Skip to main content
Yes, we use AES 256-bit encryption. All the network communication for network communication is encrypted with the industry standards. Note - Please provide supporting documentation defining encryption standards and technologies.
All data volume is encrypted with AES 256-bit encryption to prevent any external snooping or unauthorized access in the multi-tenant environment.
Yes, the data is segregated with a client-specific key for proper handling and representation.
Yes, there’s a native encryption capability when it comes to sensitive data fields. As each field is equally intricate, there are no limits to such fields.
User IDs and passwords must transmit through stringent checks in an encrypted format that complies with the current Technical Security Baseline Standards.
The passwords are stored after encryption for maximum security of data.
“Yes, our policies and procedures are established as per implemented mechanisms for secure disposal and removal of data from every storage media. By this, it rests assured that the data can’t be recovered by any computer forensic means. We assure secure data disposal when storage is decommissioned or when the contract comes to an end.”
Please refer “Do you support secure deletion of data?” for an explanation. As for the procedure, here’s the protocol that we follow:
  • Storage Period would be as per regulatory conditions.
  • Personal data can be deleted based on a formal written request, with justification.
  • Xoxoday would delete the data within 30 days of receiving the request.
No, users must use certificates from Xoxoday. They are benchmarked as per the best industry standards to ensure complete encryption of data.
No, open encryption has proven to show cracks and bruises and that’s why we only equip data traversing public networks with industrial standards to ensure protection from fraud, unauthorized disclosure, modification, or compromise of data.
Yes, personal data is to be transmitted using firmly approved encrypted systems and in no way is it to be transmitted via email.
Yes, the hardened images are secure from any malicious leak or unauthorized access. These hardened images do not contain any authentication credentials.
Yes, our network communication is encrypted with highly restricted protocols to ensure maximum security.
No, the cryptographic keys, including data encryption and SSL certificates are managed by Xoxoday for optimal security of sensitive data.
We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security
Yes. We have implemented the Information Classification Policy
We use a split key mechanism to ensure that every client’s key is unique. • We perform annual key rotation. • Keys are generated using KMS service whenever needed. • We store keys in KMS.Attached the Encryption policy Name of the folder - EN01 Encryption policy
Every client’s key is unique.
Yes. Our tech team manages this.
We have encrypted the data while in transit and at rest.We use TLS1.2 encryption for Data at transit and AES256 Data at rest.
We store keys in KMS.
Yes. Backup data is also encrypted.
The data in transit will be always be encrypted.
Yes. We use google workspace and all the conversations are TLS encrypted.
Passwords are encrypted all the time.
We use logical data isolation with the help of company specific encryption keys. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256.
Backup, passwords are protected. We use encryption.
We have the ability to logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant’s data. our network environment is designed and configured to restrict any communication and connection between the tenant’s environment.
We have a multi-layered network architecture with role-based access control. All the confidential/PI data are encrypted at rest and in transit with a split key mechanism to ensure that every client’s key is unique. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.
We use TLS1.2 encryption for Data in transit and AES256 for Data at rest.
We logically segregate the tenant’s data, and it is segregated with a client-specific key for proper handling and security reasons. We use TLS1.3 encryption while data in transit and AES256 while data at rest
Yes, our logic to physically separate tenant systems is made possible by assigning each tenant’s data a client-specific key that is uniquely encrypted for maximum security.We use TLS1.3 encryption while data in transit and AES256 while data at rest
We use logical data isolation with the help of company specific encryption keys. All data volume is encrypted with AES 256-bit encryption to prevent any external snooping or unauthorized access in the multi-tenant environment.We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security.
By default the users will not have access to our customer information or PII. These PII or Sensitive information will be visible only to authorized users and only to the extent needed to perform activities. We do not share or transfer any of the customer data with any other parties. We do not provide access to the PII/SPII to any personnel who do not need the access and implemented the role based access control mechanism.
We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security.
We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security.
All the confidential/PI data are encrypted at rest and in transit with a split key mechanism to ensure that every client’s key is unique. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest
Data backups are done on daily basis and in a secured way on AWS. This has been tested on regular basis.
We use TLS1.2 encryption for Data in transit and AES256 for Data at rest.
Yes. The data at rest encrypted in the cloud.We use AES256 while data at rest. Attached the evidence.
We use TLS1.3 encryption while data in transit and AES256 while data at rest
Each tenant data is uniquely encrypted using client specific key. We use AES 256 bit encryption for data at rest to ensure maximum security measures.our network communication is encrypted with highly restricted protocols to ensure maximum security. the cryptographic keys, including data encryption and SSL certificates are managed by Xoxoday for optimal security of sensitive data. The passwords are also stored after encryption for maximum security of data
Yes. All the data at rest is encrypted using AES-256-bit standards and all the data in transit encryption is HTTPS with TLS 1.2
we logically segregate the tenant’s data and the application.Each tenant data is uniquely encrypted using client specific key. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security.
We are compliant with EU GDPR and CPRA (California Privacy Rights Act)
We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks.In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behavior.
Our network environment is designed and configured to restrict any communication and connection between the tenant’s environment and our corporate network.We use logical data isolation with the help of company-specific encryption keys. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security.
