# Payments and Wallet Source: https://help-plum.xoxoday.com/account-administration/reporting/payments See how to view and track payment records for your Plum account, including wallet top-ups and reward-related transactions. *Plum's reports offer detailed insights into Reward transactions, enabling admins to manage organizational activities effectively.* Plum keeps track of all the transactions of Reward Points, Reward Codes, Reward Links, Perks History, and Plum GiftCard API. Reports allow you to check the status of your transactions along with details like invoice date, amount, invoice note, balance, and comments. You can also view the redemption history of the recipients. Plum diligently keeps track of all transactions involving Reward Points, Reward Codes, Reward Links, Perks History, and interactions via the Plum GiftCard API. Through detailed reports, users gain insight into the status of their transactions, including crucial details such as invoice dates, transaction amounts, invoice notes, current balance, and any accompanying comments. Additionally, users have the ability to delve into the redemption history of recipients, providing a comprehensive understanding of reward utilization. *** ## Accessing Reports as an Admin To access the plethora of reports available as a Super Admin, users simply need to navigate to the designated "Reports" section within the admin dashboard's navigation menu. Super Admins are granted access to a wide array of reports encompassing various transactional activities within the organization. **Note:** Admins view only their sent rewards, while Super Admins access all reports. It's important to note that while regular Admins are limited to viewing reports related to rewards they've issued, Super Admins have the privilege of accessing all types of reports, providing a more holistic view of organizational activities. Navigate to the "Reports" section in the admin dashboard's navigation menu as a Super Admin. * Access various reports covering organizational transactions. * Review scheduled future rewards and cancel them if needed. * Download reports via the "Download" button in the top right corner. In addition to viewing transactional reports, users can also manage scheduled future rewards, with the ability to cancel them if necessary, offering flexibility and control over reward disbursements. Furthermore, users can easily download reports by simply clicking on the "Download" button located in the top right corner of the page, facilitating seamless access to comprehensive transactional data. *** ## Exploring Payment Details ### Checking Payments Download From Mintlify * Click on 'Wallet icon on the nav menu * Click on 'Transaction history' * Customize payment reports using filters. * Explore payment details including invoice, amount, recharge, date, and status. * Export Excel reports to your email. Upon accessing the "Reports" section, users will encounter a screen similar to the one depicted in the provided image. To delve into payment details, users can simply click on the "View Report" option under the "Wallet History" section, initiating a deeper exploration into payment-related activities. **Pro tip:** Once within the payment report interface, users have the flexibility to customize their view by utilizing various filters to cater to specific requirements. This customization empowers users to extract pertinent information efficiently. Within the payment section, users can review detailed payment information, including invoice details, transaction amounts, the entity responsible for the recharge, transaction dates, and current payment statuses. This comprehensive overview enables users to gain valuable insights into financial activities within the organization. Furthermore, users can seamlessly export payment details in Excel format to their designated email addresses, facilitating easy access and further analysis of transactional data. By leveraging these robust reporting capabilities, users can effectively monitor and manage transactional activities within the Xoxoday Plum application, ensuring transparency, accountability, and informed decision-making. # Plum Gift Cards API Report Source: https://help-plum.xoxoday.com/account-administration/reporting/plum-gift-cards-api-report Learn how to access and read the Plum gift cards API report, used to track gift card transactions sent through the API. *Access detailed Gift Card reports for insights on product usage and recipient details.* *** ## Accessing Gift Card Reports Follow these steps to view detailed reports for Gift Card Reports: Go to dashboard and click "**Reports**". Within the "**Reports**" section, click on "**Gift Card**". You can select the sent date by clicking in the box "**Sent Date UTC**". Here you'll find detailed reports containing the following information fields: * Order ID * Product Name * Product ID * Recipient Email * Currency * Denominations * Date with Timestamp * Amount Charged * Status * Actions By following these steps, you can easily access and review reports specific to gift cards, providing valuable insights into product usage and recipient details. *** ## Filter the Report Click on the filter icon to filter the report by: * Order ID * Recipient Email * Sent Date * Delivered Date * Status * PO Number * Tag *** ## Manage Columns Click on ||| Columns Icon to manage the columns you wish to show in the report. Simply check or uncheck the boxes based on your requirement. The reports can be downloaded using the "Download" button on the top right. Feedback or Questions: Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com) # Reports Source: https://help-plum.xoxoday.com/account-administration/reporting/reporting-faqs Find answers to frequently asked questions about generating, reading, and troubleshooting reward reports in Plum. *** ## Can your reporting tools provide both a unified and department/program-specific breakdown so we can track performance and metrics across teams? Absolutely. The Xoxoday reward marketplace platform includes advanced reporting tools that offer both holistic and granular insights. Admins can view cross-team performance data or generate custom reports for specific departments or programs, helping stakeholders monitor redemption trends, participant engagement, and ROI. *** ### Is monthly reporting on points requests, including accepted and rejected transactions, supported? Yes, the Xoxoday survey rewards platform offers detailed monthly reports covering all redemption activities, including accepted and rejected requests. Admins can access, export, and schedule these reports to maintain full transparency and auditability across all rewards-related transactions. *FAQ on Notification and Cancellation* *** ## How do I receive notifications if scheduled rewards are not sent? In the event that scheduled rewards are canceled due to low balance or exceeding threshold limits, both admins and Super Admins will receive notifications. These notifications will provide detailed information about the canceled rewards, allowing swift corrective action to maintain a seamless rewarding experience for all users. *** ## Can I cancel rewards in bulk? Yes, users now have the ability to cancel rewards in bulk. Simply select all the users for whom you wish to cancel rewards and click on the "Cancel reward" button, as illustrated below: # Overview Source: https://help-plum.xoxoday.com/account-administration/reporting/reporting-overview Get an overview of Plum's reporting tools, covering how to track reward distribution, spend, and redemption activity across your account. *Explore insights into various reports within Plum* This article provides an overview of the reports available within Plum, a platform for managing rewards, incentives, and payments efficiently. Below are the different report types offered: * **Rewards API Report** — This report provides detailed insights regarding the usage of the Rewards API within Plum. Users can track API usage, performance metrics, and any issues encountered during API transactions. * **Reward Code Report** — The Reward Code report offers a comprehensive overview of all reward codes generated and redeemed within the platform. Users can monitor the distribution of reward codes, redemption rates, and any associated trends or patterns. * **Reward Link Report** — Users can leverage the Reward Link report to analyze the effectiveness of reward links distributed through Plum. This report provides insights on link clicks, conversions, and overall engagement with the reward links. * **Integration Report** — The Integration report provides insights into Xoxoday Plum's integration with external systems. Users can monitor integration status, track data synchronization, and troubleshoot any related issues. * **Payment and Wallet Report** — This report focuses on providing users with a detailed overview of payment transactions and wallet activities within Plum. Users can track payments, withdrawals, account balances, and any financial transactions processed through the platform. Through these reports, users can effectively monitor, analyze, and optimize their reward, incentive, and payment strategies within Plum. Whether it's tracking API performance, analyzing reward distribution, or monitoring financial transactions, these reports offer valuable insights to drive informed decision-making and enhance overall platform performance. Feedback or Questions: Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Reward Code Report Source: https://help-plum.xoxoday.com/account-administration/reporting/reward-code-report See how to generate and interpret the reward code report in Plum, covering distribution status and redemption activity. *Discover how to access detailed transaction reports for Reward Code* To view transaction reports for Reward Code, navigate to the Reports and then to the "Reward Code" tab. The reports provide detailed information such as recipient name, recipient email, date of delivery, campaign details, status, and more. *** ## How to Access Reward Code Reports To view the report for Reward Code, simply navigate to the "**Reward Code**" section. In this section, you'll find comprehensive transaction details, including "**Unique ID**", "**Payment Reference ID**", "**Recipient Name**", and "**Recipient Email**", along with other relevant information. To download the report, click on "**Download**" at the top right corner of the page. Select your desired time frame for viewing reports by clicking Send Date UTC. *** ## Tracking Email and SMS Activity in Rewards Code Report You can easily track Email and SMS activity in the Rewards Code report, enabling you to monitor and analyze the communication activities related to rewards distribution. Navigate to **Admin Dashboard > Reports > Reward Code.** Click the **'three dots icon'** to move ahead. Click **'View Details'** and, using the dropdown menu, view **'Activity Timeline'.** *** ## Filter the Report Click on the filter icon to filter the report by the options given. *** ## Manage Columns Click on ||| Columns Icon to manage the columns you wish to show in the report. Simply check or uncheck the boxes based on your requirement. Feedback or Questions - Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Reward Link Report Source: https://help-plum.xoxoday.com/account-administration/reporting/reward-link-report See how to generate and interpret the reward link report in Plum, covering distribution status and redemption activity. *Discover how to access and navigate detailed Reward Link reports with filtering options.* To view transaction reports for Reward Links, navigate to **Reports > Reward Link.** The reports provide detailed information such as recipient name, recipient email, date of delivery, campaign details, status, and more. *** ## How to Access Reward Links Reports * Click on **Reports >> Reward Link** * Explore detailed reports for Reward Links, including **recipient name, recipient email, date of delivery, campaign details, status**, and more. * Utilize the filter options provided to obtain specific reports based on criteria such as **recipient name, recipient email, batch ID, phone number, generation date range,** and more. * Download the report using the top **download button.** * Select your desired time frame by clicking on **Sent Date (UTC)** and choosing the range. *** ## Filter the Report Click on the filter icon to filter the report by: * Unique ID * Payment Reference ID * Recipient Name * Recipient Phone * Sent Date (UTC) * Redemption Date (UTC) * Status * Campaign * Batch ID *** ## Manage Columns Click on ||| Columns Icon to manage the columns you wish to show in the report. Simply check or uncheck the boxes based on your requirement. Feedback or Questions - Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Reward Points Reports Source: https://help-plum.xoxoday.com/account-administration/reporting/reward-points-reports Learn how to generate and interpret reward points reports in Plum, covering points issued, redeemed, and outstanding balances. *Easily view and download Reward Points transaction reports.* To view transaction reports for Reward Point, navigate to **Reports > Wallet History > Reward Point** tab. The reports provide detailed information such as recipient name, recipient email, date of delivery, campaign details, status, and more. *** ## How to Access Reward Points Reports * Navigate to **Reports.** * Click on **Reward Points.** * Utilize the filter options to obtain specific reports based on criteria such as recipient name, recipient email, batch ID, phone number, generation date range, and more. * Download the report using the top **download button.** * You can also select your desired time frame by clicking on Sent Date (UTC) and choosing the range. Select your desired time frame by clicking on **Sent Date (UTC)** and choosing the range. *** ## Tracking Email and SMS Activity in Rewards Reports You can easily track Email and SMS activity in the Rewards Points report, enabling you to monitor and analyze the communication activities related to rewards distribution. Navigate to **Admin Dashboard > Reports > Wallet History > Reward Points.** Click the **'three dots icon'** to move ahead. Click **'Take Action'** and the using dropdown view **'Activity Timeline'.** *** ## Filter the Report Click on the filter icon to filter the report. *** ## Manage Columns Click on ||| Columns Icon to manage the columns you wish to show in the report. Simply check or uncheck the boxes based on your requirement. Feedback or Questions: Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Manage Admins Source: https://help-plum.xoxoday.com/account-administration/user-management/add-admin-user Learn how to add a new admin user to your Plum account, including how to set their access level and permissions during setup. The **All Admins** page enables Super Admins to manage users who have access to the Plum Admin Dashboard. Super Admins can add Admins, assign or modify roles, configure rewarding thresholds, or delete Admin. To access the **All Admins** page, navigate to **Settings > Admin > All Admins**. Screenshot 2026 08 30 At 8 52 25 PM ## Add an Admin To add a new Admin: 1. On the **All Admins** page, click **Add New**. 2. In the **Add Admin** form, enter the user's **Name** and **Email Address**. 3. Select the appropriate role: * **Admin:** Provides access to the Plum Admin Dashboard with the permissions assigned to the Admin role, including the configured rewarding threshold. * **Super Admin:** Provides full access to the account and Super Admin features. 4. Click **Save**. The new user can sign in to the Plum Admin Dashboard with the permissions assigned to their role. ## Edit Admin Super Admins can change an Admin's role at any time. To change an Admin's role: 1. Locate the user in the **All Admins** list. 2. Click the **three-dot menu** under the **Actions** column. 3. Select **Edit Admin**. 4. Change the **Role** to **Admin** or **Super Admin**. 5. Click **Save**. Screenshot 2026 08 30 At 8 52 50 PM The user's permissions are updated automatically based on the newly assigned role. * Changing an **Admin** to a **Super Admin** grants access to Super Admin features. * Changing a **Super Admin** to an **Admin** removes access to Super Admin-only features. The updated settings take effect immediately. ## Change to Report View Super Admins can change an Admin's access to **Report View**, where applicable. Report View provides access to relevant reporting information without providing the administrative permissions available to an Admin or Super Admin. To change an Admin to Report View: 1. Locate the Admin in the **All Admins** list. 2. Click the **three-dot menu** under the **Actions** column. 3. Select **Edit Admin**. 4. Change the access or role to **Report View**. 5. Click **Save**. Screenshot 2026 08 30 At 8 53 47 PM The user's access is updated based on the permissions associated with **Report View**. Administrative actions that are not included in Report View are no longer available to the user. ## Delete an Admin Super Admins can delete an Admin to revoke their access to the Plum Admin Dashboard. To delete an Admin: 1. Locate the Admin in the **All Admins** list. 2. Click the **three-dot menu** under the **Actions** column. 3. Select **Delete Admin**. 4. Confirm the action. Screenshot 2026 08 30 At 8 54 27 PM Once deleted, the user can no longer sign in to the Plum Admin Dashboard. Historical activity associated with the user is retained for audit purposes. # Manage Thresholds Source: https://help-plum.xoxoday.com/account-administration/user-management/managing-threshold See how to configure approval thresholds for admin users in Plum, controlling how much they can send without additional sign-off. ## Edit Rewarding Threshold Super Admins can configure or modify the **rewarding threshold** for an Admin. The rewarding threshold defines the maximum amount that the Admin is permitted to reward, based on the limits configured for the account. To edit the rewarding threshold: 1. Locate the Admin in the **All Admins** list. 2. Click the **three-dot menu** under the **Actions** column. Screenshot 2026 08 30 At 8 53 47 PM 2 3. Select **Edit Admin**. 4. Update the **Rewarding Threshold** as required. Screenshot 2026 08 30 At 8 53 14 PM 5. Click **Save**. The updated rewarding threshold takes effect immediately and applies to subsequent rewards initiated by the Admin. ## Reset Amount Spent Super Admins can reset the **Amount Spent** for an Admin from the **All Admins** page. This resets the amount accumulated against the Admin's rewarding threshold without changing the threshold itself. To reset the amount spent: 1. Navigate to **Settings > Admin > All Admins**. 2. Locate the required Admin. 3. Click the **three-dot menu** under the **Actions** column. 4. Select **Edit**. 5. Click on Reset and Update Once the action is confirmed: * The **Amount Spent** is reset to **0**. * The **Rewarding Threshold** remains unchanged. * The Admin's available balance is restored based on the existing threshold. * Previous reward transactions remain unchanged. **Example:** If an Admin has a rewarding threshold of **USD 1,000** and has spent **USD 800**, resetting the amount spent changes the amount spent to **USD 0** and restores the available balance to **USD 1,000**. **Note:** Resetting the amount spent only resets the spending counter. It does not change the Admin's rewarding threshold or delete historical reward transactions. # Switching Account Source: https://help-plum.xoxoday.com/account-administration/user-management/switching-account See how to switch between multiple Plum accounts as an admin, useful if you manage rewards across more than one organization. The **Switch Account** feature allows you to switch between multiple Xoxoday Plum accounts associated with your login credentials. To switch between accounts: Screenshot 2026 09 05 At 10 51 35 PM 1 Screenshot 2026 08 31 At 12 27 31 AM You are redirected to the selected account and can access it based on the permissions assigned to your user profile. If the required account is not available in the list, ensure that your user profile has been added to that account. Feedback or Questions: Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Manage Profile and Password Source: https://help-plum.xoxoday.com/account-administration/user-management/updating-profile-password The **Profile** section allows administrators to manage their account information and update their password from the Plum Admin Dashboard. You can only change/update Name and Password. Please reach out to [cs@xoxoday.com](mailto:cs@xoxoday.com). ## Update Profile Information To update your profile information: 1. Sign in to the **Plum Admin Dashboard**. 2. Click the **Profile** icon in the top-right corner. Screenshot 2026 09 05 At 10 51 35 PM 3. Select the option to edit your profile. 4. Update the required information, such as your **Name** or **Password**. Screenshot 2026 09 05 At 10 57 35 PM 5. Save the changes. The updated information is applied to your Plum account. Feedback or Questions: Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Overview Source: https://help-plum.xoxoday.com/account-administration/user-management/user-management Get an overview of user management in Plum, covering how to add, remove, and control access for admin users on your account. Plum supports two administrative roles: **Super Admin** and **Admin**. These roles determine the level of access a user has within the Plum Admin Dashboard. By default, the user who creates a Plum account is assigned the Super Admin role. ## Super Admin A Super Admin has full access to the Plum Admin Dashboard and can manage users, company settings, campaigns, reports, and wallet operations. ## Admin An Admin has access to operational features required to send rewards and manage day-to-day activities. Access to administrative settings and account-level configurations is restricted. ## Permissions Comparison | Feature | Super Admin | Admin | | :--------------------------------------------------------- | :---------------------------------- | :---------------------------------------------------------------- | | Recharge Company Wallet | ✓ | ✗ | | Reward Spending Limit | Unlimited | Restricted by the assigned spending threshold | | View Reports | Access to all reports | Access to self-reports only; company-level reports are restricted | | Maker–Checker Capabilities | Can be assigned as Maker or Checker | Can be assigned as Maker or Checker | | Add, Edit, or Deactivate Admins | ✓ | ✗ | | Set Admin Spending Thresholds | ✓ | ✗ | | View All Admins and Spending Thresholds | ✓ | ✗ | | Self-Approval | Not allowed | Not allowed | | Send Rewards (Xoxo Points, Reward Codes, and Reward Links) | ✓ | ✓ | | Campaigns | Create, modify, and use campaigns | Use existing campaigns only; cannot create new campaigns | | Access to Plum Pro | Full access | Can distribute brand vouchers | | Edit Company Details | ✓ | ✗ | If Maker–Checker workflows are enabled for your organization, users can be assigned as either a Maker or a Checker. However, users cannot approve their own requests, even if they are assigned both roles. Feedback or Questions: Reach out to [cs@xoxoday.com](mailto:cs@xoxoday.com). # Admin Settings Source: https://help-plum.xoxoday.com/account-settings/admin/admin-settings The **Admin Settings** page allows Super Admins to control the features and capabilities available to other Admins across the organisation. These settings help manage information visibility, reporting access, and approval workflows. To access **Admin Settings**, navigate to **Settings > Admin > Admin Settings**. Screenshot 2026 08 30 At 9 54 57 PM All settings on this page are **toggle-based**. Super Admins can enable or disable each setting based on the organisation's requirements. ## Show Wallet Balance to Admins Allows Admins to view the organisation's available wallet balance during the reward flow. When enabled, Admins can view the available wallet balance while sending rewards. This helps Admins track the available balance and avoid initiating rewards when sufficient funds are not available. ## Show Redemption Data to Admins Allows Admins to view redemption data while creating or managing campaigns. When enabled, Admins can access redemption information to understand how rewards are being used and make informed decisions when managing campaigns. ## Enable Custom Reports Allows Super Admins to create and share custom reports with designated **Report Viewers**. When enabled, Super Admins can grant or revoke access to custom reports. Users with access can view the reports and dashboards shared with them. ## Enable Workflow Requests Enables an approval workflow for supported Admin actions. When enabled, selected actions performed by Admins are submitted as requests and require approval from a designated approver before they take effect. This provides additional control over administrative changes and helps organisations maintain appropriate governance over platform activities. # Report Settings Source: https://help-plum.xoxoday.com/account-settings/admin/report-setting The **Report Settings** page allows Super Admins to create and manage **Custom Reports** for their organization. Super Admins can configure the data included in each report and control which users have access to view the reports. To access **Report Settings**, navigate to **Settings > Admin > Report Settings**. Screenshot 2026 08 30 At 10 15 47 PM ## Create a Custom Report Super Admins can create custom reports based on the organisation's reporting requirements. When creating a custom report, you can: * Enter a **Report Name**. * Select the **Columns** to include in the report. * Assign the report to one or more users. Each report can be configured independently based on the requirements of different teams or users. Screenshot 2026 08 30 At 10 20 35 PM ## Share a Custom Report Super Admins can provide selected users with access to a custom report. Once a report is assigned to a user, the user can access it from the **Reports** section of the Plum Admin Dashboard. A user can be assigned to multiple custom reports based on their responsibilities. Screenshot 2026 08 30 At 10 14 01 PM ## Edit a Report Configuration Super Admins can update an existing custom report at any time. You can: * Change the **Report Name**. * Add or remove **Report Columns**. * Add or remove users who have access to the report. Any changes to the report configuration are reflected the next time the user accesses the report. ## Revoke Report Access Super Admins can remove a user's access to a custom report at any time. If a user is no longer assigned to any custom reports, their **Report Viewer** access is automatically removed. ## Example Custom reports can be configured for different teams based on the information they require. For example: * A **Finance Report** can include fields such as order value, cost, and markup. * A **Customer Support Report** can include fields such as customer name, product, and delivery status. This allows each user to access only the reports and information relevant to their responsibilities. # Configure IP Whitelisting Source: https://help-plum.xoxoday.com/account-settings/api/ip-whitelisting IP Whitelisting is a security feature that restricts access to the Rewards API to approved IP addresses. Once enabled, only API requests originating from whitelisted IP addresses are accepted. Requests from any other IP address are rejected. This feature helps organizations secure their API integrations and ensure that only trusted servers can communicate with the Rewards API. ## Benefits of IP Whitelisting IP Whitelisting can help organizations: * Secure access to the Rewards API. * Restrict API requests to trusted servers or networks. * Prevent unauthorized access to API credentials. * Meet internal security and compliance requirements. ## How It Works After one or more IP addresses are whitelisted: * API requests from approved IP addresses are processed normally. * API requests from any other IP address are rejected. * Changes to the IP allowlist take effect immediately. If a request is made from an IP address that is not on the allowlist, the API returns an error indicating that the request originated from a non-whitelisted IP address. Example: If your organization whitelists the public IP addresses of its office network or application servers, only requests originating from those IP addresses can access the Rewards API. Requests from any other location are blocked. ## Add a Whitelisted IP Address To add an IP address to the allowlist: The IP address is added to the allowlist and can immediately be used to access the Rewards API. ## Manage Whitelisted IP Addresses Organizations can whitelist multiple IP addresses to support different servers or environments. To remove an IP address: Once removed, requests originating from that IP address are no longer authorized to access the Rewards API. # Overview Source: https://help-plum.xoxoday.com/account-settings/email-domain-auth/email-domain-authentication-overview Get an overview of email domain authentication in Plum and how it improves the deliverability of your reward emails. *Using your brands custom domain in Xoxoday* Domain authentication serves as a proactive step to boost the delivery, security, and trustworthiness of your reward emails. This, in turn, aids in the effectiveness of your email marketing endeavors and cultivates favorable connections with recipients. ### Why you should consider Authenticating your Domain: Check out below *** ## Improved Email Deliverability Authenticating your domain increases the likelihood that your reward emails will be delivered successfully to recipients' inboxes. Email service providers often prioritize authenticated domains, reducing the chances of emails being marked as spam or bouncing. ## Enhanced Security Domain authentication helps prevent unauthorized use of your domain for sending emails. By confirming ownership of your domain, you reduce the risk of phishing attacks and other fraudulent activities that could damage your organization's reputation. ## Credibility and Trust Authenticated domains convey credibility and trustworthiness to recipients. When recipients see emails coming from an authenticated domain, they are more likely to trust the content and take desired actions, such as opening the email and engaging with its contents. ## Brand Recognition By authenticating your domain, you reinforce your brand identity in recipients' minds. Consistently sending emails from a verified domain helps recipients recognize and remember your brand, leading to increased brand loyalty and engagement. ## Compliance with Email Standards Domain authentication aligns with industry standards and best practices for email communication. It demonstrates your commitment to adhering to email authentication protocols, such as SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance). ## Reduced Risk of Spam Filtering Authenticated domains are less likely to trigger spam filters, ensuring that your reward emails reach recipients' primary inboxes instead of being diverted to spam or junk folders. This maximizes the visibility and effectiveness of your email campaigns. Feedback or Questions: Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Email Whitelisting Source: https://help-plum.xoxoday.com/account-settings/email-domain-auth/email-whitelisting Learn how to whitelist Plum's sending domain with your email provider so reward emails don't get filtered as spam. *Learn how to whitelist your email.* For emails to not land in spam and properly open images in email services like Microsoft Outlook and Gmail, follow the steps below. *** ## Microsoft Outlook Email Whitelisting Process ### Option 1: For Individual Email Addresses to be whitelisted from inside email message In an open message that was sent from a particular email address or domain, right-click on a blocked item. Do one of the following: * Click Add Sender to Safe Senders List. * Click Add the Domain \[@domain] to Safe Senders List. *** ### Option 2: For Email Address to be whitelisted from settings Untick the option which says "Don't download pictures automatically in HTML email messages or RSS items." *** ### Option 3: For Email Address to be whitelisted from Microsoft Admin Step by Step Instructions (Admin Side) * Login to [https://portal.microsoftonlie.com](https://portal.microsoftonlie.com/) * Go to **Admin > Exchange > Mail Flow** Mail Flow enables you to set rules on the server before the email is delivered to Outlook. * This is similar to setting rules using Outlook's built in rules. * New rule details in Office 365. Click to view larger. * Click the + and select Bypass Spam Filtering * Apply this rule if… > The sender… > domain is Enter the domain name (example: rolet.com) * Under specify domain, be sure to click the + to add the domain to the list. You can come back to this rule and add domain names for each domain you want to whitelist. There is no need to create additional global rules in Mail Flow for each domain. * Click ok * Check Stop processing more rules * Click save *** ## Google Email Whitelisting Process * In the Admin console Go to **Apps > G Suite Gmail > Advanced settings.** * Scroll to the Spam section, hover over the setting, and click **"Configure".** * Enter a unique name for the setting. * Check the Bypass spam filters for messages received from addresses or domains within this approved senders lists box. * Click **"Use existing or Create a new one"**, enter a new list name, and click **"Create".** * Hover over the list name, click **"Edit"**, and then click **"Add".** * Enter domain name 'abc.com' * **Save** *** ## DMARC Quarantine Issue Error Message: DMARC Message from domain xoxoday.com, DMARC fail, (SPF aligned False, DKIM aligned False) DMARC policy is quarantine, applied policy is quarantine. For the above Error, please do the whitelisting process for your respective email services. Feedback or Questions: Reach out to us [cs@xoxoday.com](mailto:cs@xoxoday.com). # Authenticate Domain Source: https://help-plum.xoxoday.com/account-settings/email-domain-auth/step-by-step-guide-to-authenticate-your-domain Follow this step-by-step guide to authenticate your email domain so reward communications from Plum reach recipients reliably. The **Domain Authentication** feature allows organisations to use their own custom domain to send reward communications from Plum. Authenticating your domain verifies that the organisation owns the domain and helps ensure that emails sent from the domain are recognised as legitimate. This can improve the credibility and deliverability of reward communication and prevent the sender address from displaying **“via [notifications@xoxoday.com](mailto:notifications@xoxoday.com)”** to recipients. Check out this for entire list of benefits and why you should consider authenticating your domain [Email Domain Authentication](/account-settings/email-domain-auth/email-domain-authentication-overview) *** ## Prerequisites Before authenticating your domain, ensure that: * **KYB (Know Your Business)** verification has been approved. * You have **Super Admin** access to the Plum Admin Dashboard. * You have access to your organisation's **DNS Manager** or hosting provider. * If you do not have DNS access, coordinate with your organisation's IT or DNS administrator to add the required records. **Tip:** If you do not have access to the DNS Manager, you can use the email option in Plum to send the required DNS records to your IT or DNS administrator. *** ## Step by step guide to Authenticate Your Domain Ensure you are logged in as Super Admin with approved KYB. If not done already, head over to: Submitting Verification Details Navigate to **Settings > Notifications.** Click on **'Authenticate your Domain'.** Now click on **'Save and Proceed'.** The following DNS records need to be added in your DNS Settings. Access your DNS provider portal and input these records. Note that all records are CNAME. **Send DNS Records to IT Admin** If you lack access to the DNS Manager Portal, forward these DNS records to your IT Admin or DNS Manager. The records will be sent via email along with a CSV file. **Pro tip:** Coordinate with your company's IT Admin responsible for DNS management. You can use the inbuilt emailing tool to send the DNS records to your IT Admin colleague. We will send DNS records in email along with CSV to your IT Admin. After the IT Admin has added the records: * Check the box 'Please verify that your records have been added'. * Once selected, the Verify button will activate. Click on **'Verify'.** If your DNS records are added correctly and given sufficient time to take DNS changes to take place, on verification your domain is now authenticated. Feedback or Questions: Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Troubleshoot Source: https://help-plum.xoxoday.com/account-settings/email-domain-auth/troubleshoot-domain-authentication Troubleshoot the most common issues that come up while setting up email domain authentication for your Plum account. After you've connected your domain or **email-sending domain, it can take up to 24 hours for the DNS changes to propagate and reflect in Xoxoday. If your domain** isn't connecting as expected after 24 hours, follow the steps below to troubleshoot your domain. *** ## Check the status of your Domain Authentication Verify that the DNS records have been updated in Xoxoday and in your domain host. * In your Xoxoday Plum account, go to **Settings > Notifications.** * In the left sidebar menu, navigate to **Website > Domains & URLs.** If your domain has **pending**, then acknowledge that Records are added and click Verify to authenticate domain. * If your domain connection failed, you need to **Verify** again. * If Xoxoday cannot connect your domain. There are three error types: **Typo:** the record added to your domain host is different from what's in Xoxoday. **Missing record:** Xoxoday is unable to identify the record in your domain host. **Conflicting record:** there is a conflicting DNS record in your domain host. To resolve these errors, ensure that the records in your domain host match what's in Xoxoday. You should also check the status of your DNS records in your domain host. * Log in to your DNS host. * Confirm that the CNAME records match the Host(name) and Values provided by Xoxoday during the connection process. * If you've confirmed that your DNS records have been updated correctly, you can click either Refresh or **check them again** in the domain setup within Xoxoday to confirm your records have been updated and your domain can be connected. **If this does not work, you can try copying and pasting the provided values again, or review the following common DNS record issues.** *** ## Common DNS issues If you are unable to connect your domains, here are some common DNS issues that you can check for in your DNS host. ### Duplicated Domain Some domain hosts will add a root domain to your CNAME records by default. For example, when entering xox\*\*.\_domainkey.example.com\*\*, an additional domain will be added. The records would then propagate as xox\*.\_domainkey.example.com.example.com\*. You can use external tools to check for a duplicated root domain. For example, you can use [Dig](https://toolbox.googleapps.com/apps/dig/) to check your email sending domains or [Whatsmydns](https://www.whatsmydns.net/) for your site domains. If your domain name was duplicated in your CNAME record: * Keep the domain manager tool open in your browser. * In a new tab or window, log in to your DNS provider and navigate to your DNS Zone File (sometimes appears as Domain Files, Manage DNS). * Enter your **host(name) values** without the domain. This will look different for domains and email-sending domains. For example: Domain: you can enter info. rather than [info.example.com](http://info.example.com/). Email sending domain: you can enter xox.\_domainkey rather than xox\*\*.\_domainkey.example.com\*\*. ### Records invalidated by domain host If your domain name was not duplicated in your CNAME record, but you're seeing a record invalid error in your domain manager, the updated records may have been invalidated by your domain host. Your DNS provider may have invalidated your CNAME record because of certain characters, such as an underscore ("\_") or a hyphen ("--"). You should contact your provider's support team for further assistance. The CNAME records that appears in your Xoxoday email sending domain setup strictly adheres to the DKIM protocol and are supported by most major DNS providers. *** ## Use Whatsmydns to troubleshoot site domains Whatsmydns is a tool used to check DNS records and DNS propagation for your site domains. You can use Whatsmydns to confirm that your DNS records have been correctly updated and are propagating successfully. Navigate to [Whatsmydns.net](https://www.whatsmydns.net/) In the top left, enter the **domain** you're trying to connect to in Xoxoday. Click the dropdown menu and select **CNAME.** Click **Search.