Skip to main content
Yes, our policies and procedures are established and implemented to enforce two-factor authentication for privileged account management/authentication while accessing tenant data/systems.
Yes, systems must be configured to log all successful and unsuccessful login attempts by accounts with privileged access. These authentication logs must be retained for a minimum of 180 days and in accordance with the Company’s records retention guidelines.
Yes, users can re-authenticate a change in credentials and we comply to any attempted change in authentication information.
No, we do not present login notices to users before they log in as the users are redirected through SAP SuccessFactors.
Yes, there is a protocol in place to ensure that no information beyond an unsuccessful login attempt goes through prior to a successful login.
Yes, our partnerships with a wide array of integration partners ensure existing customer based Single Sign On (SSO) capability for all users to seamlessly use Xoxoday’s products. With an easy DIY setup, your SSO solution would be plugged in and ready to go. Please refer to our list of integrations to know more.
Yes, our identity federation standards include SAML 2.0, SPML, WS-Federation and more as means of authenticating and authorizing users with airtight security protocol.
We isolate our machines, network and storage with respect to the AWS Standards in order to keep it safe and secure.
No, tenants are only allowed to use our secure protocols and procedures to prevent cracks and folds in data handling.
Yes, we do support our clients’ and tenants’ access review policies.
Our password setting requirements comply with all factors to ensure that strong passwords are created. Passwords should be of a minimum length and contain special characters, capitalized letters, and alpha-numeric combinations.
No, customers/tenants must comply with Xoxoday’s account lockout and password polices that have been incorporated for maximum security.
No, the user can set their own password from the very first login attempt.
No. As Xoxoday’s products use single sign on (SSO), the users can login via their suite email and credentials.
Yes, audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
Yes, to ensure the maximum safety and authority of data in right hands, the physical and logical adult log access of users can only be accessed by authorized personnel.
No, logs are automatically audited, but are not integrated with tenant’s security ops. In case the tenant requests for logs, they can shared when asked for by the clients.
Yes, regular audit logs are stored with Xoxoday and retained for future references.
The event logs are stores in a bucket wherein nobody can access them without an approval from the high authorities i.e. the Chief Technical Officer.
Yes, all the mechanisms related to security and policies are implemented to facilitate timely decision and investigation by root-cause analysis. These incidences are analyzed with network intrusion detection (IDS) tools.
Please refer to: “Threat & Vulnerabilities Management Procedures”.
Yes, in case specific incidents arise for particular tenants, our logging and monitoring framework allows isolation of incidents.
Yes, there are measures to limit the access of tenant’s data from non-authorized devices. Please refer to “Access Control Procedures”.
No. In case the accounts are deactivated or dormant, they would still be in the Xoxoday’s domain. The admin would have to manually reach out and disable the accounts that they wish to declare dormant or inactive.
Yes. Passwords once used cannot be reused with the password history technique in order to disallow the reuse of old passwords. Please refer to “Password Management Policy”.
Yes, with access control limit, super admins and admins can give out access to authorized individuals as per requests raised by them in order to handle their platform as well as the personal data accordingly.
Yes, the role of “admin” and “super admin” holds the high regards and these roles can process the personal data of users as per their choice with the access control limit capability.
Yes, personal data is stored are registered databases that comply to all necessary inputs of a standard inventory repository.
Yes, all the given credentials are safely stored in a TCCC-approved centralized system in order to securely process the personal data.
Yes, our roles and job duties are segregated through role-based access to ensure maximum security of tenants’ databases.
Yes, in case an incident occurs with respect to inappropriate access of data, we shall share the reports.
Yes, we do support measures to enforce strong multifactor authentication when it comes to accessing highly restricted data.
No, the data can be accessed by Xoxoday’s authorized personnel to serve you better with maximum security.
We have AWS Identity and Access Management (IAM). Access to data and systems is based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. A strong identification and authentication system and logging systems are deployed and provide centralized control to administer, monitor, and review all critical access events.
