. Medium patches within 15 days. Low within 25 days. Patch Management Procedure is attached.
Yes. We test patches before deploying in the production environment.

Change Management

We have implemented the Change Management Procedure. All IT changes take place as per the Change Management Procedure.
Yes. Changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates.
Yes. Change management procedures are attached. We are compliant.
Yes. We have implemented the change management procedures, and this applies to all Xoxoday assets, infrastructure, processes, software, and third-party activities. The procedure also applies to employees, vendors, and all other individuals who have access to, or are responsible for Xoxoday information processing facilities.
Yes. Our production team and QA team test all new releases or changes made to the existing product.
Yes. We will notify the customer if there are any major changes.
Yes. Our customer support team will communicate.

Antivirus & Endpoint Security

We have installed antivirus on all workstations and servers.
Yes. We have the controls in place. We have blocked connecting Hard disk, USB, CD-ROM, etc. to computers and all devices are centrally managed.
We use Bitdefender Endpoint security software to prevent malware and protect data. Additionally, we have AWS GuardDuty that continuously monitors for malicious activity and unauthorised behaviour. We use a cloud-hosted VPN with strict access controls linked with SSO/Active Directory.
We use endpoint security for prevention.
We have an alerting system in place and we perform scanning immediately to reduce the risk.
We have all required security controls for protecting endpoints — VPN, Firewall, IDS/IPS, Anti-Virus software, Audit log monitoring, Active Directory, etc.
We maintain up-to-date endpoint security to safeguard from attack scripts, viruses, worms, Trojan horses, backdoors, and malicious active content.
We are using Linux operating systems and following security best practices. We are monitoring using Prometheus/Grafana.
We have installed endpoint security in servers and PCs of all our employees as per compliance requirements.
We have all required security controls for protecting endpoints — VPN, Firewall, IDS/IPS, Anti-Virus software, Audit log monitoring, Active Directory, etc. We use a cloud-hosted VPN with strict access controls linked with SSO/Active Directory.

SSO, Authentication & Integration

Yes. Our partnerships with a wide array of integration partners ensure existing customer-based SSO capability for all users to seamlessly use Xoxoday’s products. With an easy DIY setup, your SSO solution would be plugged in and ready to go. Please refer to our list of integrations: https://xoxoday.gitbook.io/plum/developer-resources/integrations
Please click here to know more about API integration: https://www.empuls.io/integrations
The application enables user account management through API-based integration with the customer’s HR management system. These APIs are used to access employee data to ensure users’ accounts are created, updated, and disabled securely.
We have implemented WAF, IDS/IPS, and Amazon GuardDuty for maximum security. OAuth 2.0 is used to authorize all API requests. We also conduct code reviews to make sure that the APIs are secure.
Yes. It supports SSO.
Our partnerships with a wide array of integration partners ensure existing customer-based SSO capability for all users to seamlessly use Xoxoday’s products. With an easy DIY setup, your SSO solution would be plugged in and ready to go.
It’s a web and mobile application.
Our partnerships ensure existing customer-based SSO capability for all users. Our identity federation standards include SAML 2.0, SPML, WS-Federation, and more as means of authenticating and authorizing users with airtight security protocol. Please visit: xoxoday.com/integrations
Yes. The application has robust authentication methods. We have integrated SAML 2.0 with SAP SuccessFactors and support OAuth 2.0 and Azure AD for seamless authentication.
We have an option to integrate with SSO and HRMS. For more info, please visit the link: https://www.application.io/integrations
Two standard reports are available for admins on SuccessFactors at the program level — Budget and Spot Award Nomination. Using People Analytics, customers can create their own reports and dashboards combining Spot Awards data from Recognition with data from across SuccessFactors. Admins can also access similar data via a Xoxoday logon.
Yes. Customers can extract data from SuccessFactors via Integration Center and integrate it with other third parties.
Somewhat. We have a Spot Award Approved event available via Intelligent Service Center on SuccessFactors which customers can use to build custom extensions.
User provisioning for SAP SuccessFactors — Reward and Recognition is handled the same way as the rest of SuccessFactors. For employees redeeming points via Xoxoday, user provisioning is done on the fly at the time of redeeming the awards.

Third Party & Vendor Management

We make sure that they have adequate controls in place and meet the security standard.
We are managing the platform end to end.
Yes. Incident reporting obligations are passed on to all 3rd parties as well. All contracts and agreements are reviewed by the Legal Department.
We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. Administrative logs are part of the Cloud Dashboard and are regularly reviewed.

