Skip to main content
We have deployed our application on AWS Virtual platform cloud - Singapore and USA region.
Data Security Architecture designed using an industry standard and best practices. We are adhered to CSA, ISO 27001, SOC 2 TSP. We have deployed our application on AWS Virtual platform cloud - Singapore region. The cloud infrastructure providers have high levels of physical and network security and hosting provider vendor diversity.
All our customer data is stored on AWS Virtual platform cloud. And we collect the data only throguh our application platform. We do not store any customers data locally.
File integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation.
AWS CloudTrail helps to detect changes to the build/configuration of the virtual machine
Our solution is using state of the art Cloud Native infrastructure technologies along with microservices architecture allows us to scale our operations as per the demands.
We use Web application firewall (WAF) and pfSense firewall for security reasons. 1. The Cloudflare Web Application Firewall (Cloudflare WAF) checks incoming web requests and filters undesired traffic based on the set of rules. 2. pfSense helps to monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on a defined set of security rules
We isolate our machines, network and storage with respect to the AWS Standards in order to keep it safe and secure.
We use Web application firewall (WAF) and pfSense firewall for security reasons.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently.
Yes. We monitor the compliance programs of AWS As we have stored the data on their cloud.
No. Currently, all the data is stored on AWS VPC - Singapore region.
Yes, we inform the customer on the data storage location.
We are CSA STAR Level 1 compliant. Please click here to know more - https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday
We use OWASP Software Assurance Maturity Model
Since we have deployed our application on AWS Cloud its not applicable for us.
Since we have deployed our application on AWS Cloud its not applicable for us. We provide certifite of destruction of data once the data is purged/deleted from all the places upon request from the customer.
We have deployed our product on AWS Cloud virtual platform. AWS provides physical security to the data center as a part of our subscription. AWS physical security - https://aws.amazon.com/compliance/data-center/controls/
We have implemented IDS/IPS to facilitate timely detection, investigation by root cause analysis and response to incidents
Data backups are done on daily basis and in a secured way on AWS
Data backups are done on daily basis and in a secured way on AWS - Singapore
Data backups are done on daily basis and in a secured way on AWS. This has been tested on regular basis.
Applies to all.
We have deployed our application on AWS cloud virtual platform and the data is stored on it. Only approved users will have an access and We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it’s linked with the SSO/Active Directory.
We have deployed our application on AWS cloud virtual platform. AWS provides physical security to the data center and it’s a part of our subscription. AWS physical security - https://aws.amazon.com/compliance/data-center/controls/
Yes. Its deployed on AWS cloud virtual platform.
The application is deployed on AWS cloud virtual platform. We maintain the register for hardwares, softwares, physical assets etc as per the Asset management policy. All the inventories are reviewed and updated on monthly basis. We have tagged the owners for all the assets alloted by the organization. Atatched the asset management policy.
Our application is deployed on AWS cloud virtual platform. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it’s linked with the SSO/Active Directory.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
We use AWS Platform for storing the data. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records.
Yes
We have deployed our application on AWS Cloud platform.As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks.
Yes. We comply with this.
We monitor the user activities and spread awareness about data storage, access, sharing etc. All the custoer data is stored on AWS cloud. We are not storing any information on the computers.
Data backups are done daily and in a secured way in AWS
Yes. We have implemented the Backup Recovery Procedure
Yes. Data backups are done daily and in a secured way in AWS
We do not use the backup. We only take the backup on AWS and its stored on AWS platform itself.
Its hosted on AWS
BCP and DR facilities has been provided by AWS. We do not have any other data centers
Since we are hosting our application on AWS, they are providing us a service for backup, BCP and DR for seamless customer experience.
Since we are hosting our application on AWS, they are providing us a service for backup, BCP and DR for seamless customer experience.
Amazon web service (AWS)
AWS Virtual platform cloud And AWS MSK
We have deployed the application on AWS and we have the controls in place to destruction upon request or post the retention timeframe. Since we are GDPR compliant we provide this option to our end users.
We have deployed the application on AWS Singpore.
Data backup and retrieval happens on AWS platform.
We use Public cloud for hosting
we have an intrusion detection/monitoring application that alerts on unauthorized access.
We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails.
We have deployed the application on cloud and have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour.
Its provided by AWS, it’s a part of AWS service.
Data backups are done daily and in a secured way in AWS. The customer data cannot be lost permanently. We also have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working.
Data backups are done daily and in a secured way in AWS. The customer data cannot be lost permanently. We also have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working.
We collect, store and process Name, email ID and Phone numbers and it will be stored on AWS cloud and will be deleted upon termination of the contract.
AWS Singapore
We have deployed our application on AWS virtual platform cloud and do not store any data outside cloud for security reasons. All the customer data is encrypted for maximum security. We use TLS1.3 encryption while data in transit and AES256 while data at rest
Yes. We have the backup for power supply and computer systems can be used without any interruption. We have applied the lightning protection metallic rods for the buidling for protection of premises.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long term cloud storage. All the workstations are part of the Active directory. User accounts get locked after 15 minutes of inactivity. The accounts will get locked after the predetermined unauthorised attempts for security reasons.
Yes, our web assets, email records, and end-points are sealed with data loss prevention techniques. All the customer data will be stored on only AWS virtual platform cloud. We do not store it offline for security reasons. AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. The data is stored in our secure database and is transit scrambled for maximum security. We use TLS1.3 encryption while data in transit and AES256 while data at rest
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long term cloud storage. logs are automatically audited, but are not integrated with tenant’s security operations. In case the tenant requests for logs, they can share when asked by the clients.
Attached the Infrastructure Change Control Procedure
We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
The logs are automatically audited, but are not integrated with tenant’s security ops. In case the tenant requests for logs, they can shared when asked for by the clients.
The logs are automatically audited, but are not integrated with tenant’s security ops. In case the tenant requests for logs, they can shared when asked for by the clients.
The logs are automatically audited, but are not integrated with tenant’s security ops. In case the tenant requests for logs, they can shared when asked for by the clients.
We retain the logs for at least 180 days.
