> ## Documentation Index
> Fetch the complete documentation index at: https://help-plum.xoxoday.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Application, Dev and Security

***

## Infrastructure & Compliance

<AccordionGroup>
  <Accordion title="How do you continuously monitor and report the compliance of your infrastructure in accordance to industry best practices (OWASP, SANS, SOC, ISO 27001)?">
    We take steps to securely develop and test against security threats to ensure the safety of our customer data. We maintain a Secure Development Lifecycle, in which training our developers and performing design and code reviews takes a primary role. In addition, Xoxoday employs third-party security experts to perform detailed penetration tests on different applications. In addition to the security components provided by our top-level cloud providers AWS, Xoxoday maintains its own dedicated controls by following the industry best practices. These controls cover DDoS attacks, DB protection and a dedicated web application firewall, as well as network firewall fine-grained rules configured using the highest industry standards.
  </Accordion>

  <Accordion title="Are Cloud Hosting services (IaaS) provided?">
    We provide Software as a Service (SaaS).
  </Accordion>

  <Accordion title="What is the service delivery model? (IaaS/PaaS/SaaS)">
    SaaS.
  </Accordion>

  <Accordion title="Is there an Internet-accessible self-service portal available that allows clients to configure security settings and view access logs, security events and alerts?">
    Admins can control the application and will have access to alerts and security events.
  </Accordion>

  <Accordion title="What Services/products are being/will be provided to the customer?">
    Xoxoday application is an API-driven digital rewards platform that automates rewards, incentives and gifting. The storefront has a global catalogue of 20,000+ options with 5,000+ experiences, 2,000+ gift cards and 10,000+ perks. The platform offers reward distribution modes like sending bulk vouchers via emails and generation of bulk voucher codes.
  </Accordion>

  <Accordion title="Do you offer an on-premise solution?">
    No. We are cloud hosted only.
  </Accordion>

  <Accordion title="Describe in detail your product's architecture.">
    We will share this as an attachment upon request.
  </Accordion>

  <Accordion title="Describe the key differentiators of your technical architecture.">
    Cloud hosted, microservice-based, highly scalable, High Availability.
  </Accordion>

  <Accordion title="Describe the minimum and recommended system requirements for your solution.">
    NA — We are cloud hosted.
  </Accordion>

  <Accordion title="Describe your solution's networking requirements and capabilities.">
    NA — We are cloud hosted. Users need to have internet access.
  </Accordion>

  <Accordion title="Is your solution available in a seamless manner to access as an app on different mobile devices and as web app on different desktop devices?">
    Yes. The solution is available as part of SAP SuccessFactors solution on web, as well as the SuccessFactors native mobile app for both iOS and Android.
  </Accordion>

  <Accordion title="Mobile Device Availability? (Android and iOS)">
    It's accessible in a mobile browser and can be accessed via an Android or iOS device.
  </Accordion>

  <Accordion title="Tablet Device Availability? (Android and iOS)">
    Our applications are compatible with desktops, tablets, and mobiles. No additional components are required.
  </Accordion>

  <Accordion title="Browser compatibility? (MS Edge, Chrome, Safari, IE)">
    Our applications are compatible with desktops, tablets, and mobiles. No additional components are required.
  </Accordion>

  <Accordion title="Technology Stack? (Infrastructure / Frontend / Backend / Database)">
    AWS / Kubernetes — React — Node/GraphQL — MySQL/MongoDB.
  </Accordion>

  <Accordion title="What technology languages/platforms/stacks/components are utilized in the scope of the application?">
    We have deployed our application on Amazon Web Services (AWS) cloud platform. We are using MySQL, Salt stack, Node.js and MongoDB technology.
  </Accordion>

  <Accordion title="Is the application developed on the latest language framework?">
    Yes. We are using the latest language frameworks like MySQL, JavaScript, Node.js and MongoDB.
  </Accordion>

  <Accordion title="Is the application developed using secure libraries?">
    Yes. These are approved during the code review process wherein the reviewer checks the utility and security of the libraries.
  </Accordion>

  <Accordion title="Where is the primary data center? Backup data center?">
    We have deployed our application on AWS Cloud virtual platform. The backup data center is in Singapore.
  </Accordion>

  <Accordion title="Describe the network topology.">
    The data centers are hosted completely in isolation so that access is limited and controlled. Load balancer allows shifting incremental load and can auto scale based on data load. Each instance (EC2) under a fortified VPC network is a conglomeration of Docker Container Web Services and APIs and application layer running on top. Amazon CloudWatch is implemented to enable monitoring. The data is encrypted using 256-encryption-based SSL certificate. Xoxoday plans a quarterly VAPT-based security audit.
  </Accordion>

  <Accordion title="Describe your network configuration and how your sensitive data system is protected.">
    Plum by Xoxoday is a cloud-based SaaS platform hosted on VPC infrastructure of AWS. The data centers are hosted in complete isolation. The architecture allows adding more location-specific data centers for latency and data security. Load balancers allow auto-scaling. Each EC2 instance under fortified VPC network is a conglomeration of Docker Container Web Services and APIs. Amazon CloudWatch is implemented for monitoring. Data is encrypted using TLS 1.3 in transit and AES-256 at rest.
  </Accordion>
</AccordionGroup>

***

## Backup, Recovery & Business Continuity

<AccordionGroup>
  <Accordion title="Have you implemented backup or recovery mechanisms to ensure compliance with regulatory, statutory, contractual or business requirements?">
    Data backups are done daily and in a secured way in AWS.
  </Accordion>

  <Accordion title="If using virtual infrastructure, does your cloud solution include independent hardware restore and recovery capabilities?">
    We use AWS Virtual platform cloud. We have created an Amazon CloudWatch alarm that monitors Amazon EC2 instances and automatically recovers them if impaired. EBS Snapshot functionality allows us to capture and restore virtual machine images at any time.
  </Accordion>

  <Accordion title="Does your infrastructure environment solution include software/provider independent restore and recovery capabilities?">
    Yes, the infrastructure environment solution includes software/provider independent restore and recovery capabilities.
  </Accordion>

  <Accordion title="Do you test your backup or redundancy mechanisms at least annually?">
    Yes. Data backups are automated and done daily in a secured way on AWS. We test the backup or redundancy mechanisms at least annually.
  </Accordion>

  <Accordion title="Does the RTO and RPO of CSP's contingency plan meet with vendor's customer requirements?">
    Our RTO and RPO is 60 minutes.
  </Accordion>

  <Accordion title="Has Supplier implemented data backup and recovery procedures to prevent data loss, unwanted overwrite and/or destruction?">
    Yes. Data backups are done daily and in a secured way in AWS.
  </Accordion>

  <Accordion title="Does the organisation store backups offsite?">
    Data backups are done on a daily basis and in a secured way on AWS.
  </Accordion>

  <Accordion title="Are all systems, assets and information backed up based on a BIA which establishes RPO/RTO?">
    We take automated backups on a regular basis.
  </Accordion>

  <Accordion title="Shall a backup be taken before and after any major changes to hardware, OS, application or configuration?">
    Yes. We take a backup of all data before making any major changes to hardware and software.
  </Accordion>

  <Accordion title="There shall be a detailed backup procedure based on the established RPO and RTO.">
    We have implemented the Backup Recovery Procedure.
  </Accordion>

  <Accordion title="What backup and disaster recovery plans are in place to avoid data loss/service loss in the time of contingency?">
    We have Business Continuity Policy and Business Continuity Management Procedure in place, tested periodically. Our policies are reviewed and audited annually. We test the BCP every 12 months, reviewed as part of internal and external audits.
  </Accordion>

  <Accordion title="Have you applied a data backup mechanism? What is the frequency of backup?">
    Yes. Data backups are done on a daily basis in a secured way in AWS.
  </Accordion>

  <Accordion title="Is your backup mechanism tested at least annually?">
    Yes. It is tested annually.
  </Accordion>

  <Accordion title="All backup data should be encrypted and adequately protected against unauthorized access.">
    Yes. All data backup is encrypted.
  </Accordion>

  <Accordion title="Are you able to restore user data upon loss through disk recovery mechanisms or stored backups?">
    Yes. It can be recovered.
  </Accordion>

  <Accordion title="Do you possess ISO 22301 for Business Continuity?">
    We have implemented the Business Continuity Management Policy and test the BCM plan annually. The BCM policy is attached for reference.
  </Accordion>

  <Accordion title="What type of DR options do you provide for my data within your offering?">
    We have implemented policies and procedures with regard to DR. Since we have deployed our application on AWS cloud, they provide DR services.
  </Accordion>

  <Accordion title="Please share the logical diagram with DR in place.">
    The application network architecture diagram is attached upon request.
  </Accordion>
</AccordionGroup>

***

## Application Development & SDLC

<AccordionGroup>
  <Accordion title="Do you test your applications before they are promoted into the Production environment? What types of testing do you perform?">
    We have an SDLC Policy as per ISMS requirements and follow General Coding Practice. We conduct data validation on a trusted system, use cryptographic functions to protect secrets, and perform code reviews, vulnerability assessments, and penetration testing. We follow a blue-green deployment strategy that introduces new changes without downtime and provides rollback capability.
  </Accordion>

  <Accordion title="Do you have a defined quality change control and testing process in place?">
    Yes. Changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates.
  </Accordion>

  <Accordion title="Do you have controls in place to ensure that standards of quality are being met for all software development?">
    We have implemented the SDLC Procedure and standards of quality are met for all software development.
  </Accordion>

  <Accordion title="What controls do you have in place to detect source code security defects for any outsourced software development activities?">
    We have not outsourced software development activities. Our code reviews and analysis run through stringent automated technologies as well as manual source code overviews to cover any security loopholes prior to the production phase.
  </Accordion>

  <Accordion title="Are mechanisms in place to ensure that all debugging and test code elements are removed from released software versions?">
    Yes. All debugging and test code elements are removed from released software versions.
  </Accordion>

  <Accordion title="Do you use an automated source code analysis tool to detect security defects in code prior to production?">
    Yes. We use an automated source code analysis tool.
  </Accordion>

  <Accordion title="Privacy by Design is incorporated into all your developments and services.">
    We are proactively embedding privacy into the design and operation of IT systems, networked infrastructure, and business practices.
  </Accordion>

  <Accordion title="Does the software development lifecycle in the organisation specifically focus on security?">
    We focus on security while producing software. SDLC procedures are attached for reference.
  </Accordion>

  <Accordion title="Are development, test and production environments separate?">
    Yes. All environments are separate.
  </Accordion>

  <Accordion title="Is production data ever used in a test environment?">
    No. We do not use production data in test environments.
  </Accordion>

  <Accordion title="Is testing of applications done on a separate testing facility and not on production data?">
    Yes. Both are kept separate.
  </Accordion>

  <Accordion title="Are patches tested in a UAT instance before deployment on the production server?">
    Yes.
  </Accordion>

  <Accordion title="Are applications and operating system software implemented after extensive and successful security testing?">
    Any applications and software are implemented after security testing by our IT team. All logs are monitored. We maintain an approved software/application register, audited during internal and external audits. Users are disallowed from installing software on their workstations.
  </Accordion>

  <Accordion title="Do you do static code analysis?">
    Yes. We have static code analysis.
  </Accordion>

  <Accordion title="How do you ensure code is being developed securely?">
    We have an SDLC Policy per ISMS requirements and follow General Coding Practice including data validation on a trusted system, cryptographic functions to protect secrets, and least privilege — restricting users to only the functionality, data, and system information required for their tasks.
  </Accordion>

  <Accordion title="What percentage of your production code is covered by automated tests?">
    More than 50% of our production code is covered by automated tests.
  </Accordion>

  <Accordion title="Is a staging/pre-production system used to validate build artifacts before promotion to production?">
    We do not use staging for building artifacts.
  </Accordion>

  <Accordion title="How is application security testing performed? Internal, third parties, or both? How often is it tested?">
    We conduct application security testing with the help of industry-approved third-party vendors every six months. Any observations found are addressed by our team. The primary objective is to identify and eliminate problems that could lead to a breach of confidentiality, availability, or integrity of Xoxoday data resources.
  </Accordion>

  <Accordion title="Any product pre-release security threat modeling, secure coding practice, security architecture review and penetration testing?">
    Yes. Our code reviews run through stringent automated technologies and manual source code overviews. Vulnerability scanning gives deep insight for quick identification of non-compliant systems. Xoxoday also employs third-party security experts to perform VAPT.
  </Accordion>

  <Accordion title="Is application development following secure coding standards such as OWASP?">
    Yes. Code reviews and analysis run through stringent automated technologies as well as manual source code review. Multiple security checks including code reviews, web vulnerability reviews, and advanced security tests are performed in every build.
  </Accordion>

  <Accordion title="Is the code reviewed by peer or externally?">
    Yes. Code is reviewed both internally and externally. We engage third-party vendors for security testing every six months.
  </Accordion>

  <Accordion title="Please provide further information about your handling of security requirements during development.">
    All software development procedures are supervised and monitored by Xoxoday to include: security requirements, independent security review of the environment, code reviews, quality monitoring, evaluation, and acceptance criteria for information systems.
  </Accordion>

  <Accordion title="Describe the management system in place to fix vulnerabilities identified during control activities.">
    Our QA department reviews and tests our code base. Dedicated application security engineers identify, test, and triage security vulnerabilities. We also conduct code reviews and VAPT with the help of a third-party vendor. VAPT Certificate is attached.
  </Accordion>

  <Accordion title="Do you have a managed process for approving new 3rd Party Libraries?">
    Yes. This is part of the code review process wherein the reviewer checks the utility and security of the 3rd party library.
  </Accordion>

  <Accordion title="Develop applications based on secure coding guidelines.">
    Compliant. The application is developed based on secure coding guidelines and code reviews are conducted per compliance requirements.
  </Accordion>

  <Accordion title="Implement controls to obfuscate application code prior to compilation.">
    Compliant.
  </Accordion>

  <Accordion title="Configures web services in accordance with OWASP.">
    Compliant. Yes, we follow all technical guidelines for development that come under the Open Web Application Security Project.
  </Accordion>

  <Accordion title="Configure web services to prevent sensitive information leakage in response headers.">
    Compliant. We have implemented DLP techniques and there are no possibilities of data leakage or loss.
  </Accordion>

  <Accordion title="Configure web services to use secure HTTP headers.">
    Compliant. The application uses HTTPS.
  </Accordion>

  <Accordion title="Implement strict HTTP transport security headers to protect websites against protocol downgrade attacks and cookie hijacking.">
    Compliant. We use strict HTTP transport security.
  </Accordion>

  <Accordion title="Impose file upload frequency restrictions in applications to prevent abuse or attack.">
    We cannot impose file upload frequency restrictions. However, the application has technical and organizational measures to prevent attacks through WAF, log monitoring, AWS GuardDuty, Amazon CloudWatch, IDS/IPS, etc.
  </Accordion>
</AccordionGroup>

***

## Access Control & Authentication

<AccordionGroup>
  <Accordion title="Do you have an identity management system (enabling classification of data for a customer) in place to enable both role-based and context-based entitlement to data?">
    We have a role-based access system to make sure that only authorized individuals have access to the required information.
  </Accordion>

  <Accordion title="Do you provide customers with strong (multifactor) authentication options (e.g., digital certs, tokens, biometrics)?">
    We don't provide multi-factor authentication as a default. As of now, there's OAuth 2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins.
  </Accordion>

  <Accordion title="Does the SaaS support MFA such as OTP, security tokens, or biometrics?">
    No, we don't provide multi-factor authentication as a default. As of now, there's OAuth 2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins.
  </Accordion>

  <Accordion title="Do you allow customers to define password and account lockout policies for their accounts?">
    It can be configured with Active Directory.
  </Accordion>

  <Accordion title="Do you restrict personnel access to all management functions or administrative access based on the principle of least privilege?">
    Access to data and systems is based on the principles of least privilege. All information systems and data are classified and segregated to support role-based access requirements. We use MFA, Firewall, VPN, Active Directory, etc. for maximum security.
  </Accordion>

  <Accordion title="How do you verify password strength?">
    The password needs to be a minimum of 8 characters long and contain at least one capital letter, special characters among '# \$ % \* &' and 1 digit. These are reviewed monthly.
  </Accordion>

  <Accordion title="How are passwords stored (encrypted, hashed, algorithm or hashing methodology)?">
    We store passwords hashed. We have SHA-512 hash with unique salt for every password.
  </Accordion>

  <Accordion title="How are passwords hashed?">
    We store passwords hashed. We have SHA-512 hash with unique salt for every password.
  </Accordion>

  <Accordion title="Does your solution follow any particular internationally accepted best practices or standards for password management?">
    Yes. Our password requirements comply with all factors to ensure strong passwords: minimum length, special characters, capitalized letters, and alpha-numeric combinations. Passwords are stored after encryption.
  </Accordion>

