Skip to main content
Yes, there are established policies and procedures for labeling, handling, storing, transmitting, retention/disposal, and security of TCCC data and objects which contain data, per the TCCC Information Classification Standard and Protection Measures.
Yes, there are established policies and procedures for label inheritance of TCCC data and objects which contain data, per the TCCC Information Classification Standard and Protection Measures. Mechanisms for label inheritance shall be implemented for objects that act as aggregate containers for data.
Yes, we adhere to the retention policy that the tenant sends out for optimal collaboration and smooth user experience with Xoxoday’s products and services.
Your data is of the utmost importance. All the security mechanisms and policies are established and implemented in such ways that data leak can be prevented, in transit as well as at rest.
Yes, the policy, process, and procedure is implemented to ensure proper segregation of duties. These can be asked for and delivered upon tenants’ requests. In the event of user-role conflict of interest, technical controls shall be implemented to mitigate risk (if any) from unauthorized/unintentional modification/misuse of organizations’ information assets.
Yes, our products comply with all the industrial benchmarks and standards when it comes to the Software Development Life-cycle (SDLC). All software development procedures are supervised and monitored by Xoxoday so that they include:
  • security requirements
  • independent security review of the environment by a certified individual
  • code reviewsQuality monitoring, evaluation, and acceptance criteria for information systems, upgrades, and new versions shall be established and documented for the clients’ reference.
Yes, our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase.
Yes, an independent security review is conducted by certified professionals to look for any security vulnerabilities in order to solve them before deploying to production.
Yes, our products comply with all the industrial benchmarks and standards when it comes to the Software Development Life-cycle (SDLC) security standard.
Yes, changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates and modifications. Any change in roles, rights, or responsibilities shall be documented for a seamless experience.
We have a consistent and unified framework for business continuity planning, disaster recovery, plan development. All the appropriate communications shall be established, documented, and adopted to ensure consistency in business continuity. This includes protection against natural and man-made disasters (e.g. fire, flood, earthquake, war, volcanic activity, biological hazard, civil unrest, mudslide, tectonic activity, utility services outages, etc.).
Our hosting options are limited to Xoxoday’s jurisdiction and are backed by prominent business continuity plans. Hence, we don’t find the need to provide geographically diverse hosting options.
The capability to transfer infrastructure service failover to other providers is not provided to the clients.
Business continuity plans shall be subject to test at least annually or upon significant organizational or environmental changes to ensure continuing effectiveness.
Along with an aligned enterprise-wide framework, we perform independent reviews through industry professionals along with formal risk assessments. These are done at least annually or at planned intervals to determine the likelihood and impact of all identified risks. With qualitative/quantitative methods ensuring our compliances with policies, procedures, and standards, we stick to the best standards.
Yes, our stringent checks and tests are conducted annually to keep up the cloud service infrastructure hygiene as per the industrial standards.
Annual audits are processed both internally and externally. The audit results can be sent over to tenants upon request.
Yes, the tenants can request for penetration results and get the reports from our end.
No, we do not process your payment card data for any reason other than billing purposes.
Yes, we are compliant with the Indian IT Act of 2000.
There is no such process available from our end.
We will terminate the contract as per rules and statutes. Meanwhile your data will be stored with us and won’t be given back to you. However, if the tenant wants the data to be erased, it can be done so upon request.
Yes, we store data that’s required for seamless rewarding and recognition. We conduct regular audits to ensure safety of data like employees’ names, emails, employee numbers, etc. are used for verification and rewarding purposes.
Xoxoday’s information and cyber-security team keeps a watchful eye on all potential sources of threats and areas of compromise when it comes to information security.
Roles are systematically defined for information security measures to tactfully align all operations, preventing any security breaches.
Employees must agree with the acceptable usage policy of peripherals and devices to prevent malicious activities from the inside and out.
Our environment has all the capabilities to be SOC-2 Type-II compliant but the certification is yet to come through. It shall be updated soon.
No, our environment is not CSA-certified.
Xoxoday keeps track of all security requirements with respect to legislations, statutes, and contracts. They are documented in all steps.
With different metrics tracking cyber-security measures, Xoxoday keeps the effectiveness in check with regular monitoring.
Xoxoday’s Human Resource operation procedure takes all measures of employee confidentiality into consideration.
Yes, Xoxoday performs a thorough background check on every employee before they get onboard. The Non Disclosure Agreement ensures that the information is secure even after the contract is terminated.
Yes, our Xoxoday Store vouchers are procured from third-party vendors. These vouchers are shared with the tenants in order to be showcased to users of Xoxoday platform.
No, the third parties and vendors we deal with our confidential to Xoxoday. Hence, this list cannot be shared.
Yes, there’s a third-party security policy present to safeguard the interests of Xoxoday’s tenants as well as the end users.
Yes, our third party security policy deems it clear to comply with security obligations and we monitor their compliance regularly.
Yes, we have a detailed risk management procedure in place to address situational issues like change of services being provided to tenants.
No, our customer requests are addressed by the Xoxoday customer support team for maximum efficiency.
Yes, Xoxoday’s brand protection caters to any malicious interruptions and fallacies as they are addressed in prompt time.
Yes, with media platforms being the biggest pedestal for information sharing, we keep an eye out for any brand protection issues.
Yes, in the event of a rapid spike/slump in network traffic or host activity, Xoxoday analyzes the traffic to detect and prevent unauthorized or erratic behavior.
Yes, in order to ensure airtight security of data, we have a mandatory and sessional privacy training and awareness module.
The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment.
Important features of CSA STAR LEVL – 1 are listed below
  • Operating in a low-risk environment
  • Wanting to offer increased transparency around the security controls they have in place.
  • Looking for a cost-effective way to improve trust and transparency.
Yes, We comply with these requirements. Our Cloud Security Platform, (CSP) Amazon Web Services (AWS) provides these securities to our data centers.
Production data shall not be replicated or used in non-production environments. We do not use LIVE data in any other environment. We comply with the requirement.
We take prior authorization from the concerned authority as per the Media protection procedure before relocation or transfer of hardware, software, or data to an offsite premises.
As per Mobile Security Compatibility compliance requirements we have a documented application validation process to test for mobile device, operating system, and application compatibility issues.
The California Privacy Rights Act (CPRA) is a state-wide data privacy bill that amends and expands the existing California Consumer Privacy Act (CCPA). The CPRA works as an addendum to the CCPA, strengthening data privacy rights for California residents, tightening business regulations, and establishing the California Privacy Protection Agency (CPPA) as lead enforcer and supervisor.
Yes. We are compliant with CPRA, and Our solution will continue to offer full compliance with the new and updated data privacy regime.
Yes. We support our consumers to exercise their rights as per the CPRA.
Yes. We have implemented all the privacy controls and audited the same with the help of external Auditors.
Yes. Please reach out to our sales representative/Xoxoday POC to have access to the CPRA report.
No. We do not collect any data from any users across the globe who are not 18 years old.
Yes. The data subject can authorize an agent (an “Authorized Agent”) to exercise their rights. To do this, the data subject must provide your Authorized Agent with written permission to do, and we may request a copy of this written permission from your Authorized Agent when they make a request to exercise the rights.
You may submit a Valid Request by emailing cs@xoxoday.com.
No. We will not sell, rent, or share Personal Data with third parties outside of our company. But Personal Data may be provided where we are required to do so by any privacy laws.
SOC 2 compliance is part of the AICPA Service Organization Control reporting platform. The goal of SOC 2 is to evaluate organization security and internal controls around security, availability, processing integrity, confidentiality, and privacy.
SOC 2 Compliances are developed by the American Institute of CPAs (AICPA), it defines criteria for managing customer data based on five “trust service principles”—security, availability, processing integrity, confidentiality, and privacy.
Yes. Xoxoday is SOC 2 certified organization. We have implemented all the required SOC 2 controls and got them Audited with the help of Certified Public Accountants (CPA).
Amazon Web Services (AWS) has achieved SOC 1, SOC 2, and SOC 3 reports. These reports detail the AWS controls environment and implemented controls for AICPA Trust Services Criteria (TSC) and can be leveraged as part of a cloud customer security program. AWS SOC-covered cloud services are audited periodically against the SOC reporting framework.
You may reach out to our sales representative/Xoxoday POC to have access to the SOC 2 report.
Laika Compliance LLC performs the SOC 2 audit for Xoxoday.
The SOC 2 Type I report is valid for one year following the date the report was issued.
Yes. SOC 2 is an internationally recognized standard. The SOC 2 report and certification involve an independent audit by a third party.
Yes. We do conduct the SOC 2 Audit on an annual basis.
The Auditor has validated and tested all the applicable SOC 2 controls as per the compliance requirements.
We do not process (Collect/Store) Protected Health Information (PHI).
Yes. Xoxoday is compliant with Health Insurance Portability and Accountability Act (HIPAA).
Yes. Please reach out to our sales representative/Xoxoday POC to have access to the HIPAA Audit report.
Yes. We have implemented the Data Subject Access Rights Procedure to make sure that all the data subjects will have the opportunities to exercise their rights as per the privacy laws.
The secure deletion standard like DoD 5220.22-M ECE is being followed and we provide a certificate that the data was properly sanitized from all computing resources and portable storage media.
Yes. Xoxoday is GDPR Compliant. We have implemented the Data Subject Access Rights Procedure as per the GDPR and made all the data subject rights available as per the data protection laws. This procedure sets out the key features regarding handling or responding to requests for access to personal data made by data subjects, their representatives or other interested parties.
Yes. We validate the compliance requirements of the Sub-processor and obtain the Compliance certificates and audit reports such as – ISO 27001:2013, SOC 2 Type II, ISO 27017, ISO 27701, ISO 27018, Cloud Security Alliance Controls, etc.
We conduct the independent Audits for - ISO 27001:2013, SOC 2 Type I, CPRA/CCPA, HIPAA, VA/PT Assessments.
Xoxoday maintains a disaster recovery program to ensure services remain available or are easily recoverable in the case of a disaster. Customers can stay up-to-date on availability issues through a publicly available status website covering scheduled maintenance and service incident history. The BCP and DR Plans are tested and reviewed every year. The Xoxoday BCP and DR plans are reviewed and audited as part of ISO 27001 standards and SOC 2 Type II covering availability as one of the trust service principles.
Users are not having admin access to their computer machines and only IT Support admins can install or uninstall the softwares.
CTOs and Production heads are responsible for safeguarding the customers data. Only authorised individual will have access to the production environment.
We delete the customer data upon request/termination of the contract and confirm the secure deletion. Our data cleaning process goes through an organized purge. Once the data is purged, it’s purged from all places.
We clasify the Information assets into Confidential, Restricted , Internal and Public etc..
We maintain the records of all our assets.
we logically segregate the tenant’s data, and it is segregated with a client-specific key for proper handling and security reasons.
We have restricted the ports for all the users as per Xoxoday IT Policy
The password needs to be minimum 8 characters long and should contain at least one capital letter, special characters among ’# $ % * &’ and 1 digit Maximum Password Age – 45 days Minimum Password Age – 1 day Computer machines will lockout in 15 mins from the time it became inactive.
Yes. Only authorised individual have access.
We use best practices and industry standards to achieve compliance with industry-accepted general security and privacy frameworks. We use enterprise-class security features and conduct comprehensive audits of our applications, systems, and networks to protect customer and business data. Our customers rest easy knowing their information is safe, their interactions are secure, and their businesses are protected. Please click here to know about Xoxoday Security framework - https://www.xoxoday.com/security
We are compliant. We monitor the system performance.
Yes. We maintain current architecture diagrams that include data flows between security domains/zones
All operating systems are hardened as per Xoxoday hardening guidelines.
We are compliant. We have deployed our applications on AWS Virtual platform cloud.
Appropriate roles and responsibilities have been defined and documented. Finance, Leagl, Admin, Infosec departments are active part of it.
Since its SaaS platform is not applicable.
Yes. we conduct the testing on frequent basis to comply with the requirements.
Yes. Its compliant with ISO 27001 and SOC 2 trust service principles.
Yes. We mitigate all the risk identified.
We inform the customer if there is any incidents as per the security and privacy laws.
Yes. We do conduct an internal Audit.
Yes. Privacy and security is a part of the Master Service agreements.
Xoxoday is compliant with GDPR, HIPAA, CCPA/CPRA privacy laws. And we inform the customer if there is any data breaches as per the compliance requirements.
Yes. We provide report on SLA.
We do conduct an External Audit with the help of the independent auditor.
Yes. we conduct the assessment on annual basis.
AWS is a sub-processor as we are storing data on AWS VPC. And they are AWS SOC 2, ISO 27001, ISO 27017 and ISO 27018 certified We monitor the compliances of sub-processor on frequent basis.
We continuosly train employees on privacy and security.
Yes. We have member in our organisation with dedicated information security duties. Xoxoday’s primary security focus is to safeguard our customers or users data. This is the reason that Xoxoday has invested in the appropriate resources and controls to protect and service our customers.
All our employees are having the unique log in IDs.
We have installed the firewall for maximum securty and configured to restrict unauthorized traffic
All are configured according to security standards as part of the build process
Its part of our Internal and external Audits and validated by the indeendent auditors.
We have implemented the access control policy and access will be provided only upon need and approval basis. Attached the access control policy.
We have track of the changes. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
We have installed Smoke detectors and Fire extinguishers for physical security.
security incidents reviewed to capture the root cause.
We are SOC 2 compliant and we have engaged Laika Compliance LLC, an independent assessor firm, to conduct a SOC 2 Type 1 and SOC 2 Type 2 examination for the Xoxoday Platform against the Security and Confidentiality Trust Services Categories.
Attached the ISO 27001:2013 certificate.
We provide Software as a Service.(SAAS). We are ISO 27001 certified and GDPR compliant. Attached the document.
We are ISO 27001 certified and GDPR compliant. Attached the document.
Since it’s a SaaS prodcut and deployed on cloud virtual platform only authorised individual have an access to the our production environment on need and approval basis.
We inform the client to revoke access.
We use Google workspace and have secure mode of sharing the data.
We can manage all the enpoints centrally.
We have implemented the security measures to manage the risks introduced during the use of Organization’s information assets used for managing Personally Identifiable Information.
We have a formal risk assessment process and conduct the risk assessment annually.
All the contractors/vendors have signed the NDA and contracts All the necessary clauses has been included in the agreements with regards to Confidentiality, liabilities, termination etc
Yes. We do conduct the Risk Assessment every year.
Yes. We have implemented the Data security and Information clasification policy. Attached the same.
Yes. They have signed for the agreements.
We have a biometric systems and access cards. only authorised individual can have access.
We have deployed Sensors for fire detection and fire extinguishers to detect and protect from the fire.
Yes, we will notify
Yes. Our Customer support team will notify.
Yes. We create an email accounts only after the approval from reporting managers.
We have not outsourced and does not create any email ids
Yes. IT Team is responsible.
Yes. We have a Email Security Policy and attached the same
Yes, we have implemented the security controls for email with the help of Google workspace and installed the end point security for all the laptops of the employees. All the incoming and outgoing attachments are scanned.
Yes.
Yes, We have implemented the Acceptable Usage Policy and have restricted for usage and access to internet.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. Since our application is deployed on AWS cloud we will ensure the best uptime in the insudtry.
Yes. All the changes takes place as per the change management policy implemented.
Yes. We have software register and only approved and licensed softwares will be used.
Yes, all are up to date.
Yes, we have capacity planning and monitor the hard disk space, RAM, CPU etc.
All the employees laptop is secured with Bitdefender end point security software
Yes
Yes. Taken into consideration
Annually
We do consider all of these, addition to that we also validate the controls in place with regards to cloud security, BCP, Uptime etc. AWS is ISO 27001, SOC 2 Type II certified and complied with CSA start level 2. Please click here for more details about AWS Compliance Programs - https://aws.amazon.com/compliance/programs/
We have implemented policies and procedures as per ISMS and GDPR requirements. We also conduct periodical Internal and external Audit by the third party Auditor. We have deployed our application on Cloud Virtual platform for maximum security. We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We conduct periodical Vulnerability assessment and Penetration Testing from the Inductry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications.
Yes. AWS is ISO 27017, ISO 27001:2013, ISO 2018, SOC 2 certified.
Yes. Attached the AWS ISO 27001 certificate
We ensure that we maintain confidentiality, integrity, availability and privacy of data collected, processes, stored through implementing policies and procedures. And we do conduct the internal and external Audits periodically to make sure that all the controls are working effeectively.
Yes
Yes
Yes. Audited by the independent Auditor and all the aspects of Privacy, information security, BCP, DR, Production, VAPT has been validated.
NO
Production Site - No.17, Bhagyalakshmi Square, 2nd Floor, Sector 3, HSR Layout, Bangalore -560102 We have deployed our application on AWS Singapore. Since we have deployed our application on AWS cloud they only provide DR Services.
No other location
We provide our application to the customer. We have 230+ employees. 100+ employees are involved in the production/devolopment and we have a sepearate team for IT Support and Information security. We have provided separate computers to each employees. Altogether we are having around 250 computer machines. Our application is deployed on AWS cloud virtual platform.
Xoxoday is ISO 27001:2013 certified, GDPR compliant and SOC 2 type I certified organization and have all the required technical and organizational controls in place and auditred during the internal and external audits.
We have implemented the Information classification Policy to protect against unauthorised access, disclosure, modification, or other misuse. All our assets are labelled as per the requirement.
Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. A strong identification and authentication system and logging systems are deployed and provide a centralized control to administer, monitor and review all critical access. We have a role-based access system through access control policy to make sure that only the authorised individual has access to the required information. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. The approvers are either the Product Heads or respective function Heads are their authorized delegates.
We have the Fire alarams, Smoke detectors, UPS, Temperature controler, Air conditioner, etc.. for protecting against the environmental hazards.
Yes, all our - both full-time and on-contract are bound by an agreement of non-disclosure and a confidentiality agreement as a condition of employment to protect the customers and tenant’s information.
We use the CCTV cameras to monitor the building on a 24_7_365 basis. All the enterances, exit, restricted areas are under surveilance for security reasons.
Yes. We have the Information security team.
We are compliant
In accordance with Data Protection Laws, we make available to Controller on request in a timely manner such information as is necessary to demonstrate compliance by Processor with its obligations under Data Protection Laws. Upon Controller’s written request and subject to the confidentiality obligations set forth in the Agreement, we will make available to Controller a copy of Nreach the most recent third-party audits or certifications, as applicable. We do not agree for the Surprise audits.
We have the Buiness continuity and Disaster Recovery Plan in place. These controls has been tested at least annually as per the compliacne requirements. Attached the policies for your referrence.
We have the Crisis management is in place. Attache the same. We have provided an option to work from home/remotely due to this pandamic with necessary infrastructure and security. Business continuity plan has been tested on annual basis and audited during the internal and external audits. Atatched the business continuity policy and plan.
Generic IDs are not used
We have the ability to delete the data upon request by the data subject or termination of the contract. Attached the data retension and disposal policy.