AWS is one of the critical third party for us as we have deployed our application on AWS VPC. AWS is ISO 27001 and SOC 2 certified organization and compliant with the business continnuity requirements.
Xoxoday application application has deployed on AWS Cloud virtual platform for securtity reasons and imlemented the business continuity plan. Xoxoday endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week. Business day will be considered as 24*7 and will be available for 365 days in a year for the customer support services to be provided to the Client
The data will be stored on AWS Virtual platform cloud – Singapore region.
The personal data will be uploaded on application application for rewards and recognition purposes and will be stored on AWS virtual platform cloud.
We have deployed our application on AWS Virtual platform cloud. We do not have physical access to the location where the personal data is stored.
We have deployed our application on AWS Virtual platform cloud. We have the physical access controls in place. For ex – Access cards, Biometric machines, ID cards, CCTV etc..
The personal information will be collected through application platform and stored on AWS virtual platform cloud – Singapore region.
We have only one data center and deployed our application of AWS virtual platform cloud. By Default, Xoxoday will not have access to Service Data (customer’s account/application and the associated data processed as part of using our services). The access control to the accounts (who can access the application instance) is managed by the admin from the customer end.
We use Public cloud for hosting (AWS Singapore)
AWS Virtual Platform Cloud - Singapore region.
Yes. We have deployed our product on AWS virtual platform cloud.
The data backups are done on AWS Virtual platform cloud on regular basis and implemeted the Data loss prevention techniques. We have all the capabilities to recover the data or restore. Data is available for restore within a few minutes of a backup job completing on the daily schedule. Attached the Backup Recovery Procedure
AWS is responsible for providing physical security to the data center as we have deployed our application on AWS. AWS provides physical data center access only to approved employees. All employees who need data center access must first apply for access and provide a valid business justification. These requests are granted based on the principle of least privilege, where requests must specify to which layer of the data center the individual needs access, and are time-bound. Requests are reviewed and approved by authorized personnel, and access is revoked after the requested time expires. Once granted admittance, individuals are restricted to areas specified in their permissions. Third-party access is requested by approved AWS employees, who must apply for third-party access and provide a valid business justification. These requests are granted based on the principle of least privilege, where requests must specify to which layer of the data center the individual needs access, and are time-bound. These requests are approved by authorized personnel, and access is revoked after request time expires. Once granted admittance, individuals are restricted to areas specified in their permissions. Anyone granted visitor badge access must present identification when arriving on site and are signed in and escorted by authorized staff.
We have deployed our application on AWS Virtual platform cloud. Our solution is using state of the art Cloud Native infrastructure technologies along with microservices architecture allows us to scale our operations as per the demands.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. We make these logs available upon tenents request.
We make these logs available upon tenents request
The logs are collected using the AWS Audit Trail and application related logs are collected in our Elastic Search server.
AWS Cloud virtual platform.
Its on AWS cloud virtual platform.
We have deployed our product on AWS Cloud virtual platform.
We do not connect to the customer network. Since it’s a SaaS prodcut and deployed on cloud virtual platform only authorised individual have an access to the our production environment on need and approval basis.
We have implemented the security measures to manage the risks introduced during the use of Organization’s information assets used for managing Personally Identifiable Information. Attached the Personally Identifiable Information (PII) Policy.
We have deployed our application on AWS cloud virtual platform. AWS provides physical security to the data center and it’s a part of our subscription. AWS physical security - https://aws.amazon.com/compliance/data-center/controls/
We have deployed our application on AWS cloud virtual platform. AWS provides physical security to the data center and it’s a part of our subscription. AWS physical security - https://aws.amazon.com/compliance/data-center/controls/
We have deployed our application on AWS Virtual platform cloud. We use Web application firewall, IDs/IDs, AWS Audit trail, Amazon guard duty etc..
Yes. Data backups are done on daily basis in a secured way in AWS
Yes.
Yes.
Its on AWS Cloud virtual platform Cloud.
Yes
The data will be stored on AWS cloud virtual platform Singapore. Since we are a multi tenant system, we have common infrastructure for all clients.But All data volume is encrypted with AES 256-bit encryption to prevent any external snooping or unauthorized access in the multi-tenant environment.
We do not use any in-house devoloped applications. We have deployed our application on AWS cloud virtual platform. And AWS is SOC 2, ISO 27001, ISO 27017 and ISO 27701 certified organization. Shared the certificates.
We do not use any in-house devoloped applications. We have deployed our application on AWS cloud virtual platform. And AWS is SOC 2, ISO 27001, ISO 27017 and ISO 27701 certified organization. Shared the certificates.
We have deployed our application on AWS cloud virtual platform.
We have deployed our application on AWS cloud virtual platform.
Data storage location will be AWS Singapore.
Data backups are done on daily and in a secured way in AWS. Attached the Backup Recovery Procedure.
We have deployed our application on AWS Virtual platform cloud - Singapore and we operate from our corporate office located in Bangalore, India.
We have deployed our application on AWS Virtual platform cloud - Singapore region and all the data will be stored there. All the end users from various parts in the world can access the platform. We inform the customer if we need to change the data center location.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. The Cloudflare Web Application Firewall (Cloudflare WAF) checks incoming web requests and filters undesired traffic based on the set of rules. pfSense generation firewall helps to monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on a defined set of security rules We also have implemented the IDS/IPS and Amazon guard duty which continuously monitors our AWS accounts and workloads for malicious activity and delivers detailed security findings for visibility and remediation.
We have implemented the data backup policy and attached the same. The data backups are done daily in a secured way in AWS and tested on weekly basis.These backup process are automated and does not require any mannual effort. Since we are SAAS product, we maintain backup and restore all the customer data by ourselves. We use AES 256 encryption for data at rest. All the backups are stored on Cloud and does not store any data off-cloud.
NA. We have deployed our application on AWS Virtual platform cloud.
We have deployed our application on AWS Virtual Platform cloud. application is a cloud based application. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently.