  <Accordion title="Does the solution force the new user to change the password for their first logon and on expiry?">
    Yes.
  </Accordion>

  <Accordion title="Can passwords be changed by the user at anytime?">
    Yes.
  </Accordion>

  <Accordion title="Can the solution alert the security administrator to delete a UserID if it has not been used for predefined days?">
    The solution does not allow login using credentials that have not been used. Admins can create and delete user accounts.
  </Accordion>

  <Accordion title="Can users be prevented from logging into multiple terminals simultaneously?">
    It's a SaaS solution. Users can log in from multiple locations.
  </Accordion>

  <Accordion title="Does the solution have other options of logon inputs besides user ID and password?">
    No. Users need to login with user ID and password. However, we have integrations with Zoho CRM, HubSpot, DarwinBox, SurveyMonkey, Freshdesk, etc.
  </Accordion>

  <Accordion title="What is the idle session timeout and session expiration?">
    Since it's a SaaS product, session timeout can be set with the help of Active Directory. For example — 15 min or 20 mins as per requirements.
  </Accordion>

  <Accordion title="Is there account lockout functionality? What is the maximum number of failed login attempts before the account gets locked out?">
    The account will get automatically locked after 5 unsuccessful login attempts.
  </Accordion>

  <Accordion title="What is the account unlock process?">
    Users will get a reset password link and can unlock their account through that.
  </Accordion>

  <Accordion title="Share the User ID lifecycle process, from creation till termination of a user ID/account.">
    User accounts will be created by the admin and linked with the email ID of the users. Please refer to the admin guide: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1)
  </Accordion>

  <Accordion title="Does access provided to users and administrators follow Need to Know basis?">
    Yes.
  </Accordion>

  <Accordion title="Is two-factor authentication enabled for end users and Administrators?">
    Yes. Two-factor authentication is enabled. MFA devices like Google Authenticator are available for OTP/Codes/Passwords.
  </Accordion>

  <Accordion title="Does MFA apply while accessing cloud environment/applications remotely (VPN, VDI)?">
    Yes.
  </Accordion>

  <Accordion title="How is Segregation of Duties (SoD) implemented for various user access roles?">
    We have procedures for Roles, Responsibilities & Authorities at Xoxoday. Per the access control policy, access to data is provided only to authorized and appropriate individuals.
  </Accordion>

  <Accordion title="Detail out the organization password policy.">
    Password policy: Must contain at least 8 characters, numbers and letters, uppercase (A-Z), lowercase (a-z), digits (0-9), and non-alphabetic characters (e.g., !, \$, #, %). Password must be changed every 90 days. Passwords are shared through secure, encrypted channels.
  </Accordion>

  <Accordion title="Supplier has internal processes for identity and access management.">
    Yes. Policies and procedures enforce two-factor authentication for privileged account management while accessing tenant data/systems. An IAM solution manages user access through role-based access profiles based on the need-to-know principle and segregation of duties.
  </Accordion>

  <Accordion title="Control panel or administration console to the service is properly protected from abuse. Segregation of duties is implemented for privileged users.">
    By default, Xoxoday will not have access to service data. Access control is managed by the admin from the customer end. If we require access for troubleshooting, we request temporary access, and the customer decides. Access to our production environment is allowed only via the Xoxoday corporate network to authorized individuals.
  </Accordion>

  <Accordion title="What kind of identity and access management services are provided?">
    Please refer to the admin guide on SSO Logins: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/getting-started](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/getting-started)
  </Accordion>

  <Accordion title="Are access to utility programs used to manage virtualized partitions appropriately restricted and monitored?">
    Yes. Access has been restricted and monitored for security reasons.
  </Accordion>

  <Accordion title="Do you have complexity or length requirements for passwords?">
    Yes. We have complexity and length requirements for passwords.
  </Accordion>

  <Accordion title="Do you review user access and rights at least annually?">
    We review user access on a periodical basis, validated during internal and external audits.
  </Accordion>
</AccordionGroup>

***

## Network Security & Firewall

<AccordionGroup>
  <Accordion title="Do your network architecture diagrams clearly identify high-risk environments and data flows?">
    Yes. We have captured this information in our architecture and data flow diagrams.
  </Accordion>

  <Accordion title="Are all non-internet facing systems placed behind a firewall?">
    Yes, we have a firewall.
  </Accordion>

  <Accordion title="Does the vendor have a comprehensive network architecture diagram covering infrastructure used for customer operations?">
    Yes, we have the network architecture diagram.
  </Accordion>

  <Accordion title="Is the internet access secure through a proxy/firewall?">
    Yes, we have configured secure internet access.
  </Accordion>

  <Accordion title="Are roles and responsibilities defined for Firewall configuration?">
    Yes, we have configured these.
  </Accordion>

  <Accordion title="Is there a proactive mechanism to monitor unauthorised network access attempts?">
    Yes. We have IDS and IPS implemented and receive alerts for unauthorised network access.
  </Accordion>

  <Accordion title="Is the firewall rule base reviewed at regular intervals?">
    Yes. It's reviewed on a monthly basis.
  </Accordion>

  <Accordion title="Does the firewall have real-time logging and alerting capability?">
    Yes.
  </Accordion>

  <Accordion title="Are prior management approvals obtained and communication provided to the customer in case of any external connections to parties other than the customer?">
    Yes.
  </Accordion>

  <Accordion title="Are all servers, end user devices configured according to security standards as part of the build process?">
    Yes. All are configured according to security standards as part of the build process.
  </Accordion>

  <Accordion title="Are Intrusion Detection Systems (IDS) or Intrusion Prevention Systems (IPS) used by your organisation?">
    We have implemented IDS/IPS to facilitate timely detection, investigation by root cause analysis, and response to incidents.
  </Accordion>

  <Accordion title="Is wireless access allowed in your organisation?">
    Wireless access is allowed and handled with high-quality routers, password protection and restriction on internet usage.
  </Accordion>

  <Accordion title="Are network boundaries protected by firewalls?">
    Yes. We have installed firewalls for maximum security and configured them to restrict unauthorised traffic.
  </Accordion>

  <Accordion title="Is data import, data export, and service management conducted over secure, industry-accepted standardized network protocols?">
    All data is collected only through the Xoxoday Platform.
  </Accordion>

  <Accordion title="What type/model of Firewall is implemented to segregate security zones and protect the infrastructure from external attacks?">
    We use a Web Application Firewall (WAF).
  </Accordion>

  <Accordion title="How are operating systems hardened to provide only the necessary ports, protocols and services to meet business needs?">
    We harden the operating systems and restrict access to all ports, applications, and software, monitored on a regular basis.
  </Accordion>

  <Accordion title="Describe how you protect your wireless network environment from unauthorized access.">
    We have implemented policies and mechanisms to protect the wireless network environment. We use a cloud-hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and linked with SSO/Active Directory.
  </Accordion>

  <Accordion title="Is the network used for providing service to the customer logically and physically segregated? Is the server placed on a separate LAN?">
    Yes. It's logically and physically segregated. We have deployed our application on AWS Cloud platform.
  </Accordion>

  <Accordion title="Are external access (e.g., remote, wireless, third party) to the network only permitted after a user has been identified and authenticated?">
    We do not provide external access.
  </Accordion>

  <Accordion title="Whether Firewall, IPS/IDS, DLP, Anti APT, SIEM, AntiSpoofing and other security solutions have been implemented?">
    We have implemented IDS/IPS, Endpoint security, Firewall, DLP, Antispoofing, VPN, Active Directory and other security solutions for maximum security.
  </Accordion>

  <Accordion title="Are internal and external networks separated by firewalls with access policies and rules?">
    Yes. With multiple layered firewalls configured with deny-all mode allowing only specific rules required for business, network traffic is regulated. We have implemented intrusion detection and prevention system tools for timely detection and investigation.
  </Accordion>

  <Accordion title="Is there a standard approach for protecting network devices to prevent unauthorised access/network related attacks and data theft?">
    With multiple layered firewalls in deny-all mode, network traffic is regulated. We use tools that analyze various traffic patterns and correlate network events. Early warning signals trigger alerts to our team. We are equipped to detect and mitigate threats, DDoS attacks, session hijacks, login spoofs, or any other data extraction strategies.
  </Accordion>

  <Accordion title="Any host-based IPS for critical systems? Any next generation firewall, IPS and web application firewall?">
    Yes. As part of WAF, rate limiters are installed to block multiple requests from specific IPs to prevent DDoS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats.
  </Accordion>

  <Accordion title="Are network components and computers password protected?">
    All our network components and computers are password protected to ensure compliance with integrity, availability, and confidentiality principles of Information Security.
  </Accordion>

  <Accordion title="Is the production network segmented into different zones based on security levels?">
    Yes.
  </Accordion>

  <Accordion title="What is the process for making changes to network configuration?">
    We have Network Access Control and Security Procedure in place. Network resources must be on a need-to-know basis and authorizations must be obtained from appropriate authorities. Networks are logically or physically divided based on the criticality of the information stored.
  </Accordion>

  <Accordion title="Describe how you protect against attacks that target virtual infrastructure directly (shimming, Blue Pill, Hyper jumping, etc.)">
    We have WAF, IDS/IPS, AWS GuardDuty, Cloudflare, and data encryption. We conduct code reviews and VAPT annually with a third-party vendor. We are equipped to detect and mitigate DDoS attacks, session hijacks, login spoofs, or any other data extraction strategies.
  </Accordion>

  <Accordion title="Is application deployed behind the firewall and IDS/IPS?">
    We use Cloudflare Web Application Firewall (WAF) and IDS/IPS for maximum security.
  </Accordion>

  <Accordion title="Does WAF protect from application attacks?">
    Yes. We have implemented the Web Application Firewall (WAF).
  </Accordion>

  <Accordion title="Service Provider should have solid application security controls such as WAF and RASP to detect and block web-based attacks such as XSS, SQL Injection, and CSRF.">
    We have a web application firewall, IDS/IPS, SQL injection protection. We use Cloudflare for the same.
  </Accordion>

  <Accordion title="What cryptographic frameworks are used to secure data in transit over public networks?">
    Yes. Our network communication is encrypted with highly restricted protocols to ensure maximum security. We use TLS 1.2 encryption for data in transit.
  </Accordion>

  <Accordion title="Describe the network protocols used to communicate between components of the system (e.g., HTTPs, LDAP, SSL).">
    We use HTTPS and our network communication is encrypted with highly restricted protocols to ensure maximum security.
  </Accordion>

  <Accordion title="I cannot find anywhere in their documentation that they support IP address range restriction for the application API, could we get confirmation?">
    We do not provide support for IP address range restriction. Our restrictions/security are based on our OAuth process and do not restrict to specific IPs.
  </Accordion>
</AccordionGroup>

***

## Logging, Monitoring & Audit

<AccordionGroup>
  <Accordion title="Do you monitor and log privileged access (e.g., administrator level) to information security management systems?">
    Yes. We monitor the logs. Application and infrastructure logs are centrally collected and backed up in a secure manner for internal development and audit-related concerns.
  </Accordion>

  <Accordion title="Does the organisation maintain audit logs of user activities, exceptions, and security events on all systems that store or process sensitive data?">
    Yes. We maintain the records.
  </Accordion>

  <Accordion title="Do these audit logs contain details regarding the User ID, timestamp, and what actions were performed?">
    Yes. Since we record Services and Server logs at the level of virtual machine, and Audit and Access logs at the level of AWS, all these are covered.
  </Accordion>

  <Accordion title="At what frequency are these logs reviewed?">
    Monthly.
  </Accordion>

  <Accordion title="Is the ability to delete event logs restricted to only superadmin or host admin?">
    Yes. Only authorised individuals can do this.
  </Accordion>

  <Accordion title="Are changes made to virtual machines or moving of an image made immediately available to customers through electronic methods?">
    Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. We provide logs to the customer on a need and approval basis.
  </Accordion>

  <Accordion title="Are system administrator and system operator activities monitored and logged?">
    We maintain logs and monitor for security and audit purposes.
  </Accordion>

  <Accordion title="Are the system clocks of all information processing systems synchronized with an agreed accurate time source?">
    Yes. System clocks of all relevant information processing systems are synchronized to facilitate tracing and reconstitution of activity timelines.
  </Accordion>

  <Accordion title="Do you use a synchronized time-service protocol (e.g., NTP) to ensure all systems have a common time reference?">
    Yes.
  </Accordion>

  <Accordion title="What is the log retention policy? Who has access to logs in your organization?">
    We maintain logs for at least 180 days. Only the CTO and Production Head will have access to these logs. There will be no modification to these logs.
  </Accordion>

  <Accordion title="Who has access to Security logs?">
    Only authorised individuals have access to the security logs — e.g., CTO, DevOps Head, Production Head.
  </Accordion>

  <Accordion title="How long are security logs maintained by the provider?">
    At least 180 days.
  </Accordion>

  <Accordion title="IS logging enabled for all components, such as network devices, servers, DBs, IAM, Cloud Services?">
    Yes. Only authorised individuals have access.
  </Accordion>

  <Accordion title="Do you have a SIEM for monitoring and maintaining logs over security incidents?">
    Yes. We have a SIEM in place for monitoring and maintaining logs over security incidents from various components.
  </Accordion>

  <Accordion title="Provide the scope of data sources merged in your SIEM and confirm if configured for granular analysis and real-time alerting.">
    Yes, SIEM has been implemented. Our event management systems merge data sources to maintain log data within the SIEM. This helps in proper analysis and driving out alerts in case of contingency. Audit logs are reviewed and recorded automatically. These logs are integrated with security operations/SIEM solutions.
  </Accordion>

  <Accordion title="Is a SOC implemented to monitor the software solution? Can the customer gain access to the SOC alert and response reporting?">
    We have implemented the Security Operations Center to monitor, prevent, detect, investigate, and respond to cyber threats around the clock.
  </Accordion>

  <Accordion title="Does the Company run a Security Operations Center (or equivalent) which allows detection and response to Cyber Security Incidents?">
    Cyber security incidents are analyzed with network intrusion detection (IDS) tools. The incident response team is immediately notified for counter-actions and defense mechanisms. We have a Security incident management process to classify and handle incidents and security breaches.
  </Accordion>

  <Accordion title="Are all security events (authentication events, SSH session commands, privilege elevations) in production logged?">
    Yes.
  </Accordion>

  <Accordion title="Can logs be integrated into a SIEM system?">
    No. Logs are automatically audited but are not integrated with tenant's security ops. In case the tenant requests logs, they can be shared when asked by the clients.
  </Accordion>

  <Accordion title="Is a service available for APIs to push the logs of our company's administrators' operations on the Vendor platform in real time?">
    No. We do not have such a service. The key admin actions are present in the application reports. Our support team can help with a deep dive into a specific incident with the help of audit logs.
  </Accordion>

  <Accordion title="Is there a support for operation logs on the admin console? What operations do the audit logs monitor?">
    Yes. Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
  </Accordion>

  <Accordion title="Logging and monitoring is in place for analysing activities of privileged users as well as for inspecting and analysing network traffic.">
    All infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. The audit logs are reviewed and recorded automatically. These logs are integrated with security operations/SIEM solutions.
  </Accordion>

  <Accordion title="Logs are reviewed in a continuous manner to improve performance as well as detect potential security issues.">
    Yes. Our event management systems merge data sources to maintain log data within the SIEM. This helps in proper analysis and driving out alerts if needed.
  </Accordion>

  <Accordion title="Do you monitor and log user, system and administrative access?">
    We monitor logs on a regular basis. Infrastructure logs are collected using AWS Audit Trail. Application related logs are collected in our Elastic Search server and retained in long-term cloud storage.
  </Accordion>

  <Accordion title="What logging and monitoring capabilities are in place to detect unauthorised access to data or hacking attempts?">
    We use a cloud-hosted VPN with strict access controls. We have implemented intrusion detection tools for timely detection and investigation. File integrity and network intrusion detection (IDS) tools are implemented. We also have Endpoint security software for all computers.
  </Accordion>

  <Accordion title="Are independent IT security testing programs, assurance, audit and/or assessments performed? How frequently?">
    We perform internal and external audits annually. We also conduct security assessments and testing like VAPT every six months. We communicate these assessment results to clients on a yearly basis.
  </Accordion>

  <Accordion title="Does your internal security group carry out audits on your Information Security Management System?">
    Yes. We conduct audits on our Information Security Management System. The last audit date was 16th June 2021.
  </Accordion>

  <Accordion title="Will event logging/audit mechanisms be turned on at all times for the system?">
    Yes.
  </Accordion>

  <Accordion title="Will logs be regularly reviewed?">
    Yes. Administrative logs are part of the Cloud Dashboard and are regularly reviewed.
  </Accordion>

  <Accordion title="Are systems and networks monitored for security events?">
    We use Bitdefender Endpoint security software to prevent malware and protect data. Additionally, we have AWS GuardDuty threat detection service that continuously monitors for malicious activity and unauthorised behaviour. We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails.
  </Accordion>