** If your DNS update was successful, the results should correspond to the values provided in Xoxoday. If the Whatsmydns results do not match the value provided in Xoxoda, this means that the DNS record may have been incorrectly updated or is not propagating correctly. You can try updating your DNS record again, or reach out to your domain provider to troubleshoot further. If you're still seeing problems after completing the troubleshooting steps above, you can reach out to [cs@giift.com](mailto:cs@giift.com) # Email Settings Source: https://help-plum.xoxoday.com/account-settings/notification/email-setting The **Email Settings** page allows Admins to customise the emails sent to reward recipients. Admins can configure the email footer, sender details, and PDF gift certificate settings. To access **Email Settings**, navigate to **Settings > Notifications**. Screenshot 2026 08 30 At 11 35 24 PM ## Customize the Email Footer The **Custom Footer** setting allows Admins to add custom text to the footer of reward emails. You can use the footer to include: * Company contact information * Support details * Legal disclaimers * Other relevant information that should appear in reward emails The configured footer is included in reward emails sent to recipients. ## Configure the Sender Name The **Sender Name** determines the name displayed in the **From** field of reward emails. By default, **Xoxoday** is displayed as the sender. Admins can replace this with a custom sender name, such as **Acme Rewards** or **HR Team**, to provide a branded email experience. ## Configure the Sender Email Address The **Sender Email** determines the email address displayed in the **From** field of reward emails. By default, reward emails are sent from [**notifications@xoxoday.com**](mailto:notifications@xoxoday.com). Organiszations can configure a custom sender email address, such as [**rewards@company.com**](mailto:rewards@company.com), to align reward communications with their corporate domain. A custom sender email address requires **domain authentication** using SPF, DKIM, and DMARC DNS records. Without domain authentication, emails may be delivered to spam folders or rejected by recipient mail servers. ## Enable PDF Generation The **Enable PDF Generation** setting allows reward emails to include a **PDF gift certificate** as an attachment. The PDF contains the relevant reward or gift card details and can be downloaded or printed by the recipient. This setting is available for: * **Reward Codes (Xoxo Codes)** * **Gift Cards (Plum Pro)** # Reminders Source: https://help-plum.xoxoday.com/account-settings/notification/low-balance-alerts # **Low Balance Alert** The **Low Balance Alert** feature helps organizations monitor their Plum wallet balance and avoid interruptions to their reward programs. Super Admins can configure a minimum wallet balance and receive email notifications when the wallet balance falls below the specified threshold. These alerts allow administrators to add funds to the wallet in advance and help prevent failed rewards, bookings, or order cancellations due to insufficient balance. ## Set Up Low Balance Alerts To enable Low Balance Alerts: 1. Navigate to **Settings > Notifications**. 2. Locate the **Low Balance Notification** section. 3. Turn on the notification toggle. 4. Enter the **wallet balance threshold** at which the notification should be triggered. 5. Click **Save Changes**. Screenshot 2026 08 30 At 10 49 07 PM ## How Low Balance Alerts Work When the wallet balance falls below the configured threshold, Plum sends an email notification to the **Super Admin**. The notification includes: * The current wallet balance. * An **Add Funds to Wallet** button that redirects to the wallet recharge page. If the wallet balance remains below the configured threshold, the platform sends up to **two reminder emails**. Once the wallet is recharged, the reminder counter is automatically reset. Future notifications will be triggered again when the wallet balance falls below the configured threshold. # Emails for Redemption The **Reminder Emails for Redemption** feature allows organizations to automatically notify recipients about rewards that have not yet been redeemed. These reminders help recipients redeem their rewards before they expire. ## Reminder Types You can configure the following types of redemption reminders: ### Scheduled Reminders Scheduled reminders are sent at regular intervals until the reward is redeemed or expires. This option is useful for rewards with longer validity periods. The available frequencies are: * **Monthly** * **Quaterly** ### Pre-Expiry Reminders Pre-expiry reminders are sent once before the reward expires. These reminders encourage recipients to redeem their rewards before the expiry date. The available reminder intervals are: * **30 days before expiry** * **15 days before expiry** * **7 days before expiry** ## Configure Reminder Emails To configure Reminder Emails for Redemption: 1. Navigate to **Settings > Notifications**. 2. Locate the **Reminder Emails** section. 3. Select the required reminder type and frequency. 4. Click **Save Changes**. Screenshot 2026 08 30 At 11 26 39 PM Once configured, the platform automatically sends reminder emails according to the selected schedule. Scheduled reminders continue until the reward is redeemed or expires, while pre-expiry reminders are sent once before the reward expires. # Branding Source: https://help-plum.xoxoday.com/account-settings/storefront/branding The **Storefront** page allows Admins to customise the Plum storefront and manage the rewards available to users. You can configure the storefront URL, company logo, favicon, theme colour, and global reward catalog. To access these settings, navigate to **Settings > Storefront**. ## Redemption Marketplace URL The Storefront URL (also referred to as the Marketplace URL or Domain) is the unique web address for your Plum storefront, for example: `https://stores.xoxoday.com/{company-name}` The storefront URL is generated automatically during account setup based on your company name and can be configured only once. Once your account is created, the storefront URL cannot be changed from the Plum Admin Dashboard. If you need to update your storefront URL, please contact the Xoxoday Plum Support team. Screenshot 2026 08 30 At 11 39 56 PM *** ## Company Logo You can also upload a custom logo. Navigate to **Settings > Storefront > Company Logo** and click on **"Change".** * Choose a transparent logo file (maximum size: 240 x 80 px). * Upload it to the platform and click **"Save".** Your brand logo will prominently appear in the upper left corner of your website and in all email communications. Switch to the storefront to preview its placement and appearance. *** ## Update the Favicon The favicon is the small icon displayed in the browser tab when users open your storefront. Navigate to **Settings > Storefront > Branding** and click **Change** under Favicon. Choose the favicon image and upload it to the platform. Click **Save**. The uploaded favicon replaces the default Xoxoday icon and is displayed in the browser tab whenever users visit your storefront. *** ## Storefront Theme The theme color controls the primary color used across your storefront. Navigate to **Settings > Storefront > Branding** and select or enter your preferred theme color (Hex code). Click **Save**. The selected color is applied across the storefront, including buttons, the navigation bar, category highlights, and call-to-action (CTA) links, giving your storefront a consistent branded appearance. Screenshot 2026 08 30 At 11 42 39 PM *** ## Hero Banner The **Hero Banners** feature allows you to add promotional banners to the homepage of your Plum storefront. You can use banners to highlight campaigns, offers, announcements, or other relevant information. Banners are displayed vertically on the storefront homepage in the order configured by the Admin. ## Add a Hero Banner To add a banner: 1. Navigate to **Settings > Storefront**. 2. Locate the **Hero Banner** section. 3. Click **Add Banner**. 4. Upload the **Banner Image**. * The image must be in **PNG or JPG** format. * The maximum file size is **2 MB**. 5. Enter a **Banner Name**. 6. Enter the **Redirect URL**. This is the URL that opens when a user clicks the banner. 7. Click **Save Banner**. Screenshot 2026 08 30 At 11 44 13 PM ## Manage Promotional Banners You can manage the banners displayed on your storefront homepage. * Banners are displayed **vertically** on the homepage. * Banners do not rotate automatically. * Banners cannot be scheduled for specific dates or times. * You can **drag and drop** banners to change their display order. The updated banner order is reflected on the storefront homepage. *** ## Global Reward Catalog This feature allow to customise the reward catalog shown in our marketplace. You can enable or disable categories like Gift Cards, Merchandise, Experience and Perks along with control of restricting some catalog for different countries. Navigate to **Settings > Storefront > Global Reward Catalog** and click on **"Customize".** Define the value range by entering a minimum and maximum denomination. Filter your results by selecting the specific countries or geographic regions you wish to include. You can choose to view and customise the global reward catalog of 1000+ brand vouchers. You can see a list of categories which includes: * Gift Card * Merchandise * Lounge * Charity * Experience * Perks * Flights * Hotels * Miles * Mobile Top-ups Click on "**Customise**" next to the catalog item. You will a list of items here. Simply check and uncheck the box to include or exclude the item on storefront. Feedback or Questions: Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Customization Source: https://help-plum.xoxoday.com/account-settings/storefront/customization The Customization section allows Admins to configure various settings for the Plum storefront. You can customise the points terminology, payment options, redemption requirements, storefront footer, and delivery address settings. To access these settings, navigate to **Settings > Storefront > Customization**. Screenshot 2026 08 30 At 11 53 52 PM ## Change Point Name You can customise the name used to refer to points on the Plum storefront. This allows organisations to use terminology that is consistent with their internal rewards program. For example, an organisation may refer to points as **Ace Points**, **Coins**, or **Credits**. To change the point name: 1. Navigate to **Settings > Storefront > Customise**. 2. Click **Change Point Name**. 3. Enter the preferred point name. 4. Save the changes. The updated point name is displayed across the storefront wherever points are referenced. Screenshot 2026 08 30 At 11 56 16 PM ## Change Points Icon The **Change Points Icon** setting allows you to customise the icon displayed next to the points balance in the storefront header. You can upload a custom icon to replace the default coin icon. To change the points icon: 1. Navigate to **Settings > Storefront > Customise**. 2. Locate **Change Points Icon**. 3. Upload the required icon. 4. Save the changes. The uploaded icon is displayed next to the points balance in the storefront header. Screenshot 2026 08 30 At 11 56 16 PM 2 **See where it appears**: Open the storefront to view the updated points icon. ## Allow Digital Payments The **Allow Digital Payments to Users** setting allows users to make partial payments using a personal credit or debit card or bank account when their available points or codes do not cover the full purchase amount. This option is enabled by default. To enable or disable digital payments: 1. Navigate to **Settings > Storefront > Customise**. 2. Locate **Allow Digital Payments to Users**. 3. Turn the toggle **on** or **off** based on your requirements. When disabled, users cannot use a personal payment method to pay the remaining amount after applying their available points or codes. Screenshot 2026 08 30 At 11 56 16 PM 1 ## Set a Minimum Value for Points Redemption The **Set a Minimum Value for Reward Points Redemption** setting allows you to define the minimum number of points a user must accumulate before they can redeem rewards. To configure the minimum redemption value: 1. Navigate to **Settings > Storefront > Customise**. 2. Turn on **Set a Minimum Value for Reward Points Redemption**. 3. Enter the required minimum points value. 4. Save the changes. Users can redeem rewards only after their available points meet the configured minimum value. Screenshot 2026 08 30 At 11 56 16 PM 3 ## Enable Storefront Footer The **Enable Storefront Footer** setting allows you to display a footer at the bottom of your Plum storefront. To enable or disable the storefront footer: 1. Navigate to **Settings > Storefront > Customise**. 2. Locate **Enable Storefront Footer**. 3. Turn the toggle **on** or **off**. 4. Save the changes. When enabled, the footer is displayed to users on the storefront. Screenshot 2026 08 31 At 12 00 18 AM ## Manage Delivery Addresses The **Saved Addresses** feature allows Admins to save delivery addresses for physical rewards, such as merchandise and physical gift cards. Saved addresses can be reused across eligible reward campaigns, reducing the need to enter the same delivery details for each order. Screenshot 2026 08 31 At 12 02 44 AM ### Add a Delivery Address To add a delivery address: 1. Navigate to **Settings > Storefront > Customise**. 2. Click **Add New Address**. 3. Enter the required delivery details. 4. Click **Save**. ### Edit or Delete a Delivery Address To manage an existing delivery address: 1. Navigate to **Settings > Storefront > Customise**. 2. Select the saved address. 3. Choose **Edit** or **Delete**. 4. Make the required changes or confirm the deletion. Saved addresses can be used across eligible reward campaigns unless **Lock Delivery Address** is enabled. Screenshot 2026 08 31 At 12 02 00 AM ## Lock Delivery Address The **Lock Delivery Address** setting allows organisations to restrict deliveries to a specific verified or approved address. When this setting is enabled: * The delivery address is pre-filled during checkout. * Users cannot edit, delete, or replace the locked address. * Users cannot add a new delivery address during checkout. Users must use the locked delivery address to complete the order. If the address is incorrect, contact the organisation or program administrator for assistance. # Admin Activity Source: https://help-plum.xoxoday.com/admin/admin-activity The **Admin Activity** page provides an audit trail of threshold changes made for administrators within an organisation. It enables Super Admins to track threshold updates, monitor amount-spent resets, and identify the Super Admin who performed each action. The **Admin Activity** page is available only to Super Admins. To access the page, navigate to **Settings > Admins > Admin Activity**. Screenshot 2026 08 30 At 9 35 38 PM ## Activity Details Each activity record includes the following information: | Field | Description | | :--------------------- | :---------------------------------------------------------------------------------------------------------------------------------------- | | **Date** | The date on which the action was performed. | | **Action** | The type of update performed, such as **Threshold Increased**, **Threshold Decreased**, **Threshold Updated**, or **Amount Spent Reset**. | | **Account Affected** | The administrator whose threshold or spending details were updated. | | **Existing Threshold** | The threshold value before the change. | | **New Threshold** | The updated threshold value after the change. | | **Amount Spent** | The amount spent by the administrator when the activity was recorded. | | **Admin Balance** | The remaining available balance after the update. | | **Action Taken By** | The Super Admin who performed the action. | ## Filter Activity Use the available filters to find specific activity records. * **Date Range:** Filter activities by a specific date range. By default, the page displays activity from the last **30 days**. * **Account Affected:** View activities for a specific administrator. * **Action Taken By:** View activities performed by a specific Super Admin. * **Action:** Filter activities by the type of action performed: * **Threshold Increased** * **Threshold Decreased** * **Threshold Updated** * **Amount Spent Reset** ## Customize the Table The **Columns** option allows Super Admins to select the information displayed in the activity table. The **Date** and **Action** columns are always displayed and cannot be hidden. ## Download Activity Click **Download** to export the activity log as a CSV file. The exported file includes the activity details available in the log and can be used for reporting, auditing, or record-keeping purposes. # Delete or Disable Campaign Source: https://help-plum.xoxoday.com/campaigns/campaign-management/delete-or-disable-a-reward-campaign See how to permanently delete a reward campaign, or disable it temporarily without losing its configuration, in Plum. *Learn how to delete or disable a campaign* *** ## Reward Code Campaign Whilst it is not possible to delete your Reward Code Campaign, you can disable it by clicking the "**Disable" button under the "Actions**" tab. Now click on the "**Disable**" button on the screen above. You can also choose to "**Enable**" it later if you ever change your mind. *** ## Reward Link Campaign Click on the "Reward Link Campaign" section. You can now choose to disable a Reward Link Campaign, by clicking on the "Disable" button under the "**Actions**" tab. # Edit Campaign Source: https://help-plum.xoxoday.com/campaigns/campaign-management/edit-a-reward-campaign Learn how to edit an existing reward campaign in Plum, including updating its budget, recipients, and reward details after launch. *Learn how to edit your reward link or reward code campaigns* *** ## Editing the Reward Campaigns Go to the **"Campaign**" section in the Admin Dashboard. Now, under the "Actions", choose to **"Edit"** the Campaign. You can now change the name of the campaign and update the campaign accordingly. You can choose to select/deselect the categories and subcategories to include in the campaign. You can also choose the customize the mailer. Congratulations! You have successfully updated your campaign. *** Feedback or Questions: Email [cs@xoxoday.com](mailto:cs@xoxoday.com) # Overview Source: https://help-plum.xoxoday.com/campaigns/campaigns-overview Get an overview of reward campaigns in Plum, including how to distribute gift cards, reward links, and reward codes to groups at scale. *Learn how to create and manage customized campaigns in Xoxoday Plum.* *** ## Campaigns Xoxoday Plum enables Super Admins and Admins to create and manage bespoke campaigns, enriching the rewarding experience for end-users by offering customizable storefronts and personalized rewards, thereby boosting engagement and satisfaction levels. Within Plum, you can seamlessly create two types of campaigns: * **Reward Code Campaign** * **Reward Link Campaign** Each campaign type offers unique features and benefits, catering to diverse requirements. Whether it's an employee recognition program, customer loyalty initiative, or any other rewarding campaign, Plum provides comprehensive solutions. In the following section, we'll guide you through the step-by-step process of creating, editing, and disabling your Plum campaigns. You'll learn everything from naming your campaign to customizing email and SMS content, ensuring unforgettable reward experiences for your audience. *** **Pro Tip** Maximize engagement by periodically refreshing your campaign content and rewards to keep your audience excited and motivated. Experiment with different customization options and monitor performance metrics to optimize your campaigns for maximum impact. *** Feedback or Questions: Email [cs@xoxoday.com](mailto:cs@xoxoday.com) # Create Reward Code Campaign Source: https://help-plum.xoxoday.com/campaigns/create-a-reward-code-campaign Learn how to create a reward code campaign in Plum so you can distribute reward codes to a large group of recipients in bulk. *Learn how to create a Reward Code Campaign* Plum lets you customize Reward Code Campaigns with tailored storefronts and custom landing pages for enhanced user engagement and redemption experiences. *** ## Creating a Reward Code Campaign Customize Catalog **Customize Catalog** Customize the email subject and content to align with your campaign goals. - You can also edit the logo by clicking on "Edit Logo" and uploading a new logo. * You can also edit the logo by clicking on "Edit Logo" and uploading a new logo. * Xoxoday Plum allows for editing or removing the banner. Click on "**Edit/Remove Banner**" and follow the steps. - Click on "Edit Message" to make changes to the message. # * Click on "Edit Message" to make changes to the message. * **Configure Message Details** Toggle the recipient's name on or off and choose from our library of greetings (or create a custom one). Define your message by entering a title and body text, then adjust the content alignment to your preference. ## \*\*​Step 6: Setting Up the Campaign ## **​Step 6: Setting Up the Campaign Once all configurations are complete, click "Create**" to launch your Reward Code Campaign. Once all configurations are complete, click "Create\*\*" to launch your Reward Code Campaign. Navigate to Settings > Campaigns, select Reward Code and click "**Create Reward Code Campaign**." Customize Catalog Start by giving your campaign a name. You can then choose the specific categories you wish to include or exclude. Customize Catalog Utilize the campaign to tailor the storefront for your end-users. This customization encompasses options such as country, brand, and categories. Once adjustments are made, remember to save the changes. Customize Catalog Enhance personalization by incorporating a custom landing page. When recipients receive the reward code, they will first encounter this landing page before being directed to the storefront for redemption. Customize Catalog Customize Catalog Customize the email subject and content to align with your campaign goals. * You can also edit the logo by clicking on "Edit Logo" and uploading a new logo. * You can also edit the logo by clicking on "Edit Logo" and uploading a new logo. * Xoxoday Plum allows for editing or removing the banner. Click on "**Edit/Remove Banner**" and follow the steps. * Click on "Edit Message" to make changes to the message. * Click on "Edit Message" to make changes to the message. * **Configure Message Details** Toggle the recipient's name on or off and choose from our library of greetings (or create a custom one). Define your message by entering a title and body text, then adjust the content alignment to your preference. Once all configurations are complete, click "**Create**" to launch your Reward Code Campaign. Once all configurations are complete, click "**Create**" to launch your Reward Code Campaign. Congratulations! You have successfully created a Reward Code Campaign. For any feedback or questions reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com). Congratulations! You have successfully created a Reward Code Campaign. For any feedback or questions reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Create Reward Link Campaign Source: https://help-plum.xoxoday.com/campaigns/create-a-reward-link-campaign Learn how to create a reward link campaign in Plum so you can distribute reward links to a large group of recipients in bulk. *Learn to create campaigns with Reward Links tailored to your audience's preferences.* *** ## Creating a Reward Link Campaign Step-by-step guide to creating Reward Link Campaign: Navigate to **Settings > Campaign, select the tab Reward Link and click "Create Reward Link Campaign**". Choose a descriptive and memorable name for your campaign so that it is easy to identify later. Consider including the campaign objective or target audience in the name. Tailor the reward amount and country selection based on your target audience's preferences. You can choose either gift cards or merchandise as the reward type. Click "**Customise"** to adjust the amount and currency. Image Carefully select vouchers that align with your audience's interests and preferences. **Pro tip** Consider offering a variety of options to cater to diverse tastes and maximize redemption rates. Customize your email and SMS campaigns to resonate with your audience by using personalization tokens to address recipients by name and segmenting your messaging based on demographics or past interactions. **Pro tip** You can customize communication at the time of sending reward links as well. Learn more here: [Customize Reward Communication](/send-rewards/reward-links/reward-link-customize-reward-communication) Always preview your campaign setup before finalizing it. Check for any errors or inconsistencies in the content and ensure that the campaign flows smoothly from start to finish. Once previewed, click **"Create**" to proceed. *** Feedback or Questions: Email [cs@xoxoday.com](mailto:cs@xoxoday.com) # Manage Campaigns Source: https://help-plum.xoxoday.com/campaigns/duplicate-or-disable-a-campaign See how to duplicate an existing reward campaign to reuse its settings, or disable a campaign that is no longer needed in Plum. The Campaign Duplication feature helps you save time by creating new campaigns based on existing ones. Whether you're working with Reward Codes or Reward Links, you can duplicate any campaign in just a few clicks. *** ## What is Campaign Duplication? Instead of starting from scratch every time you want to run a similar campaign, you can **duplicate** an existing one. This copies all the settings and configurations of the original campaign, allowing you to make only the necessary changes. ## Where to Find This Feature You can access the duplication feature from the Campaigns section under **Settings**. *** ## How to Duplicate a Campaign Choose between: * **Reward Codes Campaigns** * Reward Links Campaigns Each campaign is listed with a **three-dot menu (⋮)** on the right. Click on the three dots to open more options. Click **"Duplicate Campaign"** from the menu. * Default name: `Copy of #"Original Campaign Name"}` * You can rename it or keep the default. Click "Customize Your Communications" to proceed. Customize the email template as needed, then click **"Create"**. ### What Gets Duplicated? When you duplicate a campaign, the following elements are copied: * Campaign settings * Rules and configurations * Templates and assets (if applicable) The new campaign is created in a **draft/inactive** state so you can review and activate it when ready. ### Tips and Best Practices * Use duplication to run recurring campaigns with similar setups. * Rename duplicated campaigns clearly to avoid confusion. * Review and adjust expiry dates, reward quantities, and other variables before activating. *** ## Disable a Campaign Go to Campaigns and click on the Reward Code or Reward Link tab. Click the **three-dot menu (⋮)** next to it. In the confirmation pop-up, click **Yes, Disable**. Done — the campaign is now paused. *** For any queries or feedback, reach out to [cs@xoxoday.com](mailto:cs@xoxoday.com). # Admin and Business Source: https://help-plum.xoxoday.com/faq/security-compliance/adminbusiness Find answers to frequently asked questions about Plum's administrative controls and business continuity practices. *Access Admin and Business security policy documents.* [Open document](https://drive.google.com/file/d/1LyE7ogFTxdbUiaSLBOYaMbFxsvXbuI3v/view) [Open document](https://drive.google.com/file/d/1jNgN1Rc9hMM8xcVPcB6Rd32NKHqvHdyo/view?usp=sharing) [Open document](https://drive.google.com/file/d/10sWqTxSQqSdfdPi4q4lwIjHtoJhrn5UQ/view?usp=sharing) [Open document](https://drive.google.com/file/d/16c7bYIdwy8ei58QnYydnA5qT07UD_meb/view?usp=sharing) [Open document](https://drive.google.com/file/d/1WJL_C6MLX9PCDfTisFUokTzoLK5qdoiw/view?usp=sharing) [Open document](https://drive.google.com/file/d/1ZDDnbuxb8X39t39QP-riP2wwQjl9crhc/view?usp=sharing) [Open document](https://drive.google.com/file/d/1NjQR15_VDeHqKB1OHHBFOIv_1n3igI48/view?usp=sharing) [Open document](https://drive.google.com/file/d/1xr3hhkLmYu6c5tpR8aG3iF2NyQ2ormZa/view?usp=sharing) # Application, Dev and Security Source: https://help-plum.xoxoday.com/faq/security-compliance/application-dev-and-security Find answers to frequently asked questions about Plum's application development lifecycle and secure coding practices. *** ## Infrastructure & Compliance We take steps to securely develop and test against security threats to ensure the safety of our customer data. We maintain a Secure Development Lifecycle, in which training our developers and performing design and code reviews takes a primary role. In addition, Xoxoday employs third-party security experts to perform detailed penetration tests on different applications. In addition to the security components provided by our top-level cloud providers AWS, Xoxoday maintains its own dedicated controls by following the industry best practices. These controls cover DDoS attacks, DB protection and a dedicated web application firewall, as well as network firewall fine-grained rules configured using the highest industry standards. We provide Software as a Service (SaaS). SaaS. Admins can control the application and will have access to alerts and security events. Xoxoday application is an API-driven digital rewards platform that automates rewards, incentives and gifting. The storefront has a global catalogue of 20,000+ options with 5,000+ experiences, 2,000+ gift cards and 10,000+ perks. The platform offers reward distribution modes like sending bulk vouchers via emails and generation of bulk voucher codes. No. We are cloud hosted only. We will share this as an attachment upon request. Cloud hosted, microservice-based, highly scalable, High Availability. NA — We are cloud hosted. NA — We are cloud hosted. Users need to have internet access. Yes. The solution is available as part of SAP SuccessFactors solution on web, as well as the SuccessFactors native mobile app for both iOS and Android. It's accessible in a mobile browser and can be accessed via an Android or iOS device. Our applications are compatible with desktops, tablets, and mobiles. No additional components are required. Our applications are compatible with desktops, tablets, and mobiles. No additional components are required. AWS / Kubernetes — React — Node/GraphQL — MySQL/MongoDB. We have deployed our application on Amazon Web Services (AWS) cloud platform. We are using MySQL, Salt stack, Node.js and MongoDB technology. Yes. We are using the latest language frameworks like MySQL, JavaScript, Node.js and MongoDB. Yes. These are approved during the code review process wherein the reviewer checks the utility and security of the libraries. We have deployed our application on AWS Cloud virtual platform. The backup data center is in Singapore. The data centers are hosted completely in isolation so that access is limited and controlled. Load balancer allows shifting incremental load and can auto scale based on data load. Each instance (EC2) under a fortified VPC network is a conglomeration of Docker Container Web Services and APIs and application layer running on top. Amazon CloudWatch is implemented to enable monitoring. The data is encrypted using 256-encryption-based SSL certificate. Xoxoday plans a quarterly VAPT-based security audit. Plum by Xoxoday is a cloud-based SaaS platform hosted on VPC infrastructure of AWS. The data centers are hosted in complete isolation. The architecture allows adding more location-specific data centers for latency and data security. Load balancers allow auto-scaling. Each EC2 instance under fortified VPC network is a conglomeration of Docker Container Web Services and APIs. Amazon CloudWatch is implemented for monitoring. Data is encrypted using TLS 1.3 in transit and AES-256 at rest. *** ## Backup, Recovery & Business Continuity Data backups are done daily and in a secured way in AWS. We use AWS Virtual platform cloud. We have created an Amazon CloudWatch alarm that monitors Amazon EC2 instances and automatically recovers them if impaired. EBS Snapshot functionality allows us to capture and restore virtual machine images at any time. Yes, the infrastructure environment solution includes software/provider independent restore and recovery capabilities. Yes. Data backups are automated and done daily in a secured way on AWS. We test the backup or redundancy mechanisms at least annually. Our RTO and RPO is 60 minutes. Yes. Data backups are done daily and in a secured way in AWS. Data backups are done on a daily basis and in a secured way on AWS. We take automated backups on a regular basis. Yes. We take a backup of all data before making any major changes to hardware and software. We have implemented the Backup Recovery Procedure. We have Business Continuity Policy and Business Continuity Management Procedure in place, tested periodically. Our policies are reviewed and audited annually. We test the BCP every 12 months, reviewed as part of internal and external audits. Yes. Data backups are done on a daily basis in a secured way in AWS. Yes. It is tested annually. Yes. All data backup is encrypted. Yes. It can be recovered. We have implemented the Business Continuity Management Policy and test the BCM plan annually. The BCM policy is attached for reference. We have implemented policies and procedures with regard to DR. Since we have deployed our application on AWS cloud, they provide DR services. The application network architecture diagram is attached upon request. *** ## Application Development & SDLC We have an SDLC Policy as per ISMS requirements and follow General Coding Practice. We conduct data validation on a trusted system, use cryptographic functions to protect secrets, and perform code reviews, vulnerability assessments, and penetration testing. We follow a blue-green deployment strategy that introduces new changes without downtime and provides rollback capability. Yes. Changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates. We have implemented the SDLC Procedure and standards of quality are met for all software development. We have not outsourced software development activities. Our code reviews and analysis run through stringent automated technologies as well as manual source code overviews to cover any security loopholes prior to the production phase. Yes. All debugging and test code elements are removed from released software versions. Yes. We use an automated source code analysis tool. We are proactively embedding privacy into the design and operation of IT systems, networked infrastructure, and business practices. We focus on security while producing software. SDLC procedures are attached for reference. Yes. All environments are separate. No. We do not use production data in test environments. Yes. Both are kept separate. Yes. Any applications and software are implemented after security testing by our IT team. All logs are monitored. We maintain an approved software/application register, audited during internal and external audits. Users are disallowed from installing software on their workstations. Yes. We have static code analysis. We have an SDLC Policy per ISMS requirements and follow General Coding Practice including data validation on a trusted system, cryptographic functions to protect secrets, and least privilege — restricting users to only the functionality, data, and system information required for their tasks. More than 50% of our production code is covered by automated tests. We do not use staging for building artifacts. We conduct application security testing with the help of industry-approved third-party vendors every six months. Any observations found are addressed by our team. The primary objective is to identify and eliminate problems that could lead to a breach of confidentiality, availability, or integrity of Xoxoday data resources. Yes. Our code reviews run through stringent automated technologies and manual source code overviews. Vulnerability scanning gives deep insight for quick identification of non-compliant systems. Xoxoday also employs third-party security experts to perform VAPT. Yes. Code reviews and analysis run through stringent automated technologies as well as manual source code review. Multiple security checks including code reviews, web vulnerability reviews, and advanced security tests are performed in every build. Yes. Code is reviewed both internally and externally. We engage third-party vendors for security testing every six months. All software development procedures are supervised and monitored by Xoxoday to include: security requirements, independent security review of the environment, code reviews, quality monitoring, evaluation, and acceptance criteria for information systems. Our QA department reviews and tests our code base. Dedicated application security engineers identify, test, and triage security vulnerabilities. We also conduct code reviews and VAPT with the help of a third-party vendor. VAPT Certificate is attached. Yes. This is part of the code review process wherein the reviewer checks the utility and security of the 3rd party library. Compliant. The application is developed based on secure coding guidelines and code reviews are conducted per compliance requirements. Compliant. Compliant. Yes, we follow all technical guidelines for development that come under the Open Web Application Security Project. Compliant. We have implemented DLP techniques and there are no possibilities of data leakage or loss. Compliant. The application uses HTTPS. Compliant. We use strict HTTP transport security. We cannot impose file upload frequency restrictions. However, the application has technical and organizational measures to prevent attacks through WAF, log monitoring, AWS GuardDuty, Amazon CloudWatch, IDS/IPS, etc. *** ## Access Control & Authentication We have a role-based access system to make sure that only authorized individuals have access to the required information. We don't provide multi-factor authentication as a default. As of now, there's OAuth 2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins. No, we don't provide multi-factor authentication as a default. As of now, there's OAuth 2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins. It can be configured with Active Directory. Access to data and systems is based on the principles of least privilege. All information systems and data are classified and segregated to support role-based access requirements. We use MFA, Firewall, VPN, Active Directory, etc. for maximum security. The password needs to be a minimum of 8 characters long and contain at least one capital letter, special characters among '# \$ % \* &' and 1 digit. These are reviewed monthly. We store passwords hashed. We have SHA-512 hash with unique salt for every password. We store passwords hashed. We have SHA-512 hash with unique salt for every password. Yes. Our password requirements comply with all factors to ensure strong passwords: minimum length, special characters, capitalized letters, and alpha-numeric combinations. Passwords are stored after encryption. Yes. Yes. The solution does not allow login using credentials that have not been used. Admins can create and delete user accounts. It's a SaaS solution. Users can log in from multiple locations. No. Users need to login with user ID and password. However, we have integrations with Zoho CRM, HubSpot, DarwinBox, SurveyMonkey, Freshdesk, etc. Since it's a SaaS product, session timeout can be set with the help of Active Directory. For example — 15 min or 20 mins as per requirements. The account will get automatically locked after 5 unsuccessful login attempts. Users will get a reset password link and can unlock their account through that. User accounts will be created by the admin and linked with the email ID of the users. Please refer to the admin guide: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1) Yes. Yes. Two-factor authentication is enabled. MFA devices like Google Authenticator are available for OTP/Codes/Passwords. Yes. We have procedures for Roles, Responsibilities & Authorities at Xoxoday. Per the access control policy, access to data is provided only to authorized and appropriate individuals. Password policy: Must contain at least 8 characters, numbers and letters, uppercase (A-Z), lowercase (a-z), digits (0-9), and non-alphabetic characters (e.g., !, \$, #, %). Password must be changed every 90 days. Passwords are shared through secure, encrypted channels. Yes. Policies and procedures enforce two-factor authentication for privileged account management while accessing tenant data/systems. An IAM solution manages user access through role-based access profiles based on the need-to-know principle and segregation of duties. By default, Xoxoday will not have access to service data. Access control is managed by the admin from the customer end. If we require access for troubleshooting, we request temporary access, and the customer decides. Access to our production environment is allowed only via the Xoxoday corporate network to authorized individuals. Please refer to the admin guide on SSO Logins: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/getting-started](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/getting-started) Yes. Access has been restricted and monitored for security reasons. Yes. We have complexity and length requirements for passwords. We review user access on a periodical basis, validated during internal and external audits. *** ## Network Security & Firewall Yes. We have captured this information in our architecture and data flow diagrams. Yes, we have a firewall. Yes, we have the network architecture diagram. Yes, we have configured secure internet access. Yes, we have configured these. Yes. We have IDS and IPS implemented and receive alerts for unauthorised network access. Yes. It's reviewed on a monthly basis. Yes. Yes. Yes. All are configured according to security standards as part of the build process. We have implemented IDS/IPS to facilitate timely detection, investigation by root cause analysis, and response to incidents. Wireless access is allowed and handled with high-quality routers, password protection and restriction on internet usage. Yes. We have installed firewalls for maximum security and configured them to restrict unauthorised traffic. All data is collected only through the Xoxoday Platform. We use a Web Application Firewall (WAF). We harden the operating systems and restrict access to all ports, applications, and software, monitored on a regular basis. We have implemented policies and mechanisms to protect the wireless network environment. We use a cloud-hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and linked with SSO/Active Directory. Yes. It's logically and physically segregated. We have deployed our application on AWS Cloud platform. We do not provide external access. We have implemented IDS/IPS, Endpoint security, Firewall, DLP, Antispoofing, VPN, Active Directory and other security solutions for maximum security. Yes. With multiple layered firewalls configured with deny-all mode allowing only specific rules required for business, network traffic is regulated. We have implemented intrusion detection and prevention system tools for timely detection and investigation. With multiple layered firewalls in deny-all mode, network traffic is regulated. We use tools that analyze various traffic patterns and correlate network events. Early warning signals trigger alerts to our team. We are equipped to detect and mitigate threats, DDoS attacks, session hijacks, login spoofs, or any other data extraction strategies. Yes. As part of WAF, rate limiters are installed to block multiple requests from specific IPs to prevent DDoS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats. All our network components and computers are password protected to ensure compliance with integrity, availability, and confidentiality principles of Information Security. Yes. We have Network Access Control and Security Procedure in place. Network resources must be on a need-to-know basis and authorizations must be obtained from appropriate authorities. Networks are logically or physically divided based on the criticality of the information stored. We have WAF, IDS/IPS, AWS GuardDuty, Cloudflare, and data encryption. We conduct code reviews and VAPT annually with a third-party vendor. We are equipped to detect and mitigate DDoS attacks, session hijacks, login spoofs, or any other data extraction strategies. We use Cloudflare Web Application Firewall (WAF) and IDS/IPS for maximum security. Yes. We have implemented the Web Application Firewall (WAF). We have a web application firewall, IDS/IPS, SQL injection protection. We use Cloudflare for the same. Yes. Our network communication is encrypted with highly restricted protocols to ensure maximum security. We use TLS 1.2 encryption for data in transit. We use HTTPS and our network communication is encrypted with highly restricted protocols to ensure maximum security. We do not provide support for IP address range restriction. Our restrictions/security are based on our OAuth process and do not restrict to specific IPs. *** ## Logging, Monitoring & Audit Yes. We monitor the logs. Application and infrastructure logs are centrally collected and backed up in a secure manner for internal development and audit-related concerns. Yes. We maintain the records. Yes. Since we record Services and Server logs at the level of virtual machine, and Audit and Access logs at the level of AWS, all these are covered. Monthly. Yes. Only authorised individuals can do this. Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. We provide logs to the customer on a need and approval basis. We maintain logs and monitor for security and audit purposes. Yes. System clocks of all relevant information processing systems are synchronized to facilitate tracing and reconstitution of activity timelines. Yes. We maintain logs for at least 180 days. Only the CTO and Production Head will have access to these logs. There will be no modification to these logs. Only authorised individuals have access to the security logs — e.g., CTO, DevOps Head, Production Head. At least 180 days. Yes. Only authorised individuals have access. Yes. We have a SIEM in place for monitoring and maintaining logs over security incidents from various components. Yes, SIEM has been implemented. Our event management systems merge data sources to maintain log data within the SIEM. This helps in proper analysis and driving out alerts in case of contingency. Audit logs are reviewed and recorded automatically. These logs are integrated with security operations/SIEM solutions. We have implemented the Security Operations Center to monitor, prevent, detect, investigate, and respond to cyber threats around the clock. Cyber security incidents are analyzed with network intrusion detection (IDS) tools. The incident response team is immediately notified for counter-actions and defense mechanisms. We have a Security incident management process to classify and handle incidents and security breaches. Yes. No. Logs are automatically audited but are not integrated with tenant's security ops. In case the tenant requests logs, they can be shared when asked by the clients. No. We do not have such a service. The key admin actions are present in the application reports. Our support team can help with a deep dive into a specific incident with the help of audit logs. Yes. Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. All infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. The audit logs are reviewed and recorded automatically. These logs are integrated with security operations/SIEM solutions. Yes. Our event management systems merge data sources to maintain log data within the SIEM. This helps in proper analysis and driving out alerts if needed. We monitor logs on a regular basis. Infrastructure logs are collected using AWS Audit Trail. Application related logs are collected in our Elastic Search server and retained in long-term cloud storage. We use a cloud-hosted VPN with strict access controls. We have implemented intrusion detection tools for timely detection and investigation. File integrity and network intrusion detection (IDS) tools are implemented. We also have Endpoint security software for all computers. We perform internal and external audits annually. We also conduct security assessments and testing like VAPT every six months. We communicate these assessment results to clients on a yearly basis. Yes. We conduct audits on our Information Security Management System. The last audit date was 16th June 2021. Yes. Yes. Administrative logs are part of the Cloud Dashboard and are regularly reviewed. We use Bitdefender Endpoint security software to prevent malware and protect data. Additionally, we have AWS GuardDuty threat detection service that continuously monitors for malicious activity and unauthorised behaviour. We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails. We have an intrusion detection/monitoring application that alerts on unauthorized access. We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails. Infrastructure logs are collected using AWS Audit Trail. Application related logs are collected in our Elastic Search server and retained in long-term cloud storage. Yes. All audit logs are monitored as a best practice. Yes. Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. Yes. Our event management systems merge the data sources to maintain a log data within the SIEM. This helps in proper analysis and driving out alerts if needed in case of contingency. At Xoxoday, the following are recorded in audit logs: 1. Infrastructure logs — collected using AWS Audit Trail. 2. Application related logs — collected in our Elastic Search server and retained in long-term cloud storage. *** ## Data Protection & Encryption Yes. We can freeze data from a specific time without freezing other data if needed. We have a data loss prevention solution in place and data will not be lost. Personal data will be processed only for rewards and redemption purposes. Yes. We can provide the data flow diagram. We use technologies like DLP, Data encryption, access control, and log monitoring. All data is collected only through the Xoxoday Platform. Yes. The data is segregated with a client-specific key for proper handling and representation. Physical segregation is done for production and non-production environments. We use a split key mechanism to ensure that every client's key is unique. It's generated automatically from our end. We have WAF, IDS/IPS, AWS GuardDuty, Cloudflare, and encrypted data. We conduct code reviews per compliance requirements and VAPT annually with a third-party vendor. We are equipped to detect and mitigate threats, DDoS attacks, session hijacks, login spoofs, or any other data extraction strategies. Yes. We do testing before deploying in the production environment. All data is collected only through the Xoxoday Platform. We do not transfer any data externally. However, we have implemented encryption, VPN, Firewall, IDS/IPS, and monitoring systems. We have disabled all ports and users do not have access to USB, CD-ROM, Disks, tapes, or Hard drives. All data including backups has been encrypted. We use TLS 1.2 for data in transit and AES-256 for data at rest. All customer data including backup data is stored on AWS virtual platform cloud and does not store anything locally. We use TLS 1.2 for data in transit and AES-256 for data at rest. We have also implemented the Media handling procedure. Yes. Our web application, email records, and endpoints are sealed with data loss prevention techniques. We have the capability to respond immediately. We logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant's data. All security mechanisms and policies are established to prevent data leaks in transit as well as at rest. Exhaustive VAPT has been conducted along with business logic testing based on the OWASP framework, which incorporates 120+ test cases. No. We use logical data isolation with the help of company-specific encryption keys. Yes. We have implemented Data Loss Prevention techniques on AWS. We have implemented data loss prevention techniques to make sure that the data is not lost permanently. It's a part of our data loss prevention techniques. Our web assets, email records, and endpoints are sealed with data loss prevention techniques even when the endpoint is disconnected from the corporate network. Each tenant's data is uniquely encrypted using a client-specific key. We use AES-256 bit encryption for data at rest. Our network communication is encrypted with highly restricted protocols. The cryptographic keys, including data encryption and SSL certificates, are managed by Xoxoday for optimal security. We use a split key mechanism to ensure that every client's key is unique. We perform annual key rotation. Keys are generated using KMS service whenever needed. We store keys in KMS. We use a split key mechanism to ensure that every client's key is unique. We perform annual key rotation. Keys are generated using KMS service whenever needed. We store keys in KMS. We use logical data isolation with the help of company-specific encryption keys. Password can be reset by employees. We do not send the password in plain text. We use TLS 1.2 for data in transit and AES-256 for data at rest. We store passwords hashed. We have SHA-512 hash with unique salt for every password. Only our product engineering team members have access as per their job functions and role-based logical access. We do not provide access to any third parties and all development and testing is done by internal employees. Yes. We use TLS 1.2 for data in transit and AES-256 for data at rest. All data including backups is encrypted. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. Yes. Per our policies and procedures, we ensure secure disposal and removal of data from every storage media. The data cannot be recovered by any computer forensic means. We assure secure data disposal when storage is decommissioned or when the contract comes to an end. The only user data stored within the system is personal information — names, emails, and contact numbers. This data is not put to any use by Xoxoday and resides within the system. The data can be deleted upon the tenant's request. We have implemented the Data Retention and Disposal Policy. We retain logs for a minimum of 180 days and in accordance with the Company's records retention guidelines. We do not process any e-PHI. *** ## Patch Management We update patches on a routine basis. We update patches on a routine basis for servers as well. We test patches before implementation in the production environment. Patches are updated regularly. Security patches are rated as Critical, High, Medium, and Low. Critical patches will be deployed immediately. High patches will be deployed within 5 days. Medium patches within 15 days. Low within 25 days. Patch Management Procedure is attached. Yes. We update patches periodically for our operating systems, software, servers, and network infrastructure. Yes. We test the patches on the testing environment and deploy to production upon validation. Yes. Security patches are regularly monitored and applied to the network security devices. All critical patches will be deployed immediately. We update patches periodically. See Patch Management Procedure attached. Yes. We regularly update our instance and make sure we follow security best practices. There is a process in place for regularly updating the servers and monitoring for latest updates across the entire stack. We have implemented the Patch Management Procedure. We follow the Change Management process to implement the compensatory control. We follow the Change Management process. Patches are updated on time. Critical patches will be deployed immediately. High patches within 5 days. Medium patches within 15 days. Low within 25 days. Patch Management Procedure is attached. Yes. We test patches before deploying in the production environment. *** ## Change Management We have implemented the Change Management Procedure. All IT changes take place as per the Change Management Procedure. Yes. Changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates. Yes. Change management procedures are attached. We are compliant. Yes. We have implemented the change management procedures, and this applies to all Xoxoday assets, infrastructure, processes, software, and third-party activities. The procedure also applies to employees, vendors, and all other individuals who have access to, or are responsible for Xoxoday information processing facilities. Yes. Our production team and QA team test all new releases or changes made to the existing product. Yes. We will notify the customer if there are any major changes. Yes. Our customer support team will communicate. *** ## Antivirus & Endpoint Security We have installed antivirus on all workstations and servers. Yes. We have the controls in place. We have blocked connecting Hard disk, USB, CD-ROM, etc. to computers and all devices are centrally managed. We use Bitdefender Endpoint security software to prevent malware and protect data. Additionally, we have AWS GuardDuty that continuously monitors for malicious activity and unauthorised behaviour. We use a cloud-hosted VPN with strict access controls linked with SSO/Active Directory. We use endpoint security for prevention. We have an alerting system in place and we perform scanning immediately to reduce the risk. We have all required security controls for protecting endpoints — VPN, Firewall, IDS/IPS, Anti-Virus software, Audit log monitoring, Active Directory, etc. We maintain up-to-date endpoint security to safeguard from attack scripts, viruses, worms, Trojan horses, backdoors, and malicious active content. We are using Linux operating systems and following security best practices. We are monitoring using Prometheus/Grafana. We have installed endpoint security in servers and PCs of all our employees as per compliance requirements. Yes. We update patches periodically and ensure that all endpoints have the latest available security-related patches. We have all required security controls for protecting endpoints — VPN, Firewall, IDS/IPS, Anti-Virus software, Audit log monitoring, Active Directory, etc. We use a cloud-hosted VPN with strict access controls linked with SSO/Active Directory. *** ## SSO, Authentication & Integration Yes. Our partnerships with a wide array of integration partners ensure existing customer-based SSO capability for all users to seamlessly use Xoxoday's products. With an easy DIY setup, your SSO solution would be plugged in and ready to go. Please refer to our list of integrations: [https://xoxoday.gitbook.io/plum/developer-resources/integrations](https://xoxoday.gitbook.io/plum/developer-resources/integrations) Yes. The application has robust authentication methods. We have integrated SAML 2.0 with SAP SuccessFactors and also support OAuth 2.0 for seamless authentication. API Documentation: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis) Please click here to know more about API integration: [https://www.empuls.io/integrations](https://www.empuls.io/integrations) The application enables user account management through API-based integration with the customer's HR management system. These APIs are used to access employee data to ensure users' accounts are created, updated, and disabled securely. Please click here for API Documentation: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis) We have implemented WAF, IDS/IPS, and Amazon GuardDuty for maximum security. OAuth 2.0 is used to authorize all API requests. We also conduct code reviews to make sure that the APIs are secure. Yes. It supports SSO. Our partnerships with a wide array of integration partners ensure existing customer-based SSO capability for all users to seamlessly use Xoxoday's products. With an easy DIY setup, your SSO solution would be plugged in and ready to go. Application Integrations: [https://www.application.io/integrations?tab=tab-collaborations](https://www.application.io/integrations?tab=tab-collaborations) It's a web and mobile application. Our partnerships ensure existing customer-based SSO capability for all users. Our identity federation standards include SAML 2.0, SPML, WS-Federation, and more as means of authenticating and authorizing users with airtight security protocol. Please visit: xoxoday.com/integrations Yes. The application has robust authentication methods. We have integrated SAML 2.0 with SAP SuccessFactors and support OAuth 2.0 and Azure AD for seamless authentication. We have an option to integrate with SSO and HRMS. For more info, please visit the link: [https://www.application.io/integrations](https://www.application.io/integrations) Two standard reports are available for admins on SuccessFactors at the program level — Budget and Spot Award Nomination. Using People Analytics, customers can create their own reports and dashboards combining Spot Awards data from Recognition with data from across SuccessFactors. Admins can also access similar data via a Xoxoday logon. Yes. Customers can extract data from SuccessFactors via Integration Center and integrate it with other third parties. Somewhat. We have a Spot Award Approved event available via Intelligent Service Center on SuccessFactors which customers can use to build custom extensions. User provisioning for SAP SuccessFactors — Reward and Recognition is handled the same way as the rest of SuccessFactors. For employees redeeming points via Xoxoday, user provisioning is done on the fly at the time of redeeming the awards. *** ## Third Party & Vendor Management We make sure that they have adequate controls in place and meet the security standard. We are managing the platform end to end. Yes. Incident reporting obligations are passed on to all 3rd parties as well. All contracts and agreements are reviewed by the Legal Department. We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. Administrative logs are part of the Cloud Dashboard and are regularly reviewed. *** ## Service, Support & Upgrades It will be the responsibility of Xoxoday. The process for upgrades is automated using Continuous Integration and Deployment. Since our services are delivered via the web, upgrades and updates are seamless and usually do not involve any actions from end-users. Xoxoday's architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows. The process for upgrades is automated using CI/CD. We try to release product hotfixes once every week and major features once every month. The process for upgrades is automated using CI/CD. Upgrades and updates are seamless. We try to release hotfixes once every week and major features once every month. Product updates and feature enhancements are done periodically by the application team. These updates are available to all customers by default. The customer need not do anything from their end to update the product version as the application is hosted on AWS Cloud. The time of support ranges between two to forty-eight hours. This depends on the level of service and the gravity of incidents. We have Email Support and an application help center for helping users. We will be providing training for the admin and the end user and also provide extensive support through our customer support team. Yes. We have an Information security team and group of people with responsibility for security within the organization. Yes. We fix the issues found at no cost. We understand that consumer data protection is a high priority. We have implemented a Bug Bounty Program and encourage the reporting of security issues. If any outsiders or customers report security-related issues, we fix them free of cost. We have deployed our application on Amazon Web Services (AWS) cloud platform. We are using MySQL, Salt stack, Node.js, and MongoDB technology. See the application high-level diagram of CI/CD attached. See the following policies attached — Infrastructure Change Control Procedure, Patch Management Procedure, Information System Acquisition Development and Maintenance Procedure, SDLC Procedure, Threat and Vulnerability Management. Please click here for more details: [https://help.empuls.io/](https://help.empuls.io/) Payments are redirected to PayU gateway or PayPal websites to complete purchases securely. We are also implementing PCI DSS compliance controls and will provide the certification as soon as possible. Approximately 2 weeks. No installation. We are an out-of-the-box SaaS solution. No recommendations as such. The application is a SaaS product supported by a comprehensive web application that can be accessed via desktop and mobile browsers on all compatible devices, including Android and iOS. We have a multi-layered network architecture with role-based access control. All confidential/PII data is encrypted at rest with a split key mechanism to ensure that every client's key is unique. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access. Yes. Yes. Yes. We have deployed our application on AWS Virtual platform cloud. We use WAF, IDS/IPS, AWS Audit Trail, Amazon GuardDuty, etc. Yes. Segregation is done for production and non-production environments. The production center location will be Bangalore. *** ## Compliance Statements Xoxoday would act as liaison partner between customer and merchants. We process the budgets which are approved by the customer. Xoxoday application is a SaaS Product. The logs are automatically audited, but are not integrated with tenant's security ops. In case the tenant requests logs, they can be shared when asked by the clients. It's a multi-tenant system. We use logical data isolation with the help of company-specific encryption keys and it is isolated from other customers' data. Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. We provide these logs on a need and approval basis for forensic investigation. We can freeze data from a specific time without freezing other data if needed. We are compliant. We have implemented the password management policy and follow the concept of least privilege. Only a limited number of approved users have privileged access. All access will be provided on a need and approval basis. We maintain a ticketing system to make sure that the appropriate process is followed. We have implemented the Password Management Policy for maximum security of data. We are compliant. The password will be changed every 90 days. These are integrated with security operations/SIEM solutions. We have a secure log-on process and are compliant with these requirements. We have a secure log-off process and are compliant with these requirements. Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. We review architecture diagrams and data flow diagrams on a periodical basis. This is also validated during our internal and external independent audits. We logically segregate the tenant's data, and it is segregated with a client-specific key for proper handling and security reasons. We do not use any unsecured protocols. All critical applications are reviewed and tested before deployment. We have a separate test and production environment. We monitor systems and network utilization. We have implemented file integrity (host) and network intrusion detection (IDS) tools to help facilitate timely detection and investigation. We make sure that we follow industry best practices, the PDCA cycle, and standards in order to safeguard the Information Security System. All critical patches are applied rapidly. We are a multi-tenant SaaS system and all our logs will contain data of all customers. We will have our own log monitoring and security analysis. Yes. All critical patches will be deployed immediately. We ensure that our infrastructure is always using up-to-date systems. We have the ability to logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant's data. Compliant. We have deployed our application and database on separate servers. Since the application is a SaaS Platform, this would not be applicable. Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. Administrative logs are part of the Cloud Dashboard and are regularly reviewed. Yes. We logically segregate the tenant's data and the application. WAF and rate limiters are installed to block multiple requests from specific IPs to prevent DDoS-type attacks. Once the user logs out from the application, all pages, forms, and pop-ups will get closed. We maintain logs and monitor on a regular basis for security reasons. Compliant. We have resources to meet these requirements. *** ## Infrastructure & Compliance We take steps to securely develop and test against security threats to ensure the safety of our customer data. We maintain a Secure Development Lifecycle, in which training our developers and performing design and code reviews takes a primary role. In addition, Xoxoday employs third-party security experts to perform detailed penetration tests on different applications. In addition to the security components provided by our top-level cloud providers AWS, Xoxoday maintains its own dedicated controls by following the industry best practices. These controls cover DDoS attacks, DB protection and a dedicated web application firewall, as well as network firewall fine-grained rules configured using the highest industry standards. We provide Software as a Service (SaaS). SaaS. Admins can control the application and will have access to alerts and security events. Xoxoday application is an API-driven digital rewards platform that automates rewards, incentives and gifting. The storefront has a global catalogue of 20,000+ options with 5,000+ experiences, 2,000+ gift cards and 10,000+ perks. The platform offers reward distribution modes like sending bulk vouchers via emails and generation of bulk voucher codes. No. We are cloud hosted only. We will share this as an attachment upon request. Cloud hosted, microservice-based, highly scalable, High Availability. NA — We are cloud hosted. NA — We are cloud hosted. Users need to have internet access. Yes. The solution is available as part of SAP SuccessFactors solution on web, as well as the SuccessFactors native mobile app for both iOS and Android. It's accessible in a mobile browser and can be accessed via an Android or iOS device. Our applications are compatible with desktops, tablets, and mobiles. No additional components are required. Our applications are compatible with desktops, tablets, and mobiles. No additional components are required. AWS / Kubernetes — React — Node/GraphQL — MySQL/MongoDB. We have deployed our application on Amazon Web Services (AWS) cloud platform. We are using MySQL, Salt stack, Node.js and MongoDB technology. Yes. We are using the latest language frameworks like MySQL, JavaScript, Node.js and MongoDB. Yes. These are approved during the code review process wherein the reviewer checks the utility and security of the libraries. We have deployed our application on AWS Cloud virtual platform. The backup data center is in Singapore. The data centers are hosted completely in isolation so that access is limited and controlled. Load balancer allows shifting incremental load and can auto scale based on data load. Each instance (EC2) under a fortified VPC network is a conglomeration of Docker Container Web Services and APIs and application layer running on top. Amazon CloudWatch is implemented to enable monitoring. The data is encrypted using 256-encryption-based SSL certificate. Xoxoday plans a quarterly VAPT-based security audit. Plum by Xoxoday is a cloud-based SaaS platform hosted on VPC infrastructure of AWS. The data centers are hosted in complete isolation. The architecture allows adding more location-specific data centers for latency and data security. Load balancers allow auto-scaling. Each EC2 instance under fortified VPC network is a conglomeration of Docker Container Web Services and APIs. Amazon CloudWatch is implemented for monitoring. Data is encrypted using TLS 1.3 in transit and AES-256 at rest. *** ## Backup, Recovery & Business Continuity Data backups are done daily and in a secured way in AWS. We use AWS Virtual platform cloud. We have created an Amazon CloudWatch alarm that monitors Amazon EC2 instances and automatically recovers them if impaired. EBS Snapshot functionality allows us to capture and restore virtual machine images at any time. Yes, the infrastructure environment solution includes software/provider independent restore and recovery capabilities. Yes. Data backups are automated and done daily in a secured way on AWS. We test the backup or redundancy mechanisms at least annually. Our RTO and RPO is 60 minutes. Yes. Data backups are done daily and in a secured way in AWS. Data backups are done on a daily basis and in a secured way on AWS. We take automated backups on a regular basis. Yes. We take a backup of all data before making any major changes to hardware and software. We have implemented the Backup Recovery Procedure. We have Business Continuity Policy and Business Continuity Management Procedure in place, tested periodically. Our policies are reviewed and audited annually. We test the BCP every 12 months, reviewed as part of internal and external audits. Yes. Data backups are done on a daily basis in a secured way in AWS. Yes. It is tested annually. Yes. All data backup is encrypted. Yes. It can be recovered. We have implemented the Business Continuity Management Policy and test the BCM plan annually. The BCM policy is attached for reference. We have implemented policies and procedures with regard to DR. Since we have deployed our application on AWS cloud, they provide DR services. The application network architecture diagram is attached upon request. *** ## Application Development & SDLC We have an SDLC Policy as per ISMS requirements and follow General Coding Practice. We conduct data validation on a trusted system, use cryptographic functions to protect secrets, and perform code reviews, vulnerability assessments, and penetration testing. We follow a blue-green deployment strategy that introduces new changes without downtime and provides rollback capability. Yes. Changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates. We have implemented the SDLC Procedure and standards of quality are met for all software development. We have not outsourced software development activities. Our code reviews and analysis run through stringent automated technologies as well as manual source code overviews to cover any security loopholes prior to the production phase. Yes. All debugging and test code elements are removed from released software versions. Yes. We use an automated source code analysis tool. We are proactively embedding privacy into the design and operation of IT systems, networked infrastructure, and business practices. We focus on security while producing software. SDLC procedures are attached for reference. Yes. All environments are separate. No. We do not use production data in test environments. Yes. Both are kept separate. Yes. Any applications and software are implemented after security testing by our IT team. All logs are monitored. We maintain an approved software/application register, audited during internal and external audits. Users are disallowed from installing software on their workstations. Yes. We have static code analysis. We have an SDLC Policy per ISMS requirements and follow General Coding Practice including data validation on a trusted system, cryptographic functions to protect secrets, and least privilege — restricting users to only the functionality, data, and system information required for their tasks. More than 50% of our production code is covered by automated tests. We do not use staging for building artifacts. We conduct application security testing with the help of industry-approved third-party vendors every six months. Any observations found are addressed by our team. The primary objective is to identify and eliminate problems that could lead to a breach of confidentiality, availability, or integrity of Xoxoday data resources. Yes. Our code reviews run through stringent automated technologies and manual source code overviews. Vulnerability scanning gives deep insight for quick identification of non-compliant systems. Xoxoday also employs third-party security experts to perform VAPT. Yes. Code reviews and analysis run through stringent automated technologies as well as manual source code review. Multiple security checks including code reviews, web vulnerability reviews, and advanced security tests are performed in every build. Yes. Code is reviewed both internally and externally. We engage third-party vendors for security testing every six months. All software development procedures are supervised and monitored by Xoxoday to include: security requirements, independent security review of the environment, code reviews, quality monitoring, evaluation, and acceptance criteria for information systems. Our QA department reviews and tests our code base. Dedicated application security engineers identify, test, and triage security vulnerabilities. We also conduct code reviews and VAPT with the help of a third-party vendor. VAPT Certificate is attached. Yes. This is part of the code review process wherein the reviewer checks the utility and security of the 3rd party library. Compliant. The application is developed based on secure coding guidelines and code reviews are conducted per compliance requirements. Compliant. Compliant. Yes, we follow all technical guidelines for development that come under the Open Web Application Security Project. Compliant. We have implemented DLP techniques and there are no possibilities of data leakage or loss. Compliant. The application uses HTTPS. Compliant. We use strict HTTP transport security. We cannot impose file upload frequency restrictions. However, the application has technical and organizational measures to prevent attacks through WAF, log monitoring, AWS GuardDuty, Amazon CloudWatch, IDS/IPS, etc. *** ## Access Control & Authentication We have a role-based access system to make sure that only authorized individuals have access to the required information. We don't provide multi-factor authentication as a default. As of now, there's OAuth 2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins. No, we don't provide multi-factor authentication as a default. As of now, there's OAuth 2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins. It can be configured with Active Directory. Access to data and systems is based on the principles of least privilege. All information systems and data are classified and segregated to support role-based access requirements. We use MFA, Firewall, VPN, Active Directory, etc. for maximum security. The password needs to be a minimum of 8 characters long and contain at least one capital letter, special characters among '# \$ % \* &' and 1 digit. These are reviewed monthly. We store passwords hashed. We have SHA-512 hash with unique salt for every password. We store passwords hashed. We have SHA-512 hash with unique salt for every password. Yes. Our password requirements comply with all factors to ensure strong passwords: minimum length, special characters, capitalized letters, and alpha-numeric combinations. Passwords are stored after encryption. Yes. Yes. The solution does not allow login using credentials that have not been used. Admins can create and delete user accounts. It's a SaaS solution. Users can log in from multiple locations. No. Users need to login with user ID and password. However, we have integrations with Zoho CRM, HubSpot, DarwinBox, SurveyMonkey, Freshdesk, etc. Since it's a SaaS product, session timeout can be set with the help of Active Directory. For example — 15 min or 20 mins as per requirements. The account will get automatically locked after 5 unsuccessful login attempts. Users will get a reset password link and can unlock their account through that. User accounts will be created by the admin and linked with the email ID of the users. Please refer to the admin guide: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1) Yes. Yes. Two-factor authentication is enabled. MFA devices like Google Authenticator are available for OTP/Codes/Passwords. Yes. We have procedures for Roles, Responsibilities & Authorities at Xoxoday. Per the access control policy, access to data is provided only to authorized and appropriate individuals. Password policy: Must contain at least 8 characters, numbers and letters, uppercase (A-Z), lowercase (a-z), digits (0-9), and non-alphabetic characters (e.g., !, \$, #, %). Password must be changed every 90 days. Passwords are shared through secure, encrypted channels. Yes. Policies and procedures enforce two-factor authentication for privileged account management while accessing tenant data/systems. An IAM solution manages user access through role-based access profiles based on the need-to-know principle and segregation of duties. By default, Xoxoday will not have access to service data. Access control is managed by the admin from the customer end. If we require access for troubleshooting, we request temporary access, and the customer decides. Access to our production environment is allowed only via the Xoxoday corporate network to authorized individuals. Please refer to the admin guide on SSO Logins: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/getting-started](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/getting-started) Yes. Access has been restricted and monitored for security reasons. Yes. We have complexity and length requirements for passwords. We review user access on a periodical basis, validated during internal and external audits. *** ## Network Security & Firewall Yes. We have captured this information in our architecture and data flow diagrams. Yes, we have a firewall. Yes, we have the network architecture diagram. Yes, we have configured secure internet access. Yes, we have configured these. Yes. We have IDS and IPS implemented and receive alerts for unauthorised network access. Yes. It's reviewed on a monthly basis. Yes. Yes. Yes. All are configured according to security standards as part of the build process. We have implemented IDS/IPS to facilitate timely detection, investigation by root cause analysis, and response to incidents. Wireless access is allowed and handled with high-quality routers, password protection and restriction on internet usage. Yes. We have installed firewalls for maximum security and configured them to restrict unauthorised traffic. All data is collected only through the Xoxoday Platform. We use a Web Application Firewall (WAF). We harden the operating systems and restrict access to all ports, applications, and software, monitored on a regular basis. We have implemented policies and mechanisms to protect the wireless network environment. We use a cloud-hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and linked with SSO/Active Directory. Yes. It's logically and physically segregated. We have deployed our application on AWS Cloud platform. We do not provide external access. We have implemented IDS/IPS, Endpoint security, Firewall, DLP, Antispoofing, VPN, Active Directory and other security solutions for maximum security. Yes. With multiple layered firewalls configured with deny-all mode allowing only specific rules required for business, network traffic is regulated. We have implemented intrusion detection and prevention system tools for timely detection and investigation. With multiple layered firewalls in deny-all mode, network traffic is regulated. We use tools that analyze various traffic patterns and correlate network events. Early warning signals trigger alerts to our team. We are equipped to detect and mitigate threats, DDoS attacks, session hijacks, login spoofs, or any other data extraction strategies. Yes. As part of WAF, rate limiters are installed to block multiple requests from specific IPs to prevent DDoS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats. All our network components and computers are password protected to ensure compliance with integrity, availability, and confidentiality principles of Information Security. Yes. We have Network Access Control and Security Procedure in place. Network resources must be on a need-to-know basis and authorizations must be obtained from appropriate authorities. Networks are logically or physically divided based on the criticality of the information stored. We have WAF, IDS/IPS, AWS GuardDuty, Cloudflare, and data encryption. We conduct code reviews and VAPT annually with a third-party vendor. We are equipped to detect and mitigate DDoS attacks, session hijacks, login spoofs, or any other data extraction strategies. We use Cloudflare Web Application Firewall (WAF) and IDS/IPS for maximum security. Yes. We have implemented the Web Application Firewall (WAF). We have a web application firewall, IDS/IPS, SQL injection protection. We use Cloudflare for the same. Yes. Our network communication is encrypted with highly restricted protocols to ensure maximum security. We use TLS 1.2 encryption for data in transit. We use HTTPS and our network communication is encrypted with highly restricted protocols to ensure maximum security. We do not provide support for IP address range restriction. Our restrictions/security are based on our OAuth process and do not restrict to specific IPs. *** ## Logging, Monitoring & Audit Yes. We monitor the logs. Application and infrastructure logs are centrally collected and backed up in a secure manner for internal development and audit-related concerns. Yes. We maintain the records. Yes. Since we record Services and Server logs at the level of virtual machine, and Audit and Access logs at the level of AWS, all these are covered. Monthly. Yes. Only authorised individuals can do this. Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. We provide logs to the customer on a need and approval basis. We maintain logs and monitor for security and audit purposes. Yes. System clocks of all relevant information processing systems are synchronized to facilitate tracing and reconstitution of activity timelines. Yes. We maintain logs for at least 180 days. Only the CTO and Production Head will have access to these logs. There will be no modification to these logs. Only authorised individuals have access to the security logs — e.g., CTO, DevOps Head, Production Head. At least 180 days. Yes. Only authorised individuals have access. Yes. We have a SIEM in place for monitoring and maintaining logs over security incidents from various components. Yes, SIEM has been implemented. Our event management systems merge data sources to maintain log data within the SIEM. This helps in proper analysis and driving out alerts in case of contingency. Audit logs are reviewed and recorded automatically. These logs are integrated with security operations/SIEM solutions. We have implemented the Security Operations Center to monitor, prevent, detect, investigate, and respond to cyber threats around the clock. Cyber security incidents are analyzed with network intrusion detection (IDS) tools. The incident response team is immediately notified for counter-actions and defense mechanisms. We have a Security incident management process to classify and handle incidents and security breaches. Yes. No. Logs are automatically audited but are not integrated with tenant's security ops. In case the tenant requests logs, they can be shared when asked by the clients. No. We do not have such a service. The key admin actions are present in the application reports. Our support team can help with a deep dive into a specific incident with the help of audit logs. Yes. Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. All infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. The audit logs are reviewed and recorded automatically. These logs are integrated with security operations/SIEM solutions. Yes. Our event management systems merge data sources to maintain log data within the SIEM. This helps in proper analysis and driving out alerts if needed. We monitor logs on a regular basis. Infrastructure logs are collected using AWS Audit Trail. Application related logs are collected in our Elastic Search server and retained in long-term cloud storage. We use a cloud-hosted VPN with strict access controls. We have implemented intrusion detection tools for timely detection and investigation. File integrity and network intrusion detection (IDS) tools are implemented. We also have Endpoint security software for all computers. We perform internal and external audits annually. We also conduct security assessments and testing like VAPT every six months. We communicate these assessment results to clients on a yearly basis. Yes. We conduct audits on our Information Security Management System. The last audit date was 16th June 2021. Yes. Yes. Administrative logs are part of the Cloud Dashboard and are regularly reviewed. We use Bitdefender Endpoint security software to prevent malware and protect data. Additionally, we have AWS GuardDuty threat detection service that continuously monitors for malicious activity and unauthorised behaviour. We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails. We have an intrusion detection/monitoring application that alerts on unauthorized access. We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails. Infrastructure logs are collected using AWS Audit Trail. Application related logs are collected in our Elastic Search server and retained in long-term cloud storage. Yes. All audit logs are monitored as a best practice. Yes. Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. Yes. Our event management systems merge the data sources to maintain a log data within the SIEM. This helps in proper analysis and driving out alerts if needed in case of contingency. At Xoxoday, the following are recorded in audit logs: 1. Infrastructure logs — collected using AWS Audit Trail. 2. Application related logs — collected in our Elastic Search server and retained in long-term cloud storage. *** ## Data Protection & Encryption Yes. We can freeze data from a specific time without freezing other data if needed. We have a data loss prevention solution in place and data will not be lost. Personal data will be processed only for rewards and redemption purposes. Yes. We can provide the data flow diagram. We use technologies like DLP, Data encryption, access control, and log monitoring. All data is collected only through the Xoxoday Platform. Yes. The data is segregated with a client-specific key for proper handling and representation. Physical segregation is done for production and non-production environments. We use a split key mechanism to ensure that every client's key is unique. It's generated automatically from our end. We have WAF, IDS/IPS, AWS GuardDuty, Cloudflare, and encrypted data. We conduct code reviews per compliance requirements and VAPT annually with a third-party vendor. We are equipped to detect and mitigate threats, DDoS attacks, session hijacks, login spoofs, or any other data extraction strategies. Yes. We do testing before deploying in the production environment. All data is collected only through the Xoxoday Platform. We do not transfer any data externally. However, we have implemented encryption, VPN, Firewall, IDS/IPS, and monitoring systems. We have disabled all ports and users do not have access to USB, CD-ROM, Disks, tapes, or Hard drives. All data including backups has been encrypted. We use TLS 1.2 for data in transit and AES-256 for data at rest. All customer data including backup data is stored on AWS virtual platform cloud and does not store anything locally. We use TLS 1.2 for data in transit and AES-256 for data at rest. We have also implemented the Media handling procedure. Yes. Our web application, email records, and endpoints are sealed with data loss prevention techniques. We have the capability to respond immediately. We logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant's data. All security mechanisms and policies are established to prevent data leaks in transit as well as at rest. Exhaustive VAPT has been conducted along with business logic testing based on the OWASP framework, which incorporates 120+ test cases. No. We use logical data isolation with the help of company-specific encryption keys. Yes. We have implemented Data Loss Prevention techniques on AWS. We have implemented data loss prevention techniques to make sure that the data is not lost permanently. It's a part of our data loss prevention techniques. Our web assets, email records, and endpoints are sealed with data loss prevention techniques even when the endpoint is disconnected from the corporate network. Each tenant's data is uniquely encrypted using a client-specific key. We use AES-256 bit encryption for data at rest. Our network communication is encrypted with highly restricted protocols. The cryptographic keys, including data encryption and SSL certificates, are managed by Xoxoday for optimal security. We use a split key mechanism to ensure that every client's key is unique. We perform annual key rotation. Keys are generated using KMS service whenever needed. We store keys in KMS. We use a split key mechanism to ensure that every client's key is unique. We perform annual key rotation. Keys are generated using KMS service whenever needed. We store keys in KMS. We use logical data isolation with the help of company-specific encryption keys. Password can be reset by employees. We do not send the password in plain text. We use TLS 1.2 for data in transit and AES-256 for data at rest. We store passwords hashed. We have SHA-512 hash with unique salt for every password. Only our product engineering team members have access as per their job functions and role-based logical access. We do not provide access to any third parties and all development and testing is done by internal employees. Yes. We use TLS 1.2 for data in transit and AES-256 for data at rest. All data including backups is encrypted. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. Yes. Per our policies and procedures, we ensure secure disposal and removal of data from every storage media. The data cannot be recovered by any computer forensic means. We assure secure data disposal when storage is decommissioned or when the contract comes to an end. The only user data stored within the system is personal information — names, emails, and contact numbers. This data is not put to any use by Xoxoday and resides within the system. The data can be deleted upon the tenant's request. We have implemented the Data Retention and Disposal Policy. We retain logs for a minimum of 180 days and in accordance with the Company's records retention guidelines. We do not process any e-PHI. *** ## Patch Management We update patches on a routine basis. We update patches on a routine basis for servers as well. We test patches before implementation in the production environment. Patches are updated regularly. Security patches are rated as Critical, High, Medium, and Low. Critical patches will be deployed immediately. High patches will be deployed within 5 days. Medium patches within 15 days. Low within 25 days. Patch Management Procedure is attached. Yes. We update patches periodically for our operating systems, software, servers, and network infrastructure. Yes. We test the patches on the testing environment and deploy to production upon validation. Yes. Security patches are regularly monitored and applied to the network security devices. All critical patches will be deployed immediately. We update patches periodically. See Patch Management Procedure attached. Yes. We regularly update our instance and make sure we follow security best practices. There is a process in place for regularly updating the servers and monitoring for latest updates across the entire stack. We have implemented the Patch Management Procedure. We follow the Change Management process to implement the compensatory control. We follow the Change Management process. Patches are updated on time. Critical patches will be deployed immediately. High patches within 5 days. Medium patches within 15 days. Low within 25 days. Patch Management Procedure is attached. Yes. We test patches before deploying in the production environment. *** ## Change Management We have implemented the Change Management Procedure. All IT changes take place as per the Change Management Procedure. Yes. Changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates. Yes. Change management procedures are attached. We are compliant. Yes. We have implemented the change management procedures, and this applies to all Xoxoday assets, infrastructure, processes, software, and third-party activities. The procedure also applies to employees, vendors, and all other individuals who have access to, or are responsible for Xoxoday information processing facilities. Yes. Our production team and QA team test all new releases or changes made to the existing product. Yes. We will notify the customer if there are any major changes. Yes. Our customer support team will communicate. *** ## Antivirus & Endpoint Security We have installed antivirus on all workstations and servers. Yes. We have the controls in place. We have blocked connecting Hard disk, USB, CD-ROM, etc. to computers and all devices are centrally managed. We use Bitdefender Endpoint security software to prevent malware and protect data. Additionally, we have AWS GuardDuty that continuously monitors for malicious activity and unauthorised behaviour. We use a cloud-hosted VPN with strict access controls linked with SSO/Active Directory. We use endpoint security for prevention. We have an alerting system in place and we perform scanning immediately to reduce the risk. We have all required security controls for protecting endpoints — VPN, Firewall, IDS/IPS, Anti-Virus software, Audit log monitoring, Active Directory, etc. We maintain up-to-date endpoint security to safeguard from attack scripts, viruses, worms, Trojan horses, backdoors, and malicious active content. We are using Linux operating systems and following security best practices. We are monitoring using Prometheus/Grafana. We have installed endpoint security in servers and PCs of all our employees as per compliance requirements. Yes. We update patches periodically and ensure that all endpoints have the latest available security-related patches. We have all required security controls for protecting endpoints — VPN, Firewall, IDS/IPS, Anti-Virus software, Audit log monitoring, Active Directory, etc. We use a cloud-hosted VPN with strict access controls linked with SSO/Active Directory. *** ## SSO, Authentication & Integration Yes. Our partnerships with a wide array of integration partners ensure existing customer-based SSO capability for all users to seamlessly use Xoxoday's products. With an easy DIY setup, your SSO solution would be plugged in and ready to go. Please refer to our list of integrations: [https://xoxoday.gitbook.io/plum/developer-resources/integrations](https://xoxoday.gitbook.io/plum/developer-resources/integrations) Yes. The application has robust authentication methods. We have integrated SAML 2.0 with SAP SuccessFactors and also support OAuth 2.0 for seamless authentication. API Documentation: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis) Please click here to know more about API integration: [https://www.empuls.io/integrations](https://www.empuls.io/integrations) The application enables user account management through API-based integration with the customer's HR management system. These APIs are used to access employee data to ensure users' accounts are created, updated, and disabled securely. Please click here for API Documentation: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis) We have implemented WAF, IDS/IPS, and Amazon GuardDuty for maximum security. OAuth 2.0 is used to authorize all API requests. We also conduct code reviews to make sure that the APIs are secure. Yes. It supports SSO. Our partnerships with a wide array of integration partners ensure existing customer-based SSO capability for all users to seamlessly use Xoxoday's products. With an easy DIY setup, your SSO solution would be plugged in and ready to go. Application Integrations: [https://www.application.io/integrations?tab=tab-collaborations](https://www.application.io/integrations?tab=tab-collaborations) It's a web and mobile application. Our partnerships ensure existing customer-based SSO capability for all users. Our identity federation standards include SAML 2.0, SPML, WS-Federation, and more as means of authenticating and authorizing users with airtight security protocol. Please visit: xoxoday.com/integrations Yes. The application has robust authentication methods. We have integrated SAML 2.0 with SAP SuccessFactors and support OAuth 2.0 and Azure AD for seamless authentication. We have an option to integrate with SSO and HRMS. For more info, please visit the link: [https://www.application.io/integrations](https://www.application.io/integrations) Two standard reports are available for admins on SuccessFactors at the program level — Budget and Spot Award Nomination. Using People Analytics, customers can create their own reports and dashboards combining Spot Awards data from Recognition with data from across SuccessFactors. Admins can also access similar data via a Xoxoday logon. Yes. Customers can extract data from SuccessFactors via Integration Center and integrate it with other third parties. Somewhat. We have a Spot Award Approved event available via Intelligent Service Center on SuccessFactors which customers can use to build custom extensions. User provisioning for SAP SuccessFactors — Reward and Recognition is handled the same way as the rest of SuccessFactors. For employees redeeming points via Xoxoday, user provisioning is done on the fly at the time of redeeming the awards. *** ## Third Party & Vendor Management We make sure that they have adequate controls in place and meet the security standard. We are managing the platform end to end. Yes. Incident reporting obligations are passed on to all 3rd parties as well. All contracts and agreements are reviewed by the Legal Department. We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. Administrative logs are part of the Cloud Dashboard and are regularly reviewed. *** ## Service, Support & Upgrades It will be the responsibility of Xoxoday. The process for upgrades is automated using Continuous Integration and Deployment. Since our services are delivered via the web, upgrades and updates are seamless and usually do not involve any actions from end-users. Xoxoday's architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows. The process for upgrades is automated using CI/CD. We try to release product hotfixes once every week and major features once every month. The process for upgrades is automated using CI/CD. Upgrades and updates are seamless. We try to release hotfixes once every week and major features once every month. Product updates and feature enhancements are done periodically by the application team. These updates are available to all customers by default. The customer need not do anything from their end to update the product version as the application is hosted on AWS Cloud. The time of support ranges between two to forty-eight hours. This depends on the level of service and the gravity of incidents. We have Email Support and an application help center for helping users. We will be providing training for the admin and the end user and also provide extensive support through our customer support team. Yes. We have an Information security team and group of people with responsibility for security within the organization. Yes. We fix the issues found at no cost. We understand that consumer data protection is a high priority. We have implemented a Bug Bounty Program and encourage the reporting of security issues. If any outsiders or customers report security-related issues, we fix them free of cost. We have deployed our application on Amazon Web Services (AWS) cloud platform. We are using MySQL, Salt stack, Node.js, and MongoDB technology. See the application high-level diagram of CI/CD attached. See the following policies attached — Infrastructure Change Control Procedure, Patch Management Procedure, Information System Acquisition Development and Maintenance Procedure, SDLC Procedure, Threat and Vulnerability Management. Please click here for more details: [https://help.empuls.io/](https://help.empuls.io/) Payments are redirected to PayU gateway or PayPal websites to complete purchases securely. We are also implementing PCI DSS compliance controls and will provide the certification as soon as possible. Approximately 2 weeks. No installation. We are an out-of-the-box SaaS solution. No recommendations as such. The application is a SaaS product supported by a comprehensive web application that can be accessed via desktop and mobile browsers on all compatible devices, including Android and iOS. We have a multi-layered network architecture with role-based access control. All confidential/PII data is encrypted at rest with a split key mechanism to ensure that every client's key is unique. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access. Yes. Yes. Yes. We have deployed our application on AWS Virtual platform cloud. We use WAF, IDS/IPS, AWS Audit Trail, Amazon GuardDuty, etc. Yes. Segregation is done for production and non-production environments. The production center location will be Bangalore. *** ## Compliance Statements Xoxoday would act as liaison partner between customer and merchants. We process the budgets which are approved by the customer. Xoxoday application is a SaaS Product. The logs are automatically audited, but are not integrated with tenant's security ops. In case the tenant requests logs, they can be shared when asked by the clients. It's a multi-tenant system. We use logical data isolation with the help of company-specific encryption keys and it is isolated from other customers' data. Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. We provide these logs on a need and approval basis for forensic investigation. We can freeze data from a specific time without freezing other data if needed. We are compliant. We have implemented the password management policy and follow the concept of least privilege. Only a limited number of approved users have privileged access. All access will be provided on a need and approval basis. We maintain a ticketing system to make sure that the appropriate process is followed. We have implemented the Password Management Policy for maximum security of data. We are compliant. The password will be changed every 90 days. These are integrated with security operations/SIEM solutions. We have a secure log-on process and are compliant with these requirements. We have a secure log-off process and are compliant with these requirements. Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. We review architecture diagrams and data flow diagrams on a periodical basis. This is also validated during our internal and external independent audits. We logically segregate the tenant's data, and it is segregated with a client-specific key for proper handling and security reasons. We do not use any unsecured protocols. All critical applications are reviewed and tested before deployment. We have a separate test and production environment. We monitor systems and network utilization. We have implemented file integrity (host) and network intrusion detection (IDS) tools to help facilitate timely detection and investigation. We make sure that we follow industry best practices, the PDCA cycle, and standards in order to safeguard the Information Security System. All critical patches are applied rapidly. We are a multi-tenant SaaS system and all our logs will contain data of all customers. We will have our own log monitoring and security analysis. Yes. All critical patches will be deployed immediately. We ensure that our infrastructure is always using up-to-date systems. We have the ability to logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant's data. Compliant. We have deployed our application and database on separate servers. Since the application is a SaaS Platform, this would not be applicable. Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. Administrative logs are part of the Cloud Dashboard and are regularly reviewed. Yes. We logically segregate the tenant's data and the application. WAF and rate limiters are installed to block multiple requests from specific IPs to prevent DDoS-type attacks. Once the user logs out from the application, all pages, forms, and pop-ups will get closed. We maintain logs and monitor on a regular basis for security reasons. Compliant. We have resources to meet these requirements. # DPDP Act Source: https://help-plum.xoxoday.com/faq/security-compliance/certifications/dpdp-act Learn about Plum's compliance with India's Digital Personal Data Protection (DPDP) Act and how it safeguards personal data. *Learn more about Digital Personal Data Protection Act, 2023* The Digital Personal Data Protection (DPDP) Act, 2023 governs the processing of digital personal data in India, emphasizing user consent, purpose limitation, and data accuracy. Enacted in August 2023 with rules effective from 2025, it applies to both online and offline data, protecting individual rights while allowing certain exceptions for the state. The Digital Personal Data Protection Act, 2023 (DPDP Act) helps by protecting individuals' personal data and ensuring it is processed lawfully, transparently, and for specific purposes. It strengthens citizens' rights over their data while imposing clear obligations on organizations to prevent misuse and data breaches. This promotes trust, accountability, and responsible digital governance in India. The complete assessment report can be shared through a proper Trust Center portal that provides controlled access and undergoes an NDA process before granting visibility. Under the Digital Personal Data Protection Act, 2023, clients must clearly understand their role as Data Fiduciaries, while we act as a Data Processor supporting compliance. Only necessary personal data should be collected, processed for lawful purposes, and protected with reasonable security safeguards. Teams must ensure mechanisms exist to handle data principal rights (access, correction, erasure) and follow proper breach notification procedures. All responsibilities, security commitments, and data handling terms should be clearly defined in contracts. Feedback or Questions? Write to us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Certifications and Compliance Source: https://help-plum.xoxoday.com/faq/security-compliance/certifications/others-documents Access additional compliance certifications and supporting documentation available for Plum beyond the core certifications. [Open document](https://drive.google.com/file/d/10gHjDefPzKBB3EC1BPHZ4SbqpcluKLjw/view?usp=sharing) [Open document](https://drive.google.com/file/d/1LyE7ogFTxdbUiaSLBOYaMbFxsvXbuI3v/view?usp=sharing) [Open document](https://drive.google.com/file/d/1gIJySTLQSSWGoeF3P8ukvr3xZhMGGePY/view?usp=sharing) [Open document](https://drive.google.com/file/d/161zus2TDtFeoIshMKAdKe8FDDGf_aaq0/view?usp=sharing) [Open document](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view?usp=sharing) [Open document](https://drive.google.com/file/d/16ICZUl9dbFC-PGHaU2jj49rzs0jzi_-S/view?usp=sharing) [Open document](https://drive.google.com/file/d/1dWf4on16eN2MebO7fNDFMuUJDp0CR1hW/view?usp=sharing) [Open document](https://drive.google.com/file/d/1K1zwc6qEjgYu4I8qYJcxBuPgsiPgtLnP/view?usp=sharing) # Cloud Security Source: https://help-plum.xoxoday.com/faq/security-compliance/cloud-security Find answers to frequently asked questions about the cloud security infrastructure and safeguards protecting the Plum platform. We have deployed our application on AWS Virtual platform cloud - Singapore and USA region. Data Security Architecture designed using an industry standard and best practices. We are adhered to CSA, ISO 27001, SOC 2 TSP. We have deployed our application on AWS Virtual platform cloud - Singapore region. The cloud infrastructure providers have high levels of physical and network security and hosting provider vendor diversity. All our customer data is stored on AWS Virtual platform cloud. And we collect the data only throguh our application platform. We do not store any customers data locally. File integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation. AWS CloudTrail helps to detect changes to the build/configuration of the virtual machine Our solution is using state of the art Cloud Native infrastructure technologies along with microservices architecture allows us to scale our operations as per the demands. We use Web application firewall (WAF) and pfSense firewall for security reasons. 1. The Cloudflare Web Application Firewall (Cloudflare WAF) checks incoming web requests and filters undesired traffic based on the set of rules. 2. pfSense helps to monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on a defined set of security rules We isolate our machines, network and storage with respect to the AWS Standards in order to keep it safe and secure. We use Web application firewall (WAF) and pfSense firewall for security reasons. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently. Yes. We monitor the compliance programs of AWS As we have stored the data on their cloud. No. Currently, all the data is stored on AWS VPC - Singapore region. Yes, we inform the customer on the data storage location. We are CSA STAR Level 1 compliant. Please click here to know more - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday) We use OWASP Software Assurance Maturity Model Since we have deployed our application on AWS Cloud its not applicable for us. Since we have deployed our application on AWS Cloud its not applicable for us. We provide certifite of destruction of data once the data is purged/deleted from all the places upon request from the customer. We have deployed our product on AWS Cloud virtual platform. AWS provides physical security to the data center as a part of our subscription. AWS physical security - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/) We have implemented IDS/IPS to facilitate timely detection, investigation by root cause analysis and response to incidents Data backups are done on daily basis and in a secured way on AWS Data backups are done on daily basis and in a secured way on AWS - Singapore Data backups are done on daily basis and in a secured way on AWS. This has been tested on regular basis. Applies to all. We have deployed our application on AWS cloud virtual platform and the data is stored on it. Only approved users will have an access and We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it's linked with the SSO/Active Directory. We have deployed our application on AWS cloud virtual platform. AWS provides physical security to the data center and it's a part of our subscription. AWS physical security - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/) Yes. We have deployed our application on AWS cloud virtual platform for maximum security. Yes. Its deployed on AWS cloud virtual platform. The application is deployed on AWS cloud virtual platform. We maintain the register for hardwares, softwares, physical assets etc as per the Asset management policy. All the inventories are reviewed and updated on monthly basis. We have tagged the owners for all the assets alloted by the organization. Atatched the asset management policy. Our application is deployed on AWS cloud virtual platform. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it's linked with the SSO/Active Directory. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. We use AWS Platform for storing the data. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records. Yes We have deployed our application on AWS Cloud platform.As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. Yes. We comply with this. We monitor the user activities and spread awareness about data storage, access, sharing etc. All the custoer data is stored on AWS cloud. We are not storing any information on the computers. Data backups are done daily and in a secured way in AWS Yes. We have implemented the Backup Recovery Procedure Yes. Data backups are done daily and in a secured way in AWS We do not use the backup. We only take the backup on AWS and its stored on AWS platform itself. Its hosted on AWS BCP and DR facilities has been provided by AWS. We do not have any other data centers Since we are hosting our application on AWS, they are providing us a service for backup, BCP and DR for seamless customer experience. Since we are hosting our application on AWS, they are providing us a service for backup, BCP and DR for seamless customer experience. Amazon web service (AWS) AWS Virtual platform cloud And AWS MSK 99.00% Yes. Xoxoday or AWS does not share the data. We have deployed the application on AWS and we have the controls in place to destruction upon request or post the retention timeframe. Since we are GDPR compliant we provide this option to our end users. We have deployed the application on AWS Singpore. Data backup and retrieval happens on AWS platform. We use Public cloud for hosting we have an intrusion detection/monitoring application that alerts on unauthorized access. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. We have deployed the application on cloud and have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. Its provided by AWS, it's a part of AWS service. Please click here for more details about AWS Compliance Programs - [https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/) It will be hosted on AWS singapore Data backups are done daily and in a secured way in AWS. The customer data cannot be lost permanently. We also have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working. Data backups are done daily and in a secured way in AWS. The customer data cannot be lost permanently. We also have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working. Data backups are done on daily basis and in a secured way in AWS. We monitor the same. We collect, store and process Name, email ID and Phone numbers and it will be stored on AWS cloud and will be deleted upon termination of the contract. AWS Singapore [Xoxoday application is a SaaS product deployed on AWS Virtual platform cloud. Please click to know more about application - https://xoxoday.gitbook.io/application/](https://xoxoday.gitbook.io/plum/) We have deployed our application on AWS virtual platform cloud and do not store any data outside cloud for security reasons. All the customer data is encrypted for maximum security. We use TLS1.3 encryption while data in transit and AES256 while data at rest Yes. We have the backup for power supply and computer systems can be used without any interruption. We have applied the lightning protection metallic rods for the buidling for protection of premises. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long term cloud storage. All the workstations are part of the Active directory. User accounts get locked after 15 minutes of inactivity. The accounts will get locked after the predetermined unauthorised attempts for security reasons. Yes, our web assets, email records, and end-points are sealed with data loss prevention techniques. All the customer data will be stored on only AWS virtual platform cloud. We do not store it offline for security reasons. AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. The data is stored in our secure database and is transit scrambled for maximum security. We use TLS1.3 encryption while data in transit and AES256 while data at rest Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long term cloud storage. logs are automatically audited, but are not integrated with tenant's security operations. In case the tenant requests for logs, they can share when asked by the clients. Attached the Infrastructure Change Control Procedure We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. The logs are automatically audited, but are not integrated with tenant's security ops. In case the tenant requests for logs, they can shared when asked for by the clients. The logs are automatically audited, but are not integrated with tenant's security ops. In case the tenant requests for logs, they can shared when asked for by the clients. The logs are automatically audited, but are not integrated with tenant's security ops. In case the tenant requests for logs, they can shared when asked for by the clients. We retain the logs for at least 180 days. AWS is one of the critical third party for us as we have deployed our application on AWS VPC. AWS is ISO 27001 and SOC 2 certified organization and compliant with the business continnuity requirements. Xoxoday application application has deployed on AWS Cloud virtual platform for securtity reasons and imlemented the business continuity plan. Xoxoday endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week. Business day will be considered as 24\*7 and will be available for 365 days in a year for the customer support services to be provided to the Client The data will be stored on AWS Virtual platform cloud – Singapore region. The personal data will be uploaded on application application for rewards and recognition purposes and will be stored on AWS virtual platform cloud. We have deployed our application on AWS Virtual platform cloud. We do not have physical access to the location where the personal data is stored. We have deployed our application on AWS Virtual platform cloud. We have the physical access controls in place. For ex – Access cards, Biometric machines, ID cards, CCTV etc.. The personal information will be collected through application platform and stored on AWS virtual platform cloud – Singapore region. We have only one data center and deployed our application of AWS virtual platform cloud. By Default, Xoxoday will not have access to Service Data (customer's account/application and the associated data processed as part of using our services). The access control to the accounts (who can access the application instance) is managed by the admin from the customer end. We use Public cloud for hosting (AWS Singapore) AWS Virtual Platform Cloud - Singapore region. We have deployed our application on AWS Virtual platform cloud and Xoxoday is GDPR certified. We have implemented the policies and procedures as per the ISMS and GDPR and implemented across the organization. We collect only three PIIs on our platform such as - Name, email ID and phone number. Xoxodau GDPR - [https://www.xoxoday.com/gdpr](https://www.xoxoday.com/gdpr) Xoxoday Privacy - [https://www.xoxoday.com/privacy-policy](https://www.xoxoday.com/privacy-policy) Yes. We have deployed our product on AWS virtual platform cloud. The data backups are done on AWS Virtual platform cloud on regular basis and implemeted the Data loss prevention techniques. We have all the capabilities to recover the data or restore. Data is available for restore within a few minutes of a backup job completing on the daily schedule. Attached the Backup Recovery Procedure AWS is responsible for providing physical security to the data center as we have deployed our application on AWS. AWS provides physical data center access only to approved employees. All employees who need data center access must first apply for access and provide a valid business justification. These requests are granted based on the principle of least privilege, where requests must specify to which layer of the data center the individual needs access, and are time-bound. Requests are reviewed and approved by authorized personnel, and access is revoked after the requested time expires. Once granted admittance, individuals are restricted to areas specified in their permissions. Third-party access is requested by approved AWS employees, who must apply for third-party access and provide a valid business justification. These requests are granted based on the principle of least privilege, where requests must specify to which layer of the data center the individual needs access, and are time-bound. These requests are approved by authorized personnel, and access is revoked after request time expires. Once granted admittance, individuals are restricted to areas specified in their permissions. Anyone granted visitor badge access must present identification when arriving on site and are signed in and escorted by authorized staff. We have deployed our application on AWS Virtual platform cloud. Our solution is using state of the art Cloud Native infrastructure technologies along with microservices architecture allows us to scale our operations as per the demands. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. We make these logs available upon tenents request. We make these logs available upon tenents request The logs are collected using the AWS Audit Trail and application related logs are collected in our Elastic Search server. AWS Cloud virtual platform. Its on AWS cloud virtual platform. We have deployed our product on AWS Cloud virtual platform. We do not connect to the customer network. Since it's a SaaS prodcut and deployed on cloud virtual platform only authorised individual have an access to the our production environment on need and approval basis. We have implemented the security measures to manage the risks introduced during the use of Organization's information assets used for managing Personally Identifiable Information. Attached the Personally Identifiable Information (PII) Policy. We have deployed our application on AWS cloud virtual platform. AWS provides physical security to the data center and it's a part of our subscription. AWS physical security - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/) We have deployed our application on AWS cloud virtual platform. AWS provides physical security to the data center and it's a part of our subscription. AWS physical security - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/) We have deployed our application on AWS Virtual platform cloud. We use Web application firewall, IDs/IDs, AWS Audit trail, Amazon guard duty etc.. Yes. Data backups are done on daily basis in a secured way in AWS Yes. Yes. Its on AWS Cloud virtual platform Cloud. Yes The data will be stored on AWS cloud virtual platform Singapore. Since we are a multi tenant system, we have common infrastructure for all clients.But All data volume is encrypted with AES 256-bit encryption to prevent any external snooping or unauthorized access in the multi-tenant environment. We do not use any in-house devoloped applications. We have deployed our application on AWS cloud virtual platform. And AWS is SOC 2, ISO 27001, ISO 27017 and ISO 27701 certified organization. Shared the certificates. We do not use any in-house devoloped applications. We have deployed our application on AWS cloud virtual platform. And AWS is SOC 2, ISO 27001, ISO 27017 and ISO 27701 certified organization. Shared the certificates. We have deployed our application on AWS cloud virtual platform. We have deployed our application on AWS cloud virtual platform. Data storage location will be AWS Singapore. Data backups are done on daily and in a secured way in AWS. Attached the Backup Recovery Procedure. We have deployed our application on AWS Virtual platform cloud - Singapore and we operate from our corporate office located in Bangalore, India. We have deployed our application on AWS Virtual platform cloud - Singapore region and all the data will be stored there. All the end users from various parts in the world can access the platform. We inform the customer if we need to change the data center location. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. The Cloudflare Web Application Firewall (Cloudflare WAF) checks incoming web requests and filters undesired traffic based on the set of rules. pfSense generation firewall helps to monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on a defined set of security rules We also have implemented the IDS/IPS and Amazon guard duty which continuously monitors our AWS accounts and workloads for malicious activity and delivers detailed security findings for visibility and remediation. We have implemented the data backup policy and attached the same. The data backups are done daily in a secured way in AWS and tested on weekly basis.These backup process are automated and does not require any mannual effort. Since we are SAAS product, we maintain backup and restore all the customer data by ourselves. We use AES 256 encryption for data at rest. All the backups are stored on Cloud and does not store any data off-cloud. NA. We have deployed our application on AWS Virtual platform cloud. We have deployed our application on AWS Virtual Platform cloud. application is a cloud based application. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently. We have tools that analyze various traffic patterns and correlate network events. We have configured early warning signals that trigger alerts to our team based on event patterns and strict thresholds. We are equipped to detect and mitigate Threats, DDOS attacks, session hijack, login spoofs or any other data extraction strategies AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. The data is stored in our secure database and is transit scrambled for maximum security. We use TLS1.3 encryption while data in transit and AES256 while data at rest. We also conduct periodical Vulnerability assessment and penetration testing and fixes the vulnerabilities identified in order to eliminate the risk. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. We use a synchronized time-service protocol (e.g., NTP) to ensure all systems have a common time reference Yes, systems must be configured to log all successful and unsuccessful login attempts by accounts with privileged access. These authentication logs must be retained for a minimum of 180 days and in accordance with the Company's records retention guidelines. We use logical data isolation with the help of company specific encryption keys and its solated from other customers data. Yes, audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. The data backups are done daily in a secured way on AWS and tested on a weekly basis. These backup processes are automated and do not require any manual effort. Since the data backup is automated and happening on a daily basis the data backup will get replaced every day and restored, if necessary/required. Yes, AWS is certified under the EU-US Privacy Shield. [https://www.privacyshield.gov/participant?id=a2zt0000000TOWQAA4](https://www.privacyshield.gov/participant?id=a2zt0000000TOWQAA4) All the data will be stored on AWS cloud virtual platform cloud - Singapore region. All user activities are logged in the audit trail. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks We use Web application firewall, IDs/Ips, AWS Audit trail, Amazon guard duty etc.. We have a dedicated non-production environment which is in a different AWS account and allows us to segregate data from the production environment. We have implemented the Backup Recovery Procedure to protect the organization information asset from the damages that may be caused due to failure of hardware system, corruption of software etc.. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long term cloud storage. The event logs are stored in a bucket wherein nobody can access them without an approval from the high authorities i.e. the Chief Technical Officer. In case the tenant requests for logs, that can be shared. At present, application application has been deployed on AWS Virtual platform cloud. [This is not feasible. AWS is compliant to the Singapore Data Privacy Regulations. https://aws.amazon.com/compliance/singapore-data-privacy/](https://aws.amazon.com/compliance/singapore-data-privacy/) All the data will be stored on AWS Singapore All the data will be collected only through our application and stored on AWS cloud platform and its situated in Singapore. All the data will be stored on AWS Singapore We are cloud security alliance level 1 compliant. We would be happy to help NSE for checking the integrity and security of the cloud computing services and compliance to applicable policies and regulations. We agreee. We comply with CSA STAR Level 1 compliance requirements. We comply with this. We have deployed our application on AWS to ensure maximum security of data. We agree. We combine enterprise-class security features with comprehensive audits of our applications, systems, and networks to ensure customer and business data is always protected. And our customers rest easy knowing their information is safe, their interactions are secure, and their businesses are protected. We do conduct internal and external audits and ensure that required remidiations are implemented. The data is hosted on Amazon Web Services (AWS) For accurate latency, the data center is selected as Singapore region for Asia specific data and Oregon for US specific data which are defined as data centers. The Xoxoday platform operates on the cloud, which means there are no removable storage devices in question. We have Media protection procedure to handle the locally stored data. We complied with the compliance requirements. We do not take any data directly. The data will be provided through our platform or application and its hosted on Amazon Web Services (AWS) We rely on AWS Cloud for Uptime mesurement. Yes. We have deployed our application on AWS cloud platform Yes. Please visit here for more details about AWS Cloud Security - [https://aws.amazon.com/security/](https://aws.amazon.com/security/) As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails We have implemented IDS/IPS Firewall. Our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting. We predominantly work on cloud-based infrastructure from Amazon Web Services which provide backup and restore services to build scalable, durable, and secure data-protection solutions Please refer to AWS site for more details: [https://aws.amazon.com/backup-restore/](https://aws.amazon.com/backup-restore/) It will be stored on AWS, and It will be encrypted (AES 256-bit encryption) Yes. We have implemented IDS/IPS Firewall. Our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting. The only user data that will stored within the system is employee personal information - names, emails and contact numbers. Infrastructure logs are collected using AWS Audit Trail Please visit for more details - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/) Our application is deployed on AWS cloud platform. We are Compliant. We have implemented the data backup policy. We do take backup of the all the users and securely stored. All our application users data back up including password will happen through AWS cloud virtual platform. We have controls in place. We have implemented the firewall and IDS/IPS for detection and prevention of security. During the testing phase we make sure that we are meeting all the security requesrements and validate the same before the deployment. All the data will be stored on AWS cloud and encrypted with Client specific keys. We do not transfer data to any external drives or media devices. We monitor these logs periodically Backup data is stored on AWS cloud for maximum security. We test the backup on a periodical basis to make sure that we follow the availability and integrity principles. We have documented our Data backup procedures. We monitor the logs as per the compliance requirements. We are compliant. All the logs are recorded in the system. We always make sure that componentory controls in place if monitoring is not feasible. We have deployed our application on AWS cluod virtual platform It's a part of cloud security services It's a part of cloud security services Data backups are done daily and in a secured way in AWS. The customer data cannot be lost permanently. We also have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working. The data is only stored on our application and its deployed on AWS Cloud. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records We have deployed our application on Amaon web services (AWS) cloud platform. We are using MySQL, Salt stack, Nodejs and MongoDB technology. LDAP, SAML2, Normal username-password We are a SAAS solution. We are cloud hosted. We are a SAAS Solution and have all the capabilities to supoprt huge number of users. Data center services are provided by AWS Data backups are done daily and in a secured way in AWS No. Application is deployed on AWS Cloud. We have both horizontal and Vertical Scaling We have auto scaling and self healing. We use a variety of tools and plugins integrated with Prometheus & Cloudwatch along with health checks for facilitating our uptime/service availability AWS Cloud virtual platform We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails Yes. We have deployed our application on AWS virtual platform cloud. And we have the process in place to handle or manage any contingent events or circumstances. We have implemented the Business continuity management and tested annually to validate the effectiveness of the controls. Attached the Business continuity management plan. We have an Admin/Facility department who is responsible and manage the Physical security and we have provided the access cards to all the employees and visitors and installed biometric machines at all the entry and exit areas. We have also installed the CCTV cameras in our building and will be monitored 24\*7 for maximum security. AWS Data centre physical security – We have deployed our application product on AWS virtual platform cloud. Physical access is strictly controlled both at the perimeter and at building ingress points by professional security staff utilizing video surveillance, intrusion detection systems, and other electronic means. Authorized staff must pass two-factor authentication a minimum of two times to access data center floors. All visitors and contractors are required to present identification and are signed in and continually escorted by authorized staff. AWS only provides data center access and information to employees and contractors who have a legitimate business need for such privileges. When an employee no longer has a business need for these privileges, access is immediately revoked, even if they continue to be an employee of Amazon or Amazon Web Services. All physical access to data centers by AWS employees is logged and audited routinely. PII will be entered through application and stored it on AWS cloud virtual platform. We store Name, email ID and phone number of the users. Reports can be generated by the admins through the application. If there are any additional support needed, our customer support team would be able to help and guide on generating report. The data will be stored on AWS Cloud and we do not share or transfer the data Xoxoday is CSA STAR LEVEL 1 Compliant. Please click here to download CAIQ - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday/services/nreach-online-services-pvt-ltd-xoxoday/](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday/services/nreach-online-services-pvt-ltd-xoxoday/) We have deployed our application on AWS Virtual platform cloud – Singapore region. Not Applicable. We have not outsourced. We have deployed our application on AWS Cloud virtual platform for maximum security. The data center is hosted completely in isolation so that the access is limited and controlled. Load balancer allows shifting incremental load and can auto scale based on data load experienced by application. We have implemented Amazon Cloud watch to enable monitoring of the functioning of the application. The data is encrypted using 256-encryption based SSL certificate. To manage security of data we conduct a quarterly VAPT based security audit of application. Yes, all the mechanisms related to security are implemented to facilitate timely decision and investigation by root-cause analysis. These incidences are analyzed with network intrusion detection (IDS) tools. We have implemented the Patch management procedures. Critical patches will be deployed immediately High patches will get deployed within 5 days Medium Patches will get deployed within 15-day Low will get deployed in 25 days. Yes. Since it's a SAAS Product we do not charge any additional cost. We have a team of 15+ who works for improving our solution security. We conduct periodical Vulnerability assessment and Penetration testing with the help of the Authorized third-party vendors and Fix the observations found during the testing in order to mitigate the risk. Our team is based out of Bangalore location. Yes. Our SAAS solution has been deployed on AWS cloud virtual platform. Its SAAS Product and implemented the security controls in order to provide secure services and make sure that the customer data is protected. We have deployed our application on AWS Cloud platform for maximum security. The data will be provided through our platform or application and its hosted-on Amazon Web Services (AWS) Our solution is very easy to use with convenient security features. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team, and it's linked with the SSO/Active Directory We have deployed our application on AWS Cloud virtual platform. AWS is met all the data center compliance requirements. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it's linked with the SSO/Active Directory We have implemented intrusion detection tools, we ensure timely detection and investigation in a prompt manner. File integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation. We also have Endpoint security software for all the computers for Protection from exploits, malicious web downloads and softwares, Application and device control etc. We have deployed the application application on AWS Cloud platform. The data center is in the Singapore region We have deployed our application on AWS cloud virtual platform. but, We have not outsourced any of services and third party will not have access to FINCARE data. Yes. We monitor their compliance, security standards, certifications and Audit Etc. [We have deployed our application on AWS cloud virtual platform. AWS is ISO 27001, ISO 27017, ISO 27701, SOC 2, PCI DSS Level 1 certified organization. Please click here for more information about AWS Audit and certification - https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/) All the data will be provided through the application and it will be stored on AWS cloud virtual platform. We use Cloudflare web application firewall for maximum security. We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. Attached the application data flow diagram We have the security controls in place. We have installed the firewalls to monitor and control the incoming and outgoing network traffic based on predetermined security rules. It helps us to establishes a barrier between a trusted network and an untrusted network. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it's linked with the SSO/Active Directory. Attached the Network Access Control and Security Procedure. Yes. we have installed Bitdefender end point security in all the devices for maximum security and have controls on Anti-Virus / Malicious Software throgh End point security. We have also enabled Network Threat Prevention, Advanced Threat Defense, Web Attack Prevention, Multi-Layer Ransomware Protection. Attached the sample screenshot of Bitdefender end point security. The application is deployed on AWS Virtual platform cloud - Singapore region. application application is deployed on AWS virtual platform cloud and storgae and scaling up would not be a challenge. Data backups are automated and done daily and in a secured way on AWS. The data at rest in encrypted only authorised individuals (CT0/Production head) will have access to protect the confidentiality, integrity, and availability of the information. These data backups are reviewed on weekly basis and has been validated during the internal and external audits. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed. Yes, audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed. We have deployed our applicaiton on AWS Virtual platform cloud. We do not use any unauthorised applications accross the organization as per the Information security policy. At Xoxoday the test environment and production environment has been seperated. We have dedicated non-production environment which is in different AWS account and allowing us to segregate data of production environment. we use Cloudflare Web application firewall (WAF), AWS Guard Duty threat detection service, Amazon CloudWatch, IDS/IPS etc.. for maximum security of data. Compliant. We do not allow un-trusted and un-validated inputs and attacker cannot insert malicious data and false entries into the logs. We do not share the source code. Our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase. At Xoxday the source code is restricted to only the authorised individuals Yes. Our solution is using state of the art Cloud Native infrastructure technologies along with microservices architecture allows us to scale our operations as per the demands. We have deployed our application on AWS Cloud virtual platform and all the data is stored on AWS. All the confidential/PI data are encrypted at rest and in transit with a split key mechanism to ensure that every client's key is unique. We use TLS1.3 encryption while data in transit and AES256 while data at rest. we use Amazon Web Services (AWS) as our Communication service provider. We review the adequate security governance periodicall to make sure that they are also complied with all the Security and Privacy compliance requirements. We are the Data processor. application is GDPR compliant. At Xoxoday, we ensure that the data is gathered, stored, and handled with respect to individual rights. The audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. At Xoxoday Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. The backup is automated and happen on AWS on regular basis. We have deployed our application on AWS Virtual platform cloud - Singapore region. The application and database server are hardened. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. We have deployed our application on AWS Virtual platform cloud - Singapore region. All the application data is stored there on AWS - Singapore. We use third party to provide necessary services to the organization on need and approval basis. For ex – Background verification vendor, VA/PT authorised third party vendor, Eternal Auditors, AWS Virtual platform cloud service providers, Google workspace etc We predominantly work on cloud-based infrastructure - Amazon Web Services which provides the Backup and Restore services to build scalable, durable, and secure data-protection solutions. No limits. Data backups are done daily and in a secured way in AWS. And Our team review the same on regular basis. Data backups are done on daily basis and in a secured way in AWS. We have the mechanism in place to delete the data upon termination of the contract upon customer request. In addition to safeguarding the rights of data subjects under the GDPR, we have implemented the Data Retention and Disposal Policy ensuring that excessive amounts of data are not retained by us. We have deployed our application on AWS Virtual platform cloud and they provide these services. We have deployed our application on AWS Virtual platform cloud - Singapore and USA region. Data Security Architecture designed using an industry standard and best practices. We are adhered to CSA, ISO 27001, SOC 2 TSP. We have deployed our application on AWS Virtual platform cloud - Singapore region. The cloud infrastructure providers have high levels of physical and network security and hosting provider vendor diversity. All our customer data is stored on AWS Virtual platform cloud. And we collect the data only throguh our application platform. We do not store any customers data locally. File integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation. AWS CloudTrail helps to detect changes to the build/configuration of the virtual machine Our solution is using state of the art Cloud Native infrastructure technologies along with microservices architecture allows us to scale our operations as per the demands. We use Web application firewall (WAF) and pfSense firewall for security reasons. 1. The Cloudflare Web Application Firewall (Cloudflare WAF) checks incoming web requests and filters undesired traffic based on the set of rules. 2. pfSense helps to monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on a defined set of security rules We isolate our machines, network and storage with respect to the AWS Standards in order to keep it safe and secure. We use Web application firewall (WAF) and pfSense firewall for security reasons. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently. Yes. We monitor the compliance programs of AWS As we have stored the data on their cloud. No. Currently, all the data is stored on AWS VPC - Singapore region. Yes, we inform the customer on the data storage location. We are CSA STAR Level 1 compliant. Please click here to know more - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday) We use OWASP Software Assurance Maturity Model Since we have deployed our application on AWS Cloud its not applicable for us. Since we have deployed our application on AWS Cloud its not applicable for us. We provide certifite of destruction of data once the data is purged/deleted from all the places upon request from the customer. We have deployed our product on AWS Cloud virtual platform. AWS provides physical security to the data center as a part of our subscription. AWS physical security - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/) We have implemented IDS/IPS to facilitate timely detection, investigation by root cause analysis and response to incidents Data backups are done on daily basis and in a secured way on AWS Data backups are done on daily basis and in a secured way on AWS - Singapore Data backups are done on daily basis and in a secured way on AWS. This has been tested on regular basis. Applies to all. We have deployed our application on AWS cloud virtual platform and the data is stored on it. Only approved users will have an access and We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it's linked with the SSO/Active Directory. We have deployed our application on AWS cloud virtual platform. AWS provides physical security to the data center and it's a part of our subscription. AWS physical security - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/) Yes. We have deployed our application on AWS cloud virtual platform for maximum security. Yes. Its deployed on AWS cloud virtual platform. The application is deployed on AWS cloud virtual platform. We maintain the register for hardwares, softwares, physical assets etc as per the Asset management policy. All the inventories are reviewed and updated on monthly basis. We have tagged the owners for all the assets alloted by the organization. Atatched the asset management policy. Our application is deployed on AWS cloud virtual platform. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it's linked with the SSO/Active Directory. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. We use AWS Platform for storing the data. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records. Yes We have deployed our application on AWS Cloud platform.As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. Yes. We comply with this. We monitor the user activities and spread awareness about data storage, access, sharing etc. All the custoer data is stored on AWS cloud. We are not storing any information on the computers. Data backups are done daily and in a secured way in AWS Yes. We have implemented the Backup Recovery Procedure Yes. Data backups are done daily and in a secured way in AWS We do not use the backup. We only take the backup on AWS and its stored on AWS platform itself. Its hosted on AWS BCP and DR facilities has been provided by AWS. We do not have any other data centers Since we are hosting our application on AWS, they are providing us a service for backup, BCP and DR for seamless customer experience. Since we are hosting our application on AWS, they are providing us a service for backup, BCP and DR for seamless customer experience. Amazon web service (AWS) AWS Virtual platform cloud And AWS MSK 99.00% Yes. Xoxoday or AWS does not share the data. We have deployed the application on AWS and we have the controls in place to destruction upon request or post the retention timeframe. Since we are GDPR compliant we provide this option to our end users. We have deployed the application on AWS Singpore. Data backup and retrieval happens on AWS platform. We use Public cloud for hosting we have an intrusion detection/monitoring application that alerts on unauthorized access. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. We have deployed the application on cloud and have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. Its provided by AWS, it's a part of AWS service. Please click here for more details about AWS Compliance Programs - [https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/) It will be hosted on AWS singapore Data backups are done daily and in a secured way in AWS. The customer data cannot be lost permanently. We also have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working. Data backups are done daily and in a secured way in AWS. The customer data cannot be lost permanently. We also have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working. Data backups are done on daily basis and in a secured way in AWS. We monitor the same. We collect, store and process Name, email ID and Phone numbers and it will be stored on AWS cloud and will be deleted upon termination of the contract. AWS Singapore [Xoxoday application is a SaaS product deployed on AWS Virtual platform cloud. Please click to know more about application - https://xoxoday.gitbook.io/application/](https://xoxoday.gitbook.io/plum/) We have deployed our application on AWS virtual platform cloud and do not store any data outside cloud for security reasons. All the customer data is encrypted for maximum security. We use TLS1.3 encryption while data in transit and AES256 while data at rest Yes. We have the backup for power supply and computer systems can be used without any interruption. We have applied the lightning protection metallic rods for the buidling for protection of premises. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long term cloud storage. All the workstations are part of the Active directory. User accounts get locked after 15 minutes of inactivity. The accounts will get locked after the predetermined unauthorised attempts for security reasons. Yes, our web assets, email records, and end-points are sealed with data loss prevention techniques. All the customer data will be stored on only AWS virtual platform cloud. We do not store it offline for security reasons. AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. The data is stored in our secure database and is transit scrambled for maximum security. We use TLS1.3 encryption while data in transit and AES256 while data at rest Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long term cloud storage. logs are automatically audited, but are not integrated with tenant's security operations. In case the tenant requests for logs, they can share when asked by the clients. Attached the Infrastructure Change Control Procedure We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. The logs are automatically audited, but are not integrated with tenant's security ops. In case the tenant requests for logs, they can shared when asked for by the clients. The logs are automatically audited, but are not integrated with tenant's security ops. In case the tenant requests for logs, they can shared when asked for by the clients. The logs are automatically audited, but are not integrated with tenant's security ops. In case the tenant requests for logs, they can shared when asked for by the clients. We retain the logs for at least 180 days. AWS is one of the critical third party for us as we have deployed our application on AWS VPC. AWS is ISO 27001 and SOC 2 certified organization and compliant with the business continnuity requirements. Xoxoday application application has deployed on AWS Cloud virtual platform for securtity reasons and imlemented the business continuity plan. Xoxoday endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week. Business day will be considered as 24\*7 and will be available for 365 days in a year for the customer support services to be provided to the Client The data will be stored on AWS Virtual platform cloud – Singapore region. The personal data will be uploaded on application application for rewards and recognition purposes and will be stored on AWS virtual platform cloud. We have deployed our application on AWS Virtual platform cloud. We do not have physical access to the location where the personal data is stored. We have deployed our application on AWS Virtual platform cloud. We have the physical access controls in place. For ex – Access cards, Biometric machines, ID cards, CCTV etc.. The personal information will be collected through application platform and stored on AWS virtual platform cloud – Singapore region. We have only one data center and deployed our application of AWS virtual platform cloud. By Default, Xoxoday will not have access to Service Data (customer's account/application and the associated data processed as part of using our services). The access control to the accounts (who can access the application instance) is managed by the admin from the customer end. We use Public cloud for hosting (AWS Singapore) AWS Virtual Platform Cloud - Singapore region. We have deployed our application on AWS Virtual platform cloud and Xoxoday is GDPR certified. We have implemented the policies and procedures as per the ISMS and GDPR and implemented across the organization. We collect only three PIIs on our platform such as - Name, email ID and phone number. Xoxodau GDPR - [https://www.xoxoday.com/gdpr](https://www.xoxoday.com/gdpr) Xoxoday Privacy - [https://www.xoxoday.com/privacy-policy](https://www.xoxoday.com/privacy-policy) Yes. We have deployed our product on AWS virtual platform cloud. The data backups are done on AWS Virtual platform cloud on regular basis and implemeted the Data loss prevention techniques. We have all the capabilities to recover the data or restore. Data is available for restore within a few minutes of a backup job completing on the daily schedule. Attached the Backup Recovery Procedure AWS is responsible for providing physical security to the data center as we have deployed our application on AWS. AWS provides physical data center access only to approved employees. All employees who need data center access must first apply for access and provide a valid business justification. These requests are granted based on the principle of least privilege, where requests must specify to which layer of the data center the individual needs access, and are time-bound. Requests are reviewed and approved by authorized personnel, and access is revoked after the requested time expires. Once granted admittance, individuals are restricted to areas specified in their permissions. Third-party access is requested by approved AWS employees, who must apply for third-party access and provide a valid business justification. These requests are granted based on the principle of least privilege, where requests must specify to which layer of the data center the individual needs access, and are time-bound. These requests are approved by authorized personnel, and access is revoked after request time expires. Once granted admittance, individuals are restricted to areas specified in their permissions. Anyone granted visitor badge access must present identification when arriving on site and are signed in and escorted by authorized staff. We have deployed our application on AWS Virtual platform cloud. Our solution is using state of the art Cloud Native infrastructure technologies along with microservices architecture allows us to scale our operations as per the demands. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. We make these logs available upon tenents request. We make these logs available upon tenents request The logs are collected using the AWS Audit Trail and application related logs are collected in our Elastic Search server. AWS Cloud virtual platform. Its on AWS cloud virtual platform. We have deployed our product on AWS Cloud virtual platform. We do not connect to the customer network. Since it's a SaaS prodcut and deployed on cloud virtual platform only authorised individual have an access to the our production environment on need and approval basis. We have implemented the security measures to manage the risks introduced during the use of Organization's information assets used for managing Personally Identifiable Information. Attached the Personally Identifiable Information (PII) Policy. We have deployed our application on AWS cloud virtual platform. AWS provides physical security to the data center and it's a part of our subscription. AWS physical security - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/) We have deployed our application on AWS cloud virtual platform. AWS provides physical security to the data center and it's a part of our subscription. AWS physical security - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/) We have deployed our application on AWS Virtual platform cloud. We use Web application firewall, IDs/IDs, AWS Audit trail, Amazon guard duty etc.. Yes. Data backups are done on daily basis in a secured way in AWS Yes. Yes. Its on AWS Cloud virtual platform Cloud. Yes The data will be stored on AWS cloud virtual platform Singapore. Since we are a multi tenant system, we have common infrastructure for all clients.But All data volume is encrypted with AES 256-bit encryption to prevent any external snooping or unauthorized access in the multi-tenant environment. We do not use any in-house devoloped applications. We have deployed our application on AWS cloud virtual platform. And AWS is SOC 2, ISO 27001, ISO 27017 and ISO 27701 certified organization. Shared the certificates. We do not use any in-house devoloped applications. We have deployed our application on AWS cloud virtual platform. And AWS is SOC 2, ISO 27001, ISO 27017 and ISO 27701 certified organization. Shared the certificates. We have deployed our application on AWS cloud virtual platform. We have deployed our application on AWS cloud virtual platform. Data storage location will be AWS Singapore. Data backups are done on daily and in a secured way in AWS. Attached the Backup Recovery Procedure. We have deployed our application on AWS Virtual platform cloud - Singapore and we operate from our corporate office located in Bangalore, India. We have deployed our application on AWS Virtual platform cloud - Singapore region and all the data will be stored there. All the end users from various parts in the world can access the platform. We inform the customer if we need to change the data center location. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. The Cloudflare Web Application Firewall (Cloudflare WAF) checks incoming web requests and filters undesired traffic based on the set of rules. pfSense generation firewall helps to monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on a defined set of security rules We also have implemented the IDS/IPS and Amazon guard duty which continuously monitors our AWS accounts and workloads for malicious activity and delivers detailed security findings for visibility and remediation. We have implemented the data backup policy and attached the same. The data backups are done daily in a secured way in AWS and tested on weekly basis.These backup process are automated and does not require any mannual effort. Since we are SAAS product, we maintain backup and restore all the customer data by ourselves. We use AES 256 encryption for data at rest. All the backups are stored on Cloud and does not store any data off-cloud. NA. We have deployed our application on AWS Virtual platform cloud. We have deployed our application on AWS Virtual Platform cloud. application is a cloud based application. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently. We have tools that analyze various traffic patterns and correlate network events. We have configured early warning signals that trigger alerts to our team based on event patterns and strict thresholds. We are equipped to detect and mitigate Threats, DDOS attacks, session hijack, login spoofs or any other data extraction strategies AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. The data is stored in our secure database and is transit scrambled for maximum security. We use TLS1.3 encryption while data in transit and AES256 while data at rest. We also conduct periodical Vulnerability assessment and penetration testing and fixes the vulnerabilities identified in order to eliminate the risk. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. We use a synchronized time-service protocol (e.g., NTP) to ensure all systems have a common time reference Yes, systems must be configured to log all successful and unsuccessful login attempts by accounts with privileged access. These authentication logs must be retained for a minimum of 180 days and in accordance with the Company's records retention guidelines. We use logical data isolation with the help of company specific encryption keys and its solated from other customers data. Yes, audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. The data backups are done daily in a secured way on AWS and tested on a weekly basis. These backup processes are automated and do not require any manual effort. Since the data backup is automated and happening on a daily basis the data backup will get replaced every day and restored, if necessary/required. Yes, AWS is certified under the EU-US Privacy Shield. [https://www.privacyshield.gov/participant?id=a2zt0000000TOWQAA4](https://www.privacyshield.gov/participant?id=a2zt0000000TOWQAA4) All the data will be stored on AWS cloud virtual platform cloud - Singapore region. All user activities are logged in the audit trail. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks We use Web application firewall, IDs/Ips, AWS Audit trail, Amazon guard duty etc.. We have a dedicated non-production environment which is in a different AWS account and allows us to segregate data from the production environment. We have implemented the Backup Recovery Procedure to protect the organization information asset from the damages that may be caused due to failure of hardware system, corruption of software etc.. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long term cloud storage. The event logs are stored in a bucket wherein nobody can access them without an approval from the high authorities i.e. the Chief Technical Officer. In case the tenant requests for logs, that can be shared. At present, application application has been deployed on AWS Virtual platform cloud. [This is not feasible. AWS is compliant to the Singapore Data Privacy Regulations. https://aws.amazon.com/compliance/singapore-data-privacy/](https://aws.amazon.com/compliance/singapore-data-privacy/) All the data will be stored on AWS Singapore All the data will be collected only through our application and stored on AWS cloud platform and its situated in Singapore. All the data will be stored on AWS Singapore We are cloud security alliance level 1 compliant. We would be happy to help NSE for checking the integrity and security of the cloud computing services and compliance to applicable policies and regulations. We agreee. We comply with CSA STAR Level 1 compliance requirements. We comply with this. We have deployed our application on AWS to ensure maximum security of data. We agree. We combine enterprise-class security features with comprehensive audits of our applications, systems, and networks to ensure customer and business data is always protected. And our customers rest easy knowing their information is safe, their interactions are secure, and their businesses are protected. We do conduct internal and external audits and ensure that required remidiations are implemented. The data is hosted on Amazon Web Services (AWS) For accurate latency, the data center is selected as Singapore region for Asia specific data and Oregon for US specific data which are defined as data centers. The Xoxoday platform operates on the cloud, which means there are no removable storage devices in question. We have Media protection procedure to handle the locally stored data. We complied with the compliance requirements. We do not take any data directly. The data will be provided through our platform or application and its hosted on Amazon Web Services (AWS) We rely on AWS Cloud for Uptime mesurement. Yes. We have deployed our application on AWS cloud platform Yes. Please visit here for more details about AWS Cloud Security - [https://aws.amazon.com/security/](https://aws.amazon.com/security/) As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails We have implemented IDS/IPS Firewall. Our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting. We predominantly work on cloud-based infrastructure from Amazon Web Services which provide backup and restore services to build scalable, durable, and secure data-protection solutions Please refer to AWS site for more details: [https://aws.amazon.com/backup-restore/](https://aws.amazon.com/backup-restore/) It will be stored on AWS, and It will be encrypted (AES 256-bit encryption) Yes. We have implemented IDS/IPS Firewall. Our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting. The only user data that will stored within the system is employee personal information - names, emails and contact numbers. Infrastructure logs are collected using AWS Audit Trail Please visit for more details - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/) Our application is deployed on AWS cloud platform. We are Compliant. We have implemented the data backup policy. We do take backup of the all the users and securely stored. All our application users data back up including password will happen through AWS cloud virtual platform. We have controls in place. We have implemented the firewall and IDS/IPS for detection and prevention of security. During the testing phase we make sure that we are meeting all the security requesrements and validate the same before the deployment. All the data will be stored on AWS cloud and encrypted with Client specific keys. We do not transfer data to any external drives or media devices. We monitor these logs periodically Backup data is stored on AWS cloud for maximum security. We test the backup on a periodical basis to make sure that we follow the availability and integrity principles. We have documented our Data backup procedures. We monitor the logs as per the compliance requirements. We are compliant. All the logs are recorded in the system. We always make sure that componentory controls in place if monitoring is not feasible. We have deployed our application on AWS cluod virtual platform It's a part of cloud security services It's a part of cloud security services Data backups are done daily and in a secured way in AWS. The customer data cannot be lost permanently. We also have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working. The data is only stored on our application and its deployed on AWS Cloud. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records We have deployed our application on Amaon web services (AWS) cloud platform. We are using MySQL, Salt stack, Nodejs and MongoDB technology. LDAP, SAML2, Normal username-password We are a SAAS solution. We are cloud hosted. We are a SAAS Solution and have all the capabilities to supoprt huge number of users. Data center services are provided by AWS Data backups are done daily and in a secured way in AWS No. Application is deployed on AWS Cloud. We have both horizontal and Vertical Scaling We have auto scaling and self healing. We use a variety of tools and plugins integrated with Prometheus & Cloudwatch along with health checks for facilitating our uptime/service availability AWS Cloud virtual platform We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails Yes. We have deployed our application on AWS virtual platform cloud. And we have the process in place to handle or manage any contingent events or circumstances. We have implemented the Business continuity management and tested annually to validate the effectiveness of the controls. Attached the Business continuity management plan. We have an Admin/Facility department who is responsible and manage the Physical security and we have provided the access cards to all the employees and visitors and installed biometric machines at all the entry and exit areas. We have also installed the CCTV cameras in our building and will be monitored 24\*7 for maximum security. AWS Data centre physical security – We have deployed our application product on AWS virtual platform cloud. Physical access is strictly controlled both at the perimeter and at building ingress points by professional security staff utilizing video surveillance, intrusion detection systems, and other electronic means. Authorized staff must pass two-factor authentication a minimum of two times to access data center floors. All visitors and contractors are required to present identification and are signed in and continually escorted by authorized staff. AWS only provides data center access and information to employees and contractors who have a legitimate business need for such privileges. When an employee no longer has a business need for these privileges, access is immediately revoked, even if they continue to be an employee of Amazon or Amazon Web Services. All physical access to data centers by AWS employees is logged and audited routinely. PII will be entered through application and stored it on AWS cloud virtual platform. We store Name, email ID and phone number of the users. Reports can be generated by the admins through the application. If there are any additional support needed, our customer support team would be able to help and guide on generating report. The data will be stored on AWS Cloud and we do not share or transfer the data Xoxoday is CSA STAR LEVEL 1 Compliant. Please click here to download CAIQ - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday/services/nreach-online-services-pvt-ltd-xoxoday/](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday/services/nreach-online-services-pvt-ltd-xoxoday/) We have deployed our application on AWS Virtual platform cloud – Singapore region. Not Applicable. We have not outsourced. We have deployed our application on AWS Cloud virtual platform for maximum security. The data center is hosted completely in isolation so that the access is limited and controlled. Load balancer allows shifting incremental load and can auto scale based on data load experienced by application. We have implemented Amazon Cloud watch to enable monitoring of the functioning of the application. The data is encrypted using 256-encryption based SSL certificate. To manage security of data we conduct a quarterly VAPT based security audit of application. Yes, all the mechanisms related to security are implemented to facilitate timely decision and investigation by root-cause analysis. These incidences are analyzed with network intrusion detection (IDS) tools. We have implemented the Patch management procedures. Critical patches will be deployed immediately High patches will get deployed within 5 days Medium Patches will get deployed within 15-day Low will get deployed in 25 days. Yes. Since it's a SAAS Product we do not charge any additional cost. We have a team of 15+ who works for improving our solution security. We conduct periodical Vulnerability assessment and Penetration testing with the help of the Authorized third-party vendors and Fix the observations found during the testing in order to mitigate the risk. Our team is based out of Bangalore location. Yes. Our SAAS solution has been deployed on AWS cloud virtual platform. Its SAAS Product and implemented the security controls in order to provide secure services and make sure that the customer data is protected. We have deployed our application on AWS Cloud platform for maximum security. The data will be provided through our platform or application and its hosted-on Amazon Web Services (AWS) Our solution is very easy to use with convenient security features. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team, and it's linked with the SSO/Active Directory We have deployed our application on AWS Cloud virtual platform. AWS is met all the data center compliance requirements. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it's linked with the SSO/Active Directory We have implemented intrusion detection tools, we ensure timely detection and investigation in a prompt manner. File integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation. We also have Endpoint security software for all the computers for Protection from exploits, malicious web downloads and softwares, Application and device control etc. We have deployed the application application on AWS Cloud platform. The data center is in the Singapore region We have deployed our application on AWS cloud virtual platform. but, We have not outsourced any of services and third party will not have access to FINCARE data. Yes. We monitor their compliance, security standards, certifications and Audit Etc. [We have deployed our application on AWS cloud virtual platform. AWS is ISO 27001, ISO 27017, ISO 27701, SOC 2, PCI DSS Level 1 certified organization. Please click here for more information about AWS Audit and certification - https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/) All the data will be provided through the application and it will be stored on AWS cloud virtual platform. We use Cloudflare web application firewall for maximum security. We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. Attached the application data flow diagram We have the security controls in place. We have installed the firewalls to monitor and control the incoming and outgoing network traffic based on predetermined security rules. It helps us to establishes a barrier between a trusted network and an untrusted network. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it's linked with the SSO/Active Directory. Attached the Network Access Control and Security Procedure. Yes. we have installed Bitdefender end point security in all the devices for maximum security and have controls on Anti-Virus / Malicious Software throgh End point security. We have also enabled Network Threat Prevention, Advanced Threat Defense, Web Attack Prevention, Multi-Layer Ransomware Protection. Attached the sample screenshot of Bitdefender end point security. The application is deployed on AWS Virtual platform cloud - Singapore region. application application is deployed on AWS virtual platform cloud and storgae and scaling up would not be a challenge. Data backups are automated and done daily and in a secured way on AWS. The data at rest in encrypted only authorised individuals (CT0/Production head) will have access to protect the confidentiality, integrity, and availability of the information. These data backups are reviewed on weekly basis and has been validated during the internal and external audits. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed. Yes, audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed. We have deployed our applicaiton on AWS Virtual platform cloud. We do not use any unauthorised applications accross the organization as per the Information security policy. At Xoxoday the test environment and production environment has been seperated. We have dedicated non-production environment which is in different AWS account and allowing us to segregate data of production environment. we use Cloudflare Web application firewall (WAF), AWS Guard Duty threat detection service, Amazon CloudWatch, IDS/IPS etc.. for maximum security of data. Compliant. We do not allow un-trusted and un-validated inputs and attacker cannot insert malicious data and false entries into the logs. We do not share the source code. Our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase. At Xoxday the source code is restricted to only the authorised individuals Yes. Our solution is using state of the art Cloud Native infrastructure technologies along with microservices architecture allows us to scale our operations as per the demands. We have deployed our application on AWS Cloud virtual platform and all the data is stored on AWS. All the confidential/PI data are encrypted at rest and in transit with a split key mechanism to ensure that every client's key is unique. We use TLS1.3 encryption while data in transit and AES256 while data at rest. we use Amazon Web Services (AWS) as our Communication service provider. We review the adequate security governance periodicall to make sure that they are also complied with all the Security and Privacy compliance requirements. We are the Data processor. application is GDPR compliant. At Xoxoday, we ensure that the data is gathered, stored, and handled with respect to individual rights. The audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. At Xoxoday Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. The backup is automated and happen on AWS on regular basis. We have deployed our application on AWS Virtual platform cloud - Singapore region. The application and database server are hardened. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. We have deployed our application on AWS Virtual platform cloud - Singapore region. All the application data is stored there on AWS - Singapore. We use third party to provide necessary services to the organization on need and approval basis. For ex – Background verification vendor, VA/PT authorised third party vendor, Eternal Auditors, AWS Virtual platform cloud service providers, Google workspace etc We predominantly work on cloud-based infrastructure - Amazon Web Services which provides the Backup and Restore services to build scalable, durable, and secure data-protection solutions. No limits. Data backups are done daily and in a secured way in AWS. And Our team review the same on regular basis. Data backups are done on daily basis and in a secured way in AWS. We have the mechanism in place to delete the data upon termination of the contract upon customer request. In addition to safeguarding the rights of data subjects under the GDPR, we have implemented the Data Retention and Disposal Policy ensuring that excessive amounts of data are not retained by us. We have deployed our application on AWS Virtual platform cloud and they provide these services. # Cloud Security Alliance Source: https://help-plum.xoxoday.com/faq/security-compliance/cloud-security-alliance Find answers to frequently asked questions about Plum's Cloud Security Alliance (CSA) compliance and cloud security posture. ## Application & Interface Security Applications and programming interfaces (APIs) shall be designed, developed, deployed, and tested in accordance with leading industry standards (e.g., OWASP for web applications) and adhere to applicable legal, statutory, or regulatory compliance obligations. Yes, we ensure the same as part of our code review, static code analysis and Web Application Firewall. Prior to granting customers access to data, assets, and information systems, identified security, contractual, and regulatory requirements for customer access shall be addressed. Yes, we provide API access only to vendors and systems authorized by the customer. Data input and output integrity routines (i.e., reconciliation and edit checks) shall be implemented for application interfaces and databases to prevent manual or systematic processing errors, corruption of data, or misuse. Yes, we follow multi layer application architecture to isolate database access Policies and procedures shall be established and maintained in support of data security to include (confidentiality, integrity and availability) across multiple system interfaces, jurisdictions and business functions to prevent improper disclosure, alteration, or destruction. Complied with the requirement - We have Information security policy in place and working effectively *** ## Audit Assurance & Compliance Audit plans shall be developed and maintained to address business process disruptions. Auditing plans shall focus on reviewing the effectiveness of the implementation of security operations. All audit activities must be agreed upon prior to executing any audits. Complied with the requirement - We are conducting the Internal and External Audit as per the requirement and focus on the evaluation of the effectiveness security controls Independent reviews and assessments shall be performed at least annually to ensure that the organization addresses nonconformities of established policies, standards, procedures, and compliance obligations. Complied with the requirement - reviews and assessments has been performed annually. Organizations shall create and maintain a control framework which captures standards, regulatory, legal, and statutory requirements relevant for their business needs. The control framework shall be reviewed at least annually to ensure changes that could affect the business processes are reflected. We are complied with the requirement - Information security team is reviewing the requirements at least annually to ensure changes that could affect the business processes are reflected. *** ## Business Continuity Management & Operational Resilience A consistent unified framework for business continuity planning and plan development shall be established, documented and adopted to ensure all business continuity plans are consistent in addressing priorities for testing, maintenance, and information security requirements. Requirements for business continuity plans include the following: • Defined purpose and scope, aligned with relevant dependencies • Accessible to and understood by those who will use them • Owned by a named person(s) who is responsible for their review, update, and approval • Defined lines of communication, roles, and responsibilities • Detailed recovery procedures, manual work-around, and reference information • Method for plan invocation We are complied with the requirement -We have Business continuity plan and procedure which is approved by the Management and tested annually once as per the compliance requirements. Business continuity and security incident response plans shall be subject to testing at planned intervals or upon significant organizational or environmental changes. Incident response plans shall involve impacted customers (tenant) and other business relationships that represent critical intra-supply chain business process dependencies. We are complied with the requirement -We have Business continuity plan and procedure which is approved by the Management and tested annually once as per the compliance requirements. Datacenter utilities services and environmental conditions (e.g., water, power, temperature and humidity controls, telecommunications,and internet connectivity) shall be secured, monitored, maintained, and tested for continual effectiveness at planned intervals to ensure protection from unauthorized interception or damage, and designed with automated fail-over or other redundancies in the event of planned or unplanned disruptions. Yes, we use Amazon Web Services (AWS) as our CSP, and they provide the same. Information system documentation (e.g., administrator and user guides, and architecture diagrams) shall be made available to authorized personnel to ensure the following: • Configuring, installing, and operating the information system • Effectively using the system's security features Yes, we have such documentation Physical protection against damage from natural causes and disasters, as well as deliberate attacks, including fire, flood, atmospheric electrical discharge, solar induced geomagnetic storm, wind, earthquake, tsunami, explosion, nuclear accident, volcanic activity, biological hazard, civil unrest, mudslide, tectonic activity, and other forms of natural or man-made disaster shall be anticipated, designed, and have countermeasures applied. We are complied with the requirement . We have Physical and Environmental Security Procedure in place and effectively working To reduce the risks from environmental threats, hazards, and opportunities for unauthorized access, equipment shall be kept away from locations subject to high probability environmental risks and supplemented by redundant equipment located at a reasonable distance. We are complied with the requirement Policies and procedures shall be established, and supporting business processes and technical measures implemented, for equipment maintenance ensuring continuity and availability of operations and support personnel. Yes. We follow this and complied with the requirement Protection measures shall be put into place to react to natural and man-made threats based upon a geographically-specific Business Impact Assessment We are complied with the requirement . We have Physical and Environmental Security Procedure in place and effectively working There shall be a defined and documented method for determining the impact of any disruption to the organization (cloud provider, cloud consumer) that must incorporate the following: • Identify critical products and services • Identify all dependencies, including processes, applications, business partners, and third party service providers • Understand threats to critical products and services • Determine impacts resulting from planned or unplanned disruptions and how these vary over time • Establish the maximum tolerable period for disruption • Establish priorities for recovery • Establish recovery time objectives for resumption of critical products and services within their maximum tolerable period of disruption • Estimate the resources required for resumption We are complied with the requirement as per the Business continuity plan and procedure. Policies and procedures shall be established, and supporting business processes and technical measures implemented, for appropriate IT governance and service management to ensure appropriate planning, delivery and support of the organization's IT capabilities supporting business functions, workforce, and/or customers based on industry acceptable standards (i.e., ITIL v4 and COBIT 5). Additionally, policies and procedures shall include defined roles and responsibilities supported by regular workforce training. Yes. We have the policies and procedures in place for approproate IT Governance and service management. Policies and procedures shall be established, and supporting business processes and technical measures implemented, for defining and adhering to the retention period of any critical asset as per established policies and procedures, as well as applicable legal, statutory, or regulatory compliance obligations. Backup and recovery measures shall be incorporated as part of business continuity planning and tested accordingly for effectiveness. We are complied with the requirement. We have data protection policy. *** ## Change Control & Configuration Management Policies and procedures shall be established, and supporting business processes and technical measures implemented, to ensure the development and/or acquisition of new data, physical or virtual applications, infrastructure network and systems components, or any corporate, operations and/or datacenter facilities have been pre-authorized by the organization's business leadership or other accountable business role or function. We are complied with the requirement External business partners shall adhere to the same policies and procedures for change management, release, and testing as internal developers within the organization (e.g. ITIL service management processes). Yes, we comply Organization shall follow a defined quality change control and testing process (e.g. ITIL Service Management) with established baselines, testing, and release standards that focus on system availability, confidentiality, and integrity of systems and services. Yes, we comply Policies and procedures shall be established, and supporting business processes and technical measures implemented, to restrict the installation of unauthorized software on organizationally-owned or managed user end-point devices (e.g., issued workstations, laptops, and mobile devices) and IT infrastructure network and systems components. We are complied with the requirement - We have installed End point security in users devices. Policies and procedures shall be established for managing the risks associated with applying changes to: • business-critical or customer (tenant)-impacting (physical and virtual) applications and system-system interface (API) designs and configurations • infrastructure network and systems components Technical measures shall be implemented to provide assurance that all changes directly correspond to a registered change request, business-critical or customer (tenant) , and/or authorization by, the customer (tenant) as per agreement (SLA) prior to deployment. Yes, we follow such a CM process. *** ## Data Security & Information Lifecycle Management Data and objects containing data shall be assigned a classification by the data owner based on data type, value, sensitivity, and criticality to the organization. Yes, We comply Policies and procedures shall be established to inventory, document, and maintain data flows for data that is resident (permanently or temporarily) within the service's applications and infrastructure network and systems. In particular, providers shall ensure that data that is subject to geographic residency requirements not be migrated beyond its defined bounds. Yes, We comply Data related to electronic commerce (e-commerce) that traverses public networks shall be appropriately classified and protected from fraudulent activity, unauthorized disclosure, or modification in such a manner to prevent contract dispute and compromise of data. Yes, We comply Policies and procedures shall be established for the labeling, handling, and security of data and objects which contain data. Mechanisms for label inheritance shall be implemented for objects that act as aggregate containers for data. We are complied with the requirements with regards to data handling/Labeling/clasification Production data shall not be replicated or used in non-production environments. Yes, We dont use LIVE data in any other environment. All data shall be designated with stewardship, with assigned responsibilities defined, documented, and communicated. Yes, We comply Any use of customer data in non-production environments requires explicit, documented approval from all customers whose data is affected, and must comply with all legal and regulatory requirements for scrubbing of sensitive data elements. Yes, We comply *** ## Datacenter Security Assets must be classified in terms of business criticality, service-level expectations, and operational continuity requirements. A complete inventory of business-critical assets located at all sites and/or geographical locations and their usage over time shall be maintained and updated regularly, and assigned ownership by defined roles and responsibilities. Yes, We comply Physical security perimeters (e.g., fences, walls, barriers, guards, gates, electronic surveillance, physical authentication mechanisms, reception desks, and security patrols) shall be implemented to safeguard sensitive data and information systems. Yes, We comply. Our CSP(AWS) provides the same. Automated equipment identification shall be used as a method of connection authentication. Location-aware technologies may be used to validate connection authentication integrity based on known equipment location. Yes, We comply. Our CSP(AWS) provides the same. Authorization must be obtained prior to relocation or transfer of hardware, software, or data to an offsite premises. We are complied - As per the Information security policy and Media protection procedure. Policies and procedures shall be established for the secure disposal of equipment (by asset type) used outside the organization's premises. This shall include a wiping solution or destruction process that renders recovery of information impossible. The erasure shall consist of a full overwrite of the drive to ensure that the erased drive is released to inventory for reuse and deployment, or securely stored until it can be destroyed. We are complied. We have Asset Management Procedure Policies and procedures shall be established, and supporting business processes implemented, for maintaining a safe and secure working environment in offices, rooms, facilities, and secure areas storing sensitive information. We are complied. Physical and Environmental Security Procedure Ingress and egress to secure areas shall be constrained and monitored by physical access control mechanisms to ensure that only authorized personnel are allowed access. We are complied. We have Physical and Environmental Security Procedure Ingress and egress points such as service areas and other points where unauthorized personnel may enter the premises shall be monitored, controlled and, if possible, isolated from data storage and processing facilities to prevent unauthorized data corruption, compromise, and loss. We are complied. We have Physical and Environmental Security Procedure and we are monitoring the office building via CCTV cameras. Physical access to information assets and functions by users and support personnel shall be restricted. We are complied. We have Physical and Environmental Security Procedure in place and provided the access card to the users to restrict the specific areas. *** ## Encryption & Key Management Keys must have identifiable owners (binding keys to identities) and there shall be key management policies. Yes, We comply. Policies and procedures shall be established for the management of cryptographic keys in the service's cryptosystem (e.g., lifecycle management from key generation to revocation and replacement, public key infrastructure, cryptographic protocol design and algorithms used, access controls in place for secure key generation, and exchange and storage including segregation of keys used for encrypted data or sessions). Upon request, provider shall inform the customer (tenant) of changes within the cryptosystem, especially if the customer (tenant) data is used as part of the service, and/or the customer (tenant) has some shared responsibility over implementation of the control. Yes, We comply. Policies and procedures shall be established, and supporting business processes and technical measures implemented, for the use of encryption protocols for protection of sensitive data in storage (e.g., file servers, databases, and end-user workstations), data in use (memory), and data in transmission (e.g., system interfaces, over public networks, and electronic messaging) as per applicable legal, statutory, and regulatory compliance obligations. Yes, We comply. Platform and data-appropriate encryption (e.g., AES-256) in open/validated formats and standard algorithms shall be required. Keys shall not be stored in the cloud (i.e. at the cloud provider in question), but maintained by the cloud consumer or trusted key management provider. Key management and key usage shall be separated duties. Yes, we use AES256 for data at rest. *** ## Governance and Risk Management Baseline security requirements shall be established for developed or acquired, organizationally-owned or managed, physical or virtual, applications and infrastructure system and network components that comply with applicable legal, statutory and regulatory compliance obligations. Deviations from standard baseline configurations must be authorized following change management policies and procedures prior to deployment, provisioning, or use. Compliance with security baseline requirements must be reassessed at least annually unless an alternate frequency has been established and authorized based on business need. We are complied with this - We have Compliance Procedure in place and reviewed by the management annually Risk assessments associated with data governance requirements shall be conducted at planned intervals and shall consider the following: • Awareness of where sensitive data is stored and transmitted across applications, databases, servers, and network infrastructure • Compliance with defined retention periods and end-of-life disposal requirements • Data classification and protection from unauthorized use, access, loss, destruction, and falsification We are complied - We have Risk Management Procedure and Data classification policy to protect unauthorized use, access, loss, destruction, and falsification Managers are responsible for maintaining awareness of, and complying with, security policies, procedures, and standards that are relevant to their area of responsibility. We are complied - we provied information security awareness training to all the employees annually once we per the ISMS requirements. An Information Security Management Program (ISMP) shall be developed, documented, approved, and implemented that includes administrative, technical, and physical safeguards to protect assets and data from loss, misuse, unauthorized access, disclosure, alteration, and destruction. The security program shall include, but not be limited to, the following areas insofar as they relate to the characteristics of the business: • Risk management • Security policy • Organization of information security • Asset management • Human resources security • Physical and environmental security • Communications and operations management • Access control • Information systems acquisition, development, and maintenance We are complied with the requirements - We have Information security management framework consisted of all the required policies and procedures. For ex - Risk management • Security policy • Organization of information security • Asset management • Human resources security • Physical and environmental security • Communications and operations management • Access control policy etc.... Executive and line management shall take formal action to support information security through clearly-documented direction and commitment, and shall ensure the action has been assigned. We are complied - The management is reviewing the performance if the Information Security department and taking necessing actions and providing the recommondation on a timely basis. And all the ISMS policies has been reviewed and approved by the management yearly once as per the requirements. Information security policies and procedures shall be established and made readily available for review by all impacted personnel and external business relationships. Information security policies must be authorized by the organization's business leadership (or other accountable business role or function) and supported by a strategic business plan and an information security management program inclusive of defined information security roles and responsibilities for business leadership. We are complied. We have all the required ISMS policies and procedures in place. A formal disciplinary or sanction policy shall be established for employees who have violated security policies and procedures. Employees shall be made aware of what action might be taken in the event of a violation, and disciplinary measures must be stated in the policies and procedures. We have Desciplinary policy in place and created an awareness among employees regarding voilation of the polciies via ISMS training. Risk assessment results shall include updates to security policies, procedures, standards, and controls to ensure that they remain relevant and effective. We have Risk Management Procedure as per the requirement. We are complied. The organization's business leadership (or other accountable business role or function) shall review the information security policy at planned intervals or as a result of changes to the organization to ensure its continuing alignment with the security strategy, effectiveness, accuracy, relevance, and applicability to legal, statutory, or regulatory compliance obligations. We are complied with the requirements - The management is reviewing the performance if the Information Security department and taking necessing actions and providing the recommondation on a timely basis. Aligned with the enterprise-wide framework, formal risk assessments shall be performed at least annually or at planned intervals, (and in conjunction with any changes to information systems) to determine the likelihood and impact of all identified risks using qualitative and quantitative methods. The likelihood and impact associated with inherent and residual risk shall be determined independently, considering all risk categories (e.g., audit results, threat and vulnerability analysis, and regulatory compliance). We are conducting Risk assessment at least once in a year as per the ISMS requirements. Risks shall be mitigated to an acceptable level. Acceptance levels based on risk criteria shall be established and documented in accordance with reasonable resolution time frames and stakeholder approval. Risk criteria has been established as per the Risk management procedure and consuct risk assessment once in a year as per the compliance requirements. *** ## Human Resources Upon termination of workforce personnel and/or expiration of external business relationships, all organizationally-owned assets shall be returned within an established period. We are complied as a part of offboarding procedure. Pursuant to local laws, regulations, ethics, and contractual constraints, all employment candidates, contractors, and third parties shall be subject to background verification proportional to the data classification to be accessed, the business requirements, and acceptable risk. We conduct background verification as per the compliance requirements and kept all the required data. Employment agreements shall incorporate provisions and/or terms for adherence to established information governance and security policies and must be signed by newly hired or on-boarded workforce personnel (e.g., full or part-time employee or contingent staff) prior to granting workforce personnel user access to corporate facilities, resources, and assets. We are complied with it. Also all the employees have signed for the Non disclosure agreements. Roles and responsibilities for performing employment termination or change in employment procedures shall be assigned, documented, and communicated. We are complied - Roles, Responsibilities & Authorities has been defined and communicated to the respective individials. Policies and procedures shall be established, and supporting business processes and technical measures implemented, to manage business risks associated with permitting mobile device access to corporate resources and may require the implementation of higher assurance compensating controls and acceptable-use policies and procedures (e.g., mandated security training, stronger identity, entitlement and access controls, and device monitoring). We are complied - We have mobile device management polciy. Requirements for non-disclosure or confidentiality agreements reflecting the organization's needs for the protection of data and operational details shall be identified, documented, and reviewed at planned intervals. We have non-disclosure or confidentiality agreements and signed by all the employees and external parties. Roles and responsibilities of contractors, employees, and third-party users shall be documented as they relate to information assets and security. We are complied - Roles, Responsibilities & Authorities has been defined and communicated to the respective individials. Policies and procedures shall be established, and supporting business processes and technical measures implemented, for defining allowances and conditions for permitting usage of organizationally-owned or managed user end-point devices (e.g., issued workstations, laptops, and mobile devices) and IT infrastructure network and systems components. Additionally, defining allowances and conditions to permit usage of personal mobile devices and associated applications with access to corporate resources (i.e., BYOD) shall be considered and incorporated as appropriate. We are complied with the requirement - We have controls in place through policies and procedure. A security awareness training program shall be established for all contractors, third-party users, and employees of the organization and mandated when appropriate. All individuals with access to organizational data shall receive appropriate awareness training and regular updates in organizational procedures, processes, and policies relating to their professional function relative to the organization. we are complied - We