AWS is responsible for providing physical security to the data center as we have deployed our application on AWS. AWS provides physical data center access only to approved employees. All employees who need data center access must first apply for access and provide a valid business justification. These requests are granted based on the principle of least privilege, where requests must specify to which layer of the data center the individual needs access and are time-bound. Requests are reviewed and approved by authorized personnel, and access is revoked after the requested time expires. Once granted admittance, individuals are restricted to areas specified in their permissions. Third-party access - Third-party access is requested by approved AWS employees, who must apply for third-party access and provide a valid business justification. These requests are granted based on the principle of least privilege, where requests must specify to which layer of the data center the individual needs access, and are time-bound. These requests are approved by authorized personnel, and access is revoked after request time expires.
Yes, we have implemented the process for termination from employment. Once the employee is terminated all the access will be revoked, IDs are disabled, assets are returned and recorded as a part of the exit clearance. We have implemented the access control procedure and all the access will be revoked upon termination or transfer of an employee as per the compliance requirements.
Yes. We use a cloud-hosted VPN with strict access controls to allow our employees to access the official network.
Yes, We have implemented the security operations center to monitor, prevent, detect, investigate, and respond to cyber threats around the clock.
We have AWS Identity and Access Management (IAM). Access to data and systems is based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. Furthermore, while defining job roles and designing access roles, privileges leading to conflicts of interests are to be avoided. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access events.
our identity federation standards include SAML 2.0, SPML, WS-Federation and more as means of authenticating and authorizing users with airtight security protocol
We use a cloud hosted VPN with strict access controls to allow our employees to access the official network.
Wireless access is allowed and handled with high quality routers, password protection and restriction on internet usage etc.
All our employees are having a unique email IDs and we have implemented the role based access control. Our product team will create an account for the admin users and the password can be changed immediately.
Yes, we have the exit procedure and all the access provided to an employee will be removed or deleted.
Yes. We review the access provided every month and the SPOC will be our system administrator.
Yes. We have defined the number of unsuccessful attempts. After 3 unsuccessful logins the account will get locked.
Yes, we have the different levels of access. For Ex - Admin, users.
Yes. Every 90 days
We will get an email for resetting the password. Once we click on it it will take us to a different window and provide an option to change or reset the password.
We use only internet connection through wifi and only after the approval process IT Team will provide an access.
Yes. We have all these controls. We have restricted access to shared folders, USB or external drives, Internet access and privileges access.
Yes. We have a track of all these information and we will remove the access once the empoyee left the organization.
Yes, we have different level of access like Admin and users and its configured in a secured manner.
It’s an application and it supports SSO and Active directory. Time our period that we configure in SSO/AD would apply.
Yes. We have segregated the areas. We have implemented the controls for having the access only to an authorised individuals for production area.
Yes, we have the controls.
Yes. We have segregated the users.
Sharing device is not allowed. All the permisson needs to be taken from the IT Team. Not provided these access to the employees.
We have different levels of users and only upon approval and need basis will get access.
At Xoxoday for all the critical applications the 2FA has been enabled.
only Xoxoday authorised individual will have an access
All the computer machines are restricted with Access to CDs, USB or any other hard drives. We do not grant access for security reasons.
The secured areas are restricted and does not have access with electronic devices or mobiles. These areas are physically locked and periodically reviewed as a part of internal and external audits. Also these restricted area are secured with CCTV cameras and monitored 24*7 for security reasons.
We have implemented the access control procedure and we revoke the access rights of the employees when not needed or termination from the employment. Access granted and revoked will be reviewed regularly and validated during the internal and external audits.
Access to the systems are based on the principles of least privilege for access. All the users have restrictions on installing and uninstalling the application/softwares, they are not provided with Admin access. Admin access will be with the the IT support head and will not be available for the normal users.
We remove the access immediately after termination of an employees as a part of exit procedures. We inform the BSLI incase of any involuntary termination of an employee working on client account within a reasonable timeframe
We have implemented the role based access control policy. We regularly monitor the user access controls and make neccessary reconciliation for security reasons.
Our employees are provided access for corporate emails. But we have restricted for accessing other email service provider, sending the PII on emails, sending an email to personal email Ids etc for maximum security.
All our employees are not provided with access to the client data. Only authorised individual will have access on need and approval basis. The approvers are either the Product Heads or CTO. Content Filtering Solution in place for cotrolled access to Internet and all the logs are monitored.