  <Accordion title="Do you have any monitoring tool in place to get timely alerts on when a device is going down, restarted, or resources are over utilized?">
    We have an intrusion detection/monitoring application that alerts on unauthorized access. We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails.
  </Accordion>

  <Accordion title="How do you monitor system integrity, logs, intrusion detection, and system access?">
    Infrastructure logs are collected using AWS Audit Trail. Application related logs are collected in our Elastic Search server and retained in long-term cloud storage.
  </Accordion>

  <Accordion title="Are audit logs maintained that record user activities, exceptions, success and failure logons, policy changes, and information security events?">
    Yes. All audit logs are monitored as a best practice.
  </Accordion>

  <Accordion title="Are servers configured to capture who accessed a system and what changes were made?">
    Yes. Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage.
  </Accordion>

  <Accordion title="Detail out the process for security event logging and monitoring (including applicable correlation rules). Detail the log retention period and protection mechanisms to prevent log tampering.">
    Yes. Our event management systems merge the data sources to maintain a log data within the SIEM. This helps in proper analysis and driving out alerts if needed in case of contingency.
  </Accordion>

  <Accordion title="What alerts can be set in the system?">
    At Xoxoday, the following are recorded in audit logs: 1. Infrastructure logs — collected using AWS Audit Trail. 2. Application related logs — collected in our Elastic Search server and retained in long-term cloud storage.
  </Accordion>
</AccordionGroup>

***

## Data Protection & Encryption

<AccordionGroup>
  <Accordion title="Are you capable of supporting litigation holds (freeze of data from a specific point in time) for a specific customer without freezing other customer data?">
    Yes. We can freeze data from a specific time without freezing other data if needed.
  </Accordion>

  <Accordion title="Do you have the capability to recover data for a specific customer in the case of a failure or data loss?">
    We have a data loss prevention solution in place and data will not be lost.
  </Accordion>

  <Accordion title="What is the purpose for processing the Personal Data?">
    Personal data will be processed only for rewards and redemption purposes.
  </Accordion>

  <Accordion title="Can Supplier provide a data map which includes all country locations where Personal Data would traverse, be stored or processed?">
    Yes. We can provide the data flow diagram.
  </Accordion>

  <Accordion title="Have you implemented measures for prevention of loss of PII data? (e.g., DLP, restricted access controls, log recording, encryption)">
    We use technologies like DLP, Data encryption, access control, and log monitoring.
  </Accordion>

  <Accordion title="Is data import, data export, and service management conducted over secure industry-accepted standardized network protocols?">
    All data is collected only through the Xoxoday Platform.
  </Accordion>

  <Accordion title="Describe how you make sure the customer's data is properly segregated from other customers' in multi-tenant solutions.">
    Yes. The data is segregated with a client-specific key for proper handling and representation. Physical segregation is done for production and non-production environments.
  </Accordion>

  <Accordion title="Would you support encryption keys generated by our own PKI that would be used to encrypt data?">
    We use a split key mechanism to ensure that every client's key is unique. It's generated automatically from our end.
  </Accordion>

  <Accordion title="What type of mechanisms do you implement to make sure Data Integrity is protected against errors, corruption or misuse?">
    We have WAF, IDS/IPS, AWS GuardDuty, Cloudflare, and encrypted data. We conduct code reviews per compliance requirements and VAPT annually with a third-party vendor. We are equipped to detect and mitigate threats, DDoS attacks, session hijacks, login spoofs, or any other data extraction strategies.
  </Accordion>

  <Accordion title="Describe how you make sure the application is properly protected against exploitation of CVE vulnerabilities prior to allowing it to go to production.">
    Yes. We do testing before deploying in the production environment.
  </Accordion>

  <Accordion title="Is data import and export conducted over secure, industry-accepted standardized network protocols?">
    All data is collected only through the Xoxoday Platform.
  </Accordion>

  <Accordion title="Is sensitive information transferred to external recipients? If so, are controls in place to protect it?">
    We do not transfer any data externally. However, we have implemented encryption, VPN, Firewall, IDS/IPS, and monitoring systems.
  </Accordion>

  <Accordion title="Do procedures exist to protect documents and computer media from unauthorized disclosure, modification, removal, and destruction?">
    We have disabled all ports and users do not have access to USB, CD-ROM, Disks, tapes, or Hard drives. All data including backups has been encrypted. We use TLS 1.2 for data in transit and AES-256 for data at rest.
  </Accordion>

  <Accordion title="Are there security procedures for the decommissioning of IT equipment and storage devices which contain sensitive information?">
    All customer data including backup data is stored on AWS virtual platform cloud and does not store anything locally. We use TLS 1.2 for data in transit and AES-256 for data at rest. We have also implemented the Media handling procedure.
  </Accordion>

  <Accordion title="Is the data classified top secret/confidential/PII stored separately from public data or data of other organizations residing on the same cloud?">
    Yes.
  </Accordion>

  <Accordion title="How is data loss prevented and how is high availability ensured?">
    Our web application, email records, and endpoints are sealed with data loss prevention techniques. We have the capability to respond immediately.
  </Accordion>

  <Accordion title="If other tenants' information/data is compromised, how is the vendor making sure that the customer organization's data is not impacted?">
    We logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant's data.
  </Accordion>

  <Accordion title="What security measures are implemented by the Application Service Provider for guarding against data leakage/data corruption/data breach?">
    All security mechanisms and policies are established to prevent data leaks in transit as well as at rest. Exhaustive VAPT has been conducted along with business logic testing based on the OWASP framework, which incorporates 120+ test cases.
  </Accordion>

  <Accordion title="Is the data for multiple customers co-mingled in the same database or schema?">
    No. We use logical data isolation with the help of company-specific encryption keys.
  </Accordion>

  <Accordion title="Is any DLP solution in place? What is implemented to prevent data leaks?">
    Yes. We have implemented Data Loss Prevention techniques on AWS.
  </Accordion>

  <Accordion title="Are rules pertaining to remote access monitoring configured on DLP solution?">
    We have implemented data loss prevention techniques to make sure that the data is not lost permanently.
  </Accordion>

  <Accordion title="Are policies configured to monitor and detect data leakage over different file types?">
    It's a part of our data loss prevention techniques.
  </Accordion>

  <Accordion title="Is the current DLP solution capable of enforcing policies even when the endpoint is disconnected from the corporate network?">
    Our web assets, email records, and endpoints are sealed with data loss prevention techniques even when the endpoint is disconnected from the corporate network.
  </Accordion>

  <Accordion title="How the encryption keys used are secured and protected from unauthorized access?">
    Each tenant's data is uniquely encrypted using a client-specific key. We use AES-256 bit encryption for data at rest. Our network communication is encrypted with highly restricted protocols. The cryptographic keys, including data encryption and SSL certificates, are managed by Xoxoday for optimal security.
  </Accordion>

  <Accordion title="Any centralized crypto materials and key management infrastructure in place?">
    We use a split key mechanism to ensure that every client's key is unique. We perform annual key rotation. Keys are generated using KMS service whenever needed. We store keys in KMS.
  </Accordion>

  <Accordion title="Please describe your Key Management controls including key rotation, key generation, key storage.">
    We use a split key mechanism to ensure that every client's key is unique. We perform annual key rotation. Keys are generated using KMS service whenever needed. We store keys in KMS.
  </Accordion>

  <Accordion title="Does your system support dynamic key for encryption? How to store the key?">
    We use logical data isolation with the help of company-specific encryption keys.
  </Accordion>

  <Accordion title="Authentication mechanisms must not allow passwords to be sent in clear text, using a minimum of TLS 1.2, and an encryption algorithm and strength of AES-256.">
    Password can be reset by employees. We do not send the password in plain text. We use TLS 1.2 for data in transit and AES-256 for data at rest.
  </Accordion>

  <Accordion title="Passwords must be Hashed while stored using a salted non-reversible hash.">
    We store passwords hashed. We have SHA-512 hash with unique salt for every password.
  </Accordion>

  <Accordion title="Which groups of staff have access to personal and sensitive data?">
    Only our product engineering team members have access as per their job functions and role-based logical access. We do not provide access to any third parties and all development and testing is done by internal employees.
  </Accordion>

  <Accordion title="Is sensitive data encrypted when stored on laptops, desktops, and server hard drives?">
    Yes. We use TLS 1.2 for data in transit and AES-256 for data at rest. All data including backups is encrypted.
  </Accordion>

  <Accordion title="Does the provider retain rights to the customer data even if data is removed from the provider?">
    Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places.
  </Accordion>

  <Accordion title="CLOUD SERVICE PROVIDER must be able to ensure any data and/or system disposal in case of service termination and in case of data and/or system end of life.">
    Yes. Per our policies and procedures, we ensure secure disposal and removal of data from every storage media. The data cannot be recovered by any computer forensic means. We assure secure data disposal when storage is decommissioned or when the contract comes to an end.
  </Accordion>

  <Accordion title="Will the application collect and/or host any User Generated Content (UGC)?">
    The only user data stored within the system is personal information — names, emails, and contact numbers. This data is not put to any use by Xoxoday and resides within the system. The data can be deleted upon the tenant's request.
  </Accordion>

  <Accordion title="Entities shall be responsible for defining and updating the information/data retention policy and procedure.">
    We have implemented the Data Retention and Disposal Policy.
  </Accordion>

  <Accordion title="Retain audit logs in accordance with retention requirements: 90 days for non-PHI activities and one year for PHI related activities.">
    We retain logs for a minimum of 180 days and in accordance with the Company's records retention guidelines. We do not process any e-PHI.
  </Accordion>
</AccordionGroup>

***

## Patch Management

<AccordionGroup>
  <Accordion title="Are system and security patches applied to workstations on a routine basis?">
    We update patches on a routine basis.
  </Accordion>

  <Accordion title="Are system and security patches applied to servers on a routine basis?">
    We update patches on a routine basis for servers as well.
  </Accordion>

  <Accordion title="Are system and security patches tested prior to implementation in the production environment?">
    We test patches before implementation in the production environment.
  </Accordion>

  <Accordion title="Are all systems and applications patched regularly?">
    Patches are updated regularly.
  </Accordion>

  <Accordion title="How are security patches rated?">
    Security patches are rated as Critical, High, Medium, and Low.
  </Accordion>

  <Accordion title="Describe the patch management process including frequency and process to apply patches, and how rapidly you can patch vulnerabilities across all components of the solution.">
    Critical patches will be deployed immediately. High patches will be deployed within 5 days. Medium patches within 15 days. Low within 25 days. Patch Management Procedure is attached.
  </Accordion>

  <Accordion title="Does the vendor have a patch management process for the operating systems and software on their PCs, servers and network infrastructure?">
    Yes. We update patches periodically for our operating systems, software, servers, and network infrastructure.
  </Accordion>

  <Accordion title="Are all security patches tested before they are deployed? How is this accomplished?">
    Yes. We test the patches on the testing environment and deploy to production upon validation.
  </Accordion>

  <Accordion title="Are security patches regularly reviewed and applied to network and security devices?">
    Yes. Security patches are regularly monitored and applied to the network security devices. All critical patches will be deployed immediately.
  </Accordion>

  <Accordion title="Please outline your planned approach to security patching of operating systems and applications.">
    We update patches periodically. See Patch Management Procedure attached.
  </Accordion>

  <Accordion title="Is there a process in place for tracking patch compliance in terms of patches successfully applied, unapplied patch ratio, and latency in rollout?">
    Yes. We regularly update our instance and make sure we follow security best practices. There is a process in place for regularly updating the servers and monitoring for latest updates across the entire stack.
  </Accordion>

  <Accordion title="Documented patch management procedures shall be developed, implemented and maintained.">
    We have implemented the Patch Management Procedure.
  </Accordion>

  <Accordion title="In the event a patch is not approved for use by the system vendor, a reason and risk mitigating controls for that patch shall be documented.">
    We follow the Change Management process to implement the compensatory control.
  </Accordion>

  <Accordion title="In the event a patch cannot be implemented due to current operations, an official exception shall be raised.">
    We follow the Change Management process.
  </Accordion>

  <Accordion title="All supporting systems used to develop or integrate systems shall be appropriately and timely patched.">
    Patches are updated on time.
  </Accordion>

  <Accordion title="Establish a dedicated patch management process for components.">
    Critical patches will be deployed immediately. High patches within 5 days. Medium patches within 15 days. Low within 25 days. Patch Management Procedure is attached.
  </Accordion>

  <Accordion title="Test patches and updates prior to deploying software in production environments.">
    Yes. We test patches before deploying in the production environment.
  </Accordion>
</AccordionGroup>

***

## Change Management

<AccordionGroup>
  <Accordion title="Does the organisation have a formal change control process for IT changes?">
    We have implemented the Change Management Procedure. All IT changes take place as per the Change Management Procedure.
  </Accordion>

  <Accordion title="Do you have technical measures in place to ensure that changes in production environments are registered, authorized and in adherence with existing SLAs?">
    Yes. Changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates.
  </Accordion>

  <Accordion title="Are the vendor's change control procedures compliant with ISO 27002?">
    Yes. Change management procedures are attached. We are compliant.
  </Accordion>

  <Accordion title="Do formal change management procedures exist for networks, systems, desktops, software releases, deployments, and software vulnerability patching activities?">
    Yes. We have implemented the change management procedures, and this applies to all Xoxoday assets, infrastructure, processes, software, and third-party activities. The procedure also applies to employees, vendors, and all other individuals who have access to, or are responsible for Xoxoday information processing facilities.
  </Accordion>

  <Accordion title="Are changes to the production environment reviewed by at least two engineers/operations staff?">
    Yes. Our production team and QA team test all new releases or changes made to the existing product.
  </Accordion>

  <Accordion title="Does the requirement discussed and agreed that CSP notify vendor for major changes of infrastructure/security configuration in cloud environment?">
    Yes. We will notify the customer if there are any major changes.
  </Accordion>

  <Accordion title="Is a communication channel established between Vendor and the customer to notify the customer on the scheduled downtime and in case of any data security breach?">
    Yes. Our customer support team will communicate.
  </Accordion>
</AccordionGroup>

***

## Antivirus & Endpoint Security

<AccordionGroup>
  <Accordion title="Is antivirus software installed on workstations?">
    We have installed antivirus on all workstations and servers.
  </Accordion>

  <Accordion title="Are controls in place to prevent administrators and other staff from downloading customer data to removable storage (USB memory sticks, CD ROM, etc.)?">
    Yes. We have the controls in place. We have blocked connecting Hard disk, USB, CD-ROM, etc. to computers and all devices are centrally managed.
  </Accordion>

  <Accordion title="What processes does the vendor have to detect and prevent viruses and other malicious software?">
    We use Bitdefender Endpoint security software to prevent malware and protect data. Additionally, we have AWS GuardDuty that continuously monitors for malicious activity and unauthorised behaviour. We use a cloud-hosted VPN with strict access controls linked with SSO/Active Directory.
  </Accordion>

  <Accordion title="Please outline any anti-malware (antivirus, etc.) tools that will be used to protect the system.">
    We use endpoint security for prevention.
  </Accordion>

  <Accordion title="In case of any exceptions due to which anti-malware activities fail, are alternative controls implemented to reduce the exposure on remote endpoints?">
    We have an alerting system in place and we perform scanning immediately to reduce the risk.
  </Accordion>

  <Accordion title="How are endpoint devices that are connected to the corporate network managed and secured?">
    We have all required security controls for protecting endpoints — VPN, Firewall, IDS/IPS, Anti-Virus software, Audit log monitoring, Active Directory, etc.
  </Accordion>

  <Accordion title="Ensure that all anti-malicious code protection is up-to-date based on entity-defined maintenance schedules.">
    We maintain up-to-date endpoint security to safeguard from attack scripts, viruses, worms, Trojan horses, backdoors, and malicious active content.
  </Accordion>

  <Accordion title="Detail Out the mechanism for Antivirus installation, monitoring and signature updates of infrastructure.">
    We are using Linux operating systems and following security best practices. We are monitoring using Prometheus/Grafana.
  </Accordion>

  <Accordion title="What are the procedures for configuration management, patch installation and malware prevention for all servers and PCs?">
    We have installed endpoint security in servers and PCs of all our employees as per compliance requirements.
  </Accordion>

  <Accordion title="Do you ensure that endpoints (laptops, desktops, etc.) have the latest available security-related patches installed?">
    Yes. We update patches periodically and ensure that all endpoints have the latest available security-related patches.
  </Accordion>

  <Accordion title="How are endpoint devices that are connected to the corporate network managed and secured?">
    We have all required security controls for protecting endpoints — VPN, Firewall, IDS/IPS, Anti-Virus software, Audit log monitoring, Active Directory, etc. We use a cloud-hosted VPN with strict access controls linked with SSO/Active Directory.
  </Accordion>
</AccordionGroup>