We have implemented the Business continuity policy and we have the ability to resume our operation from potential threats, Pandemic, flood, fire, earthquake etc. Due this pandemic/WFH situation, VPN access has been enabled with 2FA For such authorized individuals, for ensuring business continuity. We have the required controls in place for working from home or remotely due to this pandemic situation.
Its a part of our Business continuity plan and IT Support Head, HR Head, CTO, Infosec Head will be involved in the preparedness activities.
We have provided WFH option to all the employees to get protected from COVID 19.
We have provided WFH option to all the employees to get protected from COVID 19.
We test the Business continuity plan on annual basis. It was tested in the month of Aug 2021 for the last time.
It has been well defined in the in the Business continuity policy and plans. Attached the same for your referrence.
We inform our customer on any crisis and if that is effecting on our customers.
Xoxoday is a data processor.
NO. We obtain consent before such activities from the customer.
We have the DPA and appropriate controls in place – We are compliant.
ISO 27001;2013, SOC 2 Type I Certified and GDPR compliant.
YES. We have implemented the Business continuity plans and tested them annually.
No. But we are in the process of getting the insurance from the Insurance company.
We conduct the internal and External audits on a periodical basis as per the compliance requirements and obtain Audit reports and certifications. We provide the same with the customers.
application by Xoxoday, the RnR platform is a cloud-based SaaS platform hosted on VPC infrastructure of AWS. The data centers are hosted completely in isolation so that the access is limited and controlled. Each instance (EC2 Instance) under fortified VPC network is further conglomeration of Docker Container Web Services and APIs and application layer running on top of it. This helps in managing various aspects and features of application without affecting the functioning of each other and achieving a modular architecture to work as plug and play model. Amazon Cloud Watch is implemented to enable monitoring of the functioning of the application. We have Web application firewall (WAF), IDS/IPS, AWS Guardduty, and the data has been encrypted for security reasons. Attached the Architecture diagram.
Xoxoday is ISO 27001:2013 certified and GDPR compliant.
Xoxoday is ISO 27001:2013 certified and GDPR compliant. And we follow ISO 27001, NIST, CSA standards and best practices. We have Web application firewall (WAF), IDS/IPS, AWS Guardduty, Coudflare and the data has been encrypted for security reasons. We conduct code reviews as per the compliance requirements. We also conduct the Vulnerability assessment and penetration testing on annual basis with the help of the third party authorised vendor. Attached the latest VAPT certificate and ISO 27001 certificate.
Attached the ISO 27001:2013 certificate and 1st Year Surveilance audit report. We did not have any non-confirmities.
We are compliant with the data privacy and security requirements. We are having the controls in place with regards to Cyber security, Risk management, crisis management, business continuity, Network security, application security etc. Attached the Business continuity management and Cyber Crisis Management Plan, incident management procedures, SDLC etc.
Attached the Business continuity plan and procedure. We test the BCP controls on annual basis as per the compliance requirements and it has been auditted during the internal and external audits.
Xoxoday is ISO 27001:2013 certified, CSA START Level 1 and GDPR compliant. And we follow ISO 27001, NIST, CSA standards and best practices. We have Web application firewall (WAF), IDS/IPS, AWS Guardduty, Coudflare and the data has been encrypted for security reasons. We conduct code reviews as per the compliance requirements. We also conduct the Vulnerability assessment and penetration testing on annual basis with the help of the third party authorised vendor. Attached the below policies and procedures - 1. Encryption Policy 2. Password Management Policy 3. IT Policy 4. Information Classification Policy 5. Threat and Vulnerability Management 6. Cyber Crisis Management Plan 7. Backup Recovery Procedure 8. Access Control Procedure 9. Incident Management Procedure 10. Change Management Procedure
Data centers are designed to anticipate and tolerate failure while maintaining service levels. In case of failure, automated processes move traffic away from the affected area. These are tested on annual basis. AWS is also ISO 27001, ISO 27017, ISO 27701, ISO 27018, SOC 2 compliant organizatin. Please click here for more details - https://aws.amazon.com/compliance/programs/ Please click here to know more about AWS security - https://aws.amazon.com/compliance/data-center/controls/ Please click here to know more about Xoxoday Service level agreement - https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view
Please click here to know more about Xoxoday Service level agreement - https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view
Please click here to know more about data governance - https://www.xoxoday.com/gdpr
Attached the Risk Management Procedure
We have plan for having the cyber insurance. - In progress.
Each employee, when inducted, signs a confidentiality agreement and acceptable use policy, after which they undergo training in information security, privacy, and compliance. Furthermore, we evaluate their understanding through tests and quizzes to determine which topics they need further training in. We provide training on specific aspects of security that they may require based on their roles. We have implemented the Information security policy and Disciplinary policy.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently.
Please click here to know more about the Application SLA - https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view?usp=sharing
We review and get an approval from the management on annual basis as per the compliance requirements.
We have installed End point security on all the computers and monitored and updated on regular basis.
Yes. Our tenants can report the Bugs and security vulnerabilities to cs@xoxoday.com We also have Bug Bounty Program at Xoxoday and please click here to know more about - https://www.xoxoday.com/bug-bounty
Since application is a SaaS platform and deployed on AWS virtual platform cloud
NA. We have the full time employees.
We conduct the review and update the policies, procedures etc..and take an approval from the management on annual basis as per the compliance requirements. We also communicate all the policies and procesures to all the employees, contractors through HRMS platform.
We do not allow to access the infrastructure hosting.
All the information security policy and standards been approved by senior management.
We have installed the antivirus on all the workstations and servers.
Customer data security is an essential part of our product, processes, and team culture. Our facilities, processes and systems are reliable, robust, and tested by reputed quality control and data security organizations. We continuously look for opportunities to make improvements in the dynamic technology landscape and give you a highly secure, scalable system to provide a great experience. Attached the GDPR - Data security policy.
We have installed Bidefender endpoint security and restricted the access of external hard drives, USB etc to have restriction on data transfer. we use file integrity and network intrusion detection (IDS) tools to help facilitate timely detection, investigation by root cause analysis, and response to incidents
We do not use.
Annually
We have conducted the BCP test on 6th Aug 2021. Attached the Business continuity policy.
We have installed Smoke detectors and Fire extinguishers for physical security.
Attached the incident management procedure. All our policies are reveiwed annuaaly and approved by the top level management.
security incidents reviewed to capture the root cause.
Attached the Security Incident Reporting and Response Procedure
Classification of Incidents are done. Attached the Incident Management Procedure
No Security breaches till date.
We are SOC 2 compliant and we have engaged Laika Compliance LLC, an independent assessor firm, to conduct a SOC 2 Type 1 and SOC 2 Type 2 examination for the Xoxoday Platform against the Security and Confidentiality Trust Services Categories. Attached the engagement letter.
Attached the ISO 27001:2013 certificate.
We make sure that they have adequate controls in place and meet the security standard.
We are ISO 27001 certified and GDPR compliant. Attached the document.
We review these to make sure the all the controls in place.
We provide access only upon need and approval basis.
We use Google workspace and have secure mode of sharing the data.
We can manage all the enpoints centrally.
Attached the Risk Management Procedure
We have a formal risk assessment process and conduct the risk assessment annually.
All the contractors/vendors have signed the NDA and contracts All the necessary clauses has been included in the agreements with regards to Confidentiality, liabilities, termination etc
The SaaS solution is deployed on Public cloud.
Yes
Yes. We are using Bitdefender endpoint security.
Yes. We use for security reasons
Our employees will not have access by default. The data will be accessed only upon need an approval basis. The access is controlled through the AWS Identity and Access Management system that also enforces two-factor authentication
We collect only 3 types of the personal Information such as Name, email ID, phone#. , personal data is to be transmitted using firmly approved encrypted systems. We have implemented the role based acccess control to make sure that the acccess has been granted to only authorised individual.
Yes.
Yes. We inform the client about any security incidents.
Yes. Attached Incident management policy and SLA
Yes
Yes
We are compliant.
Yes, We are ISO 27001:2013 certified. Attached the certificate.
We are SOC 2 Type 1 compliant. The audit has been completed and auditor is working on the Draft audit report. We will be able to share once the report is finalized.
NA. But AWS Virtual platform cloud is ISO 27017 and 27018 certified and attached the report.
NA. We do not handles the card holder data.
the customer will be using the application product and all the information will be entered only through our application.
The data sharing between vendor and the customer will take place only through application product. There will be no manual data sharing or transfer.
PII will be entered through application and stored it on AWS cloud virtual platform. We store Name, email ID and phone number of the users.
We do not have any sub-contractors. We have deployed our application on AWS Virtual platform cloud. And AWS is ISO 27001, SOC 2, ISO 27017, ISO 27018, ISO 27701, CSA Compliant etc..
We have deployed our application on AWS Virtual Platform cloud. application is a cloud based application. We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. All the confidential/PI data are encrypted at rest and in transit with a split key mechanism to ensure that every client’s key is unique We do not decrypt the data until and unless if there any specific request from the customer.
Xoxoday endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week (“Agreed Hours of Service”). Uptime is measured based on the monthly average of availability, rounded down to the nearest minute. Please click here to know about Xoxoday SLA - https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view Xoxoday has a formal Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) defined and implemented to enable people and process support during any crisis or business interruptions. The BCP and DR Plan is tested and reviewed on a yearly basis as per the compliance requirements. The BCP and DR plan of Xoxoday is reviewed and audited as part of ISO 27001 standards and SOC 2 Audits by the independent auditor. Attached the Business Continuity Plans (BCP) and Disaster Recovery Plan (DRP) documents.
Since it’s a SaaS platform, there are no process as such.
Attached the below mentioned coompliance certifications - Attached the Audit reports. 1. ISO 27001 certificate 3. VAPT Certificates 4. VAPT Audit reports 5. SOC 2 Audit reports. 6. GDPR Data Privacy Impact assessment report 7. California Privacy Rights Act (CPRA) attestation report. 8. CSA STAR LEVEL 1 compliant - https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday We conduct these audit on annual basis and we will share it upon request.
We always provide our best service to resolve security incidents / outages. Attached the Service Level Agreement (SLA)
Xoxoday is committed to ensuring the integrity, confidentiality, availability, and security of its physical and information assets and maintaining privacy when serving the customers and organization’s needs while meeting appropriate legal, statutory, and regulatory requirements. To provide adequate protection for information assets, Xoxoday has built the Information Security Management System (ISMS), enabling everyone to follow these policies diligently, consistently, and impartially. Xoxoday will implement procedures and controls at all levels to protect the confidentiality and integrity of information stored and processed on its systems and ensure that information is available only to authorized individuals as and when required. Please click here to know more about Xoxoday Security - https://www.xoxoday.com/security
No. There were no Personal Data Breaches.
Xoxoday is committed to ensuring the integrity, confidentiality, availability, and security of its physical and information assets and maintaining privacy when serving the customers and organization’s needs while meeting appropriate legal, statutory, and regulatory requirements. To provide adequate protection for information assets, Xoxoday has built the Information Security Management System (ISMS), enabling everyone to follow these policies diligently, consistently, and impartially. Xoxoday will implement procedures and controls at all levels to protect the confidentiality and integrity of information stored and processed on its systems and ensure that information is available only to authorized individuals as and when required. Attached the below documents - 1. ISO 27001 Certificate 2. SOC 2 Audit report. 3. California Privacy Rights Act (CPRA) attestation report. 4. VAPT Certificates 5. GDPR DPIA Assessment report. 6. CSA START LEVEL 1 Compliant - https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday the customer can request the Xoxoday POC for these reports and we will provide the latest Audit reports upon request.
We are storing all the customer data on AWS Virtual platform cloud – Singapore region and consider AWS as a Sub-Processor as per EU GDPR. AWS is ISO 27001, SOC 2, ISO 27017, ISO 27018, CSA STAR, ISO 27701 certified organization. Please click here to know about AWS Compliance offerings - https://aws.amazon.com/compliance/programs/
Scope and functionalities are the part of the agreement.
Please click here for SLA - https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view We do not offer any credits/ penalties.
We have implemented all the technical and organisational measures to ensure the integrity, confidentiality, availability, and security of its physical and information assets and maintain privacy when serving the customers and organization’s needs while meeting appropriate legal, statutory, and regulatory requirements. To provide adequate protection for information assets, Xoxoday has built the Information Security Management System (ISMS), enabling everyone to follow these policies diligently, consistently, and impartially.
We do not process the data for other purposes than the one specified in the contract,
We do not share the data with third parties. But we store it on AWS Virtual platform cloud and we consider AWS as a Sub-processor. We do not disclose any of our customers personal information to any third parties. We reserve the right to disclose PI if required by law or if we reasonably believe that use or disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or comply with a law, court order, or legal process. We reject any non-legally binding requests for disclosure.
We process only the Name, phone# and Email ID as mandatory information.
We process the information as per the terms of use - https://www.xoxoday.com/terms-of-use
We are storing all the customer data on AWS Virtual platform cloud and we operate or provide services from Bangalore, India.
We inform the customer of any changes in regards to changes in sub-processors.
Xoxoday Terms & conditions - https://www.xoxoday.com/terms-of-use
Yes, the cloud provider does have a right to suspend services for specific reasons; more detailed in Section 3.3 of the Master Services Agreement. Section 3.3(a) read along with Section 2 of the MSA
We conduct the periodical Risk assessment. and it has been audited during the internal and external audits.
We also provide SLA performance report to the customer on need basis.
we have the capability to respond to security alerts, and report security vulnerabilities and information security incidents within 24 hours of discovering them
We train our employees on their role and responsibilities and also comminicate before joining the organizatin
application is an all-in-one employee engagement and motivation platform that offers Rewards & Recognition, Pulse Surveys, 1-on-1 Feedback, Social Intranet and People Analytics in one powerful solution.
Information security department is responsible for security initiatives and the Head of the Information security reports to the Board of Director of the company.
The policies and procedures have been created, reviewed and approved by the Top level management of the company.
The information security policies have been uploaded on KEKA HRMS Application and communicated to all the employees. Attached the screenshot for your reference.
Attached the Risk Management Procedure.
Attached the internal audit report.
Your data is of the utmost importance. All the security mechanisms and policies are established and implemented in such ways that data leak can be prevented, in transit as well as at rest.
We have installed Bitdefender endpoint security in all the endpoints. Bitdefender is based on a layered next-gen endpoint protection platform with the industry’s best prevention, detection and blocking capabilities, using proven machine learning techniques, behavioural analysis and continuous monitoring of running processes.
We have the capability to wipe out the data remotely for all endpoints including BYOD devices.
Attached the ISO 27001:2013 certificate and Statement of applicability.
We provide tpliance certifications upon request.
We use the Software Development Life Cycle (SDLC) process. It is aligned with ISO 27001;2013 and SOC 2 frameworks.
We have SDLC Policy as per ISMS requirements and we follow General Coding Practice. For example - We Conduct data validation on a trusted system, All cryptographic functions used to protect secrets from the application user.
We can also provide uptime status on a need basis.
We have proper forensic procedures for data collection and analysis for incident responses
Yes, in case specific incidents arise for particular tenants, our logging and monitoring framework allows isolation of incidents.
Xoxoday endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week. Uptime is measured based on the monthly average of availability.
We do not offer any penalty.
Attached the SLA
Customer Support is available on all working days (Mon - Fri) between 3.30 AM GMT to 1:30 PM GMT.
Xoxoday is – ISO 27001:2013 certified CPRA (California Privacy Rights Act) EU GDPR Compliant CSA STAR LEVEL 1 Compliant – Click here Vulnerability Assessment and Penetration Testing (VAPT) Attached these above certificates and Reports.
The backups are automated and taken on a daily basis. We delete the data upon receiving the request from the customer/end users/termination of the contract. Our data cleaning process goes through an organized purge. Once the data is purged, it’s purged from all places.
We have an ELK setup in place to ensure data monitoring in the most optimal manner. The audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
As per the SDLC Policy we follow several distinct stages, including planning, design, building, testing, code review, deployment and maintenance etc. Our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase.
It would depend on the criticality of the investigation and the type of service subscribed. Our team will be able to provide the ETA as soon as they receive the request from you and start acting immediately.
Yes. You can check this information from the user management option available for Admin console.
You can reach out to us with the help of the help center or can write an email to customer support team
Yes. We maintain and record the Audit logs and complying with various compliance requirements.
Yes. You may reach out to our support team anytime for requesting these records and they would be able to help you out on this requirement.
It would depend on the criticality of the investigation and the type of service subscribed. Our team will be able to provide the ETA as soon as they receive the request from you and start acting immediately.
Yes. We are ISO 27001:2013 certified and GDPR Compliant.
We have implemented the risk assessment procedure and conduct the risk assessment annually as per the compliance requirements.Risk assessment is used to identify the risks encountered by the information-processing facilities (or individual system components). The aim is to estimate the impact and probability of a threat occurrence. The risk assessment procedure is having Risk, Likelihood and Impact. The risk ranking is done based on the Residual Risk Rating such as High, medium and low. Attached the Risk Management Procedure for your reference.
Risk Management Procedure has been used to validate the security compliance of AWS. AWS Compliance certifications and attestations are assessed by a third-party independent auditor and result in a certification, audit report, or attestation of compliance. AWS is ISO 27001, SOC 2 Type II certified and complied with CSA start level 2. Please click here for more details about AWS Compliance Programs - https://aws.amazon.com/compliance/programs/
Yes. We can use the risk assessment framework adopted by NSE for cloud service risk assessment.. Please provide the same.
We comply with this requirement. The risk assessment procedure has defined the Risk Acceptance Criteria, Benefits, Components, Impact Rating, Risk Treatment, Risk Acceptance etc and all the controls identified in our risk assessment as per the industrial standard like ISO, SOC2, NIST, GDPR etc.
Sure. We are ISO 27001;2013 and GDPR compliant. We have policies and procedures in place with all the required compliance controls.
We comply with this requirement. We conduct annual audit by the independent auditors to test the controls in place with regards to Information Security management system(ISMS) and also for testing the service organization controls(SOC)covering the principles of Security, Availability, Confidentiality, and Privacy. AWS is also SOC 2 certified.
Sure. Attached the ISO certificate and we are in the Audit process for SOC 2. we will provide the same once the audit is completed.
We are ISO 27001;2013 certified, GDPR compliant and in the process of SOC 2 audit. We make sure that our customer data is safe and secure and meet all the compliance requirements and industry best practices. Xoxoday has built the Information Security Management System (ISMS) which includes the respective policies to be followed in a diligent, consistent, and impartial manner.
Our legal team would review and agree the terms and conditions.
We agree. NSE can review.
Our legal team would review and agree the terms and conditions.
We will inform NSE if there is any breach.
The data isolated between customers. We use logical data isolation with the help of company specific encryption keys.We use TLS1.2 encryption for Data in transit and AES256 for Data at rest
We agree. We have implemented the data breach notification procedure.
We agree. We will notify NSE.
We agree.Currently, we do not have any plans as such.
We agree. We will delete the data upon termination of the contract or request and confirm. Our data cleaning process goes through an organized purge. Once the data is purged, it’s purged from all places.
