Skip to main content
Yes, policies and procedures are established and mechanisms are implemented to detect, address, and stabilize vulnerabilities in a timeframe that matches the Security Patch Management Standards.
Yes, Xoxoday’s products are supported by leading anti-malware programs. These are connected with our cloud service offerings and are a part of all our systems.
Yes, we perform periodic scans of operating systems and databases along with server applications for vulnerability and configuration compliance. This is done by using suitable vulnerability management tools as per the industry standards.
Yes, we ensure that there is no breach in network layers with vulnerability scans as per the industrial standards.
Yes, to check the hygiene of application layer, our vulnerability scans are done as prescribed by the industrial standard.
Yes, tenants can request for vulnerability scan reports.
Yes, in order to detect any unauthorized changes in the data or system configuration, we have a procedure in place for host/file integrity monitoring.
No, our periodic vulnerability scans are conducted just the right number of times to ensure the prominence of security measures and protection of the operating system layer.
No, our periodic vulnerability scans are conducted just the right number of times to ensure prominence of security measures and protection of the database layer.
No, our periodic vulnerability scans are conducted just the right number of times to ensure the prominence of security measures and protection of the application layer.
Yes, vulnerability scans and penetration tests are conducted periodically by third parties and external services to test our security measures.
Reach out to us at cs@xoxoday.com to raise a ticket, if you happen to notice any potential security issue whilst meeting all the required criteria in our policy. The validation of the reported issue in terms of severity & authenticity will be done by our security team in around 90 days. Post validation, steps will be taken to fix the security issues in accordance with our security policies. The owner of the ticket will be informed once the issue is resolved.
Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing.
We have fixed all the issues identified during the VAPT Audit and rescanned it once again to make sure that all the vulnerabilities are remideiated. Post confirmation of these fixes we got the final VAPT Certificate for our product.
Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing.
60 days.
We conduct the VA/PT on annual basis as per the compliance requirements. Manual and third party tools are used for this assessment.
Yes. We have the capabilities to patch the vulnerabilities.
We conduct VAPT on annual basis.
we follow all the technical guidelines for development of our code and applications that come under the Open Web Application Security Project. And also we conduct VAPT Assessment for our application and remidiate the findings
we perform periodic scans of operating systems and databases along with server applications for vulnerability and configuration compliance. This is done by using suitable vulnerability management tools as per the industry standards.
our periodic vulnerability scans are conducted just the right number of times to ensure prominence of security measures and protection of the database layer.
We have implemented the Threat and Vulnerability Management procedures. We close the identified vulnerabilities or fixes the issues.
We conduct code reviews, VA-PT assessments, Log monitoring, Incident reportings etc and these controls are monitored and reviewed during the internal and external parties.
Attached the latest VAPT Certificate.
Attached the letest VAPT Certificate.
Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing. Attached the Threat and Vulnerability Management and Patch Management Procedure.
We conduct the Vulnerability assessment and penetration testing for maximum security.
We conduct on yearly basis as per the compliance requirements.
Attached the Threat and Vulnerability Management Policy.
Yes. As part of every build, the third-party libraries are scanned for security vulnerability.
Our software will be free from all the vulnerabilities.
Attached the independent third party performed a Penetration Test report.
We conduct the periodical vulnerability and penetration testing as per the compliance requirements which includes Static, Dynamic, API, Manual etc..
We perform the VA/PT on an annual basis as per the compliance requirements. Attached the VA/PT report and certificate.
We do conduct Vulnerability and Penetration testing from the Authorized vendor.
We comply with the requirements. We also conduct periodical Vulnerability assessment and penetration testing with the help of the authorised third party vendor.
We conduct internal review and audited by the exteranal auditors for our security standard certification and VAPT assessment
We conduct periodical Vulnerability assessment and Penetration Testing from the Inductry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications.
Exhaustive Vulnerability Assessment and Penetration Testing has been conducted along with business logic testing based on OWASP framework which incorporates 120+ test cases like Access Controls, Authentication and Session Management, Cross-site Request Forgery, Cross-site Scripting, Cryptography and Insecure Storage, Data Validation, Information Leakage and Error Handling, Malicious Execution etc.
We have conducted Vulnerability assessment and penetration testing with the help of Industry approved third party vendor. We conduct VAPT for every six months. During the testing, if any observations found by the auditor our team will work on those Audit observations and fix the issues.
See Threat and Vulnerabilities Management procedure attached. Periodic scans has been performed on all network assets deployed on Xoxoday by the third party vendor.
The critical vulnerabilities are fixed immediately within a span of 5 days.
We have the third party vendor called Appknox for scanning the vulnerabilities. They use Appknox tool(Mannual and Automated) for vulnerability management
See Threat and Vulnerabilities Management procedure attached. Periodic scans has been performed for application and the identified observation has been fixed by our engineering team.