We have the documented procedure in place for user access management. Attached the Access Control Procedure. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need to know basis and support segregation of duties. Access to data and systems are based on the principles of least privilege for access and need to know basis. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. Only authorised individual will have access on need and approval basis. The approvers are either the Product Heads or CTO.
We provide option of work from home/remotely to our employees. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory.
All the computer machines are restricted with Access to CDs, USB or any other hard drives. We do not grant access for security reasons. We have Changed default credentials and turned off services that are not needed. MFA has been enabled to make sure that only authorised individuals have access. We have implemented Cloudflare web application firewall, IDS, Guard Duty etc in order to prevent DDOS-type attacks. (Attached the evidence of Cloudflare web application firewall, IDS, VA/PT reports, guard Duty etc) We have implemented the role-based access control system and Only authorized users have access to the servers. logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long-term cloud storage. mechanisms are implemented to detect, address, and stabilize vulnerabilities We also have implemented the backup plan. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. Data backups are done daily and in a secured way in AWS.
All the systems are secured with Bitdefender end point security, VPN, Active directory, Firewall etc for maximum security.
All the sensitive areas are restricted and authorized personnel only can have access. Our facility is having Biometric access system and all the logs are maintained and periodically reviewed. We also have visitors management guidelines and All visitors and contractors are required to present identification and are signed in and continually escorted by authorized staff.
AWS Identity and Access Management (IAM) enables us to manage access to AWS services and resources securely
We have 3 types of roles - User, Admin and Super Admin. Based on the roles and responsibility these access can be provided on need and and approval basis.
Xoxoday application platform collects PII like Name, email ID and Phone number of the employees those who will be using this platform. Xoxoday is ISO 27001:2013 certified, GDPR compliant and SOC 2 type I certified organization and have all the required technical and organizational controls in place and auditred during the internal and external audits. We have implemented the role-based access control system and Only authorized users have access to the servers. We use Amazon IAM for Identity access management. logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long-term cloud storage. mechanisms are implemented to detect, address, and stabilize vulnerabilities We also have implemented the backup plan. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. Data backups are done daily and in a secured way in AWS.
Our network is protected through the use of key cloud security services, integration with our Cloudflare edge protection networks, regular audits, and network intelligence technologies, which monitor and/or block known malicious traffic and network attacks. Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a Vulnerability assessment and penetration testing.
Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role based access requirements. Furthermore, while defining job roles and designing access roles, privileges leading to conflicts of interests are to be avoided. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access. We conduct the access control review on frequent basis and revoke all the access provided for exit employees.
We have unique user IDs for all and does not use generic user IDs.Access to data and systems are based on the principles of least privilege for access. We conduct the access control review on frequent basis and revoke all the access provided for exit employees. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need to know basis and support segregation of duties. Privileges relating to Administration of user access privileges and role configurations are different from the authorized approver that approves access requests. The approvers are either the Product Heads or respective function Heads are their authorized delegates. Attached the Access control procedure.
An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need to know basis and support segregation of duties.
All our employees are having the unique log in IDs.
We use a cloud hosted VPN with strict access controls to allow our employees to access the official network.
We provide application web application.
Admins can control the application and will have an access to alerts and security events.
We inform the the customer to revoke access.
We have the alerting system in place and we perfom the scaning immediately in order to reduce the risk.
They do not have access.
Yes. We have role-based access system through access control policy to make sure that only the authorised individual has access to the required information. All the Access to data and systems are based on the principles of least privilege for access. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. The approvers are either the Product Heads or respective function Heads are their authorized delegates.
Yes, We have the necessary controls in place in order to protec the information according to the data classification. For ex - Identity access management (IAM)
Yes. We have a SIEM in pance for monitoring and maintaining logs over security incidents from various components.
Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access. We have role-based access system through access control policy to make sure that only the authorised individual has access to the required information. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles
Only authorised individual would access on need and approval basis. We also use SSO.
All our employees are using official email IDs
We have implemented Role based Access control policy and only authorised individual will have access upon need and approval basis.
Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role based access requirements. Furthermore, while defining job roles and designing access roles, privileges leading to conflicts of interests are to be avoided. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it’s linked with the SSO/Active Directory.
We monitor and review these privileged access provided and do the necessary reconciliation as per the Access control policy implemented.
  1. Xoxoday application has a rich set of integrations with HRMS, HRIS, CRM, Survey, Marketing automation, SSO, SAML tools like SAP SuccessFactors, Zoho People, Darwin Box, Hubspot, Freshworks, Zapier, Hubspot, Type Form, Survey Monkey, Survey Gizmo, SAML 2.0, etc 2. SSO SSO Redirection - The client has to generate temporary token for SSO and redirect the user to Xoxoday with this temporary token. Please click here - https://xoxoday.gitbook.io/application/developer-resources/storefront-integration/api-endpoints/sso-redirection#sso-token-from-company-session
Access to our production environment is allowed only via Xoxoday corporate network and access is allowed only to authorized individuals of the infrastructure and engineering team. Given the pandemic/WFH situation, VPN access has been enabled with 2FA For such authorized individuals, for ensuring business continuity. All our admins accounts has been sealed with MFA. and also we use AWS IAM for managing privileged identities.
We revoke the access once the tasks is performed or terminated from the organization as per the access control policy and part of the HR Exit clearance. Yes. access revocation process synchronized throughout all the systems. Attached the Access control policy.
We have implemented the Role-Based Access Control (RBAC) An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need to know basis and support segregation of duties. Privileges relating to Administration of user access privileges and role configurations are different from the authorized approver that approves access requests. The approvers are either the Product Heads or respective function Heads are their authorized delegates. We review the access rights on monthly basis. Attached the access control policy.
We have implemented the incident management procedure and attached the same. We communicate with Preliminary Incident Synopsis and Root Cause Analysis report (RCA) including the details of Business Impact, Issue Description, Root Cause, and Corrective Actions.
We use logical data isolation with the help of company specific encryption keys. We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. The incidents in other tenants would have no effect on the customer’s services.
We are adhered to ISO 27001:2013, GDPR, CPRA, SOC 2, CSA STAR and VA/PT - Shared these certifications and Audit reports. We have implemented the Access control policy and shared the same for your reference. All our admins’ accounts have been sealed with MFA. and also, we use AWS IAM for managing privileged identities. All our Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long-term cloud storage. The audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
application support many SSO options such as - Google workspace. Azure AD, OKTA SSO, Onelogin, Ping Identity, Centrify etc..
There are four access roles: Super Admin, General Admin, Manager and Employee. Manage the level of access for each role through the access controls page
application is a web application and also supports Android and iOS apps. application is supported by a comprehensive web application that can be accessed via desktop and mobile browsers on all compatible devices. For ex -Google chrome, Internet explorer, Microsoft edge etc..
The access control mechanism like RBAC is built in the application. We have a Super Admin, Admin, and user’s account.
Please click here to know more about SSO integration - https://www.application.io/integrations It supports Azure AD, Google workspace, Okta SSO, One login, Ping identity SSO, Centrify etc..
Its supports Azure AD integration.
No. it does not. Once SSO is enabled, the users are not presented with any password options.
Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. A strong identification and authentication system and logging systems are deployed and provide a centralized control to administer, monitor and review all critical access. We have a role-based access system through access control policy to make sure that only the authorised individual has access to the required information. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. The approvers are either the Product Heads or respective function Heads are their authorized delegates.
We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team, and it’s linked with the SSO/Active Directory In addition to that we also use Encryption, Firewall, Bitdefender end point security etc.
We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team, and it’s linked with the SSO/Active Directory
We have implemented the Web application firewall, IDs/IPs and amazon guard duty etc for maximum security. OAuth2 is used to authorize all API requests. We also conduct code review to make sure that the APIs are secure.
Yes. application supports SSO like Okta SSO, Onelogin SSO, Ping Identity SSO, Centrify etc.. Please click here to know more about application SSO - https://www.application.io/integrations?tab=tab-sso
Our identity federation standards include SAML 2.0, SPML, WS-Federation
It Supports MS Azure active directory.
No.