We have implemented Asset Management Procedure in place and maintain all the records of IT Assets like, hardware, software, licenses, accessories etc.
We review and update the inventory as per the Asset management policy.
The database server, application server or storage devices hosting NSE’s data & information is not made available publicly. We isolate our machines, network and storage with respect to the AWS Standards in order to keep it safe and secure
Yes, one can write to us at our 24*7 support team at cs@xoxoday.com
We help the clinets in setting up from both admin and end user side, and traiing is also provided on how application can be used for hasslefree awards distribution
We provide trainging over internet , if possible we provide telephonic assistance also.
Yes we provide “on demand training” , this incur no additional cost to the company
We have a 24*7 available support team, once a ticket is generated , It is assigned to one of the cs team executive and we intent to solve the issue within next 24hrs.
Xoxoday employees and third party would have an access. We provide acess on case to case basis as per the Information security and access control policy. We also have role based access system to meet the compliance requirements of the data security . The data is hosted on Amazon Web Services (AWS)
We do conduct employees and contractors background verification as per the compliance requirements before onboarding process. We will onboard them only after passing the background verification. We are ISO 27001:2013 certified organization.
We conduct periodical review of the access provided and make the necessary chages as per the Role based access management and access control policy. We also conduct Internal and external audits in a timely manner.
Our Information security compliance policies and procedures are established and implemented to enforce two-factor authentication
We are ISO 27001:2013 certified organization The User access are monitored and recorded internally as per the compliance requirement and Access Control Procedures.
Yes we have implemented intrusion detection tools, we ensure timely detection and investigation in a prompt manner.
Yes. file integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation.
Yes. Implemented SIEM
Yes. All the controls are audited annually.
Yes, We will share the Data protection policy. Access control policy and Information security policies
Size of the team is 5 and all are having 5+ years of experience
personal data is stored are registered databases that comply to all necessary inputs of a standard inventory repository and its transit scrambled for maximum security.
We use AWS Platform for storing the data. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records.
As per the Information security policy and Data protection policy only the authorised individual have an access to the data through internal approving and ticketing system.
No. Planned downtime will not be calculated uptime
No. Planned downtime will not count against the SLA
We have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working.
We test it annually once as per the compliance requirements.
Xoxoday’s architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows.
We have Business Continuity Policy and Business Continuity Management Procedure in place and tested periodically. And also our Policies has been reviwed and Audited annually.
Yes. We have implemented IDS/IPS, Firewall and our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting
Yes. We have procedures in place to support Government
We have the clauses for suppporting local government and law enforcement requesting customer data in data protection policy. We will share the copy of it.
We have deployed our application on Amaon web services (AWS) AWS is designed to help us build secure, high-performing, resilient, and efficient infrastructure for our applications. AWS is also ISO 27001:2013 and SOC 2 type II Certified and provide all applicable security to the data center.
Yes. We have industry approved vendor called Appknox for Vulnerability assessment anf Penetration Testing. Appknox performs Static, Dynamic, API, and as well as Behavioral Analysis. And they helps to detect and address security vulnerabilities.
We collect only personal information through our application. We collect name, email ID and mobile numbers.
Yes. We have capabilities to anonymize data. By Anonymization users are able to make use of sensitive information without having access to the identifiable data items. And its used within a secure environment with employee access on a need to know basis.
No. we do not have it in hard copy
Yes. We conduct vendor Risk assessment and also external Auditor validate the critical vendor documentations during the annual and Internal Audit.
Yes. We have Information Security Program
Yes. We review Information Security Policies every year.
Yes. We have Information security risk management program
Yes. Our management is supportive and evaluate, Recommend and take action on security risks
Yes, we have Information security team and the Infosec head is reporting to Chief Operating Officer of Xoxoday.
Yes
Yes. Please visit here for more details - https://www.xoxoday.com/bug-bounty
Yes. All the endpoint laptops that connect directly to production networks centrally managed
All the employees laptop is secured with Bitdefender end point security software. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory.
No. sensitive or private data never reside on endpoint devices. This is enforced throgh access control policy.
We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour.
Yes. Our incient response plan is tested every year as per the ISMS requirements.
We follow SDLC policy during the design phase of devolopment. See SDLC procedure attached
We have SDLC procedure and Information System Acquisition Development and Maintenance Procedure. Devolopers are trained on the Secure Coding Practices as soon as they joined our organization
We conduct vendor risk assessment and collect all the required security policies, procedures, VAPT reports, ISO 27001, SOC 2 reports. And also our internal and exteranal auditors validate the security controls of our crtical vendors during the Audit.
NO
NA. We do not have custom-built software
Yes
Internal Audit has been conducted by the inhouse Infosec and ISMS Lead Auditor. All the projects, business processes and ISMS controls has been included in the scope and opportunity of improvements has been communicated to all the respective teams with the remideiation plan. And the frequency of the Internal audit is annually.
We have the external Auditor for ISMS Audit. All the projects, business processes and ISMS controls has been included in the scope and opportunity of improvements has been communicated to all the respective teams with the remideiation plan. And the frequency of the external audit is annually.
See ISOIEC 270012013 Certificate and Internal Audit report attached.
NA. We do not use for own purposes
Yes
Yes. All the employees and third party service providers are required to sign Confidentiality Agreements to protect customer information as per ISMS compliance requirements.
We have dedicated IT Team and Admin team who looks after the hardware security and, we have implemented the security controls as per the ISO 27001:2013 and SOC 2 Compliance requirements. We are hosting our application on AWS, and they are providing physical security to our data centre. We have Asset Management Procedure in place to identify, classify, label, and handle the Information and Information assets according to their criticality and sensitivity. We have Media protection procedure to handle the locally stored data as per the Information security compliance requirements.
As per the Physical and Environmental Security policy we have security guards and CCTV Camera’s to safeguard the office building and also to provide an access to the building only for the authorized individuals. We also have Media protection policy which also defines on how to handle the Paper documents as per the compliance requirements. Physical documents are handled with at most care and followed the policies and procedures of an organisation to make sure that the data is protected.
We have Physical and Environmental Security policy and Vendor management guidelines in place and working effectively. We have implemented controls on Physical entry, Securing offices, rooms, facilities, Working in secure areas, Delivery and Loading areas etc. Only the authorised individuals will get an access upon verification. And we also conduct periodical verification of the effectiveness of these controls periodically through internal and external Audit. We provide access to the outsiders or suppliers on approval and escorting mechanism of vendor management guidelines by issuing the access cards.
All our assets are classified, labelled, and maintained in the register by our IT Team. Access granted only to, authorized individuals. We have locked environment for our hardware’s which would store the data. We also have implemented the Media protection procedure to protect the data which are stored physically.
Yes. Backups are stored in a safe place. We have backup Recovery Procedure and implemented the controls to protect the organization information asset from the damages that may be caused due to failure of hardware system, corruption of software, breaches leading to data destruction and or not being able to retrieve and use. We predominantly work on cloud-based infrastructure and the teams may consider adoption of Amazon Web Services which provides the Backup and Restore services to build scalable, durable and secure data-protection solutions. AWS claims the following benefits and the teams may evaluate the benefits to the respective context that may lead to realize the following outcomes: 1. Data Type and Durability 2. Flexibility and Scalability 3. Security and Compliance The following AWS based offering for the following use cases offered by AWS may be considered based on the contractual needs of the subject under consideration: 1. Hybrid Cloud Backup 2. Data Lifecycle Management 3. Tape Replacement 4. Global Data Resiliency 5. Data Backup 6. Archive & Compliance
We are ISO 27001:2013 certified and GDPR compliant organization. We have Information security policy and Data security policies in place with regards to data protection. We make sure that the below principle of data security has been followed as per the compliance requirements. 1. Fairness and lawfulness When personal data processed by us, we make sure that the individual rights of the data subjects must be protected. We will ensure that the personal data is collected and processed in a legal and fair manner. 2. Confidentiality - Restriction to a specific purpose We make sure that the any processing of personal data should be lawful, fair, and transparent. Personal data will be processed only for the purpose that was defined before the data was collected. Subsequent changes to the purpose are only possible to a limited extent and require substantiation. 3. Transparency We make sure that we maintain the transparency with regards to the data collected, stored and disposed. We also provide rights to data subjects as per the GDPR compliance requirements. For ex - Right to Rectification, Right to Portability and Right to be Forgotten. 4. Integrity and data security Personal data is subjected to the data secrecy. We have controls on confidentiality, Integrity and data security. We follow secured suitable organizational and technical measures to make sure that the data is protected from an unauthorized access, illegal processing or distribution, as well as accidental loss, modification or destruction etc. Sensitive data - We do Inform involved parties about how we will process their data Inform involved parties about who has access to their information Have provisions in cases of lost, corrupted, or compromised data Allow involved parties to request that we modify, erase, reduce or correct data contained in our databases. Sensitive data - We do not Communicated informally. Stored for more than a specified amount of time. Distribute to any party other than the ones agreed upon by the data’s owner (exempting legitimate requests from law enforcement authorities. In addition to ways of handling the data the company has direct obligations towards people to whom the data belongs.
We have controls in place to protect the information or to maintain privacy. We conduct Data Privacy impact assessment and Audits periodically as per the compliance requirements. We have Personally Identifiable Information Policy, Data Security policy, Data Subject Access Rights Procedure, Data Retention and Disposal Policy as per GDPR compliance.
We conduct periodic vendor risk assessment. Information security documents are validated by theiInternal and external auditors during the assessments.
Yes.
We have an access control policy. The policy is attached for reference. Only authorised employees will have access to the data.
Yes. Xoxoday is ISO/IEC 27001:2013 certified organization. See certificate attached.
Yes. We have a well-defined policy for roles and responsibilities. We have communicated each employee about their responsibilities across the organization. We do maintain appropriate contracts with relevant authorities and ensure that applicable regulations are complied with
Yes. We provide these rights to the data subject as per GDPR
Yes. We conduct internal and external audits and all the applicable controls have been validated as per the compliance requirements.
Yes
We have a media handling procedure. See attached for reference.
No. We do not transfer the data outside our organization.
Yes. See Infrastructure Change Control Procedure attached.
Yes.
Security inceidents will be reported by our Information security team or customer support team within 48 hours.
We have implemented physical security controls as per the compliance requirements. We have CCTV, access cards, security guards for monitoring and only authorised individual have access.
Segregation is done for production and non-production or Testing environments. We maintain the test accounts seperately and delete or terminate the accounts immediately once the testing is completed. Only Admins have an access to create these tests accounts on need and approval basis.
We have implemented the Roles and Resposibilities policy and defined the Duties of all the system users and segragated based on the defined roles. Only authorised individual will have an access to the Information system on need and approval basis.
We maintain these records for Audit purposes.
We have controls in place to monitor the user access system. We have implemented Role based access management system through access control policy. Our application also supports Role based access control system to make sure that only authorised individual will have an access to the Information system on need and approval basis.
We maintain these records for Audit purposes.
We are Compliant. We monitor these controls on a periodical basis and also during the internal and external Audits. Successful and failed login attempts will be logged, we use privileged accounts are used only for system administration activities,we remove default credentials and use the new credentials for all our systems.
We use Multifactor authentication menthods to make sure that only authenticated individual have an access to the Information system wherever strong authentication is required. We use Biomentric verification and access cards methods for physical security purposes.
We have these controls in place. We have a restriction for Physical access, monitor these access periodically and validate to make sure that only the authorised individual have an access.
The credentilas has been comminocated via secured mode to make sure that confidentiality is maintained.
We are Compliant.These controls are audited during the internal and external Audits.
We are Compliant.Only authorised individual will have an access.
We are cothe customerant. We maintain the records of Audit logs.
We have restricted the access of external harddrives, USB etc for all the systems through Active directory and End point security.
We have the security controls in place. We have installed the firewalls to monitor and control the incoming and outgoing network traffic based on predetermined security rules. It helps us to establishes a barrier between a trusted network and an untrusted network.
We have implemented the asset management procedure to identify, classify, label and handle the Information and Information assets according to their criticality and sensitivity.
We have labeled the aseets in order to identify and make sure that the access control permissions are maintained.
we have implemented intrusion detection and prevention tools, we ensure timely detection and investigation in a prompt manner.
These are integrated with security operations/SIEM solutions.
We take an approval from the concerned authority before procuring the equipment or routing connections and test the same before installing it.
All the network devices are securely configured and we always make sure that we monitor the same on regular basis and take appropriate action on any detections.
We use vendor supplied softwares without any changes wherever feasible, if all the security controls are in place.
We consider these factors before making these changes to the softwares.
Yes, we test the changes made on testing environment before moving it to a production environment.
Only authorised individual have an acces to the approved information assets.
we are compliant. We document or have a track of all the changes made to protect the information system.
We are compliant and have these controls in place.
We have the appropriate clauses in the agreements wherever necessary.
We provide guidance for using our products appropriately and take all the possible benefits.
We have the controls in place. All the Critical patches will be deployed immediately
We inform our customers on the vulnerabilities wherever is required from the compliance perspective.
Our product is free from dormant malicious programmes
We test the systems before deploying into operational environment.
We have implemented the System Devolopment Life Cycle procedures and all the testing of new features are documented.
We conduct security assessments before accepting the products and take appropriate approval to make sure that all the security requirements are met.
All the test results are documented.
We record these in the Risk register and documented before purchasing the product.
We make sure that these are met before acquiring and products.
The customer responsible staff can confirm upon validation of the security requirements.
All the design and implemetation has been documented. We conduct the security Risk assessment in order to identify and mitigate the risks.
We have kept Testing and production environment seperately. We do not use any data from our production environment for testing purposes.
All our contracts or agreeements are having appropriate clauses with regards to security compliance, privacy, Audit requirements etc.
we use only licensed softwares or assets
We are compliant. We maintain these records for Audit purposes.
Attached the Information Security Manual. It prescribes the policies that govern the management and administration of the Information Security Management System (ISMS) for application.It specifies the scope and the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving the information security controls.
We have not subcontracted or outsourced any of services with regards to the product.
We have documented the Transfer of Information and it’s a part of our Information security policy
We do not transfer the data. But if its necessary it will be done only upon the approval of the management.
We have documented the Transfer of Information and it’s a part of our Information security policy
We maintain these records for Audit purposes.
We monitor and audit the logs.
We are complied. We have controls in place to make sure that Information system is protected.
We conduct the Risk assessment to identify and mitigate the risks involved.
We use Google workspace as email solution and adequate security features has been enabled to make sure that Information system is protected.
We do not connect.NA
We make sure that all the controls and compensatory controls are in place in order to protect against the Security threats.
We have implemeted the risk management procedure and defined the Risk Treatment, Risk Treatment, Risk Mitigation, and Risk transfer etc
We have implemeted the risk management procedure and defined the Risk Treatment, Risk Treatment, Risk Mitigation, and Risk transfer etc We implement the Compensating security controls wherever measures cannot be applied due to technical or operational infeasibility.
We maintain these records for Audit purposes.
It’s a part of our Internal and external Audits.
We make sure that these controls are in place and security has not been degraded below the accepted level. We also validate these controls during our internal and external Audits.
We have implemented the role based access system and change management policy in order to make sure that we provide an access to an individual only upon need and approval basis. All the changes has been tracked and maintained the records for audit purposes.
We have a up to date records of all the assets used.
We make sure that we follow the Industry best practices and security standard to make sure that we secure the information asset.
We make sure that we follow the existing security controls and implement the compensatory controls to make sure that the information system is secure.
We have implemented the control.
We conduct the Risk assessment to identify and mitigate the risks involved.
Compliant.We review and validate these controls on a periodical basis and These are part of an Internal and external Audits.
Compliant.We review and validate these controls on a periodical basis.
We have the required security controls in place.
We do not use outdated computer hardware, software, technology, services or practices
We upgrade the systems make sure that do not use outdated computer hardware, software, technology, services or practices
We have installed the end point security software on all the computers and servers to keep the computer and personal information protected.
We have installed the end point security software on all the computers and servers to keep the computer and personal information protected.
We are compliant.
We have enabled these features.
We have installed end point security softwares to safeguard from attack scripts, viruses, worms, Trojan horses, backdoors and malicious active content. We also conduct periodical scanning in order to make sure that all the information assets are safe. These are centrally managed and have control on all the end points.
We make sure the Vulnerability assessment has been conducted for our products as per the compliance requirements.
We are compliant.
the customer Sensitive information will not be exposed to the general public.
We document and maintain all the security issues.
We are complaint.
We are compliant. We have clasified, labeled our assets and periodically monitored. All the logs and realtime trafic is monitored.
Implemented. We are compliant.
These are all part of CSP agreement.
We have these controls in place as a part of our Business continuity plan.
We have these controls in place as a part of our Business continuity plan. It has been tested periodically and part of our internal and external Audit.
Agreed. We will sign the NDA
SLA can be documented and agreed by the both the party.
Only authorised individual have an acces to the approved information assets.
We allow our customer to audit but atlease 30 days prior notice with the scope of the audit needs to be communicated
Its documented as per the Risk management procedure.
We have all the details in SLA
We can make our audit reports available
We maintain appropriate reports and records, to monitor and measure the compliance with the security requirements.
We make sure that we follow the risk management procedure and take these factors into consideration.
We have these in place and tested annually.
We have these in place and tested annually.
Our BCP/DR plan supports this.
We review these on annual basis
We have cmmunicated to all the internal and external parties.
It’s a part of Business continuity documents and attached the same for your reference.
The BCP Test and lessons learned has been documented.
It’s a part of BCP documents and we review and update when changes takes place.
These are part of internal and external audits
We have implemented the Corrective Action Procedure.
We conduc the security assessments by the Internal and external auditors
We share the data with our Internal and external auditors
We make sure the Assessments and Audits will be conducted and reported independently.
All the Sensitive information shall be handled as per Policies and procedures implemented.
We have defined it in our compliance policy and Corrective Action Procedure
We allow our customer to audit or assess but atlease 30 days prior notice with the scope of the audit needs to be communicated
We continuously monitor and improve Information security framework to make sure that we safegurd the Information and all the controls are in place.
We make sure that we brings these improvements to Information security systems from the incidents reported and audit observations etc
We have implemented the corrective action plan procedure and review the policies and procedures on annual basis.
It can be included in the agreement and our legal team will review and confirm
Statement of work will have a details of product/service to be provided
We can include the service levels in the agreement. We are not currently having an options for service credits/liquidated damages, if SLA are not met.
We make sure that we have all the controls in place.
We will do this as part of the agreement
We are a multi tenant SAAS system and all our logs will contain data of all customers. We will have our own log monitoring and security analysis.
Attached the BCP/DR documents
We end point security in place
We allow our customer to audit, but atlease 30 days prior notice with the scope of the audit needs to be communicated
We have deployed our application on Amazon web services (AWS) Virtual platform cloud. AWS provides data center security to our application. AWS is ISO 27001;2013, ISO 27017, ISO 27018, SOC 2 certified organization. Xoxoday is also ISO 27001:2013 and GDPR compliant organization. Only the authorised individual have an access as per Access control policy. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access. Xoxoday’s architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows.