***

## SSO, Authentication & Integration

<AccordionGroup>
  <Accordion title="Mandatory Active Directory (SSO) Integration preferably through ADFS.">
    Yes. Our partnerships with a wide array of integration partners ensure existing customer-based SSO capability for all users to seamlessly use Xoxoday's products. With an easy DIY setup, your SSO solution would be plugged in and ready to go. Please refer to our list of integrations: [https://xoxoday.gitbook.io/plum/developer-resources/integrations](https://xoxoday.gitbook.io/plum/developer-resources/integrations)
  </Accordion>

  <Accordion title="Can your solution link to our Identity Federation Tool in order to authenticate users and retrieve their user profile using SAML or OAuth?">
    Yes. The application has robust authentication methods. We have integrated SAML 2.0 with SAP SuccessFactors and also support OAuth 2.0 for seamless authentication.
  </Accordion>

  <Accordion title="Are there interactions between the proposed solution and third-party applications/middleware?">
    API Documentation: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis)
  </Accordion>

  <Accordion title="Is API integration available?">
    Please click here to know more about API integration: [https://www.empuls.io/integrations](https://www.empuls.io/integrations)
  </Accordion>

  <Accordion title="Does the application have APIs available for user provisioning and deprovisioning?">
    The application enables user account management through API-based integration with the customer's HR management system. These APIs are used to access employee data to ensure users' accounts are created, updated, and disabled securely.
  </Accordion>

  <Accordion title="Does the application support any APIs? How are they consumed internally and externally?">
    Please click here for API Documentation: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis)
  </Accordion>

  <Accordion title="How the security of the exposed APIs is managed?">
    We have implemented WAF, IDS/IPS, and Amazon GuardDuty for maximum security. OAuth 2.0 is used to authorize all API requests. We also conduct code reviews to make sure that the APIs are secure.
  </Accordion>

  <Accordion title="Does the platform support typical Single Sign-On paradigms (e.g., Active Directory)?">
    Yes. It supports SSO.
  </Accordion>

  <Accordion title="Explain how the system supports single sign-on and an external roles-based access control system.">
    Our partnerships with a wide array of integration partners ensure existing customer-based SSO capability for all users to seamlessly use Xoxoday's products. With an easy DIY setup, your SSO solution would be plugged in and ready to go.
  </Accordion>

  <Accordion title="How to Authentication/Single Sign On (SSO): products should support the SAML2 standard?">
    Application Integrations: [https://www.application.io/integrations?tab=tab-collaborations](https://www.application.io/integrations?tab=tab-collaborations)
  </Accordion>

  <Accordion title="Products should support the secure VPN standard.">
    It's a web and mobile application.
  </Accordion>

  <Accordion title="Describe your SSO and Federated Identity Enablement integration options.">
    Our partnerships ensure existing customer-based SSO capability for all users. Our identity federation standards include SAML 2.0, SPML, WS-Federation, and more as means of authenticating and authorizing users with airtight security protocol. Please visit: xoxoday.com/integrations
  </Accordion>

  <Accordion title="Does your solution support modern authentication methods, e.g., SAML and OAuth/OIDC against Azure AD?">
    Yes. The application has robust authentication methods. We have integrated SAML 2.0 with SAP SuccessFactors and support OAuth 2.0 and Azure AD for seamless authentication.
  </Accordion>

  <Accordion title="Will the service/solution require integration with other customer solutions/data, either on-premise or in the cloud?">
    We have an option to integrate with SSO and HRMS. For more info, please visit the link: [https://www.application.io/integrations](https://www.application.io/integrations)
  </Accordion>

  <Accordion title="Does your service include Standard Reporting and Analytics Functionalities?">
    Two standard reports are available for admins on SuccessFactors at the program level — Budget and Spot Award Nomination. Using People Analytics, customers can create their own reports and dashboards combining Spot Awards data from Recognition with data from across SuccessFactors. Admins can also access similar data via a Xoxoday logon.
  </Accordion>

  <Accordion title="Can your service, via standard or custom interfaces/APIs, integrate with third party analytics?">
    Yes. Customers can extract data from SuccessFactors via Integration Center and integrate it with other third parties.
  </Accordion>

  <Accordion title="Do you support a Pub Sub architecture model for data transfer?">
    Somewhat. We have a Spot Award Approved event available via Intelligent Service Center on SuccessFactors which customers can use to build custom extensions.
  </Accordion>

  <Accordion title="Please describe user provisioning, on-boarding and off-boarding of end users to the platform.">
    User provisioning for SAP SuccessFactors — Reward and Recognition is handled the same way as the rest of SuccessFactors. For employees redeeming points via Xoxoday, user provisioning is done on the fly at the time of redeeming the awards.
  </Accordion>
</AccordionGroup>

***

## Third Party & Vendor Management

<AccordionGroup>
  <Accordion title="Do contracts with third party vendors that access or host your organization's information assets contain security requirements commensurate with your organization's security standards?">
    We make sure that they have adequate controls in place and meet the security standard.
  </Accordion>

  <Accordion title="Are you managing the offer from end to end or do you rely on suppliers and/or subcontractors?">
    We are managing the platform end to end.
  </Accordion>

  <Accordion title="Are incident reporting obligations passed on to all 3rd parties who are subcontracted by you?">
    Yes. Incident reporting obligations are passed on to all 3rd parties as well. All contracts and agreements are reviewed by the Legal Department.
  </Accordion>

  <Accordion title="Are third party connections to your network monitored and reviewed to confirm only authorized access and appropriate usage?">
    We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. Administrative logs are part of the Cloud Dashboard and are regularly reviewed.
  </Accordion>
</AccordionGroup>

***

## Service, Support & Upgrades

<AccordionGroup>
  <Accordion title="Is application of patches and upgrades under the provider's responsibility or the customer's?">
    It will be the responsibility of Xoxoday.
  </Accordion>

  <Accordion title="How is the customer informed of application upgrades impacting the end user's client?">
    The process for upgrades is automated using Continuous Integration and Deployment. Since our services are delivered via the web, upgrades and updates are seamless and usually do not involve any actions from end-users.
  </Accordion>

  <Accordion title="Can customers control the timing of software upgrades? What support do you provide during the upgrade process?">
    Xoxoday's architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows.
  </Accordion>

  <Accordion title="How often is the platform scheduled for software patches and updates?">
    The process for upgrades is automated using CI/CD. We try to release product hotfixes once every week and major features once every month.
  </Accordion>

  <Accordion title="What is the process for upgrades? How often are new versions released?">
    The process for upgrades is automated using CI/CD. Upgrades and updates are seamless. We try to release hotfixes once every week and major features once every month.
  </Accordion>

  <Accordion title="Support requirement (version updates, future enhancement etc.)">
    Product updates and feature enhancements are done periodically by the application team. These updates are available to all customers by default. The customer need not do anything from their end to update the product version as the application is hosted on AWS Cloud.
  </Accordion>

  <Accordion title="What SLAs apply to the product/service?">
    The time of support ranges between two to forty-eight hours. This depends on the level of service and the gravity of incidents.
  </Accordion>

  <Accordion title="What support methods are available?">
    We have Email Support and an application help center for helping users.
  </Accordion>

  <Accordion title="How would you service and support Union Pacific as a customer?">
    We will be providing training for the admin and the end user and also provide extensive support through our customer support team.
  </Accordion>

  <Accordion title="Is there an individual or group with responsibility for security within the organization?">
    Yes. We have an Information security team and group of people with responsibility for security within the organization.
  </Accordion>

  <Accordion title="If your customer later finds and reports a security hole/issue in the solution, will you provide the patch/fix at no cost?">
    Yes. We fix the issues found at no cost. We understand that consumer data protection is a high priority. We have implemented a Bug Bounty Program and encourage the reporting of security issues. If any outsiders or customers report security-related issues, we fix them free of cost.
  </Accordion>

  <Accordion title="Confirm with CSP which technologies and processes are used to ensure high levels of performance, reliability and availability.">
    We have deployed our application on Amazon Web Services (AWS) cloud platform. We are using MySQL, Salt stack, Node.js, and MongoDB technology.
  </Accordion>

  <Accordion title="Please provide a high-level diagram of your Continuous Integration and Continuous Deployment (CI/CD) pipeline.">
    See the application high-level diagram of CI/CD attached.
  </Accordion>

  <Accordion title="What are the digital infrastructure secure configuration, vulnerability management and patch management policies, procedures and processes?">
    See the following policies attached — Infrastructure Change Control Procedure, Patch Management Procedure, Information System Acquisition Development and Maintenance Procedure, SDLC Procedure, Threat and Vulnerability Management.
  </Accordion>

  <Accordion title="Do you provide customers with security administrative guides that detail configurable security settings, their interpretation and how to implement them?">
    Please click here for more details: [https://help.empuls.io/](https://help.empuls.io/)
  </Accordion>

  <Accordion title="It seems they support credit card processing for adding funds, what is their PCI DSS compliance exposure and level achieved?">
    Payments are redirected to PayU gateway or PayPal websites to complete purchases securely. We are also implementing PCI DSS compliance controls and will provide the certification as soon as possible.
  </Accordion>

  <Accordion title="Estimate implementation duration from project start to go live in first market.">
    Approximately 2 weeks.
  </Accordion>

  <Accordion title="Please describe the typical installation time and resources required for your solution.">
    No installation. We are an out-of-the-box SaaS solution.
  </Accordion>

  <Accordion title="What are any prerequisites recommended to use or access the solution/services effectively?">
    No recommendations as such. The application is a SaaS product supported by a comprehensive web application that can be accessed via desktop and mobile browsers on all compatible devices, including Android and iOS.
  </Accordion>

  <Accordion title="How do you limit data exfiltration from production endpoint devices?">
    We have a multi-layered network architecture with role-based access control. All confidential/PII data is encrypted at rest with a split key mechanism to ensure that every client's key is unique. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.
  </Accordion>

  <Accordion title="Do you have breach detection systems and/or anomaly detection with alerting?">
    Yes.
  </Accordion>

  <Accordion title="Are the hosts where the service is running uniformly configured?">
    Yes.
  </Accordion>

  <Accordion title="If hosted on public cloud (Amazon, Google, Azure etc.) — security configurations are aligned with public cloud vendor security requirements?">
    Yes. We have deployed our application on AWS Virtual platform cloud. We use WAF, IDS/IPS, AWS Audit Trail, Amazon GuardDuty, etc.
  </Accordion>

  <Accordion title="Is there a service that will be a separate test environment? Will this include the use of dummy or live data?">
    Yes. Segregation is done for production and non-production environments.
  </Accordion>

  <Accordion title="Which all locations is the vendor working from or are their offices located?">
    The production center location will be Bangalore.
  </Accordion>
</AccordionGroup>

***

## Compliance Statements

<AccordionGroup>
  <Accordion title="Mandatory Business ownership to be mapped for all applications on-boarded.">
    Xoxoday would act as liaison partner between customer and merchants. We process the budgets which are approved by the customer. Xoxoday application is a SaaS Product.
  </Accordion>

  <Accordion title="Logs should be sent to the customer SIEM for continuous monitoring of security events from the application.">
    The logs are automatically audited, but are not integrated with tenant's security ops. In case the tenant requests logs, they can be shared when asked by the clients.
  </Accordion>

  <Accordion title="When infrastructure is shared, the tenant environments are properly segregated and isolated.">
    It's a multi-tenant system. We use logical data isolation with the help of company-specific encryption keys and it is isolated from other customers' data.
  </Accordion>

  <Accordion title="Vendor has network forensics capabilities in place, and when required, the customer is assisted by the Vendor in performing any investigations on suspicious activities.">
    Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. We provide these logs on a need and approval basis for forensic investigation. We can freeze data from a specific time without freezing other data if needed.
  </Accordion>

  <Accordion title="The concept of least privilege should be employed for specific duties to adequately mitigate risk.">
    We are compliant. We have implemented the password management policy and follow the concept of least privilege. Only a limited number of approved users have privileged access. All access will be provided on a need and approval basis. We maintain a ticketing system to make sure that the appropriate process is followed.
  </Accordion>

  <Accordion title="Passwords shall be implemented on sensitive components to prevent unauthorised access and all default passwords shall be changed.">
    We have implemented the Password Management Policy for maximum security of data.
  </Accordion>

  <Accordion title="Passwords shall be changed at an agreed upon interval.">
    We are compliant. The password will be changed every 90 days.
  </Accordion>

  <Accordion title="Implement network-based technical controls that monitor communications with external systems and with key internal systems for suspicious traffic.">
    These are integrated with security operations/SIEM solutions.
  </Accordion>

  <Accordion title="Secure log-on procedures shall be in place (warning banners, protection against brute force, logging of authentication events, etc.).">
    We have a secure log-on process and are compliant with these requirements.
  </Accordion>

  <Accordion title="Secure log-off procedures shall be followed (maximum session times, termination of inactive sessions).">
    We have a secure log-off process and are compliant with these requirements.
  </Accordion>

  <Accordion title="System logging and auditing features are enabled and configured.">
    Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
  </Accordion>

  <Accordion title="System architecture/interconnection diagrams showing data flows, and physical and logical segmentation shall be reviewed and updated at least quarterly.">
    We review architecture diagrams and data flow diagrams on a periodical basis. This is also validated during our internal and external independent audits.
  </Accordion>

  <Accordion title="Segregation, physically and/or logically, shall be implemented ensuring that the required levels of control for data flows and users are met.">
    We logically segregate the tenant's data, and it is segregated with a client-specific key for proper handling and security reasons.
  </Accordion>

  <Accordion title="Unsecured protocols or protocols with known vulnerabilities shall not be used.">
    We do not use any unsecured protocols.
  </Accordion>

  <Accordion title="All critical applications shall be reviewed and tested after operating system changes or other major changes.">
    All critical applications are reviewed and tested before deployment.
  </Accordion>

  <Accordion title="Development, test and production environments shall be segregated.">
    We have a separate test and production environment.
  </Accordion>

  <Accordion title="Performance and capacity monitoring, such as system and network utilisation, shall be practiced.">
    We monitor systems and network utilization.
  </Accordion>

  <Accordion title="Network IDS may be provided where necessary.">
    We have implemented file integrity (host) and network intrusion detection (IDS) tools to help facilitate timely detection and investigation.
  </Accordion>

  <Accordion title="Performance improvement plans shall be outlined based on successive progression of security controls maturity and based on identified nonconformities.">
    We make sure that we follow industry best practices, the PDCA cycle, and standards in order to safeguard the Information Security System.
  </Accordion>

  <Accordion title="Service Provider shall have strict patching practice to ensure security patches are applied rapidly.">
    All critical patches are applied rapidly.
  </Accordion>

  <Accordion title="Service Provider should have capabilities to integrate security systems with the customer's Security monitoring solution (SIEM).">
    We are a multi-tenant SaaS system and all our logs will contain data of all customers. We will have our own log monitoring and security analysis.
  </Accordion>

  <Accordion title="CLOUD SERVICE PROVIDER (CSP) must ensure CLIENT that its infrastructure is always using up-to-date systems.">
    Yes. All critical patches will be deployed immediately. We ensure that our infrastructure is always using up-to-date systems.
  </Accordion>

  <Accordion title="In multi-tenancy cloud environment, CLOUD SERVICE PROVIDER must ensure the CLIENT environment is segregated from other tenants' environment.">
    We have the ability to logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant's data.
  </Accordion>

  <Accordion title="The solution is to be deployed and operationalized in a configuration where application and data storage components will reside and operate on separate physical or virtual servers.">
    Compliant. We have deployed our application and database on separate servers.
  </Accordion>

  <Accordion title="Configure REST/Web services to explicitly validate content types.">
    Since the application is a SaaS Platform, this would not be applicable.
  </Accordion>

  <Accordion title="Applications must be designed in such a way that it captures evidence of any action taken by the user to protect itself from denying authenticity of the activity.">
    Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. Administrative logs are part of the Cloud Dashboard and are regularly reviewed.
  </Accordion>

  <Accordion title="The hosted application's architecture must be configured in such a way that data stores containing confidential or regulated information are logically located in a secure network segment.">
    Yes. We logically segregate the tenant's data and the application.
  </Accordion>

  <Accordion title="The hosted web application's architecture is to be deployed and configured with a web application firewall to protect the application.">
    WAF and rate limiters are installed to block multiple requests from specific IPs to prevent DDoS-type attacks.
  </Accordion>

  <Accordion title="All application created sessions, windows, forms, pages, and pop-ups that display highly confidential information must be terminated or closed after the user logs out.">
    Once the user logs out from the application, all pages, forms, and pop-ups will get closed.
  </Accordion>

  <Accordion title="Implement controls to log TLS connection failures.">
    We maintain logs and monitor on a regular basis for security reasons.
  </Accordion>

  <Accordion title="Implement processes to measure the availability, quality, and adequate capacity of resources to deliver the required system performance.">
    Compliant. We have resources to meet these requirements.
  </Accordion>
</AccordionGroup>