We have tools that analyze various traffic patterns and correlate network events. We have configured early warning signals that trigger alerts to our team based on event patterns and strict thresholds. We are equipped to detect and mitigate Threats, DDOS attacks, session hijack, login spoofs or any other data extraction strategies AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. The data is stored in our secure database and is transit scrambled for maximum security. We use TLS1.3 encryption while data in transit and AES256 while data at rest. We also conduct periodical Vulnerability assessment and penetration testing and fixes the vulnerabilities identified in order to eliminate the risk.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. We use a synchronized time-service protocol (e.g., NTP) to ensure all systems have a common time reference
Yes, systems must be configured to log all successful and unsuccessful login attempts by accounts with privileged access. These authentication logs must be retained for a minimum of 180 days and in accordance with the Company’s records retention guidelines.
We use logical data isolation with the help of company specific encryption keys and its solated from other customers data. Yes, audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
The data backups are done daily in a secured way on AWS and tested on a weekly basis. These backup processes are automated and do not require any manual effort. Since the data backup is automated and happening on a daily basis the data backup will get replaced every day and restored, if necessary/required.
Yes, AWS is certified under the EU-US Privacy Shield. https://www.privacyshield.gov/participant?id=a2zt0000000TOWQAA4
All user activities are logged in the audit trail.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks
We use Web application firewall, IDs/Ips, AWS Audit trail, Amazon guard duty etc..
We have a dedicated non-production environment which is in a different AWS account and allows us to segregate data from the production environment.
We have implemented the Backup Recovery Procedure to protect the organization information asset from the damages that may be caused due to failure of hardware system, corruption of software etc..
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long term cloud storage. The event logs are stored in a bucket wherein nobody can access them without an approval from the high authorities i.e. the Chief Technical Officer. In case the tenant requests for logs, that can be shared.
At present, application application has been deployed on AWS Virtual platform cloud.
All the data will be stored on AWS Singapore
All the data will be collected only through our application and stored on AWS cloud platform and its situated in Singapore.
All the data will be stored on AWS Singapore
We are cloud security alliance level 1 compliant. We would be happy to help NSE for checking the integrity and security of the cloud computing services and compliance to applicable policies and regulations.
We agreee. We comply with CSA STAR Level 1 compliance requirements.
We comply with this. We have deployed our application on AWS to ensure maximum security of data.
We agree. We combine enterprise-class security features with comprehensive audits of our applications, systems, and networks to ensure customer and business data is always protected. And our customers rest easy knowing their information is safe, their interactions are secure, and their businesses are protected. We do conduct internal and external audits and ensure that required remidiations are implemented.
The data is hosted on Amazon Web Services (AWS) For accurate latency, the data center is selected as Singapore region for Asia specific data and Oregon for US specific data which are defined as data centers.
The Xoxoday platform operates on the cloud, which means there are no removable storage devices in question. We have Media protection procedure to handle the locally stored data. We complied with the compliance requirements.
We do not take any data directly. The data will be provided through our platform or application and its hosted on Amazon Web Services (AWS)
We rely on AWS Cloud for Uptime mesurement.
Yes. We have deployed our application on AWS cloud platform
Yes. Please visit here for more details about AWS Cloud Security - https://aws.amazon.com/security/
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently.
We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails We have implemented IDS/IPS Firewall. Our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting.
We predominantly work on cloud-based infrastructure from Amazon Web Services which provide backup and restore services to build scalable, durable, and secure data-protection solutions Please refer to AWS site for more details: https://aws.amazon.com/backup-restore/
It will be stored on AWS, and It will be encrypted (AES 256-bit encryption)
Yes. We have implemented IDS/IPS Firewall. Our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting.
The only user data that will stored within the system is employee personal information - names, emails and contact numbers. Infrastructure logs are collected using AWS Audit Trail
Our application is deployed on AWS cloud platform.
We are Compliant. We have implemented the data backup policy. We do take backup of the all the users and securely stored. All our application users data back up including password will happen through AWS cloud virtual platform.
We have controls in place. We have implemented the firewall and IDS/IPS for detection and prevention of security.
During the testing phase we make sure that we are meeting all the security requesrements and validate the same before the deployment.
All the data will be stored on AWS cloud and encrypted with Client specific keys. We do not transfer data to any external drives or media devices.
We monitor these logs periodically
Backup data is stored on AWS cloud for maximum security.
We test the backup on a periodical basis to make sure that we follow the availability and integrity principles.
We have documented our Data backup procedures.
We are compliant.
All the logs are recorded in the system.
We always make sure that componentory controls in place if monitoring is not feasible.
We have deployed our application on AWS cluod virtual platform
It’s a part of cloud security services
It’s a part of cloud security services
Data backups are done daily and in a secured way in AWS. The customer data cannot be lost permanently. We also have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working.
The data is only stored on our application and its deployed on AWS Cloud. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records
We have deployed our application on Amaon web services (AWS) cloud platform. We are using MySQL, Salt stack, Nodejs and MongoDB technology. LDAP, SAML2, Normal username-password
We are a SAAS solution. We are cloud hosted.
We are a SAAS Solution and have all the capabilities to supoprt huge number of users.
Data center services are provided by AWS
Data backups are done daily and in a secured way in AWS
No. Application is deployed on AWS Cloud.
We have both horizontal and Vertical Scaling
We have auto scaling and self healing.
We use a variety of tools and plugins integrated with Prometheus & Cloudwatch along with health checks for facilitating our uptime/service availability
AWS Cloud virtual platform
We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails
Yes. We have deployed our application on AWS virtual platform cloud. And we have the process in place to handle or manage any contingent events or circumstances. We have implemented the Business continuity management and tested annually to validate the effectiveness of the controls. Attached the Business continuity management plan.
We have an Admin/Facility department who is responsible and manage the Physical security and we have provided the access cards to all the employees and visitors and installed biometric machines at all the entry and exit areas. We have also installed the CCTV cameras in our building and will be monitored 24*7 for maximum security. AWS Data centre physical security – We have deployed our application product on AWS virtual platform cloud. Physical access is strictly controlled both at the perimeter and at building ingress points by professional security staff utilizing video surveillance, intrusion detection systems, and other electronic means. Authorized staff must pass two-factor authentication a minimum of two times to access data center floors. All visitors and contractors are required to present identification and are signed in and continually escorted by authorized staff. AWS only provides data center access and information to employees and contractors who have a legitimate business need for such privileges. When an employee no longer has a business need for these privileges, access is immediately revoked, even if they continue to be an employee of Amazon or Amazon Web Services. All physical access to data centers by AWS employees is logged and audited routinely.