Since our services are delivered via. Web, the upgrades and updates to the services are seamless and usually do not involve any actions from the end-users. We try to release our product hotfixes once every week & major features once every month.
Yes. Annually once.
Yes. We are ISO 27001:2013 and GDPR Compliant. We are also compliant with SOC 2 type 1 and on the last phase of Audit. We will share the report once we have it from the Auditor. Attached the ISO 27001 certificate and engagement letter that we have for SOC 2 Audit.
We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it’s linked with the SSO/Active Directory
All the employees initially inform the IT Support team through ticketing systemb the Infosec manager and Final level will be DPO and the management.
The time of support ranges depends on the level of service. RTO and RPO is - 6 mins
our products comply with all the industrial benchmarks and standards when it comes to the Software Development Life-cycle (SDLC). All software development procedures are supervised and monitored by Xoxoday so that they include: security requirements independent security review of the environment by a certified individual code reviews Quality monitoring, evaluation, and acceptance criteria for information systems, upgrades, and new versions shall be established and documented for the clients’ reference.
The data centers are hosted completely in isolation so that the access is limited and controlled. Load balancer allows shifting incremental load and can auto scale based on data load experienced by application. Each instance (EC2 Instance) under fortified VPC network is further conglomeration of Docker Container Web Services and APIs and application layer running on top of it. This helps in managing various aspects and features of application without affecting the functioning of each other and achieving a modular architecture to work as plug and play model. Amazon Cloud Watch is implemented to enable monitoring of the functioning of the application. The data is encrypted using 256-encryption based SSL certificate. To manage security of data Xoxoday plans a quarterly VAPT based security audit of application.
We have implemented policies and procedures as per ISMS and GDPR requirements. We also conduct periodical Internal and external Audit by the third party Auditor. We have deployed our application on Cloud Virtual platform for maximum security. We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We conduct periodical Vulnerability assessment and Penetration Testing from the Inductry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications. We use logical data isolation with the help of company specific encryption keys. Data in non production environment is not updated with the production data. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256 As per the Information security policy and Data protection policy only the authorised individual have an access to the data through internal approving and ticketing system.
We comply with Information security compliance - ISO 27001;2013, SOC 2 and GDPR
Our product is ISO 27001 and GDPR compliant and have the features.
We have health checks along with Self healing mechanisms in place
99.99%
We use logical data isolation with the help of company specific encryption keys. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256. We have the ability to logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant’s data. our network environment is designed and configured to restrict any communication and connection between the tenant’s environment.
Yes. We have the controls in place. We have blocked connecting Hard disk, USB, CD ROM etc to computers and all the devices are centrally managed.
The data is only stored on our application and its deployed on AWS Cloud. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records
We are a SAAS solution. We are cloud hosted.
We use a variety of tools and plugins integrated with Prometheus & Cloudwatch along with health checks for facilitating our uptime/service availability
Xoxoday’s architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows.
active-passive
Yes. we have implemented the cookies policy
Yes, we have the access controls
Yes
Yes, we have the access controls
Yes. Users can updated their information
Xoxoday - application platform has been integrated with Darwinbox with the objective of creating a reward system for employees. Organizations that are using DarwinBox will not only be able to automate their HR processes but can also reward employees to keep them motivated and engaged. Xoxoday application offers a unified rewarding platform that helps organizations build a winning organizational culture through reward and recognition programs that have a global catalog consisting of products and experiences from more than 700+ brands. Please click here to know more - https://xoxoday.gitbook.io/application/developer-resources/integrations/darwinbox-+-application
Yes. Xoxoday’s primary security focus is to safeguard our customers or users’ data. This is the reason that Xoxoday has invested in the appropriate resources and controls to protect and service our customers. We have an Infosec Manager who is responsible for Information security and reports to the Board of Directors of the company. All the job descriptions, role and responsibilities has been documented as per the compliance requirements.
Xoxoday has developed a comprehensive set of security policies covering a range of topics. These policies are shared with and made available to all employees and contractors with access to Xoxoday information assets. Each employee, when inducted, signs a confidentiality agreement and acceptable use policy, after which they undergo training in information security, privacy, and compliance. Furthermore, we evaluate their understanding through tests and quizzes to determine which topics they need further training in. We provide training on specific aspects of security that they may require based on their roles. We spread awareness about the Information security among the employees through posters in public areas, emails, training and orientations etc..
Yes. All new hires are required to sign Non-Disclosure and Confidentiality agreements. The Employee expressly agrees that he/she shall not use Confidential Information provided by the Company in the development or delivery or for personal gain from providing any products or services for his/her own account or for the account of any third party. The NDA signed will be valid till the termination from an employement.
Yes, We have implemented the process for termination from an employement. Once the employee is terminated all the access will be revoked, IDs are disabled, assets are returned and recorded as a part of the exit clearance. We have implemented the access control procedure and all the access will be revoked upon termination or transfer of an emplyees as per the compliance requirements.
Anti-Virus is deployed in all systems and servers for protection against virus and malware. We use Bitdefender end point security for protecting the systems from virus and this has been updated on daily basis and centrally managed.
  1. Reach out to us at cs@xoxoday.com to raise a ticket, if you happen to notice any potential security issue whilst meeting all the required criteria in our policy. 2. The validation of the reported issue in terms of severity & authenticity will be done by our security team in around 90 days. 3. Post validation, steps will be taken to fix the security issues in accordance with our security policies. 4. The owner of the ticket will be informed once the issue is resolved. Security Severity has been categorized as High, Medium and Low. Once the reported vulnerability is closed we will conform the same.
Reports can be generated by the admins through the application. If there are any additional support needed, our customer support team would be able to help and guide on generating report.
We do not use any in-house devoloped applications. We have deployed our application on AWS cloud virtual platform. And AWS is SOC 2, ISO 27001, ISO 27017 and ISO 27701 certified organization. Shared the certificates.
We have implemented the Web application firewall, IDs/IPs and amazon guard duty etc for maximum security. OAuth2 is used to authorize all API requests. We also conduct code review to make sure that the APIs are secure.
Yes. Our employees are having required education and certifications to perform the job.
We do conduct Internal and external Audit very year
Xoxoday is compliant with - ISO 27001:2013, CPRA (California Privacy Rights Act), SOC 2 Type I, CSA STAR Level 1 and GDPR(General Data Protection Regulation). Attached the below mentioned documents. 1. Xoxoday ISOIEC 270012013 Certificate 2. Xoxoday SOC 2 Type 1 Report 2021 3. Xoxoday VAPT Certificate (Conducted by 3rd party vendor) 4. Xoxoday application VAPT Report (Conducted by 3rd party vendor) 5. Xoxoday CPRA Attestation Report 6. CSA STAR LEVEL 1 Compliant - https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday
We have deployed our application on AWS Virtual platform cloud. The AWS Compliance Program helps to understand the robust controls in place at AWS to maintain security and compliance in the cloud. Attached the below compliance certificates and Audit reports – 1. Amazon Web Services ISO 27001 Certificate 2. AWS ISO 27017_certification 3. AWS ISO 27018_certification 4. AWS SOC 2 Report 5. AWS SOC 2 Type I Privacy Report 6. AWS CSA STAR Certificate
Yes. We follow ISO 27001:2013, SOC-2 and GDPR We are ISO 27001:2013 certified and GDPR Compliant.
Yes. We are ISO 27001:2013 certified and GDPR Compliant. We are also complied with Cloud Security Alliance (CSA) STAR level 1.
Its SAAS Solution and available 24*7
It’s a web application. And it can be presented over the calls like MS Teams, Zoom, Google meet etc.
Yes. We have an integration with other applications and provide secure communications.
Yes
Yes. Files will be transferred securely.
Yes.
The solutions integrated with other solutions like Zoho CRM, HubSpot, Darwin box, SurveyMonkey, Freshdesk etc
NA. It’s a SAAS Solution and does not require.
The data will be in our control. And AWS Cloud provide service for deploying our application. AWS is also ISO 27001 and SOC 2 certified organization and adhered to the data governance.
We have implemented all the required Infosec Policies and procedures as per ISO 27001:2013, GDPR and SOC-2
We perform Internal Audit and external Audits annually. We also conduct Security assessments and testing like Vulnerability assessment and Penetration testing every six months. Yes. We communicate these assessment results to clients on a yearly basis.
We have the arrangements in place. Storage Period would be as per regulatory conditions. Personal data can be deleted based on a formal written request. Xoxoday would delete the data within 30 days of receiving the request. We will delete the data of the customers upon the termination of the contract and Our data cleansing process goes through an organized purge. Once the data is purged, it’s purged from all places
We have implemented all the SOC controls and in the last phase of Audit. We would be able to provide SOC 2 Type I report in next 2-3 weeks
We have BCP/DR Policy as per the Infosec compliance requirements and we conduct the BCP test annually. See Business Continuity Management Procedure attached.
See attached Incident Management Procedure attached
Yes. An independent security third party audit been completed by “TUV NORD”. The last last day of Audit was 29th June 2021
We have establised the Information security management systemIt specifies the scope and the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving the information security management system (ISMS) at Xoxoday. Xoxoday is committed to ensure Integrity, Confidentiality, Availability and Security of its Physical and Information Assets and also maintaining privacy for serving the needs of the customers and organization while meeting appropriate legal, statutory and regulatory requirements. Attached the Information Security Management System Manual.
We have the Data security Controls in place. We have implemented IDS/IPS, Firewall and our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting. We have Cloudflare web application firewall for maximum security of data. We have implemented the role based access control system to make sure that the data os available only to an authorised individual. Nreach Online Services Pvt ltd, respects the individual right to their personal information and is committed to use minimum personal data with transparency, accuracy & protection of confidentiality, integrity, availability, privacy, authenticity & trustworthiness, nonrepudiation, accountability and auditability of the data received, stored, processed and destroyed for business purposes. Atatched the Xoxoday GDPR Data Security Policy
We are compliant. We collect the data only throigh our application. We have role based access system to make sure that only the authorised individual have an access to the required information All the devices and emails are having adequate security controls. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. We have installed the firewalls to monitor and control the incoming and outgoing network traffic based on predetermined security rules. It helps us to establishes a barrier between a trusted network and an untrusted network. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory for more security. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.We have SDLC Policy as per ISMS requirements and we follow General Coding Practice. For example - We Conduct data validation on a trusted system, All cryptographic functions used to protect secrets from the application user.We also have Implemented least privilege; restrict users to only the functionality, data and system information that is required to perform their tasks.
Yes. We have Implemented the SPF/ DKIM/ DMARC effectively.
We are compliant. We have implemented the Password Management Policy We store password hashed. We have SHA512 hash with unique salt for every password. The password needs to be minimum 8 characters long and should contain at least one capital letter, special characters among ’# $ % * &’ and 1 digit. Maximum Password Age is 45 days. User IDs and passwords transmit through stringent checks in an encrypted format that complies with the current Technical Security Baseline Standards. All the user can set their own password from the very first login attempt. Passwords once used cannot be reused with the password history technique in order to disallow the reuse of old passwords.
We inform Fincare if these regulatory authories agreed to inform.
Yes. 30 days prior notice and scope of the Audit needs to communicated.
We are a multi tenant SAAS system and all our logs will contain data of all customers. We will have our own log monitoring and security analysis.
Its a SAAS product and we use We use TLS1.2 encryption for Data in transit and AES256 for Data at rest.
Yes
Yes
We do not own the data centers. We deploy our application on AWS cloud virtual platform.
Attached the ISO27001:2013 certificate. We do not collect and store any Payment card details. PCI DSS is not applicable for us.
We inform the client if there is any changes of the design that impacts security posture of the system.
We take steps to securely develop and test against security threats to ensure the safety of our customer data. We maintain a Secure development Lifecycle, in which training our developers and performing design and code reviews takes a primary role. In addition, Xoxoday employs third-party security experts to perform detailed penetration tests on different applications. application is ISO 27001, GDPR, CPRA/CCPA, CSA STAR certified.
Our technical team maintains these records.
We consuct the code review as per the compliance requirements and maintain the code repository. Attached the SDLC Proedures.
Compliant.
Since application is a SaaS Platform this would be not applicable.
Since application is a SaaS Platform this would be not applicable.
Since application is a SaaS Platform this would be not applicable.
We are compliant with the requiremenrts.
We do not transfer manually. NA And we use Google workspace for emailing solution.
cryptographic keys are protected. Compliant.
We do not store any PHI. The PII(name, email ID, phone#) are encrypted. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security.
We store only the PII(name, email ID, phone#) and does not store/process PHI & PCI. We are compliant with ISO 27001, CCPA/CPRA, EU GDPR, CSA etc. Attached these compliance certificates/audit reports.
Yes, all the mechanisms related to security and policies are implemented to facilitate timely decision and investigation by root-cause analysis. These incidences are analyzed with network intrusion detection (IDS) tools.
The information used for authentication is securely stored and transmitted. We store password hashed. We have SHA512 hash with unique salt for every password
Not applicable since application is a SaaS platform.
At Xoxoday we use Google workspace and activated the MDM features. application also has iOS and Androind mobile applications.
This feature can be configured with the help of the MDM Solution that the customer use.
At Xoxoday we use Google workspace and activated the MDM features.
Compliant. We have segreated the roles and assign the responsibilities to our employees.
Since its a Cloud hosted SaaS platform deploying of the application on cloud and server scannings are under the scope of Xoxoday.
We use Web application firewall (WAF) and pfSense firewall for security reasons. 1. The Cloudflare Web Application Firewall (Cloudflare WAF) checks incoming web requests and filters undesired traffic based on the set of rules. 2. pfSense helps to monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on a defined set of security rules.
At xoxoday we monitor and maintain the logs. The Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
At Xoxoday we have implemented the Active directory and the system will get locked if its inactive for more than 15 mins and re-autentication would require.
We have the process in place for standardized approach to structured exception and error handling across all layers.
At Xoxoday the validation has been done during the development and testing and we are compliant with the requirements.
At Xoxoday Security and compliance requirements are considered during the development stage and we are ISO 27001, CPRA, CSA STAR level 1, GDPR compliant.
We have implemented the controls to monitor the application and safegurd from the attacks. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails.
Since application is SaaS Platform it would be not applicable.
We have implemented the Software Development Life Cycle (SDLC) procedure and attached the same for your reference. Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing. We remidiate or fixes the issues identified during the VA/PT assessment and make sure that the application is free from the vulnerabilities.
Since it’s a SaaS platform and deployed on AWS cloud virtual platform Singapore region. All the data will be stored on AWS VPC.
Xoxoday is ISO 27001:2013 certified. An ISMS is a framework of policies and procedures that includes all legal, physical and technical controls involved in an organisation’s information risk management processes with the aim of keeping information secure. With ISO’s robust information security management system (ISMS) in place, you gain the additional reassurance that a full spectrum of security best practices is implemented across the organization Our Goal is to protect three aspects of information - Confidentiality: only the authorized persons have the right to access information. Integrity: only the authorized persons can change the information. Availability: the information must be accessible to authorized persons whenever it is needed.
We have implemented the Access control policy to control the upload, download, viewing and modification
AV Scans takes place every week and users also can scan it whenever they can scan the machine. We have prescheduled the scanning once in a week.
We are using linux operating system which is inherently secure along with security practices like web application firewall etc We make sure that the customer data is well segregated and compartmantalized
No Breaches taken place.
We are having Robust Information security compliance framework and we are ISO 27001:2013 and GDPR complied. We follow all the applicable infosec compliance requirements to comply with the regulations
We conduct the Risk assessment and compliance review on annual basis as per the compliance requirements.
Yes. All the compliance and audit findings has been mitigated.
All the vulnerabilities identified during the assessment has been fixed.
We use Bitdefender end point security and installed on servers and development machines.
Its updated on regular basis.
Our roles and job duties are segregated through role-based access to ensure maximum security. Access to data and systems are based on the principles of least privilege for access. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access events.
Its restricted and not available to the public.
We follow the best practices ans servers are hardened for security reasons.
We have implemented the Identity access management (IAM) and follow the Access control policy.
At Xoxoday we follow the password policy.
We have deployed our application on AWS Virtual platform cloud - Singapore region.
RTO and RPO is 60 Minutes.
We have implemented the Incident Management Procedure and attached the same for your reference.
Since application is a SaaS product and the customer can use the product and services as soon as subscribed for application product usage. the customer will have the legal rights to use the Product.
We do not change the terms frequently. We will provide 30 days’ notice period for any changes of terms.
We notify Client in case of any unauthorized disclosure of or breach of any confidentiality obligation of Xoxoday with respect to Confidential Information, data or information of Client and Xoxoday shall take all necessary and required steps and measures to mitigate such unauthorized disclosure or breach and shall co-operate with Client , at Xoxoday ‘s cost, to mitigate or control the loss or liability arising out of such disclosure or breach and to retrieve such data or information.
Yes. have an active SLA in place that identifies minimum performance of the Product.
We have the SLA in place. application endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week. Uptime is measured based on the monthly average of availability.
We would be able to provide a report on need basis.
No penalties are associated with SLA.
We monitor the service continuously and make sure that the product and service is available to use all the time. We have a documented Business Continuity and Disaster Recovery Plan defined and implemented to enable people and process support during any crisis or business interruptions.
Since our services are delivered via. Web, the upgrades and updates to the services are seamless and usually do not involve any actions from the end-users.
Yes.
Our architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows. If there is any major activity and the service will be unavailable, the Maintenance hours were communicated well in advance at least 3-4 day by application.
Termination clause will be the part of Master Service agreement and both the parties can review and agree during entering into an agreement.
Since it’s a SaaS product, this is not applicable.
Termination clause will be the part of Master Service agreement and both the parties can review and agree before entering into an agreement.
Yes. changes to the production environment or development are documented, tested, and approved prior to implementation or any new releases. We conduct internal reviews and audited by the external auditors for our security standard certification. We conduct periodical Vulnerability assessment and Penetration Testing from the Industry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications.
At Xoxoday we have implemented the Cyber Crisis Management Plan to provide and support capability for reporting and responding to cyber security incidents, to eliminate or minimize impacts of such incidents
No.
We monitor the logs on regular basis with regards to network, file and server, and security system. To provide more information, the infrastructure logs are collected using AWS Audit Trail and Application related logs are collected in our Elastic Search server and retained in long term cloud storage.
No. Since we are a multi-tenant system, our logs contain information of all the tenants. We cannot isolate a single customer’s information from our logs.
At Xoxoday the Audit logs reviewed on a regular basis for security events. audit logs are set up, reviewed by our Technical team and logs are recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
We are GDPR Compliant. Our information security team and Customer support team will inform the POC of Client via email communication with Preliminary Incident Synopsis and Root Cause Analysis report (RCA) including the details of Business Impact, Issue Description, Root Cause, and Corrective Actions.
Yes. We have implemented the incident response plan and it complies with industry standards ISO 27001:2013, SOC-2, GDPR.