We store password hashed. We have SHA512 hash with unique salt for every password
No. 2FA is not required for logging into the application. We only support SSO with the help of SAML2.0 protocol.
Yes. It supports SSO and OKTA Integration
Yes. The account owner will receive an email notification and all the activities are logged.
The account owner will receive an email notification and immediately and user can act on it.
We have enabled password reset process. It identifies from the domain name of the email ID. We can Change the password of the application account by navigate to Setting in the Quick Access menu.
2FA is not supported.
Yes. We have defined accessibility features, role-based permissions, access control and can Manage user access to various account functionality based on organizational needs.
When SSO (via SAML2.0) is enabled login via password will be technically prohibited
Yes. Users can provide complex password to make sure that the account is secure.
Yes. We have enabled Multi factor authentication. Our application also support multi factor authentication.
We have implemented the access control policy to make sure that only the authorised individual have an access to the data. You may suggest if anything needs to be added as per NSE access control policy.
Super admin have complete control of the platform and can configure everything.
We have the controls in place. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks.
We have controls in place to monitor the user access system. We have implemented Role based access management system through access control policy. We also conduct internal review, Audit and external Audit from the third party auditors to make sure that we are complying with the requirements.
Yes, our identity federation standards include SAML 2.0, SPML, WS-Federation and more as means of authenticating and authorizing users with airtight security protocol.
We use Freshdesk and Jira for Authorizing access.
We have role based access system to make sure that only the authorised individual have an access to the required information. We also have Access Control Procedure as per the compliance requirements.
Yes. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory.
Yes. We have enabled MFA for maximum security
Yes
Yes. We have access control policy and change manangement policy in place. Our IT team periodically review the access granted to all the users and take necessary actions. Revocation of access and Asset submission is part of our exit procedure upon termination from the employment.
We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory.
We use AES 256-bit encryption for data at rest for securing digital identities
We store password hashed. We have SHA512 hash with unique salt for every password
The cryptographic keys, including data encryption and SSL certificates are managed by Xoxoday for optimal security of sensitive data. Each tenant data is uniquely encrypted using client specific key. We use AES 256 bit encryption for data at rest to ensure maximum security measures.
Yes
Yes
Yes
Yes
API Keys are stored in high availability ephemeral storage and not in any disc.
Yes
Yes
Yes. We follow role-based access system. We have implemented an access control policy and it will restrict access of the authorised individuals only.
At least 8 characters45 days5 attempts
Yes
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in long-term cloud storage
All users have benn assigned a unique user account. We have implemeted the Access control Policy and all the system components, network files, sensitive data will be accessed my the unique user accounts.
All users have benn assigned a unique user account. And will not be reused by other people in the future.
Admins will have a Centralised directory and can manage the users. For ex - Creation and deletion of the users.
We are Compliant. We have implemented the Network Access Control and Security Procedure. We are diligently controlling access to computer resources, enforcing policies, Firewall, Switches etc
We review the access controls on periodical basis and make sure that only authorised individual will have an access to the Information system. We grant privileges only upon the need and approval basis as per the access control policy.
We review the access controls on periodical basis and make sure that only authorised individual will have an access to the Information system
We have the monitoring system in place. Unauthorised access or attempts will be detected and prevented
We have implemented the role based access control system. Only approved users will have an access to the Business application.
We have controls in place to monitor the user access system. We have implemented Role based access management system through access control policy.
We are compliant. Only authorised individual have an acces.
We are compliant
We use 2FA wherever is required to safeguard the information system.
We grant an access to the vendor whenever is necessary on approval basis and access will be revoked upon the tasks completion.
We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory for more security.
We have granted the logical access to the third parties upon approval and Agreement in place.
We have disabled all the access for security purposes. The access will be provided only on need and approval basis for a specific period of time.
We are compliant. We have role based access system to make sure that only the authorised individual have an access to the required information All the devices and emails are having adequate security controls. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.We have SDLC Policy as per ISMS requirements and we follow General Coding Practice. For example - We Conduct data validation on a trusted system, All cryptographic functions used to protect secrets from the application user.We also have Implemented least privilege; restrict users to only the functionality, data and system information that is required to perform their tasks.