Service, Support & Upgrades

It will be the responsibility of Xoxoday.
The process for upgrades is automated using Continuous Integration and Deployment. Since our services are delivered via the web, upgrades and updates are seamless and usually do not involve any actions from end-users.
Xoxoday’s architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows.
The process for upgrades is automated using CI/CD. We try to release product hotfixes once every week and major features once every month.
The process for upgrades is automated using CI/CD. Upgrades and updates are seamless. We try to release hotfixes once every week and major features once every month.
Product updates and feature enhancements are done periodically by the application team. These updates are available to all customers by default. The customer need not do anything from their end to update the product version as the application is hosted on AWS Cloud.
The time of support ranges between two to forty-eight hours. This depends on the level of service and the gravity of incidents.
We have Email Support and an application help center for helping users.
We will be providing training for the admin and the end user and also provide extensive support through our customer support team.
Yes. We have an Information security team and group of people with responsibility for security within the organization.
Yes. We fix the issues found at no cost. We understand that consumer data protection is a high priority. We have implemented a Bug Bounty Program and encourage the reporting of security issues. If any outsiders or customers report security-related issues, we fix them free of cost.
We have deployed our application on Amazon Web Services (AWS) cloud platform. We are using MySQL, Salt stack, Node.js, and MongoDB technology.
See the application high-level diagram of CI/CD attached.
See the following policies attached — Infrastructure Change Control Procedure, Patch Management Procedure, Information System Acquisition Development and Maintenance Procedure, SDLC Procedure, Threat and Vulnerability Management.
Please click here for more details: https://help.empuls.io/
Payments are redirected to PayU gateway or PayPal websites to complete purchases securely. We are also implementing PCI DSS compliance controls and will provide the certification as soon as possible.
Approximately 2 weeks.
No installation. We are an out-of-the-box SaaS solution.
We have a multi-layered network architecture with role-based access control. All confidential/PII data is encrypted at rest with a split key mechanism to ensure that every client’s key is unique. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.
Yes.
Yes.
Yes. We have deployed our application on AWS Virtual platform cloud. We use WAF, IDS/IPS, AWS Audit Trail, Amazon GuardDuty, etc.
Yes. Segregation is done for production and non-production environments.
The production center location will be Bangalore.

Compliance Statements

Xoxoday would act as liaison partner between customer and merchants. We process the budgets which are approved by the customer. Xoxoday application is a SaaS Product.
The logs are automatically audited, but are not integrated with tenant’s security ops. In case the tenant requests logs, they can be shared when asked by the clients.
It’s a multi-tenant system. We use logical data isolation with the help of company-specific encryption keys and it is isolated from other customers’ data.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. We provide these logs on a need and approval basis for forensic investigation. We can freeze data from a specific time without freezing other data if needed.
We are compliant. We have implemented the password management policy and follow the concept of least privilege. Only a limited number of approved users have privileged access. All access will be provided on a need and approval basis. We maintain a ticketing system to make sure that the appropriate process is followed.
We have implemented the Password Management Policy for maximum security of data.
We are compliant. The password will be changed every 90 days.
These are integrated with security operations/SIEM solutions.
We have a secure log-on process and are compliant with these requirements.
We have a secure log-off process and are compliant with these requirements.
Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
We review architecture diagrams and data flow diagrams on a periodical basis. This is also validated during our internal and external independent audits.
We logically segregate the tenant’s data, and it is segregated with a client-specific key for proper handling and security reasons.
We do not use any unsecured protocols.
All critical applications are reviewed and tested before deployment.
We have a separate test and production environment.
We monitor systems and network utilization.
We have implemented file integrity (host) and network intrusion detection (IDS) tools to help facilitate timely detection and investigation.
We make sure that we follow industry best practices, the PDCA cycle, and standards in order to safeguard the Information Security System.
All critical patches are applied rapidly.
We are a multi-tenant SaaS system and all our logs will contain data of all customers. We will have our own log monitoring and security analysis.
Yes. All critical patches will be deployed immediately. We ensure that our infrastructure is always using up-to-date systems.
We have the ability to logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant’s data.
Compliant. We have deployed our application and database on separate servers.
Since the application is a SaaS Platform, this would not be applicable.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. Administrative logs are part of the Cloud Dashboard and are regularly reviewed.
Yes. We logically segregate the tenant’s data and the application.
WAF and rate limiters are installed to block multiple requests from specific IPs to prevent DDoS-type attacks.
Once the user logs out from the application, all pages, forms, and pop-ups will get closed.
We maintain logs and monitor on a regular basis for security reasons.
Compliant. We have resources to meet these requirements.