We are ISO 27001:2013 certified and attached the certificate.
Yes, there are established policies and procedures for label inheritance of TCCC data and objects which contain data, per the TCCC Information Classification Standard and Protection Measures. Mechanisms for label inheritance shall be implemented for objects that act as aggregate containers for data.
Yes, we adhere to the retention policy that the tenant sends out for optimal collaboration and smooth user experience with Xoxoday’s products and services.
Your data is of the utmost importance. All the security mechanisms and policies are established and implemented in such ways that data leak can be prevented, in transit as well as at rest.
Yes, the policy, process, and procedure is implemented to ensure proper segregation of duties. These can be asked for and delivered upon tenants’ requests. In the event of user-role conflict of interest, technical controls shall be implemented to mitigate risk (if any) from unauthorized/unintentional modification/misuse of organizations’ information assets.
Yes, our products comply with all the industrial benchmarks and standards when it comes to the Software Development Life-cycle (SDLC). All software development procedures are supervised and monitored by Xoxoday so that they include:
  • security requirements
  • independent security review of the environment by a certified individual
  • code reviewsQuality monitoring, evaluation, and acceptance criteria for information systems, upgrades, and new versions shall be established and documented for the clients’ reference.
Yes, our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase.
Yes, an independent security review is conducted by certified professionals to look for any security vulnerabilities in order to solve them before deploying to production.
Yes, our products comply with all the industrial benchmarks and standards when it comes to the Software Development Life-cycle (SDLC) security standard.
Yes, changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates and modifications. Any change in roles, rights, or responsibilities shall be documented for a seamless experience.
We have a consistent and unified framework for business continuity planning, disaster recovery, plan development. All the appropriate communications shall be established, documented, and adopted to ensure consistency in business continuity. This includes protection against natural and man-made disasters (e.g. fire, flood, earthquake, war, volcanic activity, biological hazard, civil unrest, mudslide, tectonic activity, utility services outages, etc.).
Our hosting options are limited to Xoxoday’s jurisdiction and are backed by prominent business continuity plans. Hence, we don’t find the need to provide geographically diverse hosting options.
The capability to transfer infrastructure service failover to other providers is not provided to the clients.
Business continuity plans shall be subject to test at least annually or upon significant organizational or environmental changes to ensure continuing effectiveness.
Along with an aligned enterprise-wide framework, we perform independent reviews through industry professionals along with formal risk assessments. These are done at least annually or at planned intervals to determine the likelihood and impact of all identified risks. With qualitative/quantitative methods ensuring our compliances with policies, procedures, and standards, we stick to the best standards.
Yes, our stringent checks and tests are conducted annually to keep up the cloud service infrastructure hygiene as per the industrial standards.
Annual audits are processed both internally and externally. The audit results can be sent over to tenants upon request.
Yes, the tenants can request for penetration results and get the reports from our end.
No, we do not process your payment card data for any reason other than billing purposes.
Yes, we are compliant with the Indian IT Act of 2000.
There is no such process available from our end.
We will terminate the contract as per rules and statutes. Meanwhile your data will be stored with us and won’t be given back to you. However, if the tenant wants the data to be erased, it can be done so upon request.
Yes, we store data that’s required for seamless rewarding and recognition. We conduct regular audits to ensure safety of data like employees’ names, emails, employee numbers, etc. are used for verification and rewarding purposes.
Xoxoday’s information and cyber-security team keeps a watchful eye on all potential sources of threats and areas of compromise when it comes to information security.
Roles are systematically defined for information security measures to tactfully align all operations, preventing any security breaches.
Employees must agree with the acceptable usage policy of peripherals and devices to prevent malicious activities from the inside and out.
Our environment has all the capabilities to be SOC-2 Type-II compliant but the certification is yet to come through. It shall be updated soon.
No, our environment is not CSA-certified.
Xoxoday keeps track of all security requirements with respect to legislations, statutes, and contracts. They are documented in all steps.
With different metrics tracking cyber-security measures, Xoxoday keeps the effectiveness in check with regular monitoring.
Xoxoday’s Human Resource operation procedure takes all measures of employee confidentiality into consideration.
Yes, Xoxoday performs a thorough background check on every employee before they get onboard. The Non Disclosure Agreement ensures that the information is secure even after the contract is terminated.
Yes, our Xoxoday Store vouchers are procured from third-party vendors. These vouchers are shared with the tenants in order to be showcased to users of Xoxoday platform.
No, the third parties and vendors we deal with our confidential to Xoxoday. Hence, this list cannot be shared.
Yes, there’s a third-party security policy present to safeguard the interests of Xoxoday’s tenants as well as the end users.
Yes, our third party security policy deems it clear to comply with security obligations and we monitor their compliance regularly.
Yes, we have a detailed risk management procedure in place to address situational issues like change of services being provided to tenants.
No, our customer requests are addressed by the Xoxoday customer support team for maximum efficiency.
Yes, Xoxoday’s brand protection caters to any malicious interruptions and fallacies as they are addressed in prompt time.
Yes, with media platforms being the biggest pedestal for information sharing, we keep an eye out for any brand protection issues.
Yes, in the event of a rapid spike/slump in network traffic or host activity, Xoxoday analyzes the traffic to detect and prevent unauthorized or erratic behavior.
Yes, in order to ensure airtight security of data, we have a mandatory and sessional privacy training and awareness module.
The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment.
Important features of CSA STAR LEVL – 1 are listed below
  • Operating in a low-risk environment
  • Wanting to offer increased transparency around the security controls they have in place.
  • Looking for a cost-effective way to improve trust and transparency.
Yes, We comply with these requirements. Our Cloud Security Platform, (CSP) Amazon Web Services (AWS) provides these securities to our data centers.
Production data shall not be replicated or used in non-production environments. We do not use LIVE data in any other environment. We comply with the requirement.
We take prior authorization from the concerned authority as per the Media protection procedure before relocation or transfer of hardware, software, or data to an offsite premises.
As per Mobile Security Compatibility compliance requirements we have a documented application validation process to test for mobile device, operating system, and application compatibility issues.
The California Privacy Rights Act (CPRA) is a state-wide data privacy bill that amends and expands the existing California Consumer Privacy Act (CCPA). The CPRA works as an addendum to the CCPA, strengthening data privacy rights for California residents, tightening business regulations, and establishing the California Privacy Protection Agency (CPPA) as lead enforcer and supervisor.
Yes. We are compliant with CPRA, and Our solution will continue to offer full compliance with the new and updated data privacy regime.
Yes. We support our consumers to exercise their rights as per the CPRA.
Yes. We have implemented all the privacy controls and audited the same with the help of external Auditors.
Yes. Please reach out to our sales representative/Xoxoday POC to have access to the CPRA report.
No. We do not collect any data from any users across the globe who are not 18 years old.
Yes. The data subject can authorize an agent (an “Authorized Agent”) to exercise their rights. To do this, the data subject must provide your Authorized Agent with written permission to do, and we may request a copy of this written permission from your Authorized Agent when they make a request to exercise the rights.
You may submit a Valid Request by emailing cs@xoxoday.com.
No. We will not sell, rent, or share Personal Data with third parties outside of our company. But Personal Data may be provided where we are required to do so by any privacy laws.
SOC 2 compliance is part of the AICPA Service Organization Control reporting platform. The goal of SOC 2 is to evaluate organization security and internal controls around security, availability, processing integrity, confidentiality, and privacy.
SOC 2 Compliances are developed by the American Institute of CPAs (AICPA), it defines criteria for managing customer data based on five “trust service principles”—security, availability, processing integrity, confidentiality, and privacy.
Yes. Xoxoday is SOC 2 certified organization. We have implemented all the required SOC 2 controls and got them Audited with the help of Certified Public Accountants (CPA).
Amazon Web Services (AWS) has achieved SOC 1, SOC 2, and SOC 3 reports. These reports detail the AWS controls environment and implemented controls for AICPA Trust Services Criteria (TSC) and can be leveraged as part of a cloud customer security program. AWS SOC-covered cloud services are audited periodically against the SOC reporting framework.
You may reach out to our sales representative/Xoxoday POC to have access to the SOC 2 report.
Laika Compliance LLC performs the SOC 2 audit for Xoxoday.
The SOC 2 Type I report is valid for one year following the date the report was issued.
Yes. SOC 2 is an internationally recognized standard. The SOC 2 report and certification involve an independent audit by a third party.
Yes. We do conduct the SOC 2 Audit on an annual basis.
The Auditor has validated and tested all the applicable SOC 2 controls as per the compliance requirements.
We do not process (Collect/Store) Protected Health Information (PHI).
Yes. Xoxoday is compliant with Health Insurance Portability and Accountability Act (HIPAA).
Yes. Please reach out to our sales representative/Xoxoday POC to have access to the HIPAA Audit report.
Yes. We have implemented the Data Subject Access Rights Procedure to make sure that all the data subjects will have the opportunities to exercise their rights as per the privacy laws.
The secure deletion standard like DoD 5220.22-M ECE is being followed and we provide a certificate that the data was properly sanitized from all computing resources and portable storage media.
Yes. Xoxoday is GDPR Compliant. We have implemented the Data Subject Access Rights Procedure as per the GDPR and made all the data subject rights available as per the data protection laws. This procedure sets out the key features regarding handling or responding to requests for access to personal data made by data subjects, their representatives or other interested parties.
Yes. We validate the compliance requirements of the Sub-processor and obtain the Compliance certificates and audit reports such as – ISO 27001:2013, SOC 2 Type II, ISO 27017, ISO 27701, ISO 27018, Cloud Security Alliance Controls, etc.
We conduct the independent Audits for - ISO 27001:2013, SOC 2 Type I, CPRA/CCPA, HIPAA, VA/PT Assessments.
Xoxoday maintains a disaster recovery program to ensure services remain available or are easily recoverable in the case of a disaster. Customers can stay up-to-date on availability issues through a publicly available status website covering scheduled maintenance and service incident history. The BCP and DR Plans are tested and reviewed every year. The Xoxoday BCP and DR plans are reviewed and audited as part of ISO 27001 standards and SOC 2 Type II covering availability as one of the trust service principles.
Users are not having admin access to their computer machines and only IT Support admins can install or uninstall the softwares.
CTOs and Production heads are responsible for safeguarding the customers data. Only authorised individual will have access to the production environment.
We delete the customer data upon request/termination of the contract and confirm the secure deletion. Our data cleaning process goes through an organized purge. Once the data is purged, it’s purged from all places.
We clasify the Information assets into Confidential, Restricted , Internal and Public etc..
We maintain the records of all our assets.
we logically segregate the tenant’s data, and it is segregated with a client-specific key for proper handling and security reasons.
We have restricted the ports for all the users as per Xoxoday IT Policy
The password needs to be minimum 8 characters long and should contain at least one capital letter, special characters among ’# $ % * &’ and 1 digit Maximum Password Age – 45 days Minimum Password Age – 1 day Computer machines will lockout in 15 mins from the time it became inactive.
Yes. Only authorised individual have access.
We use best practices and industry standards to achieve compliance with industry-accepted general security and privacy frameworks. We use enterprise-class security features and conduct comprehensive audits of our applications, systems, and networks to protect customer and business data. Our customers rest easy knowing their information is safe, their interactions are secure, and their businesses are protected. Please click here to know about Xoxoday Security framework - https://www.xoxoday.com/security
We are compliant. We monitor the system performance.
Yes. We maintain current architecture diagrams that include data flows between security domains/zones
All operating systems are hardened as per Xoxoday hardening guidelines.
We are compliant. We have deployed our applications on AWS Virtual platform cloud.
Appropriate roles and responsibilities have been defined and documented. Finance, Leagl, Admin, Infosec departments are active part of it.
Since its SaaS platform is not applicable.
Yes. we conduct the testing on frequent basis to comply with the requirements.
Yes. Its compliant with ISO 27001 and SOC 2 trust service principles.
Yes. We mitigate all the risk identified.
We inform the customer if there is any incidents as per the security and privacy laws.
Yes. We do conduct an internal Audit.
Yes. Privacy and security is a part of the Master Service agreements.
Xoxoday is compliant with GDPR, HIPAA, CCPA/CPRA privacy laws. And we inform the customer if there is any data breaches as per the compliance requirements.
Yes. We provide report on SLA.
We do conduct an External Audit with the help of the independent auditor.
Yes. we conduct the assessment on annual basis.
AWS is a sub-processor as we are storing data on AWS VPC. And they are AWS SOC 2, ISO 27001, ISO 27017 and ISO 27018 certified We monitor the compliances of sub-processor on frequent basis.
We continuosly train employees on privacy and security.
Yes. We have member in our organisation with dedicated information security duties. Xoxoday’s primary security focus is to safeguard our customers or users data. This is the reason that Xoxoday has invested in the appropriate resources and controls to protect and service our customers.
All our employees are having the unique log in IDs.
We have installed the firewall for maximum securty and configured to restrict unauthorized traffic
All are configured according to security standards as part of the build process
Its part of our Internal and external Audits and validated by the indeendent auditors.
We have implemented the access control policy and access will be provided only upon need and approval basis. Attached the access control policy.
We have track of the changes. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
We have installed Smoke detectors and Fire extinguishers for physical security.
security incidents reviewed to capture the root cause.
We are SOC 2 compliant and we have engaged Laika Compliance LLC, an independent assessor firm, to conduct a SOC 2 Type 1 and SOC 2 Type 2 examination for the Xoxoday Platform against the Security and Confidentiality Trust Services Categories.
Attached the ISO 27001:2013 certificate.
We provide Software as a Service.(SAAS). We are ISO 27001 certified and GDPR compliant. Attached the document.
We are ISO 27001 certified and GDPR compliant. Attached the document.
Since it’s a SaaS prodcut and deployed on cloud virtual platform only authorised individual have an access to the our production environment on need and approval basis.
We inform the client to revoke access.
We use Google workspace and have secure mode of sharing the data.
We can manage all the enpoints centrally.
We have implemented the security measures to manage the risks introduced during the use of Organization’s information assets used for managing Personally Identifiable Information.
We have a formal risk assessment process and conduct the risk assessment annually.
All the contractors/vendors have signed the NDA and contracts All the necessary clauses has been included in the agreements with regards to Confidentiality, liabilities, termination etc
Yes. We do conduct the Risk Assessment every year.
Yes. We have implemented the Data security and Information clasification policy. Attached the same.
Yes. They have signed for the agreements.
We have a biometric systems and access cards. only authorised individual can have access.
We have deployed Sensors for fire detection and fire extinguishers to detect and protect from the fire.
Yes, we will notify
Yes. Our Customer support team will notify.
Yes. We create an email accounts only after the approval from reporting managers.
We have not outsourced and does not create any email ids
Yes. IT Team is responsible.
Yes. We have a Email Security Policy and attached the same
Yes, we have implemented the security controls for email with the help of Google workspace and installed the end point security for all the laptops of the employees. All the incoming and outgoing attachments are scanned.
Yes.
Yes, We have implemented the Acceptable Usage Policy and have restricted for usage and access to internet.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. Since our application is deployed on AWS cloud we will ensure the best uptime in the insudtry.
Yes. All the changes takes place as per the change management policy implemented.
Yes. We have software register and only approved and licensed softwares will be used.
Yes, all are up to date.
Yes, we have capacity planning and monitor the hard disk space, RAM, CPU etc.
All the employees laptop is secured with Bitdefender end point security software
Yes
Yes. Taken into consideration
Annually
We do consider all of these, addition to that we also validate the controls in place with regards to cloud security, BCP, Uptime etc. AWS is ISO 27001, SOC 2 Type II certified and complied with CSA start level 2. Please click here for more details about AWS Compliance Programs - https://aws.amazon.com/compliance/programs/
We have implemented policies and procedures as per ISMS and GDPR requirements. We also conduct periodical Internal and external Audit by the third party Auditor. We have deployed our application on Cloud Virtual platform for maximum security. We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We conduct periodical Vulnerability assessment and Penetration Testing from the Inductry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications.
Yes. AWS is ISO 27017, ISO 27001:2013, ISO 2018, SOC 2 certified.
Yes. Attached the AWS ISO 27001 certificate
We ensure that we maintain confidentiality, integrity, availability and privacy of data collected, processes, stored through implementing policies and procedures. And we do conduct the internal and external Audits periodically to make sure that all the controls are working effeectively.
Yes
Yes
Yes. Audited by the independent Auditor and all the aspects of Privacy, information security, BCP, DR, Production, VAPT has been validated.
NO
Production Site - No.17, Bhagyalakshmi Square, 2nd Floor, Sector 3, HSR Layout, Bangalore -560102 We have deployed our application on AWS Singapore. Since we have deployed our application on AWS cloud they only provide DR Services.
No other location
We provide our application to the customer. We have 230+ employees. 100+ employees are involved in the production/devolopment and we have a sepearate team for IT Support and Information security. We have provided separate computers to each employees. Altogether we are having around 250 computer machines. Our application is deployed on AWS cloud virtual platform.
Xoxoday is ISO 27001:2013 certified, GDPR compliant and SOC 2 type I certified organization and have all the required technical and organizational controls in place and auditred during the internal and external audits.
We have implemented the Information classification Policy to protect against unauthorised access, disclosure, modification, or other misuse. All our assets are labelled as per the requirement.
Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. A strong identification and authentication system and logging systems are deployed and provide a centralized control to administer, monitor and review all critical access. We have a role-based access system through access control policy to make sure that only the authorised individual has access to the required information. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. The approvers are either the Product Heads or respective function Heads are their authorized delegates.
We have the Fire alarams, Smoke detectors, UPS, Temperature controler, Air conditioner, etc.. for protecting against the environmental hazards.
Yes, all our - both full-time and on-contract are bound by an agreement of non-disclosure and a confidentiality agreement as a condition of employment to protect the customers and tenant’s information.
We use the CCTV cameras to monitor the building on a 24_7_365 basis. All the enterances, exit, restricted areas are under surveilance for security reasons.
Yes. We have the Information security team.
We are compliant
In accordance with Data Protection Laws, we make available to Controller on request in a timely manner such information as is necessary to demonstrate compliance by Processor with its obligations under Data Protection Laws. Upon Controller’s written request and subject to the confidentiality obligations set forth in the Agreement, we will make available to Controller a copy of Nreach the most recent third-party audits or certifications, as applicable. We do not agree for the Surprise audits.
We have the Buiness continuity and Disaster Recovery Plan in place. These controls has been tested at least annually as per the compliacne requirements. Attached the policies for your referrence.
We have the Crisis management is in place. Attache the same. We have provided an option to work from home/remotely due to this pandamic with necessary infrastructure and security. Business continuity plan has been tested on annual basis and audited during the internal and external audits. Atatched the business continuity policy and plan.
Generic IDs are not used
We have the ability to delete the data upon request by the data subject or termination of the contract. Attached the data retension and disposal policy.