We have installed the firewalls to monitor and control the incoming and outgoing network traffic based on predetermined security rules. It helps us to establishes a barrier between a trusted network and an untrusted network. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory for more security.
we can provide limited access to different vendors or systems.
We are compliant. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network.
We have implemented the Network Access Control and Security Procedure. Network services are provided in house. We maintain the records for the service levels and reviewed during the internal and external Audits.
We always make sure that components are configured to the most restrictive mode.
We provide access to our employees to only required amount of functionalities for any software applications.We uninstall the softwares or disable the features wherever is not required.
We have disabled all the access for security purposes.
We are compliant.
We are compliant.
Only authorised individual have an acces to the approved information assets.
We provide access to authorised individual on approval basis
Our application doesn’t have a 2FA for admin functions.
We have role based access system to make sure that only the authorised individual have an access to the required information.
Yes. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest.
As per the access control policy our application controls the access of an unauthorised individual through diference levels of users like Admin, super admin and users.
Yes. We are complied. We have the access control policy and password policies.
We have access control polic and only the authorosed individual have an access to the PII on need and approval basis. We also review these access granted on monthly basis.
We have access control system in place and only the authorised individual have an access. Attached the procedure for your reference.
application supports SSO.
our identity federation standards include SAML 2.0, SPML, WS-Federation,Google SSO Login and more as means of authenticating and authorizing users with airtight security protocol
The application have robust authentication methods. We are integrated SAML 2.0 with SAP SuccessFactors, we also support OAuth 2.0 for seamless authentication.
Yes -SSO
Yes. We also fix the issues identified and conduct the test once again for confirmation of fixes.
Our partnerships with a wide array of integration partners ensure existing customer based Single Sign On (SSO) capability for all users to seamlessly use Xoxoday’s products. With an easy DIY setup, your SSO solution would be plugged in and ready to go.
Yes. We have physical access controls in place and only authorised individuals will have access. We have provided the access cards to all the employees and installed biometric machines at all the entry and exit areas. We have also installed the CCTV cameras in our building and will be monitored 24*7 for maximum security.
We have implemented the access control policy and only authorised individual will have access to the systems/application. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need to know basis and support segregation of duties Access to the production environment is restricted to a limited set of authorized users based on their job responsibilities. Users from the development and testing or QA teams do not have access to the production environment. Access to migrate changes is limited to designated and authorized individuals. Access to the production environment is approved by the Product Owner and the systems of the authorized users are registered and authenticated during login. The access is controlled through the AWS Identity and Access Management system that also enforces two-factor authentication.
Yes. The list of users who have admin access have been maintained through AD, IAM, HRMS etc..and reviewed periodically and during the internal and external audits.
Mobile devices are not allowed for production use.
Yes. All the sensitive information has been encrypted. All the data at rest also has been encrypted for maximum security.
Yes. All the software installation restricted for desktops, laptops and servers. Users does not have permission to install any software or make any changes.
Yes. Access to source application code restricted. Application code has been stored in the code repository and have access only to the authorised individuals. We have implemented SDLC Policy as per ISMS requirements and we follow General Coding Practice. For example - We Conduct data validation on a trusted system, All cryptographic functions used to protect secrets from the application user. We also have Implemented least privilege; restrict users to only the functionality, data and system information that is required to perform their tasks we follow all the technical guidelines for development of our code and applications that come under the Open Web Application Security Project.
Yes. All our users uses unique IDs. There are no shared accounts.
Only authorised individual would access on need and approval basis. We also use SSO.
All our employees are using official email IDs
We have implemented Role based Access control policy and only authorised individual will have access upon need and approval basis.
Yes. We have role-based access system through access control policy to make sure that only the authorised individual has access to the required information. All the Access to data and systems are based on the principles of least privilege for access. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. The approvers are either the Product Heads or respective function Heads are their authorized delegates.
Our employees will not have access by default. The data will be accessed only upon need an approval basis. The access is controlled through the AWS Identity and Access Management system that also enforces two-factor authentication
Yes.
No, we don’t provide multi-factor authentication. As of now, there’s oAuth2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins.