PII will be entered through application and stored it on AWS cloud virtual platform. We store Name, email ID and phone number of the users.
Reports can be generated by the admins through the application. If there are any additional support needed, our customer support team would be able to help and guide on generating report.
The data will be stored on AWS Cloud and we do not share or transfer the data
We have deployed our application on AWS Virtual platform cloud – Singapore region.
Not Applicable. We have not outsourced.
We have deployed our application on AWS Cloud virtual platform for maximum security. The data center is hosted completely in isolation so that the access is limited and controlled. Load balancer allows shifting incremental load and can auto scale based on data load experienced by application. We have implemented Amazon Cloud watch to enable monitoring of the functioning of the application. The data is encrypted using 256-encryption based SSL certificate. To manage security of data we conduct a quarterly VAPT based security audit of application.
Yes, all the mechanisms related to security are implemented to facilitate timely decision and investigation by root-cause analysis. These incidences are analyzed with network intrusion detection (IDS) tools.
We have implemented the Patch management procedures. Critical patches will be deployed immediately High patches will get deployed within 5 days Medium Patches will get deployed within 15-day Low will get deployed in 25 days.
Yes. Since it’s a SAAS Product we do not charge any additional cost.
We have a team of 15+ who works for improving our solution security. We conduct periodical Vulnerability assessment and Penetration testing with the help of the Authorized third-party vendors and Fix the observations found during the testing in order to mitigate the risk. Our team is based out of Bangalore location.
Yes. Our SAAS solution has been deployed on AWS cloud virtual platform.
Its SAAS Product and implemented the security controls in order to provide secure services and make sure that the customer data is protected.
We have deployed our application on AWS Cloud platform for maximum security. The data will be provided through our platform or application and its hosted-on Amazon Web Services (AWS) Our solution is very easy to use with convenient security features.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed.
We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team, and it’s linked with the SSO/Active Directory
We have deployed our application on AWS Cloud virtual platform. AWS is met all the data center compliance requirements.
We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it’s linked with the SSO/Active Directory We have implemented intrusion detection tools, we ensure timely detection and investigation in a prompt manner. File integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation. We also have Endpoint security software for all the computers for Protection from exploits, malicious web downloads and softwares, Application and device control etc.
We have deployed the application application on AWS Cloud platform.
The data center is in the Singapore region
We have deployed our application on AWS cloud virtual platform. but, We have not outsourced any of services and third party will not have access to FINCARE data.
Yes. We monitor their compliance, security standards, certifications and Audit Etc.
All the data will be provided through the application and it will be stored on AWS cloud virtual platform. We use Cloudflare web application firewall for maximum security. We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. Attached the application data flow diagram
We have the security controls in place. We have installed the firewalls to monitor and control the incoming and outgoing network traffic based on predetermined security rules. It helps us to establishes a barrier between a trusted network and an untrusted network. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it’s linked with the SSO/Active Directory. Attached the Network Access Control and Security Procedure.
Yes. we have installed Bitdefender end point security in all the devices for maximum security and have controls on Anti-Virus / Malicious Software throgh End point security. We have also enabled Network Threat Prevention, Advanced Threat Defense, Web Attack Prevention, Multi-Layer Ransomware Protection. Attached the sample screenshot of Bitdefender end point security.
The application is deployed on AWS Virtual platform cloud - Singapore region.
application application is deployed on AWS virtual platform cloud and storgae and scaling up would not be a challenge.
Data backups are automated and done daily and in a secured way on AWS. The data at rest in encrypted only authorised individuals (CT0/Production head) will have access to protect the confidentiality, integrity, and availability of the information. These data backups are reviewed on weekly basis and has been validated during the internal and external audits.
We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed.
Yes, audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed.
At Xoxoday the test environment and production environment has been seperated. We have dedicated non-production environment which is in different AWS account and allowing us to segregate data of production environment.
we use Cloudflare Web application firewall (WAF), AWS Guard Duty threat detection service, Amazon CloudWatch, IDS/IPS etc.. for maximum security of data.
Compliant. We do not allow un-trusted and un-validated inputs and attacker cannot insert malicious data and false entries into the logs.
We do not share the source code. Our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase.
At Xoxday the source code is restricted to only the authorised individuals
Yes. Our solution is using state of the art Cloud Native infrastructure technologies along with microservices architecture allows us to scale our operations as per the demands.
We have deployed our application on AWS Cloud virtual platform and all the data is stored on AWS. All the confidential/PI data are encrypted at rest and in transit with a split key mechanism to ensure that every client’s key is unique. We use TLS1.3 encryption while data in transit and AES256 while data at rest.
we use Amazon Web Services (AWS) as our Communication service provider. We review the adequate security governance periodicall to make sure that they are also complied with all the Security and Privacy compliance requirements.
We are the Data processor. application is GDPR compliant. At Xoxoday, we ensure that the data is gathered, stored, and handled with respect to individual rights.
The audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
At Xoxoday Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
The backup is automated and happen on AWS on regular basis.
We have deployed our application on AWS Virtual platform cloud - Singapore region.
The application and database server are hardened.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
We use third party to provide necessary services to the organization on need and approval basis. For ex – Background verification vendor, VA/PT authorised third party vendor, Eternal Auditors, AWS Virtual platform cloud service providers, Google workspace etc
We predominantly work on cloud-based infrastructure - Amazon Web Services which provides the Backup and Restore services to build scalable, durable, and secure data-protection solutions. No limits.
Data backups are done daily and in a secured way in AWS. And Our team review the same on regular basis.
Data backups are done on daily basis and in a secured way in AWS. We have the mechanism in place to delete the data upon termination of the contract upon customer request. In addition to safeguarding the rights of data subjects under the GDPR, we have implemented the Data Retention and Disposal Policy ensuring that excessive amounts of data are not retained by us.
We have deployed our application on AWS Virtual platform cloud and they provide these services.