provide Information security awareness traning to all the employees and contractors, third-party users. All personnel shall be made aware of their roles and responsibilities for: • Maintaining awareness and compliance with established policies and procedures and applicable legal, statutory, or regulatory compliance obligations. • Maintaining a safe and secure working environment We are complied - We have Roles, Responsibilities & Authorities policy in place as per the compliance requirements. Policies and procedures shall be established to require that unattended workspaces do not have openly visible (e.g., on a desktop) sensitive documents and user computing sessions are disabled after an established period of inactivity. we are complied - we have an access control policy and IT Team have implemented accounts lockout policy to safeguard the sestive documents and personal information. *** ## Identity & Access Management Access to, and use of, audit tools that interact with the organization's information systems shall be appropriately segmented and restricted to prevent compromise and misuse of log data. Yes, We comply. User access policies and procedures shall be established, and supporting business processes and technical measures implemented, for ensuring appropriate identity, entitlement, and access management for all internal corporate and customer (tenant) users with access to data and organizationally-owned or managed (physical and virtual) application interfaces and infrastructure network and systems components. These policies, procedures, processes, and measures must incorporate the following: • Procedures and supporting roles and responsibilities for provisioning and de-provisioning user account entitlements following the rule of least privilege based on job function • Business case considerations for higher levels of assurance and multi-factor authentication secrets • Access segmentation to sessions and data in multi-tenant architectures by any third party • Identity trust verification and service-to-service application (API) and information processing interoperability (e.g., SSO and federation) • Account credential lifecycle management from instantiation through revocation • Authentication, authorization, and accounting (AAA) rules for access to data and sessions • Adherence to applicable legal, statutory, or regulatory compliance requirements We are complied - Access control policy and Information security policies has been established as per the requirements. We provide an accesss to the data only to an authorised individial. User access to diagnostic and configuration ports shall be restricted to authorized individuals and applications. Complied with the requirements though End point security installation. Policies and procedures shall be established to store and manage identity information about every person who accesses IT infrastructure and to determine their level of access. Policies shall also be developed to control access to network resources based on user identity. We are complied - We have policies and procedure in place to store and manage identity information. User access policies and procedures shall be established, and supporting business processes and technical measures implemented, for restricting user access as per defined segregation of duties to address business risks associated with a user-role conflict of interest. We are complied - We have policies and procedure in place to have control on access of data. We provide access only to an authorised individials. Access to the organization's own developed applications, program, or object source code, or any other form of intellectual property (IP), and use of proprietary software shall be appropriately restricted following the rule of least privilege based on job function as per established user access policies and procedures. We have role based access system to make sure that only the authorised individual have an access to the required information. The identification, assessment, and prioritization of risks posed by business processes requiring third-party access to the organization's information systems and data shall be followed by coordinated application of resources to minimize, monitor, and measure likelihood and impact of unauthorized or inappropriate access. Compensating controls derived from the risk analysis shall be implemented prior to provisioning access. Yes, We comply. Policies and procedures are established for permissible storage and access of identities used for authentication to ensure identities are only accessible based on rules of least privilege and replication limitation only to users explicitly defined as business necessary. We have role based access system to make sure that only the authorised individual have an access to the required information. Provisioning user access (e.g., employees, contractors, customers (tenants), business partners and/or supplier relationships) to data and organizationally-owned or managed (physical and virtual) applications, infrastructure systems, and network components shall be authorized by the organization's management prior to access being granted and appropriately restricted as per established policies and procedures. Upon request, provider shall inform customer (tenant) of this user access, especially if customer (tenant) data is used as part the service and/or customer (tenant) has some shared responsibility over implementation of control. We have role based access system to make sure that only the authorised individual have an access to the required information. User access shall be authorized and revalidated for entitlement appropriateness, at planned intervals, by the organization's business leadership or other accountable business role or function supported by evidence to demonstrate the organization is adhering to the rule of least privilege based on job function. For identified access violations, remediation must follow established user access policies and procedures. We have role based access system through access control policy to make sure that only the authorised individual have an access to the required information. Timely de-provisioning (revocation or modification) of user access to data and organizationally-owned or managed (physical and virtual) applications, infrastructure systems, and network components, shall be implemented as per established policies and procedures and based on user's change in status (e.g., termination of employment or other business relationship, job change or transfer). Upon request, provider shall inform customer (tenant) of these changes, especially if customer (tenant) data is used as part the service and/or customer (tenant) has some shared responsibility over implementation of control. We have change management policy and Infrastructure Change Control Procedure to comply with this requirements. Internal corporate or customer (tenant) user account credentials shall be restricted as per the following, ensuring appropriate identity, entitlement, and access management and in accordance with established policies and procedures: • Identity trust verification and service-to-service application (API) and information processing interoperability (e.g., SSO and Federation) • Account credential lifecycle management from instantiation through revocation • Account credential and/or identity store minimization or re-use when feasible • Adherence to industry acceptable and/or regulatory compliant authentication, authorization, and accounting (AAA) rules (e.g., strong/multi-factor, expireable, non-shared authentication secrets) Yes, We comply. Utility programs capable of potentially overriding system, object, network, virtual machine, and application controls shall be restricted. Yes, We comply. *** ## Infrastructure & Virtualization Security Higher levels of assurance are required for protection, retention, and lifecyle management of audit logs, adhering to applicable legal, statutory or regulatory compliance obligations and providing unique user access accountability to detect potentially suspicious network behaviors and/or file integrity anomalies, and to support forensic investigative capabilities in the event of a security breach. Yes, We comply. The provider shall ensure the integrity of all virtual machine images at all times. Any changes made to virtual machine images must be logged and an alert raised regardless of their running state (e.g. dormant, off, or running). The results of a change or move of an image and the subsequent validation of the image's integrity must be immediately available to customers through electronic methods (e.g. portals or alerts). Yes, We comply. A reliable and mutually agreed upon external time source shall be used to synchronize the system clocks of all relevant information processing systems to facilitate tracing and reconstitution of activity timelines. Yes, We comply. The availability, quality, and adequate capacity and resources shall be planned, prepared, and measured to deliver the required system performance in accordance with legal, statutory, and regulatory compliance obligations. Projections of future capacity requirements shall be made to mitigate the risk of system overload. Yes, We comply. Implementers shall ensure that the security vulnerability assessment tools or services accommodate the virtualization technologies used (e.g. virtualization aware). Yes, We comply. Network environments and virtual instances shall be designed and configured to restrict and monitor traffic between trusted and untrusted connections. These configurations shall be reviewed at least annually, and supported by a documented justification for use for all allowed services, protocols, and ports, and by compensating controls. Yes, We comply. Each operating system shall be hardened to provide only necessary ports, protocols, and services to meet business needs and have in place supporting technical controls such as: antivirus, file integrity monitoring, and logging as part of their baseline operating build standard or template. Yes, We comply. Production and non-production environments shall be separated to prevent unauthorized access or changes to information assets. Separation of the environments may include: stateful inspection firewalls, domain/realm authentication sources, and clear segregation of duties for personnel accessing these environments as part of their job duties. Yes, We comply. Multi-tenant organizationally-owned or managed (physical and virtual) applications, and infrastructure system and network components, shall be designed, developed, deployed and configured such that provider and customer (tenant) user access is appropriately segmented from other tenant users, based on the following considerations: • Established policies and procedures • Isolation of business critical assets and/or sensitive user data, and sessions that mandate stronger internal controls and high levels of assurance • Compliance with legal, statutory and regulatory compliance obligations Yes, We comply. Secured and encrypted communication channels shall be used when migrating physical servers, applications, or data to virtualized servers and, where possible, shall use a network segregated from production-level networks for such migrations. Yes, We comply. Access to all hypervisor management functions or administrative consoles for systems hosting virtualized systems shall be restricted to personnel based upon the principle of least privilege and supported through technical controls (e.g., two-factor authentication, audit trails, IP address filtering, firewalls, and TLS encapsulated communications to the administrative consoles). Yes, We comply. Policies and procedures shall be established, and supporting business processes and technical measures implemented, to protect wireless network environments, including the following: • Perimeter firewalls implemented and configured to restrict unauthorized traffic • Security settings enabled with strong encryption for authentication and transmission, replacing vendor default settings (e.g., encryption keys, passwords, and SNMP community strings) • User access to wireless network devices restricted to authorized personnel • The capability to detect the presence of unauthorized (rogue) wireless network devices for a timely disconnect from the network Yes, We comply. Network architecture diagrams shall clearly identify high-risk environments and data flows that may have legal compliance impacts. Technical measures shall be implemented and shall apply defense-in-depth techniques (e.g., deep packet analysis, traffic throttling, and black-holing) for detection and timely response to network-based attacks associated with anomalous ingress or egress traffic patterns (e.g., MAC spoofing and ARP poisoning attacks) and/or distributed denial-of-service (DDoS) attacks. Yes, We comply. *** ## Interoperability & Portability The provider shall use open and published APIs to ensure support for interoperability between components and to facilitate migrating applications. Yes, We comply. All structured and unstructured data shall be available to the customer and provided to them upon request in an industry-standard format (e.g., .doc, .xls, .pdf, logs, and flat files) Yes, We comply. Policies, procedures, and mutually-agreed upon provisions and/or terms shall be established to satisfy customer (tenant) requirements for service-to-service application (API) and information processing interoperability, and portability for application development and information exchange, usage, and integrity persistence. Yes, We comply. The provider shall use secure (e.g., non-clear text and authenticated) standardized network protocols for the import and export of data and to manage the service, and shall make available a document to consumers (tenants) detailing the relevant interoperability and portability standards that are involved. Yes, We comply. The provider shall use an industry-recognized virtualization platform and standard virtualization formats (e.g., OVF) to help ensure interoperability, and shall have documented custom changes made to any hypervisor in use and all solution-specific virtualization hooks available for customer review. Yes, We comply. *** ## Mobile Security Anti-malware awareness training, specific to mobile devices, shall be included in the provider's information security awareness training. We are complied with this - We provide information security awareness training A documented list of approved application stores has been defined as acceptable for mobile devices accessing or storing provider managed data. We are complied with it by having Mobile device Management Policy The company shall have a documented policy prohibiting the installation of non-approved applications or approved applications not obtained through a pre-identified application store. We are complied with Mobile device Management Policy The BYOD policy and supporting awareness training clearly states the approved applications, application stores, and application extensions and plugins that may be used for BYOD usage. We are complied with it - We have BYOD policy and conducted the awareness training as per the requirements. The provider shall have a documented mobile device policy that includes a documented definition for mobile devices and the acceptable usage and requirements for all mobile devices. The provider shall post and communicate the policy and requirements through the company's security awareness and training program. We are complied with it by having Mobile device Management Policy All cloud-based services used by the company's mobile devices or BYOD shall be pre-approved for usage and the storage of company business data. We have Mobile device policy and BYOD Policies in place and given the proper guidelines for usage as per the requirements. The company shall have a documented application validation process to test for mobile device, operating system, and application compatibility issues. Yes, We comply. The BYOD policy shall define the device and eligibility requirements to allow for BYOD usage. We are complied with requirements - We have well defined BYOD policy in place. An inventory of all mobile devices used to store and access company data shall be kept and maintained. All changes to the status of these devices (i.e., operating system and patch levels, lost or decommissioned status, and to whom the device is assigned or approved for usage (BYOD)) will be included for each device in the inventory. We are complied with the requrements. A centralized, mobile device management solution shall be deployed to all mobile devices permitted to store, transmit, or process customer data. We do not have a centralized mobile device management solution but having control via Google workspace admin console on the Mobile devices. The mobile device policy shall require the use of encryption either for the entire device or for data identified as sensitive on all mobile devices and shall be enforced through technology controls. We are complied with the requrements. The mobile device policy shall prohibit the circumvention of built-in security controls on mobile devices (e.g. jailbreaking or rooting) and shall enforce the prohibition through detective and preventative controls on the device or through a centralized device management system (e.g. mobile device management). We are complied with the requrements. The BYOD policy includes clarifying language for the expectation of privacy, requirements for litigation, e-discovery, and legal holds. The BYOD policy shall clearly state the expectations regarding the loss of non-company data in the case a wipe of the device is required. We are complied with the requrements. BYOD and/or company-owned devices are configured to require an automatic lockout screen, and the requirement shall be enforced through technical controls. We are complied with the requrements. Changes to mobile device operating systems, patch levels, and/or applications shall be managed through the company's change management processes. We are complied with the requrements. Password policies, applicable to mobile devices, shall be documented and enforced through technical controls on all company devices or devices approved for BYOD usage, and shall prohibit the changing of password/PIN lengths and authentication requirements. We are complied with the requrements. The mobile device policy shall require the BYOD user to perform backups of data, prohibit the usage of unapproved application stores, and require the use of anti-malware software (where supported). We are complied with the requrements. All mobile devices permitted for use through the company BYOD program or a company-assigned mobile device shall allow for remote wipe by the company's corporate IT or shall have all company-provided data wiped by the company's corporate IT. We are complied with the requrements. Mobile devices connecting to corporate networks, or storing and accessing company information, shall allow for remote software version/patch validation. All mobile devices shall have the latest available security-related patches installed upon general release by the device manufacturer or carrier and authorized IT personnel shall be able to perform these updates remotely. We are complied with the requrements. We have defined in the policy that Devices must be kept up to date with manufacturer or network provided patches. The BYOD policy shall clarify the systems and servers allowed for use or access on a BYOD-enabled device. We are complied with the requrements. *** ## Security Incident Management, E-Discovery & Cloud Forensics Points of contact for applicable regulation authorities, national and local law enforcement, and other legal jurisdictional authorities shall be maintained and regularly updated (e.g., change in impacted-scope and/or a change in any compliance obligation) to ensure direct compliance liaisons have been established and to be prepared for a forensic investigation requiring rapid engagement with law enforcement. We are complied with the requrements. Policies and procedures shall be established, and supporting business processes and technical measures implemented, to triage security-related events and ensure timely and thorough incident management, as per established IT service management policies and procedures. We are complied with the requrements. We also have incident management plan in place and taken care by Information security team. Workforce personnel and external business relationships shall be informed of their responsibilities and, if required, shall consent and/or contractually agree to report all information security events in a timely manner. Information security events shall be reported through predefined communications channels in a timely manner adhering to applicable legal, statutory, or regulatory compliance obligations. We are complied with it - We have an conyratcs and SLA/MSA and all the external parties have signed the NDA as well. Proper forensic procedures, including chain of custody, are required for the presentation of evidence to support potential legal action subject to the relevant jurisdiction after an information security incident. Upon notification, customers and/or other external business partners impacted by a security breach shall be given the opportunity to participate as is legally permissible in the forensic investigation. Yes, We comply. Mechanisms shall be put in place to monitor and quantify the types, volumes, and costs of information security incidents. We have Security Incident Management plan and communicated to all the employees. *** ## Supply Chain Management, Transparency and Accountability Providers shall inspect, account for, and work with their cloud supply-chain partners to correct data quality errors and associated risks. Providers shall design and implement controls to mitigate and contain data security risks through proper separation of duties, role-based access, and least-privilege access for all personnel within their supply chain. Yes, We comply. The provider shall make security incident information available to all affected customers and providers periodically through electronic methods (e.g. portals). Yes, We comply. Business-critical or customer (tenant) impacting (physical and virtual) application and system-system interface (API) designs and configurations, and infrastructure network and systems components, shall be designed, developed, and deployed in accordance with mutually agreed-upon service and capacity-level expectations, as well as IT governance and service management policies and procedures. Yes, We comply. The provider shall perform annual internal assessments of conformance to, and effectiveness of, its policies, procedures, and supporting measures and metrics. We perform annual internal assessments of conformance to, and effectiveness of, its policies, procedures, and supporting measures and metrics. Supply chain agreements (e.g., SLAs) between providers and customers (tenants) shall incorporate at least the following mutually-agreed upon provisions and/or terms: • Scope of business relationship and services offered • Information security requirements, provider and customer (tenant) primary points of contact for the duration of the business relationship • Notification and/or pre-authorization of any changes controlled by the provider with customer (tenant) impacts • Timely notification of a security incident (or confirmed breach) to all customers (tenants) and other business relationships impacted • Assessment and independent verification of compliance with agreement provisions and/or terms • Expiration of the business relationship and treatment of customer (tenant) data impacted • Customer (tenant) service-to-service application (API) and data interoperability and portability requirements We are complied with it - We have an conyratcs and SLA/MSA and all the external parties have signed the NDA as well. Providers shall review the risk management and governance processes of their partners so that practices are consistent and aligned to account for risks inherited from other members of that partner's cloud supply chain. We have Risk Management Procedures in place. Policies and procedures shall be implemented to ensure the consistent review of service agreements (e.g., SLAs) between providers and customers (tenants) across the relevant supply chain (upstream/downstream). Reviews shall performed at least annually and identity non-conformance to established agreements. The reviews should result in actions to address service-level conflicts or inconsistencies resulting from disparate supplier relationships. We review the SLA/MSA and NDA with external parties annually. Providers shall assure reasonable information security across their information supply chain by performing an annual review. The review shall include all partners/third party-providers upon which their information supply chain depends on. We review the SLA/MSA and NDA with external parties annually. Third-party service providers shall demonstrate compliance with information security and confidentiality, access control, service definitions, and delivery level agreements included in third-party contracts. Third-party reports, records, and services shall undergo audit and review at least annually to govern and maintain compliance with the service delivery agreements. We have ISMS framework including all the required polcieis and procedures as per the compliance requirements. *** ## Threat and Vulnerability Management Policies and procedures shall be established, and supporting business processes and technical measures implemented, to prevent the execution of malware on organizationally-owned or managed user end-point devices (i.e., issued workstations, laptops, and mobile devices) and IT infrastructure network and systems components. We conduct Vulnerability assessment and Penetration testing on a timely interval and have controls on Anti-Virus / Malicious Software throgh End point security. Policies and procedures shall be established, and supporting processes and technical measures implemented, for timely detection of vulnerabilities within organizationally-owned or managed applications, infrastructure network and system components (e.g. network vulnerability assessment, penetration testing) to ensure the efficiency of implemented security controls. A risk-based model for prioritizing remediation of identified vulnerabilities shall be used. Changes shall be managed through a change management process for all vendor-supplied patches, configuration changes, or changes to the organization's internally developed software. Upon request, the provider informs customer (tenant) of policies and procedures and identfied weaknesses especially if customer (tenant) data is used as part the service and/or customer (tenant) has some shared responsibility over implementation of control. We conduct Vulnerability assessment and Penetration testing on a timely interval and have controls on Anti-Virus / Malicious Software throgh End point security. Policies and procedures shall be established, and supporting business processes and technical measures implemented, to prevent the execution of unauthorized mobile code, defined as software transferred between systems over a trusted or untrusted network and executed on a local system without explicit installation or execution by the recipient, on organizationally-owned or managed user end-point devices (e.g., issued workstations, laptops, and mobile devices) and IT infrastructure network and systems components. We have Threat and Vulnerabilities Management procedure and we conduct Vulnerability assessment and Penetration testing through an athorised vendor. ## Application & Interface Security Applications and programming interfaces (APIs) shall be designed, developed, deployed, and tested in accordance with leading industry standards (e.g., OWASP for web applications) and adhere to applicable legal, statutory, or regulatory compliance obligations. Yes, we ensure the same as part of our code review, static code analysis and Web Application Firewall. Prior to granting customers access to data, assets, and information systems, identified security, contractual, and regulatory requirements for customer access shall be addressed. Yes, we provide API access only to vendors and systems authorized by the customer. Data input and output integrity routines (i.e., reconciliation and edit checks) shall be implemented for application interfaces and databases to prevent manual or systematic processing errors, corruption of data, or misuse. Yes, we follow multi layer application architecture to isolate database access Policies and procedures shall be established and maintained in support of data security to include (confidentiality, integrity and availability) across multiple system interfaces, jurisdictions and business functions to prevent improper disclosure, alteration, or destruction. Complied with the requirement - We have Information security policy in place and working effectively *** ## Audit Assurance & Compliance Audit plans shall be developed and maintained to address business process disruptions. Auditing plans shall focus on reviewing the effectiveness of the implementation of security operations. All audit activities must be agreed upon prior to executing any audits. Complied with the requirement - We are conducting the Internal and External Audit as per the requirement and focus on the evaluation of the effectiveness security controls Independent reviews and assessments shall be performed at least annually to ensure that the organization addresses nonconformities of established policies, standards, procedures, and compliance obligations. Complied with the requirement - reviews and assessments has been performed annually. Organizations shall create and maintain a control framework which captures standards, regulatory, legal, and statutory requirements relevant for their business needs. The control framework shall be reviewed at least annually to ensure changes that could affect the business processes are reflected. We are complied with the requirement - Information security team is reviewing the requirements at least annually to ensure changes that could affect the business processes are reflected. *** ## Business Continuity Management & Operational Resilience A consistent unified framework for business continuity planning and plan development shall be established, documented and adopted to ensure all business continuity plans are consistent in addressing priorities for testing, maintenance, and information security requirements. Requirements for business continuity plans include the following: • Defined purpose and scope, aligned with relevant dependencies • Accessible to and understood by those who will use them • Owned by a named person(s) who is responsible for their review, update, and approval • Defined lines of communication, roles, and responsibilities • Detailed recovery procedures, manual work-around, and reference information • Method for plan invocation We are complied with the requirement -We have Business continuity plan and procedure which is approved by the Management and tested annually once as per the compliance requirements. Business continuity and security incident response plans shall be subject to testing at planned intervals or upon significant organizational or environmental changes. Incident response plans shall involve impacted customers (tenant) and other business relationships that represent critical intra-supply chain business process dependencies. We are complied with the requirement -We have Business continuity plan and procedure which is approved by the Management and tested annually once as per the compliance requirements. Datacenter utilities services and environmental conditions (e.g., water, power, temperature and humidity controls, telecommunications,and internet connectivity) shall be secured, monitored, maintained, and tested for continual effectiveness at planned intervals to ensure protection from unauthorized interception or damage, and designed with automated fail-over or other redundancies in the event of planned or unplanned disruptions. Yes, we use Amazon Web Services (AWS) as our CSP, and they provide the same. Information system documentation (e.g., administrator and user guides, and architecture diagrams) shall be made available to authorized personnel to ensure the following: • Configuring, installing, and operating the information system • Effectively using the system's security features Yes, we have such documentation Physical protection against damage from natural causes and disasters, as well as deliberate attacks, including fire, flood, atmospheric electrical discharge, solar induced geomagnetic storm, wind, earthquake, tsunami, explosion, nuclear accident, volcanic activity, biological hazard, civil unrest, mudslide, tectonic activity, and other forms of natural or man-made disaster shall be anticipated, designed, and have countermeasures applied. We are complied with the requirement . We have Physical and Environmental Security Procedure in place and effectively working To reduce the risks from environmental threats, hazards, and opportunities for unauthorized access, equipment shall be kept away from locations subject to high probability environmental risks and supplemented by redundant equipment located at a reasonable distance. We are complied with the requirement Policies and procedures shall be established, and supporting business processes and technical measures implemented, for equipment maintenance ensuring continuity and availability of operations and support personnel. Yes. We follow this and complied with the requirement Protection measures shall be put into place to react to natural and man-made threats based upon a geographically-specific Business Impact Assessment We are complied with the requirement . We have Physical and Environmental Security Procedure in place and effectively working There shall be a defined and documented method for determining the impact of any disruption to the organization (cloud provider, cloud consumer) that must incorporate the following: • Identify critical products and services • Identify all dependencies, including processes, applications, business partners, and third party service providers • Understand threats to critical products and services • Determine impacts resulting from planned or unplanned disruptions and how these vary over time • Establish the maximum tolerable period for disruption • Establish priorities for recovery • Establish recovery time objectives for resumption of critical products and services within their maximum tolerable period of disruption • Estimate the resources required for resumption We are complied with the requirement as per the Business continuity plan and procedure. Policies and procedures shall be established, and supporting business processes and technical measures implemented, for appropriate IT governance and service management to ensure appropriate planning, delivery and support of the organization's IT capabilities supporting business functions, workforce, and/or customers based on industry acceptable standards (i.e., ITIL v4 and COBIT 5). Additionally, policies and procedures shall include defined roles and responsibilities supported by regular workforce training. Yes. We have the policies and procedures in place for approproate IT Governance and service management. Policies and procedures shall be established, and supporting business processes and technical measures implemented, for defining and adhering to the retention period of any critical asset as per established policies and procedures, as well as applicable legal, statutory, or regulatory compliance obligations. Backup and recovery measures shall be incorporated as part of business continuity planning and tested accordingly for effectiveness. We are complied with the requirement. We have data protection policy. *** ## Change Control & Configuration Management Policies and procedures shall be established, and supporting business processes and technical measures implemented, to ensure the development and/or acquisition of new data, physical or virtual applications, infrastructure network and systems components, or any corporate, operations and/or datacenter facilities have been pre-authorized by the organization's business leadership or other accountable business role or function. We are complied with the requirement External business partners shall adhere to the same policies and procedures for change management, release, and testing as internal developers within the organization (e.g. ITIL service management processes). Yes, we comply Organization shall follow a defined quality change control and testing process (e.g. ITIL Service Management) with established baselines, testing, and release standards that focus on system availability, confidentiality, and integrity of systems and services. Yes, we comply Policies and procedures shall be established, and supporting business processes and technical measures implemented, to restrict the installation of unauthorized software on organizationally-owned or managed user end-point devices (e.g., issued workstations, laptops, and mobile devices) and IT infrastructure network and systems components. We are complied with the requirement - We have installed End point security in users devices. Policies and procedures shall be established for managing the risks associated with applying changes to: • business-critical or customer (tenant)-impacting (physical and virtual) applications and system-system interface (API) designs and configurations • infrastructure network and systems components Technical measures shall be implemented to provide assurance that all changes directly correspond to a registered change request, business-critical or customer (tenant) , and/or authorization by, the customer (tenant) as per agreement (SLA) prior to deployment. Yes, we follow such a CM process. *** ## Data Security & Information Lifecycle Management Data and objects containing data shall be assigned a classification by the data owner based on data type, value, sensitivity, and criticality to the organization. Yes, We comply Policies and procedures shall be established to inventory, document, and maintain data flows for data that is resident (permanently or temporarily) within the service's applications and infrastructure network and systems. In particular, providers shall ensure that data that is subject to geographic residency requirements not be migrated beyond its defined bounds. Yes, We comply Data related to electronic commerce (e-commerce) that traverses public networks shall be appropriately classified and protected from fraudulent activity, unauthorized disclosure, or modification in such a manner to prevent contract dispute and compromise of data. Yes, We comply Policies and procedures shall be established for the labeling, handling, and security of data and objects which contain data. Mechanisms for label inheritance shall be implemented for objects that act as aggregate containers for data. We are complied with the requirements with regards to data handling/Labeling/clasification Production data shall not be replicated or used in non-production environments. Yes, We dont use LIVE data in any other environment. All data shall be designated with stewardship, with assigned responsibilities defined, documented, and communicated. Yes, We comply Any use of customer data in non-production environments requires explicit, documented approval from all customers whose data is affected, and must comply with all legal and regulatory requirements for scrubbing of sensitive data elements. Yes, We comply *** ## Datacenter Security Assets must be classified in terms of business criticality, service-level expectations, and operational continuity requirements. A complete inventory of business-critical assets located at all sites and/or geographical locations and their usage over time shall be maintained and updated regularly, and assigned ownership by defined roles and responsibilities. Yes, We comply Physical security perimeters (e.g., fences, walls, barriers, guards, gates, electronic surveillance, physical authentication mechanisms, reception desks, and security patrols) shall be implemented to safeguard sensitive data and information systems. Yes, We comply. Our CSP(AWS) provides the same. Automated equipment identification shall be used as a method of connection authentication. Location-aware technologies may be used to validate connection authentication integrity based on known equipment location. Yes, We comply. Our CSP(AWS) provides the same. Authorization must be obtained prior to relocation or transfer of hardware, software, or data to an offsite premises. We are complied - As per the Information security policy and Media protection procedure. Policies and procedures shall be established for the secure disposal of equipment (by asset type) used outside the organization's premises. This shall include a wiping solution or destruction process that renders recovery of information impossible. The erasure shall consist of a full overwrite of the drive to ensure that the erased drive is released to inventory for reuse and deployment, or securely stored until it can be destroyed. We are complied. We have Asset Management Procedure Policies and procedures shall be established, and supporting business processes implemented, for maintaining a safe and secure working environment in offices, rooms, facilities, and secure areas storing sensitive information. We are complied. Physical and Environmental Security Procedure Ingress and egress to secure areas shall be constrained and monitored by physical