***

## Infrastructure & Compliance

<AccordionGroup>
  <Accordion title="How do you continuously monitor and report the compliance of your infrastructure in accordance to industry best practices (OWASP, SANS, SOC, ISO 27001)?">
    We take steps to securely develop and test against security threats to ensure the safety of our customer data. We maintain a Secure Development Lifecycle, in which training our developers and performing design and code reviews takes a primary role. In addition, Xoxoday employs third-party security experts to perform detailed penetration tests on different applications. In addition to the security components provided by our top-level cloud providers AWS, Xoxoday maintains its own dedicated controls by following the industry best practices. These controls cover DDoS attacks, DB protection and a dedicated web application firewall, as well as network firewall fine-grained rules configured using the highest industry standards.
  </Accordion>

  <Accordion title="Are Cloud Hosting services (IaaS) provided?">
    We provide Software as a Service (SaaS).
  </Accordion>

  <Accordion title="What is the service delivery model? (IaaS/PaaS/SaaS)">
    SaaS.
  </Accordion>

  <Accordion title="Is there an Internet-accessible self-service portal available that allows clients to configure security settings and view access logs, security events and alerts?">
    Admins can control the application and will have access to alerts and security events.
  </Accordion>

  <Accordion title="What Services/products are being/will be provided to the customer?">
    Xoxoday application is an API-driven digital rewards platform that automates rewards, incentives and gifting. The storefront has a global catalogue of 20,000+ options with 5,000+ experiences, 2,000+ gift cards and 10,000+ perks. The platform offers reward distribution modes like sending bulk vouchers via emails and generation of bulk voucher codes.
  </Accordion>

  <Accordion title="Do you offer an on-premise solution?">
    No. We are cloud hosted only.
  </Accordion>

  <Accordion title="Describe in detail your product's architecture.">
    We will share this as an attachment upon request.
  </Accordion>

  <Accordion title="Describe the key differentiators of your technical architecture.">
    Cloud hosted, microservice-based, highly scalable, High Availability.
  </Accordion>

  <Accordion title="Describe the minimum and recommended system requirements for your solution.">
    NA — We are cloud hosted.
  </Accordion>

  <Accordion title="Describe your solution's networking requirements and capabilities.">
    NA — We are cloud hosted. Users need to have internet access.
  </Accordion>

  <Accordion title="Is your solution available in a seamless manner to access as an app on different mobile devices and as web app on different desktop devices?">
    Yes. The solution is available as part of SAP SuccessFactors solution on web, as well as the SuccessFactors native mobile app for both iOS and Android.
  </Accordion>

  <Accordion title="Mobile Device Availability? (Android and iOS)">
    It's accessible in a mobile browser and can be accessed via an Android or iOS device.
  </Accordion>

  <Accordion title="Tablet Device Availability? (Android and iOS)">
    Our applications are compatible with desktops, tablets, and mobiles. No additional components are required.
  </Accordion>

  <Accordion title="Browser compatibility? (MS Edge, Chrome, Safari, IE)">
    Our applications are compatible with desktops, tablets, and mobiles. No additional components are required.
  </Accordion>

  <Accordion title="Technology Stack? (Infrastructure / Frontend / Backend / Database)">
    AWS / Kubernetes — React — Node/GraphQL — MySQL/MongoDB.
  </Accordion>

  <Accordion title="What technology languages/platforms/stacks/components are utilized in the scope of the application?">
    We have deployed our application on Amazon Web Services (AWS) cloud platform. We are using MySQL, Salt stack, Node.js and MongoDB technology.
  </Accordion>

  <Accordion title="Is the application developed on the latest language framework?">
    Yes. We are using the latest language frameworks like MySQL, JavaScript, Node.js and MongoDB.
  </Accordion>

  <Accordion title="Is the application developed using secure libraries?">
    Yes. These are approved during the code review process wherein the reviewer checks the utility and security of the libraries.
  </Accordion>

  <Accordion title="Where is the primary data center? Backup data center?">
    We have deployed our application on AWS Cloud virtual platform. The backup data center is in Singapore.
  </Accordion>

  <Accordion title="Describe the network topology.">
    The data centers are hosted completely in isolation so that access is limited and controlled. Load balancer allows shifting incremental load and can auto scale based on data load. Each instance (EC2) under a fortified VPC network is a conglomeration of Docker Container Web Services and APIs and application layer running on top. Amazon CloudWatch is implemented to enable monitoring. The data is encrypted using 256-encryption-based SSL certificate. Xoxoday plans a quarterly VAPT-based security audit.
  </Accordion>

  <Accordion title="Describe your network configuration and how your sensitive data system is protected.">
    Plum by Xoxoday is a cloud-based SaaS platform hosted on VPC infrastructure of AWS. The data centers are hosted in complete isolation. The architecture allows adding more location-specific data centers for latency and data security. Load balancers allow auto-scaling. Each EC2 instance under fortified VPC network is a conglomeration of Docker Container Web Services and APIs. Amazon CloudWatch is implemented for monitoring. Data is encrypted using TLS 1.3 in transit and AES-256 at rest.
  </Accordion>
</AccordionGroup>

***

## Backup, Recovery & Business Continuity

<AccordionGroup>
  <Accordion title="Have you implemented backup or recovery mechanisms to ensure compliance with regulatory, statutory, contractual or business requirements?">
    Data backups are done daily and in a secured way in AWS.
  </Accordion>

  <Accordion title="If using virtual infrastructure, does your cloud solution include independent hardware restore and recovery capabilities?">
    We use AWS Virtual platform cloud. We have created an Amazon CloudWatch alarm that monitors Amazon EC2 instances and automatically recovers them if impaired. EBS Snapshot functionality allows us to capture and restore virtual machine images at any time.
  </Accordion>

  <Accordion title="Does your infrastructure environment solution include software/provider independent restore and recovery capabilities?">
    Yes, the infrastructure environment solution includes software/provider independent restore and recovery capabilities.
  </Accordion>

  <Accordion title="Do you test your backup or redundancy mechanisms at least annually?">
    Yes. Data backups are automated and done daily in a secured way on AWS. We test the backup or redundancy mechanisms at least annually.
  </Accordion>

  <Accordion title="Does the RTO and RPO of CSP's contingency plan meet with vendor's customer requirements?">
    Our RTO and RPO is 60 minutes.
  </Accordion>

  <Accordion title="Has Supplier implemented data backup and recovery procedures to prevent data loss, unwanted overwrite and/or destruction?">
    Yes. Data backups are done daily and in a secured way in AWS.
  </Accordion>

  <Accordion title="Does the organisation store backups offsite?">
    Data backups are done on a daily basis and in a secured way on AWS.
  </Accordion>

  <Accordion title="Are all systems, assets and information backed up based on a BIA which establishes RPO/RTO?">
    We take automated backups on a regular basis.
  </Accordion>

  <Accordion title="Shall a backup be taken before and after any major changes to hardware, OS, application or configuration?">
    Yes. We take a backup of all data before making any major changes to hardware and software.
  </Accordion>

  <Accordion title="There shall be a detailed backup procedure based on the established RPO and RTO.">
    We have implemented the Backup Recovery Procedure.
  </Accordion>

  <Accordion title="What backup and disaster recovery plans are in place to avoid data loss/service loss in the time of contingency?">
    We have Business Continuity Policy and Business Continuity Management Procedure in place, tested periodically. Our policies are reviewed and audited annually. We test the BCP every 12 months, reviewed as part of internal and external audits.
  </Accordion>

  <Accordion title="Have you applied a data backup mechanism? What is the frequency of backup?">
    Yes. Data backups are done on a daily basis in a secured way in AWS.
  </Accordion>

  <Accordion title="Is your backup mechanism tested at least annually?">
    Yes. It is tested annually.
  </Accordion>

  <Accordion title="All backup data should be encrypted and adequately protected against unauthorized access.">
    Yes. All data backup is encrypted.
  </Accordion>

  <Accordion title="Are you able to restore user data upon loss through disk recovery mechanisms or stored backups?">
    Yes. It can be recovered.
  </Accordion>

  <Accordion title="Do you possess ISO 22301 for Business Continuity?">
    We have implemented the Business Continuity Management Policy and test the BCM plan annually. The BCM policy is attached for reference.
  </Accordion>

  <Accordion title="What type of DR options do you provide for my data within your offering?">
    We have implemented policies and procedures with regard to DR. Since we have deployed our application on AWS cloud, they provide DR services.
  </Accordion>

  <Accordion title="Please share the logical diagram with DR in place.">
    The application network architecture diagram is attached upon request.
  </Accordion>
</AccordionGroup>

***

## Application Development & SDLC

<AccordionGroup>
  <Accordion title="Do you test your applications before they are promoted into the Production environment? What types of testing do you perform?">
    We have an SDLC Policy as per ISMS requirements and follow General Coding Practice. We conduct data validation on a trusted system, use cryptographic functions to protect secrets, and perform code reviews, vulnerability assessments, and penetration testing. We follow a blue-green deployment strategy that introduces new changes without downtime and provides rollback capability.
  </Accordion>

  <Accordion title="Do you have a defined quality change control and testing process in place?">
    Yes. Changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates.
  </Accordion>

  <Accordion title="Do you have controls in place to ensure that standards of quality are being met for all software development?">
    We have implemented the SDLC Procedure and standards of quality are met for all software development.
  </Accordion>

  <Accordion title="What controls do you have in place to detect source code security defects for any outsourced software development activities?">
    We have not outsourced software development activities. Our code reviews and analysis run through stringent automated technologies as well as manual source code overviews to cover any security loopholes prior to the production phase.
  </Accordion>

  <Accordion title="Are mechanisms in place to ensure that all debugging and test code elements are removed from released software versions?">
    Yes. All debugging and test code elements are removed from released software versions.
  </Accordion>

  <Accordion title="Do you use an automated source code analysis tool to detect security defects in code prior to production?">
    Yes. We use an automated source code analysis tool.
  </Accordion>

  <Accordion title="Privacy by Design is incorporated into all your developments and services.">
    We are proactively embedding privacy into the design and operation of IT systems, networked infrastructure, and business practices.
  </Accordion>

  <Accordion title="Does the software development lifecycle in the organisation specifically focus on security?">
    We focus on security while producing software. SDLC procedures are attached for reference.
  </Accordion>

  <Accordion title="Are development, test and production environments separate?">
    Yes. All environments are separate.
  </Accordion>

  <Accordion title="Is production data ever used in a test environment?">
    No. We do not use production data in test environments.
  </Accordion>

  <Accordion title="Is testing of applications done on a separate testing facility and not on production data?">
    Yes. Both are kept separate.
  </Accordion>

  <Accordion title="Are patches tested in a UAT instance before deployment on the production server?">
    Yes.
  </Accordion>

  <Accordion title="Are applications and operating system software implemented after extensive and successful security testing?">
    Any applications and software are implemented after security testing by our IT team. All logs are monitored. We maintain an approved software/application register, audited during internal and external audits. Users are disallowed from installing software on their workstations.
  </Accordion>

  <Accordion title="Do you do static code analysis?">
    Yes. We have static code analysis.
  </Accordion>

  <Accordion title="How do you ensure code is being developed securely?">
    We have an SDLC Policy per ISMS requirements and follow General Coding Practice including data validation on a trusted system, cryptographic functions to protect secrets, and least privilege — restricting users to only the functionality, data, and system information required for their tasks.
  </Accordion>

  <Accordion title="What percentage of your production code is covered by automated tests?">
    More than 50% of our production code is covered by automated tests.
  </Accordion>

  <Accordion title="Is a staging/pre-production system used to validate build artifacts before promotion to production?">
    We do not use staging for building artifacts.
  </Accordion>

  <Accordion title="How is application security testing performed? Internal, third parties, or both? How often is it tested?">
    We conduct application security testing with the help of industry-approved third-party vendors every six months. Any observations found are addressed by our team. The primary objective is to identify and eliminate problems that could lead to a breach of confidentiality, availability, or integrity of Xoxoday data resources.
  </Accordion>

  <Accordion title="Any product pre-release security threat modeling, secure coding practice, security architecture review and penetration testing?">
    Yes. Our code reviews run through stringent automated technologies and manual source code overviews. Vulnerability scanning gives deep insight for quick identification of non-compliant systems. Xoxoday also employs third-party security experts to perform VAPT.
  </Accordion>

  <Accordion title="Is application development following secure coding standards such as OWASP?">
    Yes. Code reviews and analysis run through stringent automated technologies as well as manual source code review. Multiple security checks including code reviews, web vulnerability reviews, and advanced security tests are performed in every build.
  </Accordion>

  <Accordion title="Is the code reviewed by peer or externally?">
    Yes. Code is reviewed both internally and externally. We engage third-party vendors for security testing every six months.
  </Accordion>

  <Accordion title="Please provide further information about your handling of security requirements during development.">
    All software development procedures are supervised and monitored by Xoxoday to include: security requirements, independent security review of the environment, code reviews, quality monitoring, evaluation, and acceptance criteria for information systems.
  </Accordion>

  <Accordion title="Describe the management system in place to fix vulnerabilities identified during control activities.">
    Our QA department reviews and tests our code base. Dedicated application security engineers identify, test, and triage security vulnerabilities. We also conduct code reviews and VAPT with the help of a third-party vendor. VAPT Certificate is attached.
  </Accordion>

  <Accordion title="Do you have a managed process for approving new 3rd Party Libraries?">
    Yes. This is part of the code review process wherein the reviewer checks the utility and security of the 3rd party library.
  </Accordion>

  <Accordion title="Develop applications based on secure coding guidelines.">
    Compliant. The application is developed based on secure coding guidelines and code reviews are conducted per compliance requirements.
  </Accordion>

  <Accordion title="Implement controls to obfuscate application code prior to compilation.">
    Compliant.
  </Accordion>

  <Accordion title="Configures web services in accordance with OWASP.">
    Compliant. Yes, we follow all technical guidelines for development that come under the Open Web Application Security Project.
  </Accordion>

  <Accordion title="Configure web services to prevent sensitive information leakage in response headers.">
    Compliant. We have implemented DLP techniques and there are no possibilities of data leakage or loss.
  </Accordion>

  <Accordion title="Configure web services to use secure HTTP headers.">
    Compliant. The application uses HTTPS.
  </Accordion>

  <Accordion title="Implement strict HTTP transport security headers to protect websites against protocol downgrade attacks and cookie hijacking.">
    Compliant. We use strict HTTP transport security.
  </Accordion>

  <Accordion title="Impose file upload frequency restrictions in applications to prevent abuse or attack.">
    We cannot impose file upload frequency restrictions. However, the application has technical and organizational measures to prevent attacks through WAF, log monitoring, AWS GuardDuty, Amazon CloudWatch, IDS/IPS, etc.
  </Accordion>
</AccordionGroup>

***

## Access Control & Authentication

<AccordionGroup>
  <Accordion title="Do you have an identity management system (enabling classification of data for a customer) in place to enable both role-based and context-based entitlement to data?">
    We have a role-based access system to make sure that only authorized individuals have access to the required information.
  </Accordion>

  <Accordion title="Do you provide customers with strong (multifactor) authentication options (e.g., digital certs, tokens, biometrics)?">
    We don't provide multi-factor authentication as a default. As of now, there's OAuth 2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins.
  </Accordion>

  <Accordion title="Does the SaaS support MFA such as OTP, security tokens, or biometrics?">
    No, we don't provide multi-factor authentication as a default. As of now, there's OAuth 2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins.
  </Accordion>

  <Accordion title="Do you allow customers to define password and account lockout policies for their accounts?">
    It can be configured with Active Directory.
  </Accordion>

  <Accordion title="Do you restrict personnel access to all management functions or administrative access based on the principle of least privilege?">
    Access to data and systems is based on the principles of least privilege. All information systems and data are classified and segregated to support role-based access requirements. We use MFA, Firewall, VPN, Active Directory, etc. for maximum security.
  </Accordion>

  <Accordion title="How do you verify password strength?">
    The password needs to be a minimum of 8 characters long and contain at least one capital letter, special characters among '# \$ % \* &' and 1 digit. These are reviewed monthly.
  </Accordion>

  <Accordion title="How are passwords stored (encrypted, hashed, algorithm or hashing methodology)?">
    We store passwords hashed. We have SHA-512 hash with unique salt for every password.
  </Accordion>

  <Accordion title="How are passwords hashed?">
    We store passwords hashed. We have SHA-512 hash with unique salt for every password.
  </Accordion>

  <Accordion title="Does your solution follow any particular internationally accepted best practices or standards for password management?">
    Yes. Our password requirements comply with all factors to ensure strong passwords: minimum length, special characters, capitalized letters, and alpha-numeric combinations. Passwords are stored after encryption.
  </Accordion>

  <Accordion title="Does the solution force the new user to change the password for their first logon and on expiry?">
    Yes.
  </Accordion>