We have deployed our application on AWS Virtual platform cloud - Singapore and USA region.
Data Security Architecture designed using an industry standard and best practices. We are adhered to CSA, ISO 27001, SOC 2 TSP. We have deployed our application on AWS Virtual platform cloud - Singapore region. The cloud infrastructure providers have high levels of physical and network security and hosting provider vendor diversity.
All our customer data is stored on AWS Virtual platform cloud. And we collect the data only throguh our application platform. We do not store any customers data locally.
File integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation.
AWS CloudTrail helps to detect changes to the build/configuration of the virtual machine
Our solution is using state of the art Cloud Native infrastructure technologies along with microservices architecture allows us to scale our operations as per the demands.
We use Web application firewall (WAF) and pfSense firewall for security reasons. 1. The Cloudflare Web Application Firewall (Cloudflare WAF) checks incoming web requests and filters undesired traffic based on the set of rules. 2. pfSense helps to monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on a defined set of security rules
We isolate our machines, network and storage with respect to the AWS Standards in order to keep it safe and secure.
We use Web application firewall (WAF) and pfSense firewall for security reasons.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently.
Yes. We monitor the compliance programs of AWS As we have stored the data on their cloud.
No. Currently, all the data is stored on AWS VPC - Singapore region.
Yes, we inform the customer on the data storage location.
We are CSA STAR Level 1 compliant. Please click here to know more - https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday
We use OWASP Software Assurance Maturity Model
Since we have deployed our application on AWS Cloud its not applicable for us.
Since we have deployed our application on AWS Cloud its not applicable for us. We provide certifite of destruction of data once the data is purged/deleted from all the places upon request from the customer.
We have deployed our product on AWS Cloud virtual platform. AWS provides physical security to the data center as a part of our subscription. AWS physical security - https://aws.amazon.com/compliance/data-center/controls/
We have implemented IDS/IPS to facilitate timely detection, investigation by root cause analysis and response to incidents
Data backups are done on daily basis and in a secured way on AWS
Data backups are done on daily basis and in a secured way on AWS - Singapore
Data backups are done on daily basis and in a secured way on AWS. This has been tested on regular basis.
Applies to all.
We have deployed our application on AWS cloud virtual platform and the data is stored on it. Only approved users will have an access and We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it’s linked with the SSO/Active Directory.
We have deployed our application on AWS cloud virtual platform. AWS provides physical security to the data center and it’s a part of our subscription. AWS physical security - https://aws.amazon.com/compliance/data-center/controls/
Yes. Its deployed on AWS cloud virtual platform.
The application is deployed on AWS cloud virtual platform. We maintain the register for hardwares, softwares, physical assets etc as per the Asset management policy. All the inventories are reviewed and updated on monthly basis. We have tagged the owners for all the assets alloted by the organization. Atatched the asset management policy.
Our application is deployed on AWS cloud virtual platform. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it’s linked with the SSO/Active Directory.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
We use AWS Platform for storing the data. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records.
Yes
We have deployed our application on AWS Cloud platform.As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks.
Yes. We comply with this.
We monitor the user activities and spread awareness about data storage, access, sharing etc. All the custoer data is stored on AWS cloud. We are not storing any information on the computers.
Data backups are done daily and in a secured way in AWS
Yes. We have implemented the Backup Recovery Procedure
Yes. Data backups are done daily and in a secured way in AWS
We do not use the backup. We only take the backup on AWS and its stored on AWS platform itself.
Its hosted on AWS
BCP and DR facilities has been provided by AWS. We do not have any other data centers
Since we are hosting our application on AWS, they are providing us a service for backup, BCP and DR for seamless customer experience.
Since we are hosting our application on AWS, they are providing us a service for backup, BCP and DR for seamless customer experience.
Amazon web service (AWS)
AWS Virtual platform cloud And AWS MSK
We have deployed the application on AWS and we have the controls in place to destruction upon request or post the retention timeframe. Since we are GDPR compliant we provide this option to our end users.
We have deployed the application on AWS Singpore.
Data backup and retrieval happens on AWS platform.
We use Public cloud for hosting
we have an intrusion detection/monitoring application that alerts on unauthorized access.
We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails.
We have deployed the application on cloud and have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour.
Its provided by AWS, it’s a part of AWS service.
Data backups are done daily and in a secured way in AWS. The customer data cannot be lost permanently. We also have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working.
Data backups are done daily and in a secured way in AWS. The customer data cannot be lost permanently. We also have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working.
We collect, store and process Name, email ID and Phone numbers and it will be stored on AWS cloud and will be deleted upon termination of the contract.
AWS Singapore
We have deployed our application on AWS virtual platform cloud and do not store any data outside cloud for security reasons. All the customer data is encrypted for maximum security. We use TLS1.3 encryption while data in transit and AES256 while data at rest
Yes. We have the backup for power supply and computer systems can be used without any interruption. We have applied the lightning protection metallic rods for the buidling for protection of premises.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long term cloud storage. All the workstations are part of the Active directory. User accounts get locked after 15 minutes of inactivity. The accounts will get locked after the predetermined unauthorised attempts for security reasons.
Yes, our web assets, email records, and end-points are sealed with data loss prevention techniques. All the customer data will be stored on only AWS virtual platform cloud. We do not store it offline for security reasons. AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. The data is stored in our secure database and is transit scrambled for maximum security. We use TLS1.3 encryption while data in transit and AES256 while data at rest
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long term cloud storage. logs are automatically audited, but are not integrated with tenant’s security operations. In case the tenant requests for logs, they can share when asked by the clients.
Attached the Infrastructure Change Control Procedure
We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
The logs are automatically audited, but are not integrated with tenant’s security ops. In case the tenant requests for logs, they can shared when asked for by the clients.
The logs are automatically audited, but are not integrated with tenant’s security ops. In case the tenant requests for logs, they can shared when asked for by the clients.
The logs are automatically audited, but are not integrated with tenant’s security ops. In case the tenant requests for logs, they can shared when asked for by the clients.
We retain the logs for at least 180 days.