We have implemented the Business continuity policy and we have the ability to resume our operation from potential threats, Pandemic, flood, fire, earthquake etc. Due this pandemic/WFH situation, VPN access has been enabled with 2FA For such authorized individuals, for ensuring business continuity. We have the required controls in place for working from home or remotely due to this pandemic situation.
Its a part of our Business continuity plan and IT Support Head, HR Head, CTO, Infosec Head will be involved in the preparedness activities.
We have provided WFH option to all the employees to get protected from COVID 19.
We have provided WFH option to all the employees to get protected from COVID 19.
We test the Business continuity plan on annual basis. It was tested in the month of Aug 2021 for the last time.
It has been well defined in the in the Business continuity policy and plans. Attached the same for your referrence.
We inform our customer on any crisis and if that is effecting on our customers.
Xoxoday is a data processor.
NO. We obtain consent before such activities from the customer.
We have the DPA and appropriate controls in place – We are compliant.
ISO 27001;2013, SOC 2 Type I Certified and GDPR compliant.
YES. We have implemented the Business continuity plans and tested them annually.
No. But we are in the process of getting the insurance from the Insurance company.
We conduct the internal and External audits on a periodical basis as per the compliance requirements and obtain Audit reports and certifications. We provide the same with the customers.
application by Xoxoday, the RnR platform is a cloud-based SaaS platform hosted on VPC infrastructure of AWS. The data centers are hosted completely in isolation so that the access is limited and controlled. Each instance (EC2 Instance) under fortified VPC network is further conglomeration of Docker Container Web Services and APIs and application layer running on top of it. This helps in managing various aspects and features of application without affecting the functioning of each other and achieving a modular architecture to work as plug and play model. Amazon Cloud Watch is implemented to enable monitoring of the functioning of the application. We have Web application firewall (WAF), IDS/IPS, AWS Guardduty, and the data has been encrypted for security reasons. Attached the Architecture diagram.
Xoxoday is ISO 27001:2013 certified and GDPR compliant.
Xoxoday is ISO 27001:2013 certified and GDPR compliant. And we follow ISO 27001, NIST, CSA standards and best practices. We have Web application firewall (WAF), IDS/IPS, AWS Guardduty, Coudflare and the data has been encrypted for security reasons. We conduct code reviews as per the compliance requirements. We also conduct the Vulnerability assessment and penetration testing on annual basis with the help of the third party authorised vendor. Attached the latest VAPT certificate and ISO 27001 certificate.
Attached the ISO 27001:2013 certificate and 1st Year Surveilance audit report. We did not have any non-confirmities.
We are compliant with the data privacy and security requirements. We are having the controls in place with regards to Cyber security, Risk management, crisis management, business continuity, Network security, application security etc. Attached the Business continuity management and Cyber Crisis Management Plan, incident management procedures, SDLC etc.
Attached the Business continuity plan and procedure. We test the BCP controls on annual basis as per the compliance requirements and it has been auditted during the internal and external audits.
Xoxoday is ISO 27001:2013 certified, CSA START Level 1 and GDPR compliant. And we follow ISO 27001, NIST, CSA standards and best practices. We have Web application firewall (WAF), IDS/IPS, AWS Guardduty, Coudflare and the data has been encrypted for security reasons. We conduct code reviews as per the compliance requirements. We also conduct the Vulnerability assessment and penetration testing on annual basis with the help of the third party authorised vendor. Attached the below policies and procedures - 1. Encryption Policy 2. Password Management Policy 3. IT Policy 4. Information Classification Policy 5. Threat and Vulnerability Management 6. Cyber Crisis Management Plan 7. Backup Recovery Procedure 8. Access Control Procedure 9. Incident Management Procedure 10. Change Management Procedure
Data centers are designed to anticipate and tolerate failure while maintaining service levels. In case of failure, automated processes move traffic away from the affected area. These are tested on annual basis. AWS is also ISO 27001, ISO 27017, ISO 27701, ISO 27018, SOC 2 compliant organizatin. Please click here for more details - https://aws.amazon.com/compliance/programs/ Please click here to know more about AWS security - https://aws.amazon.com/compliance/data-center/controls/ Please click here to know more about Xoxoday Service level agreement - https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view
Please click here to know more about Xoxoday Service level agreement - https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view
Please click here to know more about data governance - https://www.xoxoday.com/gdpr
Attached the Risk Management Procedure
We have plan for having the cyber insurance. - In progress.
Each employee, when inducted, signs a confidentiality agreement and acceptable use policy, after which they undergo training in information security, privacy, and compliance. Furthermore, we evaluate their understanding through tests and quizzes to determine which topics they need further training in. We provide training on specific aspects of security that they may require based on their roles. We have implemented the Information security policy and Disciplinary policy.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently.
Please click here to know more about the Application SLA - https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view?usp=sharing
We review and get an approval from the management on annual basis as per the compliance requirements.
We have installed End point security on all the computers and monitored and updated on regular basis.
Yes. Our tenants can report the Bugs and security vulnerabilities to cs@xoxoday.com We also have Bug Bounty Program at Xoxoday and please click here to know more about - https://www.xoxoday.com/bug-bounty
Since application is a SaaS platform and deployed on AWS virtual platform cloud
NA. We have the full time employees.
We conduct the review and update the policies, procedures etc..and take an approval from the management on annual basis as per the compliance requirements. We also communicate all the policies and procesures to all the employees, contractors through HRMS platform.
We do not allow to access the infrastructure hosting.
All the information security policy and standards been approved by senior management.
We have installed the antivirus on all the workstations and servers.
Customer data security is an essential part of our product, processes, and team culture. Our facilities, processes and systems are reliable, robust, and tested by reputed quality control and data security organizations. We continuously look for opportunities to make improvements in the dynamic technology landscape and give you a highly secure, scalable system to provide a great experience. Attached the GDPR - Data security policy.
We have installed Bidefender endpoint security and restricted the access of external hard drives, USB etc to have restriction on data transfer. we use file integrity and network intrusion detection (IDS) tools to help facilitate timely detection, investigation by root cause analysis, and response to incidents
We do not use.
Annually
We have conducted the BCP test on 6th Aug 2021. Attached the Business continuity policy.
We have installed Smoke detectors and Fire extinguishers for physical security.
Attached the incident management procedure. All our policies are reveiwed annuaaly and approved by the top level management.
security incidents reviewed to capture the root cause.
Attached the Security Incident Reporting and Response Procedure
Classification of Incidents are done. Attached the Incident Management Procedure
No Security breaches till date.
We are SOC 2 compliant and we have engaged Laika Compliance LLC, an independent assessor firm, to conduct a SOC 2 Type 1 and SOC 2 Type 2 examination for the Xoxoday Platform against the Security and Confidentiality Trust Services Categories. Attached the engagement letter.
Attached the ISO 27001:2013 certificate.
We make sure that they have adequate controls in place and meet the security standard.
We are ISO 27001 certified and GDPR compliant. Attached the document.
We review these to make sure the all the controls in place.
We provide access only upon need and approval basis.
We use Google workspace and have secure mode of sharing the data.
We can manage all the enpoints centrally.
Attached the Risk Management Procedure
We have a formal risk assessment process and conduct the risk assessment annually.
All the contractors/vendors have signed the NDA and contracts All the necessary clauses has been included in the agreements with regards to Confidentiality, liabilities, termination etc
The SaaS solution is deployed on Public cloud.
Yes
Yes. We are using Bitdefender endpoint security.
Yes. We use for security reasons
Our employees will not have access by default. The data will be accessed only upon need an approval basis. The access is controlled through the AWS Identity and Access Management system that also enforces two-factor authentication
We collect only 3 types of the personal Information such as Name, email ID, phone#. , personal data is to be transmitted using firmly approved encrypted systems. We have implemented the role based acccess control to make sure that the acccess has been granted to only authorised individual.
Yes.
Yes. We inform the client about any security incidents.
Yes. Attached Incident management policy and SLA
Yes
Yes
We are compliant.
Yes, We are ISO 27001:2013 certified. Attached the certificate.
We are SOC 2 Type 1 compliant. The audit has been completed and auditor is working on the Draft audit report. We will be able to share once the report is finalized.
NA. But AWS Virtual platform cloud is ISO 27017 and 27018 certified and attached the report.
NA. We do not handles the card holder data.
the customer will be using the application product and all the information will be entered only through our application.
The data sharing between vendor and the customer will take place only through application product. There will be no manual data sharing or transfer.
PII will be entered through application and stored it on AWS cloud virtual platform. We store Name, email ID and phone number of the users.
We do not have any sub-contractors. We have deployed our application on AWS Virtual platform cloud. And AWS is ISO 27001, SOC 2, ISO 27017, ISO 27018, ISO 27701, CSA Compliant etc..
We have deployed our application on AWS Virtual Platform cloud. application is a cloud based application. We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. All the confidential/PI data are encrypted at rest and in transit with a split key mechanism to ensure that every client’s key is unique We do not decrypt the data until and unless if there any specific request from the customer.
Xoxoday endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week (“Agreed Hours of Service”). Uptime is measured based on the monthly average of availability, rounded down to the nearest minute. Please click here to know about Xoxoday SLA - https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view Xoxoday has a formal Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) defined and implemented to enable people and process support during any crisis or business interruptions. The BCP and DR Plan is tested and reviewed on a yearly basis as per the compliance requirements. The BCP and DR plan of Xoxoday is reviewed and audited as part of ISO 27001 standards and SOC 2 Audits by the independent auditor. Attached the Business Continuity Plans (BCP) and Disaster Recovery Plan (DRP) documents.
Since it’s a SaaS platform, there are no process as such.
Attached the below mentioned coompliance certifications - Attached the Audit reports. 1. ISO 27001 certificate 3. VAPT Certificates 4. VAPT Audit reports 5. SOC 2 Audit reports. 6. GDPR Data Privacy Impact assessment report 7. California Privacy Rights Act (CPRA) attestation report. 8. CSA STAR LEVEL 1 compliant - https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday We conduct these audit on annual basis and we will share it upon request.
We always provide our best service to resolve security incidents / outages. Attached the Service Level Agreement (SLA)
Xoxoday is committed to ensuring the integrity, confidentiality, availability, and security of its physical and information assets and maintaining privacy when serving the customers and organization’s needs while meeting appropriate legal, statutory, and regulatory requirements. To provide adequate protection for information assets, Xoxoday has built the Information Security Management System (ISMS), enabling everyone to follow these policies diligently, consistently, and impartially. Xoxoday will implement procedures and controls at all levels to protect the confidentiality and integrity of information stored and processed on its systems and ensure that information is available only to authorized individuals as and when required. Please click here to know more about Xoxoday Security - https://www.xoxoday.com/security
No. There were no Personal Data Breaches.
Xoxoday is committed to ensuring the integrity, confidentiality, availability, and security of its physical and information assets and maintaining privacy when serving the customers and organization’s needs while meeting appropriate legal, statutory, and regulatory requirements. To provide adequate protection for information assets, Xoxoday has built the Information Security Management System (ISMS), enabling everyone to follow these policies diligently, consistently, and impartially. Xoxoday will implement procedures and controls at all levels to protect the confidentiality and integrity of information stored and processed on its systems and ensure that information is available only to authorized individuals as and when required. Attached the below documents - 1. ISO 27001 Certificate 2. SOC 2 Audit report. 3. California Privacy Rights Act (CPRA) attestation report. 4. VAPT Certificates 5. GDPR DPIA Assessment report. 6. CSA START LEVEL 1 Compliant - https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday the customer can request the Xoxoday POC for these reports and we will provide the latest Audit reports upon request.
We are storing all the customer data on AWS Virtual platform cloud – Singapore region and consider AWS as a Sub-Processor as per EU GDPR. AWS is ISO 27001, SOC 2, ISO 27017, ISO 27018, CSA STAR, ISO 27701 certified organization. Please click here to know about AWS Compliance offerings - https://aws.amazon.com/compliance/programs/
Scope and functionalities are the part of the agreement.
Please click here for SLA - https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view We do not offer any credits/ penalties.
We have implemented all the technical and organisational measures to ensure the integrity, confidentiality, availability, and security of its physical and information assets and maintain privacy when serving the customers and organization’s needs while meeting appropriate legal, statutory, and regulatory requirements. To provide adequate protection for information assets, Xoxoday has built the Information Security Management System (ISMS), enabling everyone to follow these policies diligently, consistently, and impartially.
We do not process the data for other purposes than the one specified in the contract,
We do not share the data with third parties. But we store it on AWS Virtual platform cloud and we consider AWS as a Sub-processor. We do not disclose any of our customers personal information to any third parties. We reserve the right to disclose PI if required by law or if we reasonably believe that use or disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or comply with a law, court order, or legal process. We reject any non-legally binding requests for disclosure.
We process only the Name, phone# and Email ID as mandatory information.
We process the information as per the terms of use - https://www.xoxoday.com/terms-of-use
We are storing all the customer data on AWS Virtual platform cloud and we operate or provide services from Bangalore, India.
We inform the customer of any changes in regards to changes in sub-processors.
Xoxoday Terms & conditions - https://www.xoxoday.com/terms-of-use
Yes, the cloud provider does have a right to suspend services for specific reasons; more detailed in Section 3.3 of the Master Services Agreement. Section 3.3(a) read along with Section 2 of the MSA
We conduct the periodical Risk assessment. and it has been audited during the internal and external audits.
We also provide SLA performance report to the customer on need basis.
we have the capability to respond to security alerts, and report security vulnerabilities and information security incidents within 24 hours of discovering them
We train our employees on their role and responsibilities and also comminicate before joining the organizatin
application is an all-in-one employee engagement and motivation platform that offers Rewards & Recognition, Pulse Surveys, 1-on-1 Feedback, Social Intranet and People Analytics in one powerful solution.
Information security department is responsible for security initiatives and the Head of the Information security reports to the Board of Director of the company.
The policies and procedures have been created, reviewed and approved by the Top level management of the company.
The information security policies have been uploaded on KEKA HRMS Application and communicated to all the employees. Attached the screenshot for your reference.
Attached the Risk Management Procedure.
Attached the internal audit report.
Your data is of the utmost importance. All the security mechanisms and policies are established and implemented in such ways that data leak can be prevented, in transit as well as at rest.
We have installed Bitdefender endpoint security in all the endpoints. Bitdefender is based on a layered next-gen endpoint protection platform with the industry’s best prevention, detection and blocking capabilities, using proven machine learning techniques, behavioural analysis and continuous monitoring of running processes.
We have the capability to wipe out the data remotely for all endpoints including BYOD devices.
Attached the ISO 27001:2013 certificate and Statement of applicability.
We provide tpliance certifications upon request.
We use the Software Development Life Cycle (SDLC) process. It is aligned with ISO 27001;2013 and SOC 2 frameworks.
We have SDLC Policy as per ISMS requirements and we follow General Coding Practice. For example - We Conduct data validation on a trusted system, All cryptographic functions used to protect secrets from the application user.
We can also provide uptime status on a need basis.
We have proper forensic procedures for data collection and analysis for incident responses
Yes, in case specific incidents arise for particular tenants, our logging and monitoring framework allows isolation of incidents.
Xoxoday endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week. Uptime is measured based on the monthly average of availability.
We do not offer any penalty.
Attached the SLA
Customer Support is available on all working days (Mon - Fri) between 3.30 AM GMT to 1:30 PM GMT.
Xoxoday is – ISO 27001:2013 certified CPRA (California Privacy Rights Act) EU GDPR Compliant CSA STAR LEVEL 1 Compliant – Click here Vulnerability Assessment and Penetration Testing (VAPT) Attached these above certificates and Reports.
The backups are automated and taken on a daily basis. We delete the data upon receiving the request from the customer/end users/termination of the contract. Our data cleaning process goes through an organized purge. Once the data is purged, it’s purged from all places.
We have an ELK setup in place to ensure data monitoring in the most optimal manner. The audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
As per the SDLC Policy we follow several distinct stages, including planning, design, building, testing, code review, deployment and maintenance etc. Our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase.
It would depend on the criticality of the investigation and the type of service subscribed. Our team will be able to provide the ETA as soon as they receive the request from you and start acting immediately.
Yes. You can check this information from the user management option available for Admin console.
You can reach out to us with the help of the help center or can write an email to customer support team
Yes. We maintain and record the Audit logs and complying with various compliance requirements.
Yes. You may reach out to our support team anytime for requesting these records and they would be able to help you out on this requirement.
It would depend on the criticality of the investigation and the type of service subscribed. Our team will be able to provide the ETA as soon as they receive the request from you and start acting immediately.
Yes. We are ISO 27001:2013 certified and GDPR Compliant.
We have implemented the risk assessment procedure and conduct the risk assessment annually as per the compliance requirements.Risk assessment is used to identify the risks encountered by the information-processing facilities (or individual system components). The aim is to estimate the impact and probability of a threat occurrence. The risk assessment procedure is having Risk, Likelihood and Impact. The risk ranking is done based on the Residual Risk Rating such as High, medium and low. Attached the Risk Management Procedure for your reference.
Risk Management Procedure has been used to validate the security compliance of AWS. AWS Compliance certifications and attestations are assessed by a third-party independent auditor and result in a certification, audit report, or attestation of compliance. AWS is ISO 27001, SOC 2 Type II certified and complied with CSA start level 2. Please click here for more details about AWS Compliance Programs - https://aws.amazon.com/compliance/programs/
Yes. We can use the risk assessment framework adopted by NSE for cloud service risk assessment.. Please provide the same.
We comply with this requirement. The risk assessment procedure has defined the Risk Acceptance Criteria, Benefits, Components, Impact Rating, Risk Treatment, Risk Acceptance etc and all the controls identified in our risk assessment as per the industrial standard like ISO, SOC2, NIST, GDPR etc.
Sure. We are ISO 27001;2013 and GDPR compliant. We have policies and procedures in place with all the required compliance controls.
We comply with this requirement. We conduct annual audit by the independent auditors to test the controls in place with regards to Information Security management system(ISMS) and also for testing the service organization controls(SOC)covering the principles of Security, Availability, Confidentiality, and Privacy. AWS is also SOC 2 certified.
Sure. Attached the ISO certificate and we are in the Audit process for SOC 2. we will provide the same once the audit is completed.
We are ISO 27001;2013 certified, GDPR compliant and in the process of SOC 2 audit. We make sure that our customer data is safe and secure and meet all the compliance requirements and industry best practices. Xoxoday has built the Information Security Management System (ISMS) which includes the respective policies to be followed in a diligent, consistent, and impartial manner.
Our legal team would review and agree the terms and conditions.
We agree. NSE can review.
Our legal team would review and agree the terms and conditions.
We will inform NSE if there is any breach.
The data isolated between customers. We use logical data isolation with the help of company specific encryption keys.We use TLS1.2 encryption for Data in transit and AES256 for Data at rest
We agree. We have implemented the data breach notification procedure.
We agree. We will notify NSE.
We agree.Currently, we do not have any plans as such.
We agree. We will delete the data upon termination of the contract or request and confirm. Our data cleaning process goes through an organized purge. Once the data is purged, it’s purged from all places.