Yes, We have the necessary controls in place in order to protec the information according to the data classification. For ex - Identity access management (IAM)
Yes.
Yes.
We have implemented the physical access control and logical access control to protect the personal data. We have security guards, CCTV cameras, access cards etc for monitoring purposes. We use logical data isolation with the help of company specific encryption keys. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256
Only authorised individual will have an access.
Yes. The administrator has the privileged access and can add or terminate the users. Admins have complete control of the platform and can configure the addition and deletion of the users through the admin console.
Yes. application comes with a full set of integration with various platforms like AD.
No. We do not use 3rd party application framework
It’s a SAAS Solution and can login in the multiple system by using the Single user ID/Password.
Yes, there is a protocol in place to ensure that no information beyond an unsuccessful login attempt goes through prior to a successful login.
Yes. We have this mechanism.
Yes. solution disable the User ID automatically if the unsuccessful attempts exceeds the maximum of trial
Yes
Yes.
Its not shown in the screen or sent via email.
We have enabled the role-based access system to provide an access to only authorized individuals.
Yes. It can be managed centrally.
The platform will get locked out as configured in AD or SSO ect
No. Its linked with the Email IDs
Yes. We can set up an account with the help of unique email IDs
Yes
It supports Email and Mobile phone Authentication.
JSON-based token is available for maximum security direct-email logins.
We have implemented the role-based access system to make sure that only the authorized individual have access to the required information.
We have more than 100 employees for the application product including support functions. Few important positions those who are involved in Infosec and IT Security Functions Chief Operating Officer Vice president - application DevOps Head - application Product Head - application Infosec Manager IT Head
We have Access Control Procedure and role based access system to make sure that only the authorised individual has access to the required information.
application collaborated with the tools like MS Teams, Slack and HRMS tools like Gusto, Keka, SAP Successfactor, BambooHr, Ramco HRMS, people strong, Zohopeople and darwinbox. Users can also login via G Suite, Azure AD, Okta SSO, One login SSO, Ping identity SSO and Centrify.
We have 4 user access roles - Super admin, General Admin, Manager and Employee.
application collaborated with the tools like MS Teams, Slack and HRMS tools like Gusto, Keka, SAP Successfactor, BambooHr, Ramco HRMS, people strong, Zohopeople and darwinbox. Users can also login via G Suite, Azure AD, Okta SSO, One login SSO, Ping identity SSO and Centrify.
Yes. we have the Physical security controls in place. Attached the Physical and Environmental Security Procedure. All the Fincare data will be stored on AWS Cloud virtual platform and will not store anything locally. The purpose of this procedure is to prevent unauthorized physical access, damage, interference, theft or compromise to assets owned or controlled by Nreach Online Services Private Limited.
Yes. We have the Access control policy to make sure that the data os available only to an authorised individual.. Attached the Access control policy.
Yes.
Attached the Access control policy
No.. it does not. Once SSO is enabled, the users are not presented with any password options.
Super Admin (CTO) and Devops team are the custodians of the key.
Since empluls is SaaS platform this can be configured with the help of the Active directory so that the users who are inactive for more than 15 mins can re-login.
Yes. Account can be created, disabled and password can be reset.
Password is masked during the entry. We store password hashed. We have SHA512 hash with unique salt for every password.
Since empluls is SaaS platform this can be configured with the help of the Active directory.
Yes. This can be configured and users can reset the password.
Admins will have a centralised controls on the platform and will have access for creation/deletion of the users as per the requirements. Please click here to know more - https://help.application.io/platform-management/platform-settings/access-controls
Admins will have a centralised controls on the platform and will have access for creation/deletion of the users as per the requirements. Please click here to know more - https://help.application.io/platform-management/platform-settings/access-controls
application has four different user access levels, namely Super Admin, General Admin, Manager, User. Please click here to know more - https://help.application.io/platform-management/platform-settings/access-controls Application can be used only by the authorised individuals.
We have implemented the oAuth2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins.
At Xoxoday, the access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role based access requirements. A strong identification and authentication system(AWS IAM) and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access events.