  <Accordion title="Can passwords be changed by the user at anytime?">
    Yes.
  </Accordion>

  <Accordion title="Can the solution alert the security administrator to delete a UserID if it has not been used for predefined days?">
    The solution does not allow login using credentials that have not been used. Admins can create and delete user accounts.
  </Accordion>

  <Accordion title="Can users be prevented from logging into multiple terminals simultaneously?">
    It's a SaaS solution. Users can log in from multiple locations.
  </Accordion>

  <Accordion title="Does the solution have other options of logon inputs besides user ID and password?">
    No. Users need to login with user ID and password. However, we have integrations with Zoho CRM, HubSpot, DarwinBox, SurveyMonkey, Freshdesk, etc.
  </Accordion>

  <Accordion title="What is the idle session timeout and session expiration?">
    Since it's a SaaS product, session timeout can be set with the help of Active Directory. For example — 15 min or 20 mins as per requirements.
  </Accordion>

  <Accordion title="Is there account lockout functionality? What is the maximum number of failed login attempts before the account gets locked out?">
    The account will get automatically locked after 5 unsuccessful login attempts.
  </Accordion>

  <Accordion title="What is the account unlock process?">
    Users will get a reset password link and can unlock their account through that.
  </Accordion>

  <Accordion title="Share the User ID lifecycle process, from creation till termination of a user ID/account.">
    User accounts will be created by the admin and linked with the email ID of the users. Please refer to the admin guide: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1)
  </Accordion>

  <Accordion title="Does access provided to users and administrators follow Need to Know basis?">
    Yes.
  </Accordion>

  <Accordion title="Is two-factor authentication enabled for end users and Administrators?">
    Yes. Two-factor authentication is enabled. MFA devices like Google Authenticator are available for OTP/Codes/Passwords.
  </Accordion>

  <Accordion title="Does MFA apply while accessing cloud environment/applications remotely (VPN, VDI)?">
    Yes.
  </Accordion>

  <Accordion title="How is Segregation of Duties (SoD) implemented for various user access roles?">
    We have procedures for Roles, Responsibilities & Authorities at Xoxoday. Per the access control policy, access to data is provided only to authorized and appropriate individuals.
  </Accordion>

  <Accordion title="Detail out the organization password policy.">
    Password policy: Must contain at least 8 characters, numbers and letters, uppercase (A-Z), lowercase (a-z), digits (0-9), and non-alphabetic characters (e.g., !, \$, #, %). Password must be changed every 90 days. Passwords are shared through secure, encrypted channels.
  </Accordion>

  <Accordion title="Supplier has internal processes for identity and access management.">
    Yes. Policies and procedures enforce two-factor authentication for privileged account management while accessing tenant data/systems. An IAM solution manages user access through role-based access profiles based on the need-to-know principle and segregation of duties.
  </Accordion>

  <Accordion title="Control panel or administration console to the service is properly protected from abuse. Segregation of duties is implemented for privileged users.">
    By default, Xoxoday will not have access to service data. Access control is managed by the admin from the customer end. If we require access for troubleshooting, we request temporary access, and the customer decides. Access to our production environment is allowed only via the Xoxoday corporate network to authorized individuals.
  </Accordion>

  <Accordion title="What kind of identity and access management services are provided?">
    Please refer to the admin guide on SSO Logins: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/getting-started](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/getting-started)
  </Accordion>

  <Accordion title="Are access to utility programs used to manage virtualized partitions appropriately restricted and monitored?">
    Yes. Access has been restricted and monitored for security reasons.
  </Accordion>

  <Accordion title="Do you have complexity or length requirements for passwords?">
    Yes. We have complexity and length requirements for passwords.
  </Accordion>

  <Accordion title="Do you review user access and rights at least annually?">
    We review user access on a periodical basis, validated during internal and external audits.
  </Accordion>
</AccordionGroup>

***

## Network Security & Firewall

<AccordionGroup>
  <Accordion title="Do your network architecture diagrams clearly identify high-risk environments and data flows?">
    Yes. We have captured this information in our architecture and data flow diagrams.
  </Accordion>

  <Accordion title="Are all non-internet facing systems placed behind a firewall?">
    Yes, we have a firewall.
  </Accordion>

  <Accordion title="Does the vendor have a comprehensive network architecture diagram covering infrastructure used for customer operations?">
    Yes, we have the network architecture diagram.
  </Accordion>

  <Accordion title="Is the internet access secure through a proxy/firewall?">
    Yes, we have configured secure internet access.
  </Accordion>

  <Accordion title="Are roles and responsibilities defined for Firewall configuration?">
    Yes, we have configured these.
  </Accordion>

  <Accordion title="Is there a proactive mechanism to monitor unauthorised network access attempts?">
    Yes. We have IDS and IPS implemented and receive alerts for unauthorised network access.
  </Accordion>

  <Accordion title="Is the firewall rule base reviewed at regular intervals?">
    Yes. It's reviewed on a monthly basis.
  </Accordion>

  <Accordion title="Does the firewall have real-time logging and alerting capability?">
    Yes.
  </Accordion>

  <Accordion title="Are prior management approvals obtained and communication provided to the customer in case of any external connections to parties other than the customer?">
    Yes.
  </Accordion>

  <Accordion title="Are all servers, end user devices configured according to security standards as part of the build process?">
    Yes. All are configured according to security standards as part of the build process.
  </Accordion>

  <Accordion title="Are Intrusion Detection Systems (IDS) or Intrusion Prevention Systems (IPS) used by your organisation?">
    We have implemented IDS/IPS to facilitate timely detection, investigation by root cause analysis, and response to incidents.
  </Accordion>

  <Accordion title="Is wireless access allowed in your organisation?">
    Wireless access is allowed and handled with high-quality routers, password protection and restriction on internet usage.
  </Accordion>

  <Accordion title="Are network boundaries protected by firewalls?">
    Yes. We have installed firewalls for maximum security and configured them to restrict unauthorised traffic.
  </Accordion>

  <Accordion title="Is data import, data export, and service management conducted over secure, industry-accepted standardized network protocols?">
    All data is collected only through the Xoxoday Platform.
  </Accordion>

  <Accordion title="What type/model of Firewall is implemented to segregate security zones and protect the infrastructure from external attacks?">
    We use a Web Application Firewall (WAF).
  </Accordion>

  <Accordion title="How are operating systems hardened to provide only the necessary ports, protocols and services to meet business needs?">
    We harden the operating systems and restrict access to all ports, applications, and software, monitored on a regular basis.
  </Accordion>

  <Accordion title="Describe how you protect your wireless network environment from unauthorized access.">
    We have implemented policies and mechanisms to protect the wireless network environment. We use a cloud-hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and linked with SSO/Active Directory.
  </Accordion>

  <Accordion title="Is the network used for providing service to the customer logically and physically segregated? Is the server placed on a separate LAN?">
    Yes. It's logically and physically segregated. We have deployed our application on AWS Cloud platform.
  </Accordion>

  <Accordion title="Are external access (e.g., remote, wireless, third party) to the network only permitted after a user has been identified and authenticated?">
    We do not provide external access.
  </Accordion>

  <Accordion title="Whether Firewall, IPS/IDS, DLP, Anti APT, SIEM, AntiSpoofing and other security solutions have been implemented?">
    We have implemented IDS/IPS, Endpoint security, Firewall, DLP, Antispoofing, VPN, Active Directory and other security solutions for maximum security.
  </Accordion>

  <Accordion title="Are internal and external networks separated by firewalls with access policies and rules?">
    Yes. With multiple layered firewalls configured with deny-all mode allowing only specific rules required for business, network traffic is regulated. We have implemented intrusion detection and prevention system tools for timely detection and investigation.
  </Accordion>

  <Accordion title="Is there a standard approach for protecting network devices to prevent unauthorised access/network related attacks and data theft?">
    With multiple layered firewalls in deny-all mode, network traffic is regulated. We use tools that analyze various traffic patterns and correlate network events. Early warning signals trigger alerts to our team. We are equipped to detect and mitigate threats, DDoS attacks, session hijacks, login spoofs, or any other data extraction strategies.
  </Accordion>

  <Accordion title="Any host-based IPS for critical systems? Any next generation firewall, IPS and web application firewall?">
    Yes. As part of WAF, rate limiters are installed to block multiple requests from specific IPs to prevent DDoS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats.
  </Accordion>

  <Accordion title="Are network components and computers password protected?">
    All our network components and computers are password protected to ensure compliance with integrity, availability, and confidentiality principles of Information Security.
  </Accordion>

  <Accordion title="Is the production network segmented into different zones based on security levels?">
    Yes.
  </Accordion>

  <Accordion title="What is the process for making changes to network configuration?">
    We have Network Access Control and Security Procedure in place. Network resources must be on a need-to-know basis and authorizations must be obtained from appropriate authorities. Networks are logically or physically divided based on the criticality of the information stored.
  </Accordion>

  <Accordion title="Describe how you protect against attacks that target virtual infrastructure directly (shimming, Blue Pill, Hyper jumping, etc.)">
    We have WAF, IDS/IPS, AWS GuardDuty, Cloudflare, and data encryption. We conduct code reviews and VAPT annually with a third-party vendor. We are equipped to detect and mitigate DDoS attacks, session hijacks, login spoofs, or any other data extraction strategies.
  </Accordion>

  <Accordion title="Is application deployed behind the firewall and IDS/IPS?">
    We use Cloudflare Web Application Firewall (WAF) and IDS/IPS for maximum security.
  </Accordion>

  <Accordion title="Does WAF protect from application attacks?">
    Yes. We have implemented the Web Application Firewall (WAF).
  </Accordion>

  <Accordion title="Service Provider should have solid application security controls such as WAF and RASP to detect and block web-based attacks such as XSS, SQL Injection, and CSRF.">
    We have a web application firewall, IDS/IPS, SQL injection protection. We use Cloudflare for the same.
  </Accordion>

  <Accordion title="What cryptographic frameworks are used to secure data in transit over public networks?">
    Yes. Our network communication is encrypted with highly restricted protocols to ensure maximum security. We use TLS 1.2 encryption for data in transit.
  </Accordion>

  <Accordion title="Describe the network protocols used to communicate between components of the system (e.g., HTTPs, LDAP, SSL).">
    We use HTTPS and our network communication is encrypted with highly restricted protocols to ensure maximum security.
  </Accordion>

  <Accordion title="I cannot find anywhere in their documentation that they support IP address range restriction for the application API, could we get confirmation?">
    We do not provide support for IP address range restriction. Our restrictions/security are based on our OAuth process and do not restrict to specific IPs.
  </Accordion>
</AccordionGroup>

***

## Logging, Monitoring & Audit

<AccordionGroup>
  <Accordion title="Do you monitor and log privileged access (e.g., administrator level) to information security management systems?">
    Yes. We monitor the logs. Application and infrastructure logs are centrally collected and backed up in a secure manner for internal development and audit-related concerns.
  </Accordion>

  <Accordion title="Does the organisation maintain audit logs of user activities, exceptions, and security events on all systems that store or process sensitive data?">
    Yes. We maintain the records.
  </Accordion>

  <Accordion title="Do these audit logs contain details regarding the User ID, timestamp, and what actions were performed?">
    Yes. Since we record Services and Server logs at the level of virtual machine, and Audit and Access logs at the level of AWS, all these are covered.
  </Accordion>

  <Accordion title="At what frequency are these logs reviewed?">
    Monthly.
  </Accordion>

  <Accordion title="Is the ability to delete event logs restricted to only superadmin or host admin?">
    Yes. Only authorised individuals can do this.
  </Accordion>

  <Accordion title="Are changes made to virtual machines or moving of an image made immediately available to customers through electronic methods?">
    Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. We provide logs to the customer on a need and approval basis.
  </Accordion>

  <Accordion title="Are system administrator and system operator activities monitored and logged?">
    We maintain logs and monitor for security and audit purposes.
  </Accordion>

  <Accordion title="Are the system clocks of all information processing systems synchronized with an agreed accurate time source?">
    Yes. System clocks of all relevant information processing systems are synchronized to facilitate tracing and reconstitution of activity timelines.
  </Accordion>

  <Accordion title="Do you use a synchronized time-service protocol (e.g., NTP) to ensure all systems have a common time reference?">
    Yes.
  </Accordion>

  <Accordion title="What is the log retention policy? Who has access to logs in your organization?">
    We maintain logs for at least 180 days. Only the CTO and Production Head will have access to these logs. There will be no modification to these logs.
  </Accordion>

  <Accordion title="Who has access to Security logs?">
    Only authorised individuals have access to the security logs — e.g., CTO, DevOps Head, Production Head.
  </Accordion>

  <Accordion title="How long are security logs maintained by the provider?">
    At least 180 days.
  </Accordion>

  <Accordion title="IS logging enabled for all components, such as network devices, servers, DBs, IAM, Cloud Services?">
    Yes. Only authorised individuals have access.
  </Accordion>

  <Accordion title="Do you have a SIEM for monitoring and maintaining logs over security incidents?">
    Yes. We have a SIEM in place for monitoring and maintaining logs over security incidents from various components.
  </Accordion>

  <Accordion title="Provide the scope of data sources merged in your SIEM and confirm if configured for granular analysis and real-time alerting.">
    Yes, SIEM has been implemented. Our event management systems merge data sources to maintain log data within the SIEM. This helps in proper analysis and driving out alerts in case of contingency. Audit logs are reviewed and recorded automatically. These logs are integrated with security operations/SIEM solutions.
  </Accordion>

  <Accordion title="Is a SOC implemented to monitor the software solution? Can the customer gain access to the SOC alert and response reporting?">
    We have implemented the Security Operations Center to monitor, prevent, detect, investigate, and respond to cyber threats around the clock.
  </Accordion>

  <Accordion title="Does the Company run a Security Operations Center (or equivalent) which allows detection and response to Cyber Security Incidents?">
    Cyber security incidents are analyzed with network intrusion detection (IDS) tools. The incident response team is immediately notified for counter-actions and defense mechanisms. We have a Security incident management process to classify and handle incidents and security breaches.
  </Accordion>

  <Accordion title="Are all security events (authentication events, SSH session commands, privilege elevations) in production logged?">
    Yes.
  </Accordion>

  <Accordion title="Can logs be integrated into a SIEM system?">
    No. Logs are automatically audited but are not integrated with tenant's security ops. In case the tenant requests logs, they can be shared when asked by the clients.
  </Accordion>

  <Accordion title="Is a service available for APIs to push the logs of our company's administrators' operations on the Vendor platform in real time?">
    No. We do not have such a service. The key admin actions are present in the application reports. Our support team can help with a deep dive into a specific incident with the help of audit logs.
  </Accordion>

  <Accordion title="Is there a support for operation logs on the admin console? What operations do the audit logs monitor?">
    Yes. Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
  </Accordion>

  <Accordion title="Logging and monitoring is in place for analysing activities of privileged users as well as for inspecting and analysing network traffic.">
    All infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. The audit logs are reviewed and recorded automatically. These logs are integrated with security operations/SIEM solutions.
  </Accordion>

  <Accordion title="Logs are reviewed in a continuous manner to improve performance as well as detect potential security issues.">
    Yes. Our event management systems merge data sources to maintain log data within the SIEM. This helps in proper analysis and driving out alerts if needed.
  </Accordion>

  <Accordion title="Do you monitor and log user, system and administrative access?">
    We monitor logs on a regular basis. Infrastructure logs are collected using AWS Audit Trail. Application related logs are collected in our Elastic Search server and retained in long-term cloud storage.
  </Accordion>

  <Accordion title="What logging and monitoring capabilities are in place to detect unauthorised access to data or hacking attempts?">
    We use a cloud-hosted VPN with strict access controls. We have implemented intrusion detection tools for timely detection and investigation. File integrity and network intrusion detection (IDS) tools are implemented. We also have Endpoint security software for all computers.
  </Accordion>

  <Accordion title="Are independent IT security testing programs, assurance, audit and/or assessments performed? How frequently?">
    We perform internal and external audits annually. We also conduct security assessments and testing like VAPT every six months. We communicate these assessment results to clients on a yearly basis.
  </Accordion>

  <Accordion title="Does your internal security group carry out audits on your Information Security Management System?">
    Yes. We conduct audits on our Information Security Management System. The last audit date was 16th June 2021.
  </Accordion>

  <Accordion title="Will event logging/audit mechanisms be turned on at all times for the system?">
    Yes.
  </Accordion>

  <Accordion title="Will logs be regularly reviewed?">
    Yes. Administrative logs are part of the Cloud Dashboard and are regularly reviewed.
  </Accordion>

  <Accordion title="Are systems and networks monitored for security events?">
    We use Bitdefender Endpoint security software to prevent malware and protect data. Additionally, we have AWS GuardDuty threat detection service that continuously monitors for malicious activity and unauthorised behaviour. We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails.
  </Accordion>