AWS is one of the critical third party for us as we have deployed our application on AWS VPC. AWS is ISO 27001 and SOC 2 certified organization and compliant with the business continnuity requirements.
Xoxoday application application has deployed on AWS Cloud virtual platform for securtity reasons and imlemented the business continuity plan. Xoxoday endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week. Business day will be considered as 24*7 and will be available for 365 days in a year for the customer support services to be provided to the Client
The data will be stored on AWS Virtual platform cloud – Singapore region.
The personal data will be uploaded on application application for rewards and recognition purposes and will be stored on AWS virtual platform cloud.
We have deployed our application on AWS Virtual platform cloud. We do not have physical access to the location where the personal data is stored.
We have deployed our application on AWS Virtual platform cloud. We have the physical access controls in place. For ex – Access cards, Biometric machines, ID cards, CCTV etc..
The personal information will be collected through application platform and stored on AWS virtual platform cloud – Singapore region.
We have only one data center and deployed our application of AWS virtual platform cloud. By Default, Xoxoday will not have access to Service Data (customer’s account/application and the associated data processed as part of using our services). The access control to the accounts (who can access the application instance) is managed by the admin from the customer end.
We use Public cloud for hosting (AWS Singapore)
AWS Virtual Platform Cloud - Singapore region.
Yes. We have deployed our product on AWS virtual platform cloud.
The data backups are done on AWS Virtual platform cloud on regular basis and implemeted the Data loss prevention techniques. We have all the capabilities to recover the data or restore. Data is available for restore within a few minutes of a backup job completing on the daily schedule. Attached the Backup Recovery Procedure
AWS is responsible for providing physical security to the data center as we have deployed our application on AWS. AWS provides physical data center access only to approved employees. All employees who need data center access must first apply for access and provide a valid business justification. These requests are granted based on the principle of least privilege, where requests must specify to which layer of the data center the individual needs access, and are time-bound. Requests are reviewed and approved by authorized personnel, and access is revoked after the requested time expires. Once granted admittance, individuals are restricted to areas specified in their permissions. Third-party access is requested by approved AWS employees, who must apply for third-party access and provide a valid business justification. These requests are granted based on the principle of least privilege, where requests must specify to which layer of the data center the individual needs access, and are time-bound. These requests are approved by authorized personnel, and access is revoked after request time expires. Once granted admittance, individuals are restricted to areas specified in their permissions. Anyone granted visitor badge access must present identification when arriving on site and are signed in and escorted by authorized staff.
We have deployed our application on AWS Virtual platform cloud. Our solution is using state of the art Cloud Native infrastructure technologies along with microservices architecture allows us to scale our operations as per the demands.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. We make these logs available upon tenents request.
We make these logs available upon tenents request
The logs are collected using the AWS Audit Trail and application related logs are collected in our Elastic Search server.
AWS Cloud virtual platform.
Its on AWS cloud virtual platform.
We have deployed our product on AWS Cloud virtual platform.
We do not connect to the customer network. Since it’s a SaaS prodcut and deployed on cloud virtual platform only authorised individual have an access to the our production environment on need and approval basis.
We have implemented the security measures to manage the risks introduced during the use of Organization’s information assets used for managing Personally Identifiable Information. Attached the Personally Identifiable Information (PII) Policy.
We have deployed our application on AWS cloud virtual platform. AWS provides physical security to the data center and it’s a part of our subscription. AWS physical security - https://aws.amazon.com/compliance/data-center/controls/
We have deployed our application on AWS cloud virtual platform. AWS provides physical security to the data center and it’s a part of our subscription. AWS physical security - https://aws.amazon.com/compliance/data-center/controls/
We have deployed our application on AWS Virtual platform cloud. We use Web application firewall, IDs/IDs, AWS Audit trail, Amazon guard duty etc..
Yes. Data backups are done on daily basis in a secured way in AWS
Yes.
Yes.
Its on AWS Cloud virtual platform Cloud.
Yes
The data will be stored on AWS cloud virtual platform Singapore. Since we are a multi tenant system, we have common infrastructure for all clients.But All data volume is encrypted with AES 256-bit encryption to prevent any external snooping or unauthorized access in the multi-tenant environment.
We do not use any in-house devoloped applications. We have deployed our application on AWS cloud virtual platform. And AWS is SOC 2, ISO 27001, ISO 27017 and ISO 27701 certified organization. Shared the certificates.
We do not use any in-house devoloped applications. We have deployed our application on AWS cloud virtual platform. And AWS is SOC 2, ISO 27001, ISO 27017 and ISO 27701 certified organization. Shared the certificates.
We have deployed our application on AWS cloud virtual platform.
We have deployed our application on AWS cloud virtual platform.
Data storage location will be AWS Singapore.
Data backups are done on daily and in a secured way in AWS. Attached the Backup Recovery Procedure.
We have deployed our application on AWS Virtual platform cloud - Singapore and we operate from our corporate office located in Bangalore, India.
We have deployed our application on AWS Virtual platform cloud - Singapore region and all the data will be stored there. All the end users from various parts in the world can access the platform. We inform the customer if we need to change the data center location.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. The Cloudflare Web Application Firewall (Cloudflare WAF) checks incoming web requests and filters undesired traffic based on the set of rules. pfSense generation firewall helps to monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on a defined set of security rules We also have implemented the IDS/IPS and Amazon guard duty which continuously monitors our AWS accounts and workloads for malicious activity and delivers detailed security findings for visibility and remediation.
We have implemented the data backup policy and attached the same. The data backups are done daily in a secured way in AWS and tested on weekly basis.These backup process are automated and does not require any mannual effort. Since we are SAAS product, we maintain backup and restore all the customer data by ourselves. We use AES 256 encryption for data at rest. All the backups are stored on Cloud and does not store any data off-cloud.
NA. We have deployed our application on AWS Virtual platform cloud.
We have deployed our application on AWS Virtual Platform cloud. application is a cloud based application. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently.