We are EU GDPR Compliant and CPRA Certified.
The data isolated between customers. We use logical data isolation with the help of company specific encryption keys. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256
The data is stored on AWS and The IDs and passwords are stored after encryption for maximum security of data
We also conduct Network layer vulnerability and applicatioin layer vulnerability scan. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256
Yes. Data is encrypted.
Each tenant data is uniquely encrypted using client specific key
Yes. We provide importance to user’s privacy. We use AES 256-bit encryption.
We have a multi-layered network architecture with role-based access control. All the confidential/PI data are encrypted at rest and in transit with a split key mechanism to ensure that every client’s key is unique. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.
Since we are SAAS product, we maintain backup and restore all the customer data by ourselves. We use AES 256 encryption for data at rest. We have a multi AZ deployment with periodic backup for our DR.
We use logical data isolation with the help of company specific encryption keys. Data in non production environment is not updated with the production data. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256
Yes, our network communication is encrypted with highly restricted protocols to ensure maximum security.
We use AES 256 bit encryption for data at rest to ensure maximum security measures.
Yes. The data anonymization implemented. We have enabled security settings with strong encryption for authentication and transmission. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest
Our employees only have access to the data that is necessary for the completion of the business activity which they are involved in. We have role based access system to make sure that only the authorised individual have an access to the required information.
We review the role provisioning, deprovisioning, and recertification on a periodical basis and also audited by the external auditor. Our IT Team Review an access controls and approve as per the procedure. Any changes in the access levels of the users will be as per the role based logical access.
We encrypt our secretes and store them in a private respository and servers.
All the network communication for network communication is encrypted to industry standards. We use logical data isolation with the help of company specific encryption keys. Data in non-production environment is not updated with the production data. We generate separate test data at transit - TLS1.2 encryption, Data at rest - AES256
Yes
We do very limited modification or changes wherever necessary.
We have implemented the Encryption policy. We have defined generation, storage, archival, retrieval, distribution, retirement and destruction of keys. Attached the Encryption policy.
The data is segregated with a client-specific key for proper handling and representation.
All the data including the account credentials, Backup data are encrypted in transit and at rest.
All the the customer data stored on our application also be encrypted for maximum security.
We have implemented the security controls. We use TLS1.3 encryption for Data at transit and AES256 Data at rest for maximum security.We store password hashed. We have SHA512 hash with unique salt for every password
We make sure that we follow the Industry best practices and security standard to make sure that we secure the information asset.
Backup is encrypted and stored on cloud.
We use logical data isolation with the help of company specific encryption keys
We use logical data isolation with the help of company specific encryption keys. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256. We have the ability to logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant’s data. our network environment is designed and configured to restrict any communication and connection between the tenant’s environment.
Yes.We comply with all the applicable new laws and regulations. We also have a service provider who helps us with regards to Information security, compliance and certifications etc.. We have identified the upcoming CPRA and implemented the controls and achieved the CPRA Attestation with the help of the external auditor.Attached the CPRA Attestation report.
Yes. The communications are secure. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.
We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. We store password hashed. We have HA512 hash with unique salt for every password
Yes. We use encrypted channel
Yes
We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. We store password hashed. We have HA512 hash with unique salt for every password
Each tenant data is uniquely encrypted using a client specific key. All data volume is encrypted with AES 256-bit encryption to prevent any external snooping or unauthorized access in the multi-tenant environment Corporate data cannot be accessed by other clients of the service provider
Data is encrypted during transmission, at rest (database and storage), and at backup We use TLS1.2 encryption for Data in transit and AES256 for Data at rest.
We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access. Attached the Encryption Policy.
We have the ability to logically segment or encrypt customer data. our network environment is designed and configured to restrict any communication and connection between the tenant’s environment and our corporate network.our logic to physically separate tenant systems is made possible by assigning each tenant’s data a client-specific key that is uniquely encrypted for maximum security.
We do field level encryption for PII and user generated content. This encryption has a unique encryption key for each client. In addition we also do disk level encryption for the entire stored data.
We have implements cryptographic mechanisms to prevent unauthorized disclosure and modification of information at rest.We use AES 256 bit encryption for data at rest to ensure maximum security measures.Attached the encryption policy.
Sensitive data is encrypted and not stored in logs. Compliant.
Cryptographic keys are protected. Compliant.
The cryptographic keys, including data encryption and SSL certificates, are managed by Xoxoday for optimal security of sensitive data. Each tenant’s data is uniquely encrypted using client specific key.
NA. We do not store any other Sensitive personal information.The PII(name, email ID, phone#) are encrypted. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security.
The application and system backup data is encrypted
We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security.
The back up data is encrypted and only authorised individuals will have access. Test data and backup data is seperated from the production servers.
There is no integration with Infosys services/systems. The network Architecture diagram has been shared to show the TLS communication.
Yes, we use AES 256-bit encryption. All the network communication for network communication is encrypted with the industry standardsAll data volume is encrypted with AES 256-bit encryption to prevent any external snooping or unauthorized access in the multi-tenant environment
We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security.
All the PII Are encrypted.