We have implemented Asset Management Procedure in place and maintain all the records of IT Assets like, hardware, software, licenses, accessories etc.
We review and update the inventory as per the Asset management policy.
The database server, application server or storage devices hosting NSE’s data & information is not made available publicly. We isolate our machines, network and storage with respect to the AWS Standards in order to keep it safe and secure
Yes, one can write to us at our 24*7 support team at cs@xoxoday.com
We help the clinets in setting up from both admin and end user side, and traiing is also provided on how application can be used for hasslefree awards distribution
We provide trainging over internet , if possible we provide telephonic assistance also.
Yes we provide “on demand training” , this incur no additional cost to the company
We have a 24*7 available support team, once a ticket is generated , It is assigned to one of the cs team executive and we intent to solve the issue within next 24hrs.
Xoxoday employees and third party would have an access. We provide acess on case to case basis as per the Information security and access control policy. We also have role based access system to meet the compliance requirements of the data security . The data is hosted on Amazon Web Services (AWS)
We do conduct employees and contractors background verification as per the compliance requirements before onboarding process. We will onboard them only after passing the background verification. We are ISO 27001:2013 certified organization.
We conduct periodical review of the access provided and make the necessary chages as per the Role based access management and access control policy. We also conduct Internal and external audits in a timely manner.
Our Information security compliance policies and procedures are established and implemented to enforce two-factor authentication
We are ISO 27001:2013 certified organization The User access are monitored and recorded internally as per the compliance requirement and Access Control Procedures.
Yes we have implemented intrusion detection tools, we ensure timely detection and investigation in a prompt manner.
Yes. file integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation.
Yes. Implemented SIEM
Yes. All the controls are audited annually.
Yes, We will share the Data protection policy. Access control policy and Information security policies
Size of the team is 5 and all are having 5+ years of experience
personal data is stored are registered databases that comply to all necessary inputs of a standard inventory repository and its transit scrambled for maximum security.
We use AWS Platform for storing the data. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records.
As per the Information security policy and Data protection policy only the authorised individual have an access to the data through internal approving and ticketing system.
No. Planned downtime will not be calculated uptime
No. Planned downtime will not count against the SLA
We have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working.
We test it annually once as per the compliance requirements.
Xoxoday’s architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows.
We have Business Continuity Policy and Business Continuity Management Procedure in place and tested periodically. And also our Policies has been reviwed and Audited annually.
Yes. We have implemented IDS/IPS, Firewall and our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting
Yes. We have procedures in place to support Government
We have the clauses for suppporting local government and law enforcement requesting customer data in data protection policy. We will share the copy of it.
We have deployed our application on Amaon web services (AWS) AWS is designed to help us build secure, high-performing, resilient, and efficient infrastructure for our applications. AWS is also ISO 27001:2013 and SOC 2 type II Certified and provide all applicable security to the data center.
Yes. We have industry approved vendor called Appknox for Vulnerability assessment anf Penetration Testing. Appknox performs Static, Dynamic, API, and as well as Behavioral Analysis. And they helps to detect and address security vulnerabilities.
We collect only personal information through our application. We collect name, email ID and mobile numbers.
Yes. We have capabilities to anonymize data. By Anonymization users are able to make use of sensitive information without having access to the identifiable data items. And its used within a secure environment with employee access on a need to know basis.
No. we do not have it in hard copy
Yes. We conduct vendor Risk assessment and also external Auditor validate the critical vendor documentations during the annual and Internal Audit.
Yes. We have Information Security Program
Yes. We review Information Security Policies every year.
Yes. We have Information security risk management program
Yes. Our management is supportive and evaluate, Recommend and take action on security risks
Yes, we have Information security team and the Infosec head is reporting to Chief Operating Officer of Xoxoday.
Yes
Yes. Please visit here for more details - https://www.xoxoday.com/bug-bounty
Yes. All the endpoint laptops that connect directly to production networks centrally managed
All the employees laptop is secured with Bitdefender end point security software. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory.
No. sensitive or private data never reside on endpoint devices. This is enforced throgh access control policy.
We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour.
Yes. Our incient response plan is tested every year as per the ISMS requirements.
We follow SDLC policy during the design phase of devolopment. See SDLC procedure attached
We have SDLC procedure and Information System Acquisition Development and Maintenance Procedure. Devolopers are trained on the Secure Coding Practices as soon as they joined our organization
We conduct vendor risk assessment and collect all the required security policies, procedures, VAPT reports, ISO 27001, SOC 2 reports. And also our internal and exteranal auditors validate the security controls of our crtical vendors during the Audit.
NO
NA. We do not have custom-built software
Yes
Internal Audit has been conducted by the inhouse Infosec and ISMS Lead Auditor. All the projects, business processes and ISMS controls has been included in the scope and opportunity of improvements has been communicated to all the respective teams with the remideiation plan. And the frequency of the Internal audit is annually.
We have the external Auditor for ISMS Audit. All the projects, business processes and ISMS controls has been included in the scope and opportunity of improvements has been communicated to all the respective teams with the remideiation plan. And the frequency of the external audit is annually.
See ISOIEC 270012013 Certificate and Internal Audit report attached.
NA. We do not use for own purposes
Yes
Yes. All the employees and third party service providers are required to sign Confidentiality Agreements to protect customer information as per ISMS compliance requirements.
We have dedicated IT Team and Admin team who looks after the hardware security and, we have implemented the security controls as per the ISO 27001:2013 and SOC 2 Compliance requirements. We are hosting our application on AWS, and they are providing physical security to our data centre. We have Asset Management Procedure in place to identify, classify, label, and handle the Information and Information assets according to their criticality and sensitivity. We have Media protection procedure to handle the locally stored data as per the Information security compliance requirements.
As per the Physical and Environmental Security policy we have security guards and CCTV Camera’s to safeguard the office building and also to provide an access to the building only for the authorized individuals. We also have Media protection policy which also defines on how to handle the Paper documents as per the compliance requirements. Physical documents are handled with at most care and followed the policies and procedures of an organisation to make sure that the data is protected.
We have Physical and Environmental Security policy and Vendor management guidelines in place and working effectively. We have implemented controls on Physical entry, Securing offices, rooms, facilities, Working in secure areas, Delivery and Loading areas etc. Only the authorised individuals will get an access upon verification. And we also conduct periodical verification of the effectiveness of these controls periodically through internal and external Audit. We provide access to the outsiders or suppliers on approval and escorting mechanism of vendor management guidelines by issuing the access cards.
All our assets are classified, labelled, and maintained in the register by our IT Team. Access granted only to, authorized individuals. We have locked environment for our hardware’s which would store the data. We also have implemented the Media protection procedure to protect the data which are stored physically.
Yes. Backups are stored in a safe place. We have backup Recovery Procedure and implemented the controls to protect the organization information asset from the damages that may be caused due to failure of hardware system, corruption of software, breaches leading to data destruction and or not being able to retrieve and use. We predominantly work on cloud-based infrastructure and the teams may consider adoption of Amazon Web Services which provides the Backup and Restore services to build scalable, durable and secure data-protection solutions. AWS claims the following benefits and the teams may evaluate the benefits to the respective context that may lead to realize the following outcomes: 1. Data Type and Durability 2. Flexibility and Scalability 3. Security and Compliance The following AWS based offering for the following use cases offered by AWS may be considered based on the contractual needs of the subject under consideration: 1. Hybrid Cloud Backup 2. Data Lifecycle Management 3. Tape Replacement 4. Global Data Resiliency 5. Data Backup 6. Archive & Compliance
We are ISO 27001:2013 certified and GDPR compliant organization. We have Information security policy and Data security policies in place with regards to data protection. We make sure that the below principle of data security has been followed as per the compliance requirements. 1. Fairness and lawfulness When personal data processed by us, we make sure that the individual rights of the data subjects must be protected. We will ensure that the personal data is collected and processed in a legal and fair manner. 2. Confidentiality - Restriction to a specific purpose We make sure that the any processing of personal data should be lawful, fair, and transparent. Personal data will be processed only for the purpose that was defined before the data was collected. Subsequent changes to the purpose are only possible to a limited extent and require substantiation. 3. Transparency We make sure that we maintain the transparency with regards to the data collected, stored and disposed. We also provide rights to data subjects as per the GDPR compliance requirements. For ex - Right to Rectification, Right to Portability and Right to be Forgotten. 4. Integrity and data security Personal data is subjected to the data secrecy. We have controls on confidentiality, Integrity and data security. We follow secured suitable organizational and technical measures to make sure that the data is protected from an unauthorized access, illegal processing or distribution, as well as accidental loss, modification or destruction etc. Sensitive data - We do Inform involved parties about how we will process their data Inform involved parties about who has access to their information Have provisions in cases of lost, corrupted, or compromised data Allow involved parties to request that we modify, erase, reduce or correct data contained in our databases. Sensitive data - We do not Communicated informally. Stored for more than a specified amount of time. Distribute to any party other than the ones agreed upon by the data’s owner (exempting legitimate requests from law enforcement authorities. In addition to ways of handling the data the company has direct obligations towards people to whom the data belongs.
We have controls in place to protect the information or to maintain privacy. We conduct Data Privacy impact assessment and Audits periodically as per the compliance requirements. We have Personally Identifiable Information Policy, Data Security policy, Data Subject Access Rights Procedure, Data Retention and Disposal Policy as per GDPR compliance.
We conduct periodic vendor risk assessment. Information security documents are validated by theiInternal and external auditors during the assessments.
Yes.
We have an access control policy. The policy is attached for reference. Only authorised employees will have access to the data.
Yes. Xoxoday is ISO/IEC 27001:2013 certified organization. See certificate attached.
Yes. We have a well-defined policy for roles and responsibilities. We have communicated each employee about their responsibilities across the organization. We do maintain appropriate contracts with relevant authorities and ensure that applicable regulations are complied with
Yes. We provide these rights to the data subject as per GDPR
Yes. We conduct internal and external audits and all the applicable controls have been validated as per the compliance requirements.
Yes
We have a media handling procedure. See attached for reference.
No. We do not transfer the data outside our organization.
Yes. See Infrastructure Change Control Procedure attached.
Yes.
Security inceidents will be reported by our Information security team or customer support team within 48 hours.
We have implemented physical security controls as per the compliance requirements. We have CCTV, access cards, security guards for monitoring and only authorised individual have access.
Segregation is done for production and non-production or Testing environments. We maintain the test accounts seperately and delete or terminate the accounts immediately once the testing is completed. Only Admins have an access to create these tests accounts on need and approval basis.
We have implemented the Roles and Resposibilities policy and defined the Duties of all the system users and segragated based on the defined roles. Only authorised individual will have an access to the Information system on need and approval basis.
We maintain these records for Audit purposes.
We have controls in place to monitor the user access system. We have implemented Role based access management system through access control policy. Our application also supports Role based access control system to make sure that only authorised individual will have an access to the Information system on need and approval basis.
We maintain these records for Audit purposes.
We are Compliant. We monitor these controls on a periodical basis and also during the internal and external Audits. Successful and failed login attempts will be logged, we use privileged accounts are used only for system administration activities,we remove default credentials and use the new credentials for all our systems.
We use Multifactor authentication menthods to make sure that only authenticated individual have an access to the Information system wherever strong authentication is required. We use Biomentric verification and access cards methods for physical security purposes.
We have these controls in place. We have a restriction for Physical access, monitor these access periodically and validate to make sure that only the authorised individual have an access.
The credentilas has been comminocated via secured mode to make sure that confidentiality is maintained.
We are Compliant.These controls are audited during the internal and external Audits.
We are Compliant.Only authorised individual will have an access.
We are cothe customerant. We maintain the records of Audit logs.
We have restricted the access of external harddrives, USB etc for all the systems through Active directory and End point security.
We have the security controls in place. We have installed the firewalls to monitor and control the incoming and outgoing network traffic based on predetermined security rules. It helps us to establishes a barrier between a trusted network and an untrusted network.
We have implemented the asset management procedure to identify, classify, label and handle the Information and Information assets according to their criticality and sensitivity.
We have labeled the aseets in order to identify and make sure that the access control permissions are maintained.
we have implemented intrusion detection and prevention tools, we ensure timely detection and investigation in a prompt manner.
These are integrated with security operations/SIEM solutions.
We take an approval from the concerned authority before procuring the equipment or routing connections and test the same before installing it.
All the network devices are securely configured and we always make sure that we monitor the same on regular basis and take appropriate action on any detections.
We use vendor supplied softwares without any changes wherever feasible, if all the security controls are in place.
We consider these factors before making these changes to the softwares.
Yes, we test the changes made on testing environment before moving it to a production environment.
Only authorised individual have an acces to the approved information assets.
we are compliant. We document or have a track of all the changes made to protect the information system.
We are compliant and have these controls in place.
We have the appropriate clauses in the agreements wherever necessary.
We provide guidance for using our products appropriately and take all the possible benefits.
We have the controls in place. All the Critical patches will be deployed immediately
We inform our customers on the vulnerabilities wherever is required from the compliance perspective.
Our product is free from dormant malicious programmes
We test the systems before deploying into operational environment.
We have implemented the System Devolopment Life Cycle procedures and all the testing of new features are documented.
We conduct security assessments before accepting the products and take appropriate approval to make sure that all the security requirements are met.
All the test results are documented.
We record these in the Risk register and documented before purchasing the product.
We make sure that these are met before acquiring and products.
The customer responsible staff can confirm upon validation of the security requirements.
All the design and implemetation has been documented. We conduct the security Risk assessment in order to identify and mitigate the risks.
We have kept Testing and production environment seperately. We do not use any data from our production environment for testing purposes.
All our contracts or agreeements are having appropriate clauses with regards to security compliance, privacy, Audit requirements etc.
we use only licensed softwares or assets
We are compliant. We maintain these records for Audit purposes.
Attached the Information Security Manual. It prescribes the policies that govern the management and administration of the Information Security Management System (ISMS) for application.It specifies the scope and the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving the information security controls.
We have not subcontracted or outsourced any of services with regards to the product.
We have documented the Transfer of Information and it’s a part of our Information security policy
We do not transfer the data. But if its necessary it will be done only upon the approval of the management.
We have documented the Transfer of Information and it’s a part of our Information security policy
We maintain these records for Audit purposes.
We monitor and audit the logs.
We are complied. We have controls in place to make sure that Information system is protected.
We conduct the Risk assessment to identify and mitigate the risks involved.
We use Google workspace as email solution and adequate security features has been enabled to make sure that Information system is protected.
We do not connect.NA
We make sure that all the controls and compensatory controls are in place in order to protect against the Security threats.
We have implemeted the risk management procedure and defined the Risk Treatment, Risk Treatment, Risk Mitigation, and Risk transfer etc
We have implemeted the risk management procedure and defined the Risk Treatment, Risk Treatment, Risk Mitigation, and Risk transfer etc We implement the Compensating security controls wherever measures cannot be applied due to technical or operational infeasibility.
We maintain these records for Audit purposes.
It’s a part of our Internal and external Audits.
We make sure that these controls are in place and security has not been degraded below the accepted level. We also validate these controls during our internal and external Audits.
We have implemented the role based access system and change management policy in order to make sure that we provide an access to an individual only upon need and approval basis. All the changes has been tracked and maintained the records for audit purposes.
We have a up to date records of all the assets used.
We make sure that we follow the Industry best practices and security standard to make sure that we secure the information asset.
We make sure that we follow the existing security controls and implement the compensatory controls to make sure that the information system is secure.
We have implemented the control.
We conduct the Risk assessment to identify and mitigate the risks involved.
Compliant.We review and validate these controls on a periodical basis and These are part of an Internal and external Audits.
Compliant.We review and validate these controls on a periodical basis.
We have the required security controls in place.
We do not use outdated computer hardware, software, technology, services or practices
We upgrade the systems make sure that do not use outdated computer hardware, software, technology, services or practices
We have installed the end point security software on all the computers and servers to keep the computer and personal information protected.
We have installed the end point security software on all the computers and servers to keep the computer and personal information protected.
We are compliant.
We have enabled these features.
We have installed end point security softwares to safeguard from attack scripts, viruses, worms, Trojan horses, backdoors and malicious active content. We also conduct periodical scanning in order to make sure that all the information assets are safe. These are centrally managed and have control on all the end points.
We make sure the Vulnerability assessment has been conducted for our products as per the compliance requirements.
We are compliant.
the customer Sensitive information will not be exposed to the general public.
We document and maintain all the security issues.
We are complaint.
We are compliant. We have clasified, labeled our assets and periodically monitored. All the logs and realtime trafic is monitored.
Implemented. We are compliant.
These are all part of CSP agreement.
We have these controls in place as a part of our Business continuity plan.
We have these controls in place as a part of our Business continuity plan. It has been tested periodically and part of our internal and external Audit.
Agreed. We will sign the NDA
SLA can be documented and agreed by the both the party.
Only authorised individual have an acces to the approved information assets.
We allow our customer to audit but atlease 30 days prior notice with the scope of the audit needs to be communicated
Its documented as per the Risk management procedure.
We have all the details in SLA
We can make our audit reports available
We maintain appropriate reports and records, to monitor and measure the compliance with the security requirements.
We make sure that we follow the risk management procedure and take these factors into consideration.
We have these in place and tested annually.
We have these in place and tested annually.
Our BCP/DR plan supports this.
We review these on annual basis
We have cmmunicated to all the internal and external parties.
It’s a part of Business continuity documents and attached the same for your reference.
The BCP Test and lessons learned has been documented.
It’s a part of BCP documents and we review and update when changes takes place.
These are part of internal and external audits
We have implemented the Corrective Action Procedure.
We conduc the security assessments by the Internal and external auditors
We share the data with our Internal and external auditors
We make sure the Assessments and Audits will be conducted and reported independently.
All the Sensitive information shall be handled as per Policies and procedures implemented.
We have defined it in our compliance policy and Corrective Action Procedure
We allow our customer to audit or assess but atlease 30 days prior notice with the scope of the audit needs to be communicated
We continuously monitor and improve Information security framework to make sure that we safegurd the Information and all the controls are in place.
We make sure that we brings these improvements to Information security systems from the incidents reported and audit observations etc
We have implemented the corrective action plan procedure and review the policies and procedures on annual basis.
It can be included in the agreement and our legal team will review and confirm
Statement of work will have a details of product/service to be provided
We can include the service levels in the agreement. We are not currently having an options for service credits/liquidated damages, if SLA are not met.
We make sure that we have all the controls in place.
We will do this as part of the agreement
We are a multi tenant SAAS system and all our logs will contain data of all customers. We will have our own log monitoring and security analysis.
Attached the BCP/DR documents
We end point security in place
We allow our customer to audit, but atlease 30 days prior notice with the scope of the audit needs to be communicated
We have deployed our application on Amazon web services (AWS) Virtual platform cloud. AWS provides data center security to our application. AWS is ISO 27001;2013, ISO 27017, ISO 27018, SOC 2 certified organization. Xoxoday is also ISO 27001:2013 and GDPR compliant organization. Only the authorised individual have an access as per Access control policy. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access. Xoxoday’s architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows.