Yes the application have robust authentication methods. The users can re-authenticate a change in credentials and we comply to any attempted change in authentication information. our identity federation standards include SAML 2.0, SPML, WS-Federation and more as means of authenticating and authorizing users with airtight security protocol.
At Xoxoday we review the access controls on frequent basis.
We remove/revoke the access of the users upon termination or the access is not required and maintain these records for Audit purposes.
At Xoxoday we review the access controls on frequent basis. Compliant. Attached the Access control policy.
Yes. The customer will have control on the Application as they will be having the Super admin access.
Yes. The users can access the mobile application only upon successful login.
We provide remote support using the client remote access tools.
We have implemented the Role based access control machanism. Attached the Access control policy. We have the controls in place on who access the information and what level of access needs to be provided etc..
At Xoxoday we have implemented the Identity access management and all the applications are authenticated before login.
We conduct the code review and get an approval from the CTO before releasing any new versions or updates.
At Xoxoday we have implemented the Identity access management and all the applications are authenticated before login.
Compliant. Only authorised individuals can have access to the application with the help of the valid credentials.
No. Its not accessed via direct internet connection. Access to our production environment is allowed only via our corporate network and access is allowed only to authorized individuals. We use a cloud hosted VPN with strict access controls. VPN access has been enabled with 2FA For such authorized individuals.
We have Role-based access control (RBAC) system and make sure that only the autorized individual have an access to the data. And we review these access provisoining regularly and deactive the users access as per the change management policy.
No. We do not use generic IDs to access data
application application has four different user access levels, namely Super Admin, General Admin, Manager, User.
Super Admins are the default admins of application. They are also the Group Admins of Townhall. Super Admins can view what access permissions are available to various user access levels using Access Control settings. Super Admins can also delegate access for various features and tasks to General Admin, Manager & User. Within Xoxoday, Access to data and systems are based on the principles of least privilege for access. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access events.
We have implimeneted the Access Control policy and follow the role based access control system. And all the access has been reviewed and make the necessary adjustments. The roles and access rights are reviewed during the internal and external Audits as well.
Our partnerships with a wide array of integration partners ensure existing customer based Single Sign On (SSO) capability for all users to seamlessly use Xoxoday’s products. With an easy DIY setup, your SSO solution would be plugged in and ready to go. our identity federation standards include SAML 2.0
At Xoxoday we have enabled MFA for all the critical roles and privilege accounts for maximum security.
At Xoxoday user accounts will lockout after 5 unsuccessful failure login attempts.
At Xoxoday all the users enforced to change the password for every 90 days.
We store password hashed. We have SHA512 hash with unique salt for every password.
We have implemented the Identity access management and follow the Access control policy.
At Xoxoday we follow the password policy.
We have implemented the Identity access management and follow the Access control policy.
At Xoxoday we follow the password policy. Attached the same for your reference.
Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access.
We have role-based access system through access control policy to make sure that only the authorised individual has access to the required information. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. The approvers are either the Product Heads or respective function Heads are their authorized delegates.
We logically segregate the the customer environment from other clients, each customer is uniquely identified by a tenant ID. It is segregated with a client-specific key for proper handling and security reasons. The application is engineered and verified to ensure that it always fetches data only for the logged-in tenant. Per this design, no customer has access to another customer’s data.
An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. Privileges relating to Administration of user access privileges and role configurations are different from the authorized approver that approves access requests. The approvers are either the Product Heads or respective function Heads are their authorized delegates. Developers do not have access to the production environment. Access to the production environment is restricted to a limited set of authorized users based on their job responsibilities
Within Xoxoday Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. Furthermore, while defining job roles and designing access roles, privileges leading to conflicts of interests are to be avoided. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access. We use Active directory and SSO for authentication purposes.
Within Xoxoday Access to data and systems are based on the principles of least privilege for access. Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. Privileges relating to Administration of user access privileges and role configurations are different from the authorized approver that approves access requests. The approvers are either the department heads or the management.
At Xoxoday only authorised personnel from our technical team will have access. For Ex – CTO/production head, Devops Lead etc.. The event logs are stores in a bucket wherein nobody can access them without an approval from the high authorities i.e. the Chief Technical Officer.