  <Accordion title="Do you have any monitoring tool in place to get timely alerts on when a device is going down, restarted, or resources are over utilized?">
    We have an intrusion detection/monitoring application that alerts on unauthorized access. We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails.
  </Accordion>

  <Accordion title="How do you monitor system integrity, logs, intrusion detection, and system access?">
    Infrastructure logs are collected using AWS Audit Trail. Application related logs are collected in our Elastic Search server and retained in long-term cloud storage.
  </Accordion>

  <Accordion title="Are audit logs maintained that record user activities, exceptions, success and failure logons, policy changes, and information security events?">
    Yes. All audit logs are monitored as a best practice.
  </Accordion>

  <Accordion title="Are servers configured to capture who accessed a system and what changes were made?">
    Yes. Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage.
  </Accordion>

  <Accordion title="Detail out the process for security event logging and monitoring (including applicable correlation rules). Detail the log retention period and protection mechanisms to prevent log tampering.">
    Yes. Our event management systems merge the data sources to maintain a log data within the SIEM. This helps in proper analysis and driving out alerts if needed in case of contingency.
  </Accordion>

  <Accordion title="What alerts can be set in the system?">
    At Xoxoday, the following are recorded in audit logs: 1. Infrastructure logs — collected using AWS Audit Trail. 2. Application related logs — collected in our Elastic Search server and retained in long-term cloud storage.
  </Accordion>
</AccordionGroup>

***

## Data Protection & Encryption

<AccordionGroup>
  <Accordion title="Are you capable of supporting litigation holds (freeze of data from a specific point in time) for a specific customer without freezing other customer data?">
    Yes. We can freeze data from a specific time without freezing other data if needed.
  </Accordion>

  <Accordion title="Do you have the capability to recover data for a specific customer in the case of a failure or data loss?">
    We have a data loss prevention solution in place and data will not be lost.
  </Accordion>

  <Accordion title="What is the purpose for processing the Personal Data?">
    Personal data will be processed only for rewards and redemption purposes.
  </Accordion>

  <Accordion title="Can Supplier provide a data map which includes all country locations where Personal Data would traverse, be stored or processed?">
    Yes. We can provide the data flow diagram.
  </Accordion>

  <Accordion title="Have you implemented measures for prevention of loss of PII data? (e.g., DLP, restricted access controls, log recording, encryption)">
    We use technologies like DLP, Data encryption, access control, and log monitoring.
  </Accordion>

  <Accordion title="Is data import, data export, and service management conducted over secure industry-accepted standardized network protocols?">
    All data is collected only through the Xoxoday Platform.
  </Accordion>

  <Accordion title="Describe how you make sure the customer's data is properly segregated from other customers' in multi-tenant solutions.">
    Yes. The data is segregated with a client-specific key for proper handling and representation. Physical segregation is done for production and non-production environments.
  </Accordion>

  <Accordion title="Would you support encryption keys generated by our own PKI that would be used to encrypt data?">
    We use a split key mechanism to ensure that every client's key is unique. It's generated automatically from our end.
  </Accordion>

  <Accordion title="What type of mechanisms do you implement to make sure Data Integrity is protected against errors, corruption or misuse?">
    We have WAF, IDS/IPS, AWS GuardDuty, Cloudflare, and encrypted data. We conduct code reviews per compliance requirements and VAPT annually with a third-party vendor. We are equipped to detect and mitigate threats, DDoS attacks, session hijacks, login spoofs, or any other data extraction strategies.
  </Accordion>

  <Accordion title="Describe how you make sure the application is properly protected against exploitation of CVE vulnerabilities prior to allowing it to go to production.">
    Yes. We do testing before deploying in the production environment.
  </Accordion>

  <Accordion title="Is data import and export conducted over secure, industry-accepted standardized network protocols?">
    All data is collected only through the Xoxoday Platform.
  </Accordion>

  <Accordion title="Is sensitive information transferred to external recipients? If so, are controls in place to protect it?">
    We do not transfer any data externally. However, we have implemented encryption, VPN, Firewall, IDS/IPS, and monitoring systems.
  </Accordion>

  <Accordion title="Do procedures exist to protect documents and computer media from unauthorized disclosure, modification, removal, and destruction?">
    We have disabled all ports and users do not have access to USB, CD-ROM, Disks, tapes, or Hard drives. All data including backups has been encrypted. We use TLS 1.2 for data in transit and AES-256 for data at rest.
  </Accordion>

  <Accordion title="Are there security procedures for the decommissioning of IT equipment and storage devices which contain sensitive information?">
    All customer data including backup data is stored on AWS virtual platform cloud and does not store anything locally. We use TLS 1.2 for data in transit and AES-256 for data at rest. We have also implemented the Media handling procedure.
  </Accordion>

  <Accordion title="Is the data classified top secret/confidential/PII stored separately from public data or data of other organizations residing on the same cloud?">
    Yes.
  </Accordion>

  <Accordion title="How is data loss prevented and how is high availability ensured?">
    Our web application, email records, and endpoints are sealed with data loss prevention techniques. We have the capability to respond immediately.
  </Accordion>

  <Accordion title="If other tenants' information/data is compromised, how is the vendor making sure that the customer organization's data is not impacted?">
    We logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant's data.
  </Accordion>

  <Accordion title="What security measures are implemented by the Application Service Provider for guarding against data leakage/data corruption/data breach?">
    All security mechanisms and policies are established to prevent data leaks in transit as well as at rest. Exhaustive VAPT has been conducted along with business logic testing based on the OWASP framework, which incorporates 120+ test cases.
  </Accordion>

  <Accordion title="Is the data for multiple customers co-mingled in the same database or schema?">
    No. We use logical data isolation with the help of company-specific encryption keys.
  </Accordion>

  <Accordion title="Is any DLP solution in place? What is implemented to prevent data leaks?">
    Yes. We have implemented Data Loss Prevention techniques on AWS.
  </Accordion>

  <Accordion title="Are rules pertaining to remote access monitoring configured on DLP solution?">
    We have implemented data loss prevention techniques to make sure that the data is not lost permanently.
  </Accordion>

  <Accordion title="Are policies configured to monitor and detect data leakage over different file types?">
    It's a part of our data loss prevention techniques.
  </Accordion>

  <Accordion title="Is the current DLP solution capable of enforcing policies even when the endpoint is disconnected from the corporate network?">
    Our web assets, email records, and endpoints are sealed with data loss prevention techniques even when the endpoint is disconnected from the corporate network.
  </Accordion>

  <Accordion title="How the encryption keys used are secured and protected from unauthorized access?">
    Each tenant's data is uniquely encrypted using a client-specific key. We use AES-256 bit encryption for data at rest. Our network communication is encrypted with highly restricted protocols. The cryptographic keys, including data encryption and SSL certificates, are managed by Xoxoday for optimal security.
  </Accordion>

  <Accordion title="Any centralized crypto materials and key management infrastructure in place?">
    We use a split key mechanism to ensure that every client's key is unique. We perform annual key rotation. Keys are generated using KMS service whenever needed. We store keys in KMS.
  </Accordion>

  <Accordion title="Please describe your Key Management controls including key rotation, key generation, key storage.">
    We use a split key mechanism to ensure that every client's key is unique. We perform annual key rotation. Keys are generated using KMS service whenever needed. We store keys in KMS.
  </Accordion>

  <Accordion title="Does your system support dynamic key for encryption? How to store the key?">
    We use logical data isolation with the help of company-specific encryption keys.
  </Accordion>

  <Accordion title="Authentication mechanisms must not allow passwords to be sent in clear text, using a minimum of TLS 1.2, and an encryption algorithm and strength of AES-256.">
    Password can be reset by employees. We do not send the password in plain text. We use TLS 1.2 for data in transit and AES-256 for data at rest.
  </Accordion>

  <Accordion title="Passwords must be Hashed while stored using a salted non-reversible hash.">
    We store passwords hashed. We have SHA-512 hash with unique salt for every password.
  </Accordion>

  <Accordion title="Which groups of staff have access to personal and sensitive data?">
    Only our product engineering team members have access as per their job functions and role-based logical access. We do not provide access to any third parties and all development and testing is done by internal employees.
  </Accordion>

  <Accordion title="Is sensitive data encrypted when stored on laptops, desktops, and server hard drives?">
    Yes. We use TLS 1.2 for data in transit and AES-256 for data at rest. All data including backups is encrypted.
  </Accordion>

  <Accordion title="Does the provider retain rights to the customer data even if data is removed from the provider?">
    Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places.
  </Accordion>

  <Accordion title="CLOUD SERVICE PROVIDER must be able to ensure any data and/or system disposal in case of service termination and in case of data and/or system end of life.">
    Yes. Per our policies and procedures, we ensure secure disposal and removal of data from every storage media. The data cannot be recovered by any computer forensic means. We assure secure data disposal when storage is decommissioned or when the contract comes to an end.
  </Accordion>

  <Accordion title="Will the application collect and/or host any User Generated Content (UGC)?">
    The only user data stored within the system is personal information — names, emails, and contact numbers. This data is not put to any use by Xoxoday and resides within the system. The data can be deleted upon the tenant's request.
  </Accordion>

  <Accordion title="Entities shall be responsible for defining and updating the information/data retention policy and procedure.">
    We have implemented the Data Retention and Disposal Policy.
  </Accordion>

  <Accordion title="Retain audit logs in accordance with retention requirements: 90 days for non-PHI activities and one year for PHI related activities.">
    We retain logs for a minimum of 180 days and in accordance with the Company's records retention guidelines. We do not process any e-PHI.
  </Accordion>
</AccordionGroup>

***

## Patch Management

<AccordionGroup>
  <Accordion title="Are system and security patches applied to workstations on a routine basis?">
    We update patches on a routine basis.
  </Accordion>

  <Accordion title="Are system and security patches applied to servers on a routine basis?">
    We update patches on a routine basis for servers as well.
  </Accordion>

  <Accordion title="Are system and security patches tested prior to implementation in the production environment?">
    We test patches before implementation in the production environment.
  </Accordion>

  <Accordion title="Are all systems and applications patched regularly?">
    Patches are updated regularly.
  </Accordion>

  <Accordion title="How are security patches rated?">
    Security patches are rated as Critical, High, Medium, and Low.
  </Accordion>

  <Accordion title="Describe the patch management process including frequency and process to apply patches, and how rapidly you can patch vulnerabilities across all components of the solution.">
    Critical patches will be deployed immediately. High patches will be deployed within 5 days. Medium patches within 15 days. Low within 25 days. Patch Management Procedure is attached.
  </Accordion>

  <Accordion title="Does the vendor have a patch management process for the operating systems and software on their PCs, servers and network infrastructure?">
    Yes. We update patches periodically for our operating systems, software, servers, and network infrastructure.
  </Accordion>

  <Accordion title="Are all security patches tested before they are deployed? How is this accomplished?">
    Yes. We test the patches on the testing environment and deploy to production upon validation.
  </Accordion>

  <Accordion title="Are security patches regularly reviewed and applied to network and security devices?">
    Yes. Security patches are regularly monitored and applied to the network security devices. All critical patches will be deployed immediately.
  </Accordion>

  <Accordion title="Please outline your planned approach to security patching of operating systems and applications.">
    We update patches periodically. See Patch Management Procedure attached.
  </Accordion>

  <Accordion title="Is there a process in place for tracking patch compliance in terms of patches successfully applied, unapplied patch ratio, and latency in rollout?">
    Yes. We regularly update our instance and make sure we follow security best practices. There is a process in place for regularly updating the servers and monitoring for latest updates across the entire stack.
  </Accordion>

  <Accordion title="Documented patch management procedures shall be developed, implemented and maintained.">
    We have implemented the Patch Management Procedure.
  </Accordion>

  <Accordion title="In the event a patch is not approved for use by the system vendor, a reason and risk mitigating controls for that patch shall be documented.">
    We follow the Change Management process to implement the compensatory control.
  </Accordion>

  <Accordion title="In the event a patch cannot be implemented due to current operations, an official exception shall be raised.">
    We follow the Change Management process.
  </Accordion>

  <Accordion title="All supporting systems used to develop or integrate systems shall be appropriately and timely patched.">
    Patches are updated on time.
  </Accordion>

  <Accordion title="Establish a dedicated patch management process for components.">
    Critical patches will be deployed immediately. High patches within 5 days. Medium patches within 15 days. Low within 25 days. Patch Management Procedure is attached.
  </Accordion>

  <Accordion title="Test patches and updates prior to deploying software in production environments.">
    Yes. We test patches before deploying in the production environment.
  </Accordion>
</AccordionGroup>

***

## Change Management

<AccordionGroup>
  <Accordion title="Does the organisation have a formal change control process for IT changes?">
    We have implemented the Change Management Procedure. All IT changes take place as per the Change Management Procedure.
  </Accordion>

  <Accordion title="Do you have technical measures in place to ensure that changes in production environments are registered, authorized and in adherence with existing SLAs?">
    Yes. Changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates.
  </Accordion>

  <Accordion title="Are the vendor's change control procedures compliant with ISO 27002?">
    Yes. Change management procedures are attached. We are compliant.
  </Accordion>

  <Accordion title="Do formal change management procedures exist for networks, systems, desktops, software releases, deployments, and software vulnerability patching activities?">
    Yes. We have implemented the change management procedures, and this applies to all Xoxoday assets, infrastructure, processes, software, and third-party activities. The procedure also applies to employees, vendors, and all other individuals who have access to, or are responsible for Xoxoday information processing facilities.
  </Accordion>

  <Accordion title="Are changes to the production environment reviewed by at least two engineers/operations staff?">
    Yes. Our production team and QA team test all new releases or changes made to the existing product.
  </Accordion>

  <Accordion title="Does the requirement discussed and agreed that CSP notify vendor for major changes of infrastructure/security configuration in cloud environment?">
    Yes. We will notify the customer if there are any major changes.
  </Accordion>

  <Accordion title="Is a communication channel established between Vendor and the customer to notify the customer on the scheduled downtime and in case of any data security breach?">
    Yes. Our customer support team will communicate.
  </Accordion>
</AccordionGroup>

***

## Antivirus & Endpoint Security

<AccordionGroup>
  <Accordion title="Is antivirus software installed on workstations?">
    We have installed antivirus on all workstations and servers.
  </Accordion>

  <Accordion title="Are controls in place to prevent administrators and other staff from downloading customer data to removable storage (USB memory sticks, CD ROM, etc.)?">
    Yes. We have the controls in place. We have blocked connecting Hard disk, USB, CD-ROM, etc. to computers and all devices are centrally managed.
  </Accordion>

  <Accordion title="What processes does the vendor have to detect and prevent viruses and other malicious software?">
    We use Bitdefender Endpoint security software to prevent malware and protect data. Additionally, we have AWS GuardDuty that continuously monitors for malicious activity and unauthorised behaviour. We use a cloud-hosted VPN with strict access controls linked with SSO/Active Directory.
  </Accordion>

  <Accordion title="Please outline any anti-malware (antivirus, etc.) tools that will be used to protect the system.">
    We use endpoint security for prevention.
  </Accordion>

  <Accordion title="In case of any exceptions due to which anti-malware activities fail, are alternative controls implemented to reduce the exposure on remote endpoints?">
    We have an alerting system in place and we perform scanning immediately to reduce the risk.
  </Accordion>

  <Accordion title="How are endpoint devices that are connected to the corporate network managed and secured?">
    We have all required security controls for protecting endpoints — VPN, Firewall, IDS/IPS, Anti-Virus software, Audit log monitoring, Active Directory, etc.
  </Accordion>

  <Accordion title="Ensure that all anti-malicious code protection is up-to-date based on entity-defined maintenance schedules.">
    We maintain up-to-date endpoint security to safeguard from attack scripts, viruses, worms, Trojan horses, backdoors, and malicious active content.
  </Accordion>

  <Accordion title="Detail Out the mechanism for Antivirus installation, monitoring and signature updates of infrastructure.">
    We are using Linux operating systems and following security best practices. We are monitoring using Prometheus/Grafana.
  </Accordion>

  <Accordion title="What are the procedures for configuration management, patch installation and malware prevention for all servers and PCs?">
    We have installed endpoint security in servers and PCs of all our employees as per compliance requirements.
  </Accordion>

  <Accordion title="Do you ensure that endpoints (laptops, desktops, etc.) have the latest available security-related patches installed?">
    Yes. We update patches periodically and ensure that all endpoints have the latest available security-related patches.
  </Accordion>

  <Accordion title="How are endpoint devices that are connected to the corporate network managed and secured?">
    We have all required security controls for protecting endpoints — VPN, Firewall, IDS/IPS, Anti-Virus software, Audit log monitoring, Active Directory, etc. We use a cloud-hosted VPN with strict access controls linked with SSO/Active Directory.
  </Accordion>
</AccordionGroup>