We have the third party vendor called Appknox for scanning the vulnerabilities. They use Appknox tool(Mannual and Automated) for vulnerability management
We have Access control policy, and we follow Role based access system and review the access provided periodically to eliminate the risk and make sure that only the Authorised individual have access to avoid risk. We have implemented the controls with regards to avoiding source of Risk and to make sure that we prevent an unauthorised access of the data. We have implemented end point security in all the computers and servers to prevent the unauthorised access. We have Patch Management Procedure and Logging and Monitoring Procedure in place as per the compliance requirements. We also conduct periodical Vulnerability and penetration testing for identifying the source of risk and implement controls for mitigating the risk.
Yes. We update the patched and conduct the vulnerability assessment and penetration testing and remidiate the risks identified.
We have implemented the Incident Management Procedure and VAPT Audit periodically. Attached the latest VAPT Certificate.
We have implemented the Threat and Vulnerabilities Management procedures is to proactively expose security flaws and correct them before a malicious attacker can leverage the same weaknesses and cause irrecoverable damages.
We have implemented the Threat and Vulnerabilities Management procedures. We conduc the Vulnerabilities assessment and fixes the issue identified during the assessments.
We conduct the Vulnerability assessment for our application during the testing and prior to deployment.
We conduct Vulnerability assessment and penetration testing during the testing and before deployment. And we make sure that all the issues has been fixed and mitigated security vulnerabilities.
We conduct Vulnerability assessment and penetration testing for our application in order to make sure that issues has been fixed and mitigated security vulnerabilities.
We conduct Vulnerability assessment and Penetration testing in order to make sure that we identify the vulnerabilities and fixes the issue or mitigate the risk involved.
We have deployed our application on AWS cluod virtual platform and hardened in order to secure a system by reducing its surface of vulnerability.
We continuously monitor the Vulnerabilities and fixes the issue on a periodical basis. We also update the patches regularly to eliminate the security risk.
We make sure that we identify the vulnerabilities and fixes the issues in order to make sure that Information system is secure and free from vulnerabilities.
We conduct periodical vulnerability and penetration testing and fixes the issue identified and make sure that all the risk associated with these vulnerabilities are identified.
We have implemented the Threat and Vulnerability Management to identify and eliminate problems that could lead to a breach of confidentiality, availability, or the integrity of application data resources and to ensure adequate protection of client data. The treatment of vulnerabilities consists of the definition and implementation of controls and measures to eliminate vulnerabilities
Vulnerabilities will be categorized as Critical, High, Medium, Low and Information. We remidiate all the vulnerabilities identified.
We have implemented the Threat and Vulnerability Management to identify and eliminate problems that could lead to a breach of confidentiality, availability, or the integrity of application data resources and to ensure adequate protection of client data.
We monitor the vulnerabilities identified and remidiate it.
We follow this as a part of Threat and Vulnerabilities Management procedure.
We conduct Vulnerability assessment and penetration testing periodically and we can make this available for the customer on need to knoe basis.
We inform on our potential vulnerabilities and non-compliance issues aand make sure that we mitifate these issues
We conduct Penetration testing with the help of industry approved thord party vendor
Yes. We conduct third party Vulnerability assessment. Attached the certificate for your reference.
Yes. We also fix the issues identified and conduct the test once again for confirmation of fixes.
We will delete the data upon termination of the contract and confirm you. Our data cleaning process goes through an organized purge. Once the data is purged, it’s purged from all places.
Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a Vulnerability assessment and penetration testing. We conduct the VA/PT on annual basis and Attached the latest certificate. Security patches are rated as Critical, High, Medium and Low. Critical patches will be deployed immediately High patches will get deployed within 5 days Medium Patches will get deployed within 15 day Low will get deployed in 25 days.
Attached the Threat and Vulnerabilities Management program.
Attached the latest VAPT Certificate
Attached the VA/PT Executive report and Certificate issued upon remediation of all the vulnerabilities identified during the third party assessment.
VA/PT has been consucted with the help of the third party VAPT auditor. The name of the vendor is Appknox. We conduct VPAT for every six months and shared the latest VAPT Certificate.
Attached the Infrastructure Architecture diagram where all the security components are included. Attached the VAPT certificate and Cloud Computing Security Policy
Attached the Executive summary of VAPT report
Yes. As part of every build, the third party libraries are scanned for security vulnerability.
Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing.
We are compliant with this requirements. Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing as per the compliance requirements.
Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing. Attached the VAPT Certificate and executive report. All the vulnerabilities has been fixed.
We conduct the VAPT Assessment with the help of the authorised vendor and compliant with the requirement.
We conduct Vulnerability assessment and penetration testing from the Authorised vendor, and the identified Vulnerabilities will be closed in a timely manner. The treatment of vulnerabilities consists of the definition and implementation of controls and measures to eliminate vulnerabilities (e.g. applying a patch to the affect system) or to prevent the vulnerabilities from being exploited (e.g. deactivating a service or disallowing a firewall connection). Vulnerabilities will be categorized as Critical, High, Medium, Low and Information. We inform the Infosys Immediatly if any critical Vulnerability to be reported.
All are fixed and there are no open Vulnerabilities.
The testing is conducted and vulnerabilities has been mitigated before any releases.
We conduct Vulnerability assessment and Penetration testing as per the compliance requirements. The date of the most recent certificate is 01st March, 2021. Attached the vulnerability assessments/penetration tests report.