We have tools that analyze various traffic patterns and correlate network events. We have configured early warning signals that trigger alerts to our team based on event patterns and strict thresholds. We are equipped to detect and mitigate Threats, DDOS attacks, session hijack, login spoofs or any other data extraction strategies AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. The data is stored in our secure database and is transit scrambled for maximum security. We use TLS1.3 encryption while data in transit and AES256 while data at rest. We also conduct periodical Vulnerability assessment and penetration testing and fixes the vulnerabilities identified in order to eliminate the risk.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. We use a synchronized time-service protocol (e.g., NTP) to ensure all systems have a common time reference
Yes, systems must be configured to log all successful and unsuccessful login attempts by accounts with privileged access. These authentication logs must be retained for a minimum of 180 days and in accordance with the Company’s records retention guidelines.
We use logical data isolation with the help of company specific encryption keys and its solated from other customers data. Yes, audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
The data backups are done daily in a secured way on AWS and tested on a weekly basis. These backup processes are automated and do not require any manual effort. Since the data backup is automated and happening on a daily basis the data backup will get replaced every day and restored, if necessary/required.
Yes, AWS is certified under the EU-US Privacy Shield. https://www.privacyshield.gov/participant?id=a2zt0000000TOWQAA4
All user activities are logged in the audit trail.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks
We use Web application firewall, IDs/Ips, AWS Audit trail, Amazon guard duty etc..
We have a dedicated non-production environment which is in a different AWS account and allows us to segregate data from the production environment.
We have implemented the Backup Recovery Procedure to protect the organization information asset from the damages that may be caused due to failure of hardware system, corruption of software etc..
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long term cloud storage. The event logs are stored in a bucket wherein nobody can access them without an approval from the high authorities i.e. the Chief Technical Officer. In case the tenant requests for logs, that can be shared.
At present, application application has been deployed on AWS Virtual platform cloud.
All the data will be stored on AWS Singapore
All the data will be collected only through our application and stored on AWS cloud platform and its situated in Singapore.
All the data will be stored on AWS Singapore
We are cloud security alliance level 1 compliant. We would be happy to help NSE for checking the integrity and security of the cloud computing services and compliance to applicable policies and regulations.
We agreee. We comply with CSA STAR Level 1 compliance requirements.
We comply with this. We have deployed our application on AWS to ensure maximum security of data.
We agree. We combine enterprise-class security features with comprehensive audits of our applications, systems, and networks to ensure customer and business data is always protected. And our customers rest easy knowing their information is safe, their interactions are secure, and their businesses are protected. We do conduct internal and external audits and ensure that required remidiations are implemented.
The data is hosted on Amazon Web Services (AWS) For accurate latency, the data center is selected as Singapore region for Asia specific data and Oregon for US specific data which are defined as data centers.
The Xoxoday platform operates on the cloud, which means there are no removable storage devices in question. We have Media protection procedure to handle the locally stored data. We complied with the compliance requirements.
We do not take any data directly. The data will be provided through our platform or application and its hosted on Amazon Web Services (AWS)
We rely on AWS Cloud for Uptime mesurement.
Yes. We have deployed our application on AWS cloud platform
Yes. Please visit here for more details about AWS Cloud Security - https://aws.amazon.com/security/
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently.
We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails We have implemented IDS/IPS Firewall. Our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting.
We predominantly work on cloud-based infrastructure from Amazon Web Services which provide backup and restore services to build scalable, durable, and secure data-protection solutions Please refer to AWS site for more details: https://aws.amazon.com/backup-restore/
It will be stored on AWS, and It will be encrypted (AES 256-bit encryption)
Yes. We have implemented IDS/IPS Firewall. Our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting.
The only user data that will stored within the system is employee personal information - names, emails and contact numbers. Infrastructure logs are collected using AWS Audit Trail
Our application is deployed on AWS cloud platform.
We are Compliant. We have implemented the data backup policy. We do take backup of the all the users and securely stored. All our application users data back up including password will happen through AWS cloud virtual platform.
We have controls in place. We have implemented the firewall and IDS/IPS for detection and prevention of security.
During the testing phase we make sure that we are meeting all the security requesrements and validate the same before the deployment.
All the data will be stored on AWS cloud and encrypted with Client specific keys. We do not transfer data to any external drives or media devices.
We monitor these logs periodically
Backup data is stored on AWS cloud for maximum security.
We test the backup on a periodical basis to make sure that we follow the availability and integrity principles.
We have documented our Data backup procedures.
We are compliant.
All the logs are recorded in the system.
We always make sure that componentory controls in place if monitoring is not feasible.
We have deployed our application on AWS cluod virtual platform
It’s a part of cloud security services
It’s a part of cloud security services
Data backups are done daily and in a secured way in AWS. The customer data cannot be lost permanently. We also have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working.
The data is only stored on our application and its deployed on AWS Cloud. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records
We have deployed our application on Amaon web services (AWS) cloud platform. We are using MySQL, Salt stack, Nodejs and MongoDB technology. LDAP, SAML2, Normal username-password
We are a SAAS solution. We are cloud hosted.
We are a SAAS Solution and have all the capabilities to supoprt huge number of users.
Data center services are provided by AWS
Data backups are done daily and in a secured way in AWS
No. Application is deployed on AWS Cloud.
We have both horizontal and Vertical Scaling
We have auto scaling and self healing.
We use a variety of tools and plugins integrated with Prometheus & Cloudwatch along with health checks for facilitating our uptime/service availability
AWS Cloud virtual platform
We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails
Yes. We have deployed our application on AWS virtual platform cloud. And we have the process in place to handle or manage any contingent events or circumstances. We have implemented the Business continuity management and tested annually to validate the effectiveness of the controls. Attached the Business continuity management plan.
We have an Admin/Facility department who is responsible and manage the Physical security and we have provided the access cards to all the employees and visitors and installed biometric machines at all the entry and exit areas. We have also installed the CCTV cameras in our building and will be monitored 24*7 for maximum security. AWS Data centre physical security – We have deployed our application product on AWS virtual platform cloud. Physical access is strictly controlled both at the perimeter and at building ingress points by professional security staff utilizing video surveillance, intrusion detection systems, and other electronic means. Authorized staff must pass two-factor authentication a minimum of two times to access data center floors. All visitors and contractors are required to present identification and are signed in and continually escorted by authorized staff. AWS only provides data center access and information to employees and contractors who have a legitimate business need for such privileges. When an employee no longer has a business need for these privileges, access is immediately revoked, even if they continue to be an employee of Amazon or Amazon Web Services. All physical access to data centers by AWS employees is logged and audited routinely.