***

## SSO, Authentication & Integration

<AccordionGroup>
  <Accordion title="Mandatory Active Directory (SSO) Integration preferably through ADFS.">
    Yes. Our partnerships with a wide array of integration partners ensure existing customer-based SSO capability for all users to seamlessly use Xoxoday's products. With an easy DIY setup, your SSO solution would be plugged in and ready to go. Please refer to our list of integrations: [https://xoxoday.gitbook.io/plum/developer-resources/integrations](https://xoxoday.gitbook.io/plum/developer-resources/integrations)
  </Accordion>

  <Accordion title="Can your solution link to our Identity Federation Tool in order to authenticate users and retrieve their user profile using SAML or OAuth?">
    Yes. The application has robust authentication methods. We have integrated SAML 2.0 with SAP SuccessFactors and also support OAuth 2.0 for seamless authentication.
  </Accordion>

  <Accordion title="Are there interactions between the proposed solution and third-party applications/middleware?">
    API Documentation: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis)
  </Accordion>

  <Accordion title="Is API integration available?">
    Please click here to know more about API integration: [https://www.empuls.io/integrations](https://www.empuls.io/integrations)
  </Accordion>

  <Accordion title="Does the application have APIs available for user provisioning and deprovisioning?">
    The application enables user account management through API-based integration with the customer's HR management system. These APIs are used to access employee data to ensure users' accounts are created, updated, and disabled securely.
  </Accordion>

  <Accordion title="Does the application support any APIs? How are they consumed internally and externally?">
    Please click here for API Documentation: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis)
  </Accordion>

  <Accordion title="How the security of the exposed APIs is managed?">
    We have implemented WAF, IDS/IPS, and Amazon GuardDuty for maximum security. OAuth 2.0 is used to authorize all API requests. We also conduct code reviews to make sure that the APIs are secure.
  </Accordion>

  <Accordion title="Does the platform support typical Single Sign-On paradigms (e.g., Active Directory)?">
    Yes. It supports SSO.
  </Accordion>

  <Accordion title="Explain how the system supports single sign-on and an external roles-based access control system.">
    Our partnerships with a wide array of integration partners ensure existing customer-based SSO capability for all users to seamlessly use Xoxoday's products. With an easy DIY setup, your SSO solution would be plugged in and ready to go.
  </Accordion>

  <Accordion title="How to Authentication/Single Sign On (SSO): products should support the SAML2 standard?">
    Application Integrations: [https://www.application.io/integrations?tab=tab-collaborations](https://www.application.io/integrations?tab=tab-collaborations)
  </Accordion>

  <Accordion title="Products should support the secure VPN standard.">
    It's a web and mobile application.
  </Accordion>

  <Accordion title="Describe your SSO and Federated Identity Enablement integration options.">
    Our partnerships ensure existing customer-based SSO capability for all users. Our identity federation standards include SAML 2.0, SPML, WS-Federation, and more as means of authenticating and authorizing users with airtight security protocol. Please visit: xoxoday.com/integrations
  </Accordion>

  <Accordion title="Does your solution support modern authentication methods, e.g., SAML and OAuth/OIDC against Azure AD?">
    Yes. The application has robust authentication methods. We have integrated SAML 2.0 with SAP SuccessFactors and support OAuth 2.0 and Azure AD for seamless authentication.
  </Accordion>

  <Accordion title="Will the service/solution require integration with other customer solutions/data, either on-premise or in the cloud?">
    We have an option to integrate with SSO and HRMS. For more info, please visit the link: [https://www.application.io/integrations](https://www.application.io/integrations)
  </Accordion>

  <Accordion title="Does your service include Standard Reporting and Analytics Functionalities?">
    Two standard reports are available for admins on SuccessFactors at the program level — Budget and Spot Award Nomination. Using People Analytics, customers can create their own reports and dashboards combining Spot Awards data from Recognition with data from across SuccessFactors. Admins can also access similar data via a Xoxoday logon.
  </Accordion>

  <Accordion title="Can your service, via standard or custom interfaces/APIs, integrate with third party analytics?">
    Yes. Customers can extract data from SuccessFactors via Integration Center and integrate it with other third parties.
  </Accordion>

  <Accordion title="Do you support a Pub Sub architecture model for data transfer?">
    Somewhat. We have a Spot Award Approved event available via Intelligent Service Center on SuccessFactors which customers can use to build custom extensions.
  </Accordion>

  <Accordion title="Please describe user provisioning, on-boarding and off-boarding of end users to the platform.">
    User provisioning for SAP SuccessFactors — Reward and Recognition is handled the same way as the rest of SuccessFactors. For employees redeeming points via Xoxoday, user provisioning is done on the fly at the time of redeeming the awards.
  </Accordion>
</AccordionGroup>

***

## Third Party & Vendor Management

<AccordionGroup>
  <Accordion title="Do contracts with third party vendors that access or host your organization's information assets contain security requirements commensurate with your organization's security standards?">
    We make sure that they have adequate controls in place and meet the security standard.
  </Accordion>

  <Accordion title="Are you managing the offer from end to end or do you rely on suppliers and/or subcontractors?">
    We are managing the platform end to end.
  </Accordion>

  <Accordion title="Are incident reporting obligations passed on to all 3rd parties who are subcontracted by you?">
    Yes. Incident reporting obligations are passed on to all 3rd parties as well. All contracts and agreements are reviewed by the Legal Department.
  </Accordion>

  <Accordion title="Are third party connections to your network monitored and reviewed to confirm only authorized access and appropriate usage?">
    We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. Administrative logs are part of the Cloud Dashboard and are regularly reviewed.
  </Accordion>
</AccordionGroup>

***

## Service, Support & Upgrades

<AccordionGroup>
  <Accordion title="Is application of patches and upgrades under the provider's responsibility or the customer's?">
    It will be the responsibility of Xoxoday.
  </Accordion>

  <Accordion title="How is the customer informed of application upgrades impacting the end user's client?">
    The process for upgrades is automated using Continuous Integration and Deployment. Since our services are delivered via the web, upgrades and updates are seamless and usually do not involve any actions from end-users.
  </Accordion>

  <Accordion title="Can customers control the timing of software upgrades? What support do you provide during the upgrade process?">
    Xoxoday's architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows.
  </Accordion>

  <Accordion title="How often is the platform scheduled for software patches and updates?">
    The process for upgrades is automated using CI/CD. We try to release product hotfixes once every week and major features once every month.
  </Accordion>

  <Accordion title="What is the process for upgrades? How often are new versions released?">
    The process for upgrades is automated using CI/CD. Upgrades and updates are seamless. We try to release hotfixes once every week and major features once every month.
  </Accordion>

  <Accordion title="Support requirement (version updates, future enhancement etc.)">
    Product updates and feature enhancements are done periodically by the application team. These updates are available to all customers by default. The customer need not do anything from their end to update the product version as the application is hosted on AWS Cloud.
  </Accordion>

  <Accordion title="What SLAs apply to the product/service?">
    The time of support ranges between two to forty-eight hours. This depends on the level of service and the gravity of incidents.
  </Accordion>

  <Accordion title="What support methods are available?">
    We have Email Support and an application help center for helping users.
  </Accordion>

  <Accordion title="How would you service and support Union Pacific as a customer?">
    We will be providing training for the admin and the end user and also provide extensive support through our customer support team.
  </Accordion>

  <Accordion title="Is there an individual or group with responsibility for security within the organization?">
    Yes. We have an Information security team and group of people with responsibility for security within the organization.
  </Accordion>

  <Accordion title="If your customer later finds and reports a security hole/issue in the solution, will you provide the patch/fix at no cost?">
    Yes. We fix the issues found at no cost. We understand that consumer data protection is a high priority. We have implemented a Bug Bounty Program and encourage the reporting of security issues. If any outsiders or customers report security-related issues, we fix them free of cost.
  </Accordion>

  <Accordion title="Confirm with CSP which technologies and processes are used to ensure high levels of performance, reliability and availability.">
    We have deployed our application on Amazon Web Services (AWS) cloud platform. We are using MySQL, Salt stack, Node.js, and MongoDB technology.
  </Accordion>

  <Accordion title="Please provide a high-level diagram of your Continuous Integration and Continuous Deployment (CI/CD) pipeline.">
    See the application high-level diagram of CI/CD attached.
  </Accordion>

  <Accordion title="What are the digital infrastructure secure configuration, vulnerability management and patch management policies, procedures and processes?">
    See the following policies attached — Infrastructure Change Control Procedure, Patch Management Procedure, Information System Acquisition Development and Maintenance Procedure, SDLC Procedure, Threat and Vulnerability Management.
  </Accordion>

  <Accordion title="Do you provide customers with security administrative guides that detail configurable security settings, their interpretation and how to implement them?">
    Please click here for more details: [https://help.empuls.io/](https://help.empuls.io/)
  </Accordion>

  <Accordion title="It seems they support credit card processing for adding funds, what is their PCI DSS compliance exposure and level achieved?">
    Payments are redirected to PayU gateway or PayPal websites to complete purchases securely. We are also implementing PCI DSS compliance controls and will provide the certification as soon as possible.
  </Accordion>

  <Accordion title="Estimate implementation duration from project start to go live in first market.">
    Approximately 2 weeks.
  </Accordion>

  <Accordion title="Please describe the typical installation time and resources required for your solution.">
    No installation. We are an out-of-the-box SaaS solution.
  </Accordion>

  <Accordion title="What are any prerequisites recommended to use or access the solution/services effectively?">
    No recommendations as such. The application is a SaaS product supported by a comprehensive web application that can be accessed via desktop and mobile browsers on all compatible devices, including Android and iOS.
  </Accordion>

  <Accordion title="How do you limit data exfiltration from production endpoint devices?">
    We have a multi-layered network architecture with role-based access control. All confidential/PII data is encrypted at rest with a split key mechanism to ensure that every client's key is unique. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.
  </Accordion>

  <Accordion title="Do you have breach detection systems and/or anomaly detection with alerting?">
    Yes.
  </Accordion>

  <Accordion title="Are the hosts where the service is running uniformly configured?">
    Yes.
  </Accordion>

  <Accordion title="If hosted on public cloud (Amazon, Google, Azure etc.) — security configurations are aligned with public cloud vendor security requirements?">
    Yes. We have deployed our application on AWS Virtual platform cloud. We use WAF, IDS/IPS, AWS Audit Trail, Amazon GuardDuty, etc.
  </Accordion>

  <Accordion title="Is there a service that will be a separate test environment? Will this include the use of dummy or live data?">
    Yes. Segregation is done for production and non-production environments.
  </Accordion>

  <Accordion title="Which all locations is the vendor working from or are their offices located?">
    The production center location will be Bangalore.
  </Accordion>
</AccordionGroup>

***

## Compliance Statements

<AccordionGroup>
  <Accordion title="Mandatory Business ownership to be mapped for all applications on-boarded.">
    Xoxoday would act as liaison partner between customer and merchants. We process the budgets which are approved by the customer. Xoxoday application is a SaaS Product.
  </Accordion>

  <Accordion title="Logs should be sent to the customer SIEM for continuous monitoring of security events from the application.">
    The logs are automatically audited, but are not integrated with tenant's security ops. In case the tenant requests logs, they can be shared when asked by the clients.
  </Accordion>

  <Accordion title="When infrastructure is shared, the tenant environments are properly segregated and isolated.">
    It's a multi-tenant system. We use logical data isolation with the help of company-specific encryption keys and it is isolated from other customers' data.
  </Accordion>

  <Accordion title="Vendor has network forensics capabilities in place, and when required, the customer is assisted by the Vendor in performing any investigations on suspicious activities.">
    Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. We provide these logs on a need and approval basis for forensic investigation. We can freeze data from a specific time without freezing other data if needed.
  </Accordion>

  <Accordion title="The concept of least privilege should be employed for specific duties to adequately mitigate risk.">
    We are compliant. We have implemented the password management policy and follow the concept of least privilege. Only a limited number of approved users have privileged access. All access will be provided on a need and approval basis. We maintain a ticketing system to make sure that the appropriate process is followed.
  </Accordion>

  <Accordion title="Passwords shall be implemented on sensitive components to prevent unauthorised access and all default passwords shall be changed.">
    We have implemented the Password Management Policy for maximum security of data.
  </Accordion>

  <Accordion title="Passwords shall be changed at an agreed upon interval.">
    We are compliant. The password will be changed every 90 days.
  </Accordion>

  <Accordion title="Implement network-based technical controls that monitor communications with external systems and with key internal systems for suspicious traffic.">
    These are integrated with security operations/SIEM solutions.
  </Accordion>

  <Accordion title="Secure log-on procedures shall be in place (warning banners, protection against brute force, logging of authentication events, etc.).">
    We have a secure log-on process and are compliant with these requirements.
  </Accordion>

  <Accordion title="Secure log-off procedures shall be followed (maximum session times, termination of inactive sessions).">
    We have a secure log-off process and are compliant with these requirements.
  </Accordion>

  <Accordion title="System logging and auditing features are enabled and configured.">
    Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
  </Accordion>

  <Accordion title="System architecture/interconnection diagrams showing data flows, and physical and logical segmentation shall be reviewed and updated at least quarterly.">
    We review architecture diagrams and data flow diagrams on a periodical basis. This is also validated during our internal and external independent audits.
  </Accordion>

  <Accordion title="Segregation, physically and/or logically, shall be implemented ensuring that the required levels of control for data flows and users are met.">
    We logically segregate the tenant's data, and it is segregated with a client-specific key for proper handling and security reasons.
  </Accordion>

  <Accordion title="Unsecured protocols or protocols with known vulnerabilities shall not be used.">
    We do not use any unsecured protocols.
  </Accordion>

  <Accordion title="All critical applications shall be reviewed and tested after operating system changes or other major changes.">
    All critical applications are reviewed and tested before deployment.
  </Accordion>

  <Accordion title="Development, test and production environments shall be segregated.">
    We have a separate test and production environment.
  </Accordion>

  <Accordion title="Performance and capacity monitoring, such as system and network utilisation, shall be practiced.">
    We monitor systems and network utilization.
  </Accordion>

  <Accordion title="Network IDS may be provided where necessary.">
    We have implemented file integrity (host) and network intrusion detection (IDS) tools to help facilitate timely detection and investigation.
  </Accordion>

  <Accordion title="Performance improvement plans shall be outlined based on successive progression of security controls maturity and based on identified nonconformities.">
    We make sure that we follow industry best practices, the PDCA cycle, and standards in order to safeguard the Information Security System.
  </Accordion>

  <Accordion title="Service Provider shall have strict patching practice to ensure security patches are applied rapidly.">
    All critical patches are applied rapidly.
  </Accordion>

  <Accordion title="Service Provider should have capabilities to integrate security systems with the customer's Security monitoring solution (SIEM).">
    We are a multi-tenant SaaS system and all our logs will contain data of all customers. We will have our own log monitoring and security analysis.
  </Accordion>

  <Accordion title="CLOUD SERVICE PROVIDER (CSP) must ensure CLIENT that its infrastructure is always using up-to-date systems.">
    Yes. All critical patches will be deployed immediately. We ensure that our infrastructure is always using up-to-date systems.
  </Accordion>

  <Accordion title="In multi-tenancy cloud environment, CLOUD SERVICE PROVIDER must ensure the CLIENT environment is segregated from other tenants' environment.">
    We have the ability to logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant's data.
  </Accordion>

  <Accordion title="The solution is to be deployed and operationalized in a configuration where application and data storage components will reside and operate on separate physical or virtual servers.">
    Compliant. We have deployed our application and database on separate servers.
  </Accordion>

  <Accordion title="Configure REST/Web services to explicitly validate content types.">
    Since the application is a SaaS Platform, this would not be applicable.
  </Accordion>

  <Accordion title="Applications must be designed in such a way that it captures evidence of any action taken by the user to protect itself from denying authenticity of the activity.">
    Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. Administrative logs are part of the Cloud Dashboard and are regularly reviewed.
  </Accordion>

  <Accordion title="The hosted application's architecture must be configured in such a way that data stores containing confidential or regulated information are logically located in a secure network segment.">
    Yes. We logically segregate the tenant's data and the application.
  </Accordion>

  <Accordion title="The hosted web application's architecture is to be deployed and configured with a web application firewall to protect the application.">
    WAF and rate limiters are installed to block multiple requests from specific IPs to prevent DDoS-type attacks.
  </Accordion>

  <Accordion title="All application created sessions, windows, forms, pages, and pop-ups that display highly confidential information must be terminated or closed after the user logs out.">
    Once the user logs out from the application, all pages, forms, and pop-ups will get closed.
  </Accordion>

  <Accordion title="Implement controls to log TLS connection failures.">
    We maintain logs and monitor on a regular basis for security reasons.
  </Accordion>

  <Accordion title="Implement processes to measure the availability, quality, and adequate capacity of resources to deliver the required system performance.">
    Compliant. We have resources to meet these requirements.
  </Accordion>
</AccordionGroup>