Since our services are delivered via. Web, the upgrades and updates to the services are seamless and usually do not involve any actions from the end-users. We try to release our product hotfixes once every week & major features once every month.
Yes. Annually once.
Yes. We are ISO 27001:2013 and GDPR Compliant. We are also compliant with SOC 2 type 1 and on the last phase of Audit. We will share the report once we have it from the Auditor. Attached the ISO 27001 certificate and engagement letter that we have for SOC 2 Audit.
We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it’s linked with the SSO/Active Directory
All the employees initially inform the IT Support team through ticketing systemb the Infosec manager and Final level will be DPO and the management.
The time of support ranges depends on the level of service. RTO and RPO is - 6 mins
our products comply with all the industrial benchmarks and standards when it comes to the Software Development Life-cycle (SDLC). All software development procedures are supervised and monitored by Xoxoday so that they include: security requirements independent security review of the environment by a certified individual code reviews Quality monitoring, evaluation, and acceptance criteria for information systems, upgrades, and new versions shall be established and documented for the clients’ reference.
The data centers are hosted completely in isolation so that the access is limited and controlled. Load balancer allows shifting incremental load and can auto scale based on data load experienced by application. Each instance (EC2 Instance) under fortified VPC network is further conglomeration of Docker Container Web Services and APIs and application layer running on top of it. This helps in managing various aspects and features of application without affecting the functioning of each other and achieving a modular architecture to work as plug and play model. Amazon Cloud Watch is implemented to enable monitoring of the functioning of the application. The data is encrypted using 256-encryption based SSL certificate. To manage security of data Xoxoday plans a quarterly VAPT based security audit of application.
We have implemented policies and procedures as per ISMS and GDPR requirements. We also conduct periodical Internal and external Audit by the third party Auditor. We have deployed our application on Cloud Virtual platform for maximum security. We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We conduct periodical Vulnerability assessment and Penetration Testing from the Inductry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications. We use logical data isolation with the help of company specific encryption keys. Data in non production environment is not updated with the production data. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256 As per the Information security policy and Data protection policy only the authorised individual have an access to the data through internal approving and ticketing system.
We comply with Information security compliance - ISO 27001;2013, SOC 2 and GDPR
Our product is ISO 27001 and GDPR compliant and have the features.
We have health checks along with Self healing mechanisms in place
99.99%
We use logical data isolation with the help of company specific encryption keys. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256. We have the ability to logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant’s data. our network environment is designed and configured to restrict any communication and connection between the tenant’s environment.
Yes. We have the controls in place. We have blocked connecting Hard disk, USB, CD ROM etc to computers and all the devices are centrally managed.
The data is only stored on our application and its deployed on AWS Cloud. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records
We are a SAAS solution. We are cloud hosted.
We use a variety of tools and plugins integrated with Prometheus & Cloudwatch along with health checks for facilitating our uptime/service availability
Xoxoday’s architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows.
active-passive
Yes. we have implemented the cookies policy
Yes, we have the access controls
Yes
Yes, we have the access controls
Yes. Users can updated their information
Xoxoday - application platform has been integrated with Darwinbox with the objective of creating a reward system for employees. Organizations that are using DarwinBox will not only be able to automate their HR processes but can also reward employees to keep them motivated and engaged. Xoxoday application offers a unified rewarding platform that helps organizations build a winning organizational culture through reward and recognition programs that have a global catalog consisting of products and experiences from more than 700+ brands. Please click here to know more - https://xoxoday.gitbook.io/application/developer-resources/integrations/darwinbox-+-application
Yes. Xoxoday’s primary security focus is to safeguard our customers or users’ data. This is the reason that Xoxoday has invested in the appropriate resources and controls to protect and service our customers. We have an Infosec Manager who is responsible for Information security and reports to the Board of Directors of the company. All the job descriptions, role and responsibilities has been documented as per the compliance requirements.
Xoxoday has developed a comprehensive set of security policies covering a range of topics. These policies are shared with and made available to all employees and contractors with access to Xoxoday information assets. Each employee, when inducted, signs a confidentiality agreement and acceptable use policy, after which they undergo training in information security, privacy, and compliance. Furthermore, we evaluate their understanding through tests and quizzes to determine which topics they need further training in. We provide training on specific aspects of security that they may require based on their roles. We spread awareness about the Information security among the employees through posters in public areas, emails, training and orientations etc..
Yes. All new hires are required to sign Non-Disclosure and Confidentiality agreements. The Employee expressly agrees that he/she shall not use Confidential Information provided by the Company in the development or delivery or for personal gain from providing any products or services for his/her own account or for the account of any third party. The NDA signed will be valid till the termination from an employement.
Yes, We have implemented the process for termination from an employement. Once the employee is terminated all the access will be revoked, IDs are disabled, assets are returned and recorded as a part of the exit clearance. We have implemented the access control procedure and all the access will be revoked upon termination or transfer of an emplyees as per the compliance requirements.
Anti-Virus is deployed in all systems and servers for protection against virus and malware. We use Bitdefender end point security for protecting the systems from virus and this has been updated on daily basis and centrally managed.
  1. Reach out to us at cs@xoxoday.com to raise a ticket, if you happen to notice any potential security issue whilst meeting all the required criteria in our policy. 2. The validation of the reported issue in terms of severity & authenticity will be done by our security team in around 90 days. 3. Post validation, steps will be taken to fix the security issues in accordance with our security policies. 4. The owner of the ticket will be informed once the issue is resolved. Security Severity has been categorized as High, Medium and Low. Once the reported vulnerability is closed we will conform the same.
Reports can be generated by the admins through the application. If there are any additional support needed, our customer support team would be able to help and guide on generating report.
We do not use any in-house devoloped applications. We have deployed our application on AWS cloud virtual platform. And AWS is SOC 2, ISO 27001, ISO 27017 and ISO 27701 certified organization. Shared the certificates.
We have implemented the Web application firewall, IDs/IPs and amazon guard duty etc for maximum security. OAuth2 is used to authorize all API requests. We also conduct code review to make sure that the APIs are secure.
Yes. Our employees are having required education and certifications to perform the job.
We do conduct Internal and external Audit very year
Xoxoday is compliant with - ISO 27001:2013, CPRA (California Privacy Rights Act), SOC 2 Type I, CSA STAR Level 1 and GDPR(General Data Protection Regulation). Attached the below mentioned documents. 1. Xoxoday ISOIEC 270012013 Certificate 2. Xoxoday SOC 2 Type 1 Report 2021 3. Xoxoday VAPT Certificate (Conducted by 3rd party vendor) 4. Xoxoday application VAPT Report (Conducted by 3rd party vendor) 5. Xoxoday CPRA Attestation Report 6. CSA STAR LEVEL 1 Compliant - https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday
We have deployed our application on AWS Virtual platform cloud. The AWS Compliance Program helps to understand the robust controls in place at AWS to maintain security and compliance in the cloud. Attached the below compliance certificates and Audit reports – 1. Amazon Web Services ISO 27001 Certificate 2. AWS ISO 27017_certification 3. AWS ISO 27018_certification 4. AWS SOC 2 Report 5. AWS SOC 2 Type I Privacy Report 6. AWS CSA STAR Certificate
Yes. We follow ISO 27001:2013, SOC-2 and GDPR We are ISO 27001:2013 certified and GDPR Compliant.
Yes. We are ISO 27001:2013 certified and GDPR Compliant. We are also complied with Cloud Security Alliance (CSA) STAR level 1.
Its SAAS Solution and available 24*7
It’s a web application. And it can be presented over the calls like MS Teams, Zoom, Google meet etc.
Yes. We have an integration with other applications and provide secure communications.
Yes
Yes. Files will be transferred securely.
Yes.
The solutions integrated with other solutions like Zoho CRM, HubSpot, Darwin box, SurveyMonkey, Freshdesk etc
NA. It’s a SAAS Solution and does not require.
The data will be in our control. And AWS Cloud provide service for deploying our application. AWS is also ISO 27001 and SOC 2 certified organization and adhered to the data governance.
We have implemented all the required Infosec Policies and procedures as per ISO 27001:2013, GDPR and SOC-2
We perform Internal Audit and external Audits annually. We also conduct Security assessments and testing like Vulnerability assessment and Penetration testing every six months. Yes. We communicate these assessment results to clients on a yearly basis.
We have the arrangements in place. Storage Period would be as per regulatory conditions. Personal data can be deleted based on a formal written request. Xoxoday would delete the data within 30 days of receiving the request. We will delete the data of the customers upon the termination of the contract and Our data cleansing process goes through an organized purge. Once the data is purged, it’s purged from all places
We have implemented all the SOC controls and in the last phase of Audit. We would be able to provide SOC 2 Type I report in next 2-3 weeks
We have BCP/DR Policy as per the Infosec compliance requirements and we conduct the BCP test annually. See Business Continuity Management Procedure attached.
See attached Incident Management Procedure attached
Yes. An independent security third party audit been completed by “TUV NORD”. The last last day of Audit was 29th June 2021
We have establised the Information security management systemIt specifies the scope and the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving the information security management system (ISMS) at Xoxoday. Xoxoday is committed to ensure Integrity, Confidentiality, Availability and Security of its Physical and Information Assets and also maintaining privacy for serving the needs of the customers and organization while meeting appropriate legal, statutory and regulatory requirements. Attached the Information Security Management System Manual.
We have the Data security Controls in place. We have implemented IDS/IPS, Firewall and our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting. We have Cloudflare web application firewall for maximum security of data. We have implemented the role based access control system to make sure that the data os available only to an authorised individual. Nreach Online Services Pvt ltd, respects the individual right to their personal information and is committed to use minimum personal data with transparency, accuracy & protection of confidentiality, integrity, availability, privacy, authenticity & trustworthiness, nonrepudiation, accountability and auditability of the data received, stored, processed and destroyed for business purposes. Atatched the Xoxoday GDPR Data Security Policy
We are compliant. We collect the data only throigh our application. We have role based access system to make sure that only the authorised individual have an access to the required information All the devices and emails are having adequate security controls. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. We have installed the firewalls to monitor and control the incoming and outgoing network traffic based on predetermined security rules. It helps us to establishes a barrier between a trusted network and an untrusted network. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory for more security. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.We have SDLC Policy as per ISMS requirements and we follow General Coding Practice. For example - We Conduct data validation on a trusted system, All cryptographic functions used to protect secrets from the application user.We also have Implemented least privilege; restrict users to only the functionality, data and system information that is required to perform their tasks.
Yes. We have Implemented the SPF/ DKIM/ DMARC effectively.
We are compliant. We have implemented the Password Management Policy We store password hashed. We have SHA512 hash with unique salt for every password. The password needs to be minimum 8 characters long and should contain at least one capital letter, special characters among ’# $ % * &’ and 1 digit. Maximum Password Age is 45 days. User IDs and passwords transmit through stringent checks in an encrypted format that complies with the current Technical Security Baseline Standards. All the user can set their own password from the very first login attempt. Passwords once used cannot be reused with the password history technique in order to disallow the reuse of old passwords.
We inform Fincare if these regulatory authories agreed to inform.
Yes. 30 days prior notice and scope of the Audit needs to communicated.
We are a multi tenant SAAS system and all our logs will contain data of all customers. We will have our own log monitoring and security analysis.
Its a SAAS product and we use We use TLS1.2 encryption for Data in transit and AES256 for Data at rest.
Yes
Yes
We do not own the data centers. We deploy our application on AWS cloud virtual platform.
Attached the ISO27001:2013 certificate. We do not collect and store any Payment card details. PCI DSS is not applicable for us.
We inform the client if there is any changes of the design that impacts security posture of the system.
We take steps to securely develop and test against security threats to ensure the safety of our customer data. We maintain a Secure development Lifecycle, in which training our developers and performing design and code reviews takes a primary role. In addition, Xoxoday employs third-party security experts to perform detailed penetration tests on different applications. application is ISO 27001, GDPR, CPRA/CCPA, CSA STAR certified.
Our technical team maintains these records.
We consuct the code review as per the compliance requirements and maintain the code repository. Attached the SDLC Proedures.
Compliant.
Since application is a SaaS Platform this would be not applicable.
Since application is a SaaS Platform this would be not applicable.
Since application is a SaaS Platform this would be not applicable.
We are compliant with the requiremenrts.
We do not transfer manually. NA And we use Google workspace for emailing solution.
cryptographic keys are protected. Compliant.
We do not store any PHI. The PII(name, email ID, phone#) are encrypted. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security.
We store only the PII(name, email ID, phone#) and does not store/process PHI & PCI. We are compliant with ISO 27001, CCPA/CPRA, EU GDPR, CSA etc. Attached these compliance certificates/audit reports.
Yes, all the mechanisms related to security and policies are implemented to facilitate timely decision and investigation by root-cause analysis. These incidences are analyzed with network intrusion detection (IDS) tools.
The information used for authentication is securely stored and transmitted. We store password hashed. We have SHA512 hash with unique salt for every password
Not applicable since application is a SaaS platform.
At Xoxoday we use Google workspace and activated the MDM features. application also has iOS and Androind mobile applications.
This feature can be configured with the help of the MDM Solution that the customer use.
At Xoxoday we use Google workspace and activated the MDM features.
Compliant. We have segreated the roles and assign the responsibilities to our employees.
Since its a Cloud hosted SaaS platform deploying of the application on cloud and server scannings are under the scope of Xoxoday.
We use Web application firewall (WAF) and pfSense firewall for security reasons. 1. The Cloudflare Web Application Firewall (Cloudflare WAF) checks incoming web requests and filters undesired traffic based on the set of rules. 2. pfSense helps to monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on a defined set of security rules.
At xoxoday we monitor and maintain the logs. The Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
At Xoxoday we have implemented the Active directory and the system will get locked if its inactive for more than 15 mins and re-autentication would require.
We have the process in place for standardized approach to structured exception and error handling across all layers.
At Xoxoday the validation has been done during the development and testing and we are compliant with the requirements.
At Xoxoday Security and compliance requirements are considered during the development stage and we are ISO 27001, CPRA, CSA STAR level 1, GDPR compliant.
We have implemented the controls to monitor the application and safegurd from the attacks. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails.
Since application is SaaS Platform it would be not applicable.
We have implemented the Software Development Life Cycle (SDLC) procedure and attached the same for your reference. Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing. We remidiate or fixes the issues identified during the VA/PT assessment and make sure that the application is free from the vulnerabilities.
Since it’s a SaaS platform and deployed on AWS cloud virtual platform Singapore region. All the data will be stored on AWS VPC.
Xoxoday is ISO 27001:2013 certified. An ISMS is a framework of policies and procedures that includes all legal, physical and technical controls involved in an organisation’s information risk management processes with the aim of keeping information secure. With ISO’s robust information security management system (ISMS) in place, you gain the additional reassurance that a full spectrum of security best practices is implemented across the organization Our Goal is to protect three aspects of information - Confidentiality: only the authorized persons have the right to access information. Integrity: only the authorized persons can change the information. Availability: the information must be accessible to authorized persons whenever it is needed.
We have implemented the Access control policy to control the upload, download, viewing and modification
AV Scans takes place every week and users also can scan it whenever they can scan the machine. We have prescheduled the scanning once in a week.
We are using linux operating system which is inherently secure along with security practices like web application firewall etc We make sure that the customer data is well segregated and compartmantalized
No Breaches taken place.
We are having Robust Information security compliance framework and we are ISO 27001:2013 and GDPR complied. We follow all the applicable infosec compliance requirements to comply with the regulations
We conduct the Risk assessment and compliance review on annual basis as per the compliance requirements.
Yes. All the compliance and audit findings has been mitigated.
All the vulnerabilities identified during the assessment has been fixed.
We use Bitdefender end point security and installed on servers and development machines.
Its updated on regular basis.
Our roles and job duties are segregated through role-based access to ensure maximum security. Access to data and systems are based on the principles of least privilege for access. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access events.
Its restricted and not available to the public.
We follow the best practices ans servers are hardened for security reasons.
We have implemented the Identity access management (IAM) and follow the Access control policy.
At Xoxoday we follow the password policy.
We have deployed our application on AWS Virtual platform cloud - Singapore region.
RTO and RPO is 60 Minutes.
We have implemented the Incident Management Procedure and attached the same for your reference.
Since application is a SaaS product and the customer can use the product and services as soon as subscribed for application product usage. the customer will have the legal rights to use the Product.
We do not change the terms frequently. We will provide 30 days’ notice period for any changes of terms.
We notify Client in case of any unauthorized disclosure of or breach of any confidentiality obligation of Xoxoday with respect to Confidential Information, data or information of Client and Xoxoday shall take all necessary and required steps and measures to mitigate such unauthorized disclosure or breach and shall co-operate with Client , at Xoxoday ‘s cost, to mitigate or control the loss or liability arising out of such disclosure or breach and to retrieve such data or information.
Yes. have an active SLA in place that identifies minimum performance of the Product.
We have the SLA in place. application endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week. Uptime is measured based on the monthly average of availability.
We would be able to provide a report on need basis.
No penalties are associated with SLA.
We monitor the service continuously and make sure that the product and service is available to use all the time. We have a documented Business Continuity and Disaster Recovery Plan defined and implemented to enable people and process support during any crisis or business interruptions.
Since our services are delivered via. Web, the upgrades and updates to the services are seamless and usually do not involve any actions from the end-users.
Yes.
Our architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows. If there is any major activity and the service will be unavailable, the Maintenance hours were communicated well in advance at least 3-4 day by application.
Termination clause will be the part of Master Service agreement and both the parties can review and agree during entering into an agreement.
Since it’s a SaaS product, this is not applicable.
Termination clause will be the part of Master Service agreement and both the parties can review and agree before entering into an agreement.
Yes. changes to the production environment or development are documented, tested, and approved prior to implementation or any new releases. We conduct internal reviews and audited by the external auditors for our security standard certification. We conduct periodical Vulnerability assessment and Penetration Testing from the Industry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications.
At Xoxoday we have implemented the Cyber Crisis Management Plan to provide and support capability for reporting and responding to cyber security incidents, to eliminate or minimize impacts of such incidents
No.
We monitor the logs on regular basis with regards to network, file and server, and security system. To provide more information, the infrastructure logs are collected using AWS Audit Trail and Application related logs are collected in our Elastic Search server and retained in long term cloud storage.
No. Since we are a multi-tenant system, our logs contain information of all the tenants. We cannot isolate a single customer’s information from our logs.
At Xoxoday the Audit logs reviewed on a regular basis for security events. audit logs are set up, reviewed by our Technical team and logs are recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
We are GDPR Compliant. Our information security team and Customer support team will inform the POC of Client via email communication with Preliminary Incident Synopsis and Root Cause Analysis report (RCA) including the details of Business Impact, Issue Description, Root Cause, and Corrective Actions.
Yes. We have implemented the incident response plan and it complies with industry standards ISO 27001:2013, SOC-2, GDPR.
We are ISO 27001:2013 certified and attached the certificate.