PII will be entered through application and stored it on AWS cloud virtual platform. We store Name, email ID and phone number of the users.
Reports can be generated by the admins through the application. If there are any additional support needed, our customer support team would be able to help and guide on generating report.
The data will be stored on AWS Cloud and we do not share or transfer the data
We have deployed our application on AWS Virtual platform cloud – Singapore region.
Not Applicable. We have not outsourced.
We have deployed our application on AWS Cloud virtual platform for maximum security. The data center is hosted completely in isolation so that the access is limited and controlled. Load balancer allows shifting incremental load and can auto scale based on data load experienced by application. We have implemented Amazon Cloud watch to enable monitoring of the functioning of the application. The data is encrypted using 256-encryption based SSL certificate. To manage security of data we conduct a quarterly VAPT based security audit of application.
Yes, all the mechanisms related to security are implemented to facilitate timely decision and investigation by root-cause analysis. These incidences are analyzed with network intrusion detection (IDS) tools.
We have implemented the Patch management procedures. Critical patches will be deployed immediately High patches will get deployed within 5 days Medium Patches will get deployed within 15-day Low will get deployed in 25 days.
Yes. Since it’s a SAAS Product we do not charge any additional cost.
We have a team of 15+ who works for improving our solution security. We conduct periodical Vulnerability assessment and Penetration testing with the help of the Authorized third-party vendors and Fix the observations found during the testing in order to mitigate the risk. Our team is based out of Bangalore location.
Yes. Our SAAS solution has been deployed on AWS cloud virtual platform.
Its SAAS Product and implemented the security controls in order to provide secure services and make sure that the customer data is protected.
We have deployed our application on AWS Cloud platform for maximum security. The data will be provided through our platform or application and its hosted-on Amazon Web Services (AWS) Our solution is very easy to use with convenient security features.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed.
We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team, and it’s linked with the SSO/Active Directory
We have deployed our application on AWS Cloud virtual platform. AWS is met all the data center compliance requirements.
We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it’s linked with the SSO/Active Directory We have implemented intrusion detection tools, we ensure timely detection and investigation in a prompt manner. File integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation. We also have Endpoint security software for all the computers for Protection from exploits, malicious web downloads and softwares, Application and device control etc.
We have deployed the application application on AWS Cloud platform.
The data center is in the Singapore region
We have deployed our application on AWS cloud virtual platform. but, We have not outsourced any of services and third party will not have access to FINCARE data.
Yes. We monitor their compliance, security standards, certifications and Audit Etc.
All the data will be provided through the application and it will be stored on AWS cloud virtual platform. We use Cloudflare web application firewall for maximum security. We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. Attached the application data flow diagram
We have the security controls in place. We have installed the firewalls to monitor and control the incoming and outgoing network traffic based on predetermined security rules. It helps us to establishes a barrier between a trusted network and an untrusted network. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it’s linked with the SSO/Active Directory. Attached the Network Access Control and Security Procedure.
Yes. we have installed Bitdefender end point security in all the devices for maximum security and have controls on Anti-Virus / Malicious Software throgh End point security. We have also enabled Network Threat Prevention, Advanced Threat Defense, Web Attack Prevention, Multi-Layer Ransomware Protection. Attached the sample screenshot of Bitdefender end point security.
The application is deployed on AWS Virtual platform cloud - Singapore region.
application application is deployed on AWS virtual platform cloud and storgae and scaling up would not be a challenge.
Data backups are automated and done daily and in a secured way on AWS. The data at rest in encrypted only authorised individuals (CT0/Production head) will have access to protect the confidentiality, integrity, and availability of the information. These data backups are reviewed on weekly basis and has been validated during the internal and external audits.
We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed.
Yes, audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed.
At Xoxoday the test environment and production environment has been seperated. We have dedicated non-production environment which is in different AWS account and allowing us to segregate data of production environment.
we use Cloudflare Web application firewall (WAF), AWS Guard Duty threat detection service, Amazon CloudWatch, IDS/IPS etc.. for maximum security of data.
Compliant. We do not allow un-trusted and un-validated inputs and attacker cannot insert malicious data and false entries into the logs.
We do not share the source code. Our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase.
At Xoxday the source code is restricted to only the authorised individuals
Yes. Our solution is using state of the art Cloud Native infrastructure technologies along with microservices architecture allows us to scale our operations as per the demands.
We have deployed our application on AWS Cloud virtual platform and all the data is stored on AWS. All the confidential/PI data are encrypted at rest and in transit with a split key mechanism to ensure that every client’s key is unique. We use TLS1.3 encryption while data in transit and AES256 while data at rest.
we use Amazon Web Services (AWS) as our Communication service provider. We review the adequate security governance periodicall to make sure that they are also complied with all the Security and Privacy compliance requirements.
We are the Data processor. application is GDPR compliant. At Xoxoday, we ensure that the data is gathered, stored, and handled with respect to individual rights.
The audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
At Xoxoday Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
The backup is automated and happen on AWS on regular basis.
We have deployed our application on AWS Virtual platform cloud - Singapore region.
The application and database server are hardened.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
We use third party to provide necessary services to the organization on need and approval basis. For ex – Background verification vendor, VA/PT authorised third party vendor, Eternal Auditors, AWS Virtual platform cloud service providers, Google workspace etc
We predominantly work on cloud-based infrastructure - Amazon Web Services which provides the Backup and Restore services to build scalable, durable, and secure data-protection solutions. No limits.
Data backups are done daily and in a secured way in AWS. And Our team review the same on regular basis.
Data backups are done on daily basis and in a secured way in AWS. We have the mechanism in place to delete the data upon termination of the contract upon customer request. In addition to safeguarding the rights of data subjects under the GDPR, we have implemented the Data Retention and Disposal Policy ensuring that excessive amounts of data are not retained by us.
We have deployed our application on AWS Virtual platform cloud and they provide these services.