access control mechanisms to ensure that only authorized personnel are allowed access. We are complied. We have Physical and Environmental Security Procedure Ingress and egress points such as service areas and other points where unauthorized personnel may enter the premises shall be monitored, controlled and, if possible, isolated from data storage and processing facilities to prevent unauthorized data corruption, compromise, and loss. We are complied. We have Physical and Environmental Security Procedure and we are monitoring the office building via CCTV cameras. Physical access to information assets and functions by users and support personnel shall be restricted. We are complied. We have Physical and Environmental Security Procedure in place and provided the access card to the users to restrict the specific areas. *** ## Encryption & Key Management Keys must have identifiable owners (binding keys to identities) and there shall be key management policies. Yes, We comply. Policies and procedures shall be established for the management of cryptographic keys in the service's cryptosystem (e.g., lifecycle management from key generation to revocation and replacement, public key infrastructure, cryptographic protocol design and algorithms used, access controls in place for secure key generation, and exchange and storage including segregation of keys used for encrypted data or sessions). Upon request, provider shall inform the customer (tenant) of changes within the cryptosystem, especially if the customer (tenant) data is used as part of the service, and/or the customer (tenant) has some shared responsibility over implementation of the control. Yes, We comply. Policies and procedures shall be established, and supporting business processes and technical measures implemented, for the use of encryption protocols for protection of sensitive data in storage (e.g., file servers, databases, and end-user workstations), data in use (memory), and data in transmission (e.g., system interfaces, over public networks, and electronic messaging) as per applicable legal, statutory, and regulatory compliance obligations. Yes, We comply. Platform and data-appropriate encryption (e.g., AES-256) in open/validated formats and standard algorithms shall be required. Keys shall not be stored in the cloud (i.e. at the cloud provider in question), but maintained by the cloud consumer or trusted key management provider. Key management and key usage shall be separated duties. Yes, we use AES256 for data at rest. *** ## Governance and Risk Management Baseline security requirements shall be established for developed or acquired, organizationally-owned or managed, physical or virtual, applications and infrastructure system and network components that comply with applicable legal, statutory and regulatory compliance obligations. Deviations from standard baseline configurations must be authorized following change management policies and procedures prior to deployment, provisioning, or use. Compliance with security baseline requirements must be reassessed at least annually unless an alternate frequency has been established and authorized based on business need. We are complied with this - We have Compliance Procedure in place and reviewed by the management annually Risk assessments associated with data governance requirements shall be conducted at planned intervals and shall consider the following: • Awareness of where sensitive data is stored and transmitted across applications, databases, servers, and network infrastructure • Compliance with defined retention periods and end-of-life disposal requirements • Data classification and protection from unauthorized use, access, loss, destruction, and falsification We are complied - We have Risk Management Procedure and Data classification policy to protect unauthorized use, access, loss, destruction, and falsification Managers are responsible for maintaining awareness of, and complying with, security policies, procedures, and standards that are relevant to their area of responsibility. We are complied - we provied information security awareness training to all the employees annually once we per the ISMS requirements. An Information Security Management Program (ISMP) shall be developed, documented, approved, and implemented that includes administrative, technical, and physical safeguards to protect assets and data from loss, misuse, unauthorized access, disclosure, alteration, and destruction. The security program shall include, but not be limited to, the following areas insofar as they relate to the characteristics of the business: • Risk management • Security policy • Organization of information security • Asset management • Human resources security • Physical and environmental security • Communications and operations management • Access control • Information systems acquisition, development, and maintenance We are complied with the requirements - We have Information security management framework consisted of all the required policies and procedures. For ex - Risk management • Security policy • Organization of information security • Asset management • Human resources security • Physical and environmental security • Communications and operations management • Access control policy etc.... Executive and line management shall take formal action to support information security through clearly-documented direction and commitment, and shall ensure the action has been assigned. We are complied - The management is reviewing the performance if the Information Security department and taking necessing actions and providing the recommondation on a timely basis. And all the ISMS policies has been reviewed and approved by the management yearly once as per the requirements. Information security policies and procedures shall be established and made readily available for review by all impacted personnel and external business relationships. Information security policies must be authorized by the organization's business leadership (or other accountable business role or function) and supported by a strategic business plan and an information security management program inclusive of defined information security roles and responsibilities for business leadership. We are complied. We have all the required ISMS policies and procedures in place. A formal disciplinary or sanction policy shall be established for employees who have violated security policies and procedures. Employees shall be made aware of what action might be taken in the event of a violation, and disciplinary measures must be stated in the policies and procedures. We have Desciplinary policy in place and created an awareness among employees regarding voilation of the polciies via ISMS training. Risk assessment results shall include updates to security policies, procedures, standards, and controls to ensure that they remain relevant and effective. We have Risk Management Procedure as per the requirement. We are complied. The organization's business leadership (or other accountable business role or function) shall review the information security policy at planned intervals or as a result of changes to the organization to ensure its continuing alignment with the security strategy, effectiveness, accuracy, relevance, and applicability to legal, statutory, or regulatory compliance obligations. We are complied with the requirements - The management is reviewing the performance if the Information Security department and taking necessing actions and providing the recommondation on a timely basis. Aligned with the enterprise-wide framework, formal risk assessments shall be performed at least annually or at planned intervals, (and in conjunction with any changes to information systems) to determine the likelihood and impact of all identified risks using qualitative and quantitative methods. The likelihood and impact associated with inherent and residual risk shall be determined independently, considering all risk categories (e.g., audit results, threat and vulnerability analysis, and regulatory compliance). We are conducting Risk assessment at least once in a year as per the ISMS requirements. Risks shall be mitigated to an acceptable level. Acceptance levels based on risk criteria shall be established and documented in accordance with reasonable resolution time frames and stakeholder approval. Risk criteria has been established as per the Risk management procedure and consuct risk assessment once in a year as per the compliance requirements. *** ## Human Resources Upon termination of workforce personnel and/or expiration of external business relationships, all organizationally-owned assets shall be returned within an established period. We are complied as a part of offboarding procedure. Pursuant to local laws, regulations, ethics, and contractual constraints, all employment candidates, contractors, and third parties shall be subject to background verification proportional to the data classification to be accessed, the business requirements, and acceptable risk. We conduct background verification as per the compliance requirements and kept all the required data. Employment agreements shall incorporate provisions and/or terms for adherence to established information governance and security policies and must be signed by newly hired or on-boarded workforce personnel (e.g., full or part-time employee or contingent staff) prior to granting workforce personnel user access to corporate facilities, resources, and assets. We are complied with it. Also all the employees have signed for the Non disclosure agreements. Roles and responsibilities for performing employment termination or change in employment procedures shall be assigned, documented, and communicated. We are complied - Roles, Responsibilities & Authorities has been defined and communicated to the respective individials. Policies and procedures shall be established, and supporting business processes and technical measures implemented, to manage business risks associated with permitting mobile device access to corporate resources and may require the implementation of higher assurance compensating controls and acceptable-use policies and procedures (e.g., mandated security training, stronger identity, entitlement and access controls, and device monitoring). We are complied - We have mobile device management polciy. Requirements for non-disclosure or confidentiality agreements reflecting the organization's needs for the protection of data and operational details shall be identified, documented, and reviewed at planned intervals. We have non-disclosure or confidentiality agreements and signed by all the employees and external parties. Roles and responsibilities of contractors, employees, and third-party users shall be documented as they relate to information assets and security. We are complied - Roles, Responsibilities & Authorities has been defined and communicated to the respective individials. Policies and procedures shall be established, and supporting business processes and technical measures implemented, for defining allowances and conditions for permitting usage of organizationally-owned or managed user end-point devices (e.g., issued workstations, laptops, and mobile devices) and IT infrastructure network and systems components. Additionally, defining allowances and conditions to permit usage of personal mobile devices and associated applications with access to corporate resources (i.e., BYOD) shall be considered and incorporated as appropriate. We are complied with the requirement - We have controls in place through policies and procedure. A security awareness training program shall be established for all contractors, third-party users, and employees of the organization and mandated when appropriate. All individuals with access to organizational data shall receive appropriate awareness training and regular updates in organizational procedures, processes, and policies relating to their professional function relative to the organization. we are complied - We provide Information security awareness traning to all the employees and contractors, third-party users. All personnel shall be made aware of their roles and responsibilities for: • Maintaining awareness and compliance with established policies and procedures and applicable legal, statutory, or regulatory compliance obligations. • Maintaining a safe and secure working environment We are complied - We have Roles, Responsibilities & Authorities policy in place as per the compliance requirements. Policies and procedures shall be established to require that unattended workspaces do not have openly visible (e.g., on a desktop) sensitive documents and user computing sessions are disabled after an established period of inactivity. we are complied - we have an access control policy and IT Team have implemented accounts lockout policy to safeguard the sestive documents and personal information. *** ## Identity & Access Management Access to, and use of, audit tools that interact with the organization's information systems shall be appropriately segmented and restricted to prevent compromise and misuse of log data. Yes, We comply. User access policies and procedures shall be established, and supporting business processes and technical measures implemented, for ensuring appropriate identity, entitlement, and access management for all internal corporate and customer (tenant) users with access to data and organizationally-owned or managed (physical and virtual) application interfaces and infrastructure network and systems components. These policies, procedures, processes, and measures must incorporate the following: • Procedures and supporting roles and responsibilities for provisioning and de-provisioning user account entitlements following the rule of least privilege based on job function • Business case considerations for higher levels of assurance and multi-factor authentication secrets • Access segmentation to sessions and data in multi-tenant architectures by any third party • Identity trust verification and service-to-service application (API) and information processing interoperability (e.g., SSO and federation) • Account credential lifecycle management from instantiation through revocation • Authentication, authorization, and accounting (AAA) rules for access to data and sessions • Adherence to applicable legal, statutory, or regulatory compliance requirements We are complied - Access control policy and Information security policies has been established as per the requirements. We provide an accesss to the data only to an authorised individial. User access to diagnostic and configuration ports shall be restricted to authorized individuals and applications. Complied with the requirements though End point security installation. Policies and procedures shall be established to store and manage identity information about every person who accesses IT infrastructure and to determine their level of access. Policies shall also be developed to control access to network resources based on user identity. We are complied - We have policies and procedure in place to store and manage identity information. User access policies and procedures shall be established, and supporting business processes and technical measures implemented, for restricting user access as per defined segregation of duties to address business risks associated with a user-role conflict of interest. We are complied - We have policies and procedure in place to have control on access of data. We provide access only to an authorised individials. Access to the organization's own developed applications, program, or object source code, or any other form of intellectual property (IP), and use of proprietary software shall be appropriately restricted following the rule of least privilege based on job function as per established user access policies and procedures. We have role based access system to make sure that only the authorised individual have an access to the required information. The identification, assessment, and prioritization of risks posed by business processes requiring third-party access to the organization's information systems and data shall be followed by coordinated application of resources to minimize, monitor, and measure likelihood and impact of unauthorized or inappropriate access. Compensating controls derived from the risk analysis shall be implemented prior to provisioning access. Yes, We comply. Policies and procedures are established for permissible storage and access of identities used for authentication to ensure identities are only accessible based on rules of least privilege and replication limitation only to users explicitly defined as business necessary. We have role based access system to make sure that only the authorised individual have an access to the required information. Provisioning user access (e.g., employees, contractors, customers (tenants), business partners and/or supplier relationships) to data and organizationally-owned or managed (physical and virtual) applications, infrastructure systems, and network components shall be authorized by the organization's management prior to access being granted and appropriately restricted as per established policies and procedures. Upon request, provider shall inform customer (tenant) of this user access, especially if customer (tenant) data is used as part the service and/or customer (tenant) has some shared responsibility over implementation of control. We have role based access system to make sure that only the authorised individual have an access to the required information. User access shall be authorized and revalidated for entitlement appropriateness, at planned intervals, by the organization's business leadership or other accountable business role or function supported by evidence to demonstrate the organization is adhering to the rule of least privilege based on job function. For identified access violations, remediation must follow established user access policies and procedures. We have role based access system through access control policy to make sure that only the authorised individual have an access to the required information. Timely de-provisioning (revocation or modification) of user access to data and organizationally-owned or managed (physical and virtual) applications, infrastructure systems, and network components, shall be implemented as per established policies and procedures and based on user's change in status (e.g., termination of employment or other business relationship, job change or transfer). Upon request, provider shall inform customer (tenant) of these changes, especially if customer (tenant) data is used as part the service and/or customer (tenant) has some shared responsibility over implementation of control. We have change management policy and Infrastructure Change Control Procedure to comply with this requirements. Internal corporate or customer (tenant) user account credentials shall be restricted as per the following, ensuring appropriate identity, entitlement, and access management and in accordance with established policies and procedures: • Identity trust verification and service-to-service application (API) and information processing interoperability (e.g., SSO and Federation) • Account credential lifecycle management from instantiation through revocation • Account credential and/or identity store minimization or re-use when feasible • Adherence to industry acceptable and/or regulatory compliant authentication, authorization, and accounting (AAA) rules (e.g., strong/multi-factor, expireable, non-shared authentication secrets) Yes, We comply. Utility programs capable of potentially overriding system, object, network, virtual machine, and application controls shall be restricted. Yes, We comply. *** ## Infrastructure & Virtualization Security Higher levels of assurance are required for protection, retention, and lifecyle management of audit logs, adhering to applicable legal, statutory or regulatory compliance obligations and providing unique user access accountability to detect potentially suspicious network behaviors and/or file integrity anomalies, and to support forensic investigative capabilities in the event of a security breach. Yes, We comply. The provider shall ensure the integrity of all virtual machine images at all times. Any changes made to virtual machine images must be logged and an alert raised regardless of their running state (e.g. dormant, off, or running). The results of a change or move of an image and the subsequent validation of the image's integrity must be immediately available to customers through electronic methods (e.g. portals or alerts). Yes, We comply. A reliable and mutually agreed upon external time source shall be used to synchronize the system clocks of all relevant information processing systems to facilitate tracing and reconstitution of activity timelines. Yes, We comply. The availability, quality, and adequate capacity and resources shall be planned, prepared, and measured to deliver the required system performance in accordance with legal, statutory, and regulatory compliance obligations. Projections of future capacity requirements shall be made to mitigate the risk of system overload. Yes, We comply. Implementers shall ensure that the security vulnerability assessment tools or services accommodate the virtualization technologies used (e.g. virtualization aware). Yes, We comply. Network environments and virtual instances shall be designed and configured to restrict and monitor traffic between trusted and untrusted connections. These configurations shall be reviewed at least annually, and supported by a documented justification for use for all allowed services, protocols, and ports, and by compensating controls. Yes, We comply. Each operating system shall be hardened to provide only necessary ports, protocols, and services to meet business needs and have in place supporting technical controls such as: antivirus, file integrity monitoring, and logging as part of their baseline operating build standard or template. Yes, We comply. Production and non-production environments shall be separated to prevent unauthorized access or changes to information assets. Separation of the environments may include: stateful inspection firewalls, domain/realm authentication sources, and clear segregation of duties for personnel accessing these environments as part of their job duties. Yes, We comply. Multi-tenant organizationally-owned or managed (physical and virtual) applications, and infrastructure system and network components, shall be designed, developed, deployed and configured such that provider and customer (tenant) user access is appropriately segmented from other tenant users, based on the following considerations: • Established policies and procedures • Isolation of business critical assets and/or sensitive user data, and sessions that mandate stronger internal controls and high levels of assurance • Compliance with legal, statutory and regulatory compliance obligations Yes, We comply. Secured and encrypted communication channels shall be used when migrating physical servers, applications, or data to virtualized servers and, where possible, shall use a network segregated from production-level networks for such migrations. Yes, We comply. Access to all hypervisor management functions or administrative consoles for systems hosting virtualized systems shall be restricted to personnel based upon the principle of least privilege and supported through technical controls (e.g., two-factor authentication, audit trails, IP address filtering, firewalls, and TLS encapsulated communications to the administrative consoles). Yes, We comply. Policies and procedures shall be established, and supporting business processes and technical measures implemented, to protect wireless network environments, including the following: • Perimeter firewalls implemented and configured to restrict unauthorized traffic • Security settings enabled with strong encryption for authentication and transmission, replacing vendor default settings (e.g., encryption keys, passwords, and SNMP community strings) • User access to wireless network devices restricted to authorized personnel • The capability to detect the presence of unauthorized (rogue) wireless network devices for a timely disconnect from the network Yes, We comply. Network architecture diagrams shall clearly identify high-risk environments and data flows that may have legal compliance impacts. Technical measures shall be implemented and shall apply defense-in-depth techniques (e.g., deep packet analysis, traffic throttling, and black-holing) for detection and timely response to network-based attacks associated with anomalous ingress or egress traffic patterns (e.g., MAC spoofing and ARP poisoning attacks) and/or distributed denial-of-service (DDoS) attacks. Yes, We comply. *** ## Interoperability & Portability The provider shall use open and published APIs to ensure support for interoperability between components and to facilitate migrating applications. Yes, We comply. All structured and unstructured data shall be available to the customer and provided to them upon request in an industry-standard format (e.g., .doc, .xls, .pdf, logs, and flat files) Yes, We comply. Policies, procedures, and mutually-agreed upon provisions and/or terms shall be established to satisfy customer (tenant) requirements for service-to-service application (API) and information processing interoperability, and portability for application development and information exchange, usage, and integrity persistence. Yes, We comply. The provider shall use secure (e.g., non-clear text and authenticated) standardized network protocols for the import and export of data and to manage the service, and shall make available a document to consumers (tenants) detailing the relevant interoperability and portability standards that are involved. Yes, We comply. The provider shall use an industry-recognized virtualization platform and standard virtualization formats (e.g., OVF) to help ensure interoperability, and shall have documented custom changes made to any hypervisor in use and all solution-specific virtualization hooks available for customer review. Yes, We comply. *** ## Mobile Security Anti-malware awareness training, specific to mobile devices, shall be included in the provider's information security awareness training. We are complied with this - We provide information security awareness training A documented list of approved application stores has been defined as acceptable for mobile devices accessing or storing provider managed data. We are complied with it by having Mobile device Management Policy The company shall have a documented policy prohibiting the installation of non-approved applications or approved applications not obtained through a pre-identified application store. We are complied with Mobile device Management Policy The BYOD policy and supporting awareness training clearly states the approved applications, application stores, and application extensions and plugins that may be used for BYOD usage. We are complied with it - We have BYOD policy and conducted the awareness training as per the requirements. The provider shall have a documented mobile device policy that includes a documented definition for mobile devices and the acceptable usage and requirements for all mobile devices. The provider shall post and communicate the policy and requirements through the company's security awareness and training program. We are complied with it by having Mobile device Management Policy All cloud-based services used by the company's mobile devices or BYOD shall be pre-approved for usage and the storage of company business data. We have Mobile device policy and BYOD Policies in place and given the proper guidelines for usage as per the requirements. The company shall have a documented application validation process to test for mobile device, operating system, and application compatibility issues. Yes, We comply. The BYOD policy shall define the device and eligibility requirements to allow for BYOD usage. We are complied with requirements - We have well defined BYOD policy in place. An inventory of all mobile devices used to store and access company data shall be kept and maintained. All changes to the status of these devices (i.e., operating system and patch levels, lost or decommissioned status, and to whom the device is assigned or approved for usage (BYOD)) will be included for each device in the inventory. We are complied with the requrements. A centralized, mobile device management solution shall be deployed to all mobile devices permitted to store, transmit, or process customer data. We do not have a centralized mobile device management solution but having control via Google workspace admin console on the Mobile devices. The mobile device policy shall require the use of encryption either for the entire device or for data identified as sensitive on all mobile devices and shall be enforced through technology controls. We are complied with the requrements. The mobile device policy shall prohibit the circumvention of built-in security controls on mobile devices (e.g. jailbreaking or rooting) and shall enforce the prohibition through detective and preventative controls on the device or through a centralized device management system (e.g. mobile device management). We are complied with the requrements. The BYOD policy includes clarifying language for the expectation of privacy, requirements for litigation, e-discovery, and legal holds. The BYOD policy shall clearly state the expectations regarding the loss of non-company data in the case a wipe of the device is required. We are complied with the requrements. BYOD and/or company-owned devices are configured to require an automatic lockout screen, and the requirement shall be enforced through technical controls. We are complied with the requrements. Changes to mobile device operating systems, patch levels, and/or applications shall be managed through the company's change management processes. We are complied with the requrements. Password policies, applicable to mobile devices, shall be documented and enforced through technical controls on all company devices or devices approved for BYOD usage, and shall prohibit the changing of password/PIN lengths and authentication requirements. We are complied with the requrements. The mobile device policy shall require the BYOD user to perform backups of data, prohibit the usage of unapproved application stores, and require the use of anti-malware software (where supported). We are complied with the requrements. All mobile devices permitted for use through the company BYOD program or a company-assigned mobile device shall allow for remote wipe by the company's corporate IT or shall have all company-provided data wiped by the company's corporate IT. We are complied with the requrements. Mobile devices connecting to corporate networks, or storing and accessing company information, shall allow for remote software version/patch validation. All mobile devices shall have the latest available security-related patches installed upon general release by the device manufacturer or carrier and authorized IT personnel shall be able to perform these updates remotely. We are complied with the requrements. We have defined in the policy that Devices must be kept up to date with manufacturer or network provided patches. The BYOD policy shall clarify the systems and servers allowed for use or access on a BYOD-enabled device. We are complied with the requrements. *** ## Security Incident Management, E-Discovery & Cloud Forensics Points of contact for applicable regulation authorities, national and local law enforcement, and other legal jurisdictional authorities shall be maintained and regularly updated (e.g., change in impacted-scope and/or a change in any compliance obligation) to ensure direct compliance liaisons have been established and to be prepared for a forensic investigation requiring rapid engagement with law enforcement. We are complied with the requrements. Policies and procedures shall be established, and supporting business processes and technical measures implemented, to triage security-related events and ensure timely and thorough incident management, as per established IT service management policies and procedures. We are complied with the requrements. We also have incident management plan in place and taken care by Information security team. Workforce personnel and external business relationships shall be informed of their responsibilities and, if required, shall consent and/or contractually agree to report all information security events in a timely manner. Information security events shall be reported through predefined communications channels in a timely manner adhering to applicable legal, statutory, or regulatory compliance obligations. We are complied with it - We have an conyratcs and SLA/MSA and all the external parties have signed the NDA as well. Proper forensic procedures, including chain of custody, are required for the presentation of evidence to support potential legal action subject to the relevant jurisdiction after an information security incident. Upon notification, customers and/or other external business partners impacted by a security breach shall be given the opportunity to participate as is legally permissible in the forensic investigation. Yes, We comply. Mechanisms shall be put in place to monitor and quantify the types, volumes, and costs of information security incidents. We have Security Incident Management plan and communicated to all the employees. *** ## Supply Chain Management, Transparency and Accountability Providers shall inspect, account for, and work with their cloud supply-chain partners to correct data quality errors and associated risks. Providers shall design and implement controls to mitigate and contain data security risks through proper separation of duties, role-based access, and least-privilege access for all personnel within their supply chain. Yes, We comply. The provider shall make security incident information available to all affected customers and providers periodically through electronic methods (e.g. portals). Yes, We comply. Business-critical or customer (tenant) impacting (physical and virtual) application and system-system interface (API) designs and configurations, and infrastructure network and systems components, shall be designed, developed, and deployed in accordance with mutually agreed-upon service and capacity-level expectations, as well as IT governance and service management policies and procedures. Yes, We comply. The provider shall perform annual internal assessments of conformance to, and effectiveness of, its policies, procedures, and supporting measures and metrics. We perform annual internal assessments of conformance to, and effectiveness of, its policies, procedures, and supporting measures and metrics. Supply chain agreements (e.g., SLAs) between providers and customers (tenants) shall incorporate at least the following mutually-agreed upon provisions and/or terms: • Scope of business relationship and services offered • Information security requirements, provider and customer (tenant) primary points of contact for the duration of the business relationship • Notification and/or pre-authorization of any changes controlled by the provider with customer (tenant) impacts • Timely notification of a security incident (or confirmed breach) to all customers (tenants) and other business relationships impacted • Assessment and independent verification of compliance with agreement provisions and/or terms • Expiration of the business relationship and treatment of customer (tenant) data impacted • Customer (tenant) service-to-service application (API) and data interoperability and portability requirements We are complied with it - We have an conyratcs and SLA/MSA and all the external parties have signed the NDA as well. Providers shall review the risk management and governance processes of their partners so that practices are consistent and aligned to account for risks inherited from other members of that partner's cloud supply chain. We have Risk Management Procedures in place. Policies and procedures shall be implemented to ensure the consistent review of service agreements (e.g., SLAs) between providers and customers (tenants) across the relevant supply chain (upstream/downstream). Reviews shall performed at least annually and identity non-conformance to established agreements. The reviews should result in actions to address service-level conflicts or inconsistencies resulting from disparate supplier relationships. We review the SLA/MSA and NDA with external parties annually. Providers shall assure reasonable information security across their information supply chain by performing an annual review. The review shall include all partners/third party-providers upon which their information supply chain depends on. We review the SLA/MSA and NDA with external parties annually. Third-party service providers shall demonstrate compliance with information security and confidentiality, access control, service definitions, and delivery level agreements included in third-party contracts. Third-party reports, records, and services shall undergo audit and review at least annually to govern and maintain compliance with the service delivery agreements. We have ISMS framework including all the required polcieis and procedures as per the compliance requirements. *** ## Threat and Vulnerability Management Policies and procedures shall be established, and supporting business processes and technical measures implemented, to prevent the execution of malware on organizationally-owned or managed user end-point devices (i.e., issued workstations, laptops, and mobile devices) and IT infrastructure network and systems components. We conduct Vulnerability assessment and Penetration testing on a timely interval and have controls on Anti-Virus / Malicious Software throgh End point security. Policies and procedures shall be established, and supporting processes and technical measures implemented, for timely detection of vulnerabilities within organizationally-owned or managed applications, infrastructure network and system components (e.g. network vulnerability assessment, penetration testing) to ensure the efficiency of implemented security controls. A risk-based model for prioritizing remediation of identified vulnerabilities shall be used. Changes shall be managed through a change management process for all vendor-supplied patches, configuration changes, or changes to the organization's internally developed software. Upon request, the provider informs customer (tenant) of policies and procedures and identfied weaknesses especially if customer (tenant) data is used as part the service and/or customer (tenant) has some shared responsibility over implementation of control. We conduct Vulnerability assessment and Penetration testing on a timely interval and have controls on Anti-Virus / Malicious Software throgh End point security. Policies and procedures shall be established, and supporting business processes and technical measures implemented, to prevent the execution of unauthorized mobile code, defined as software transferred between systems over a trusted or untrusted network and executed on a local system without explicit installation or execution by the recipient, on organizationally-owned or managed user end-point devices (e.g., issued workstations, laptops, and mobile devices) and IT infrastructure network and systems components. We have Threat and Vulnerabilities Management procedure and we conduct Vulnerability assessment and Penetration testing through an athorised vendor. # Cryptography and Encryption Source: https://help-plum.xoxoday.com/faq/security-compliance/cryptography-and-encryption Find answers to frequently asked questions about the cryptography and encryption standards Plum uses to protect customer data. Yes, we use AES 256-bit encryption. All the network communication for network communication is encrypted with the industry standards. Note - Please provide supporting documentation defining encryption standards and technologies. All data volume is encrypted with AES 256-bit encryption to prevent any external snooping or unauthorized access in the multi-tenant environment. Yes, the data is segregated with a client-specific key for proper handling and representation. Yes, there's a native encryption capability when it comes to sensitive data fields. As each field is equally intricate, there are no limits to such fields. User IDs and passwords must transmit through stringent checks in an encrypted format that complies with the current Technical Security Baseline Standards. The passwords are stored after encryption for maximum security of data. "Yes, our policies and procedures are established as per implemented mechanisms for secure disposal and removal of data from every storage media. By this, it rests assured that the data can't be recovered by any computer forensic means. We assure secure data disposal when storage is decommissioned or when the contract comes to an end." Please refer "Do you support secure deletion of data?" for an explanation. As for the procedure, here's the protocol that we follow: * Storage Period would be as per regulatory conditions. * Personal data can be deleted based on a formal written request, with justification. * Xoxoday would delete the data within 30 days of receiving the request. No, users must use certificates from Xoxoday. They are benchmarked as per the best industry standards to ensure complete encryption of data. No, open encryption has proven to show cracks and bruises and that's why we only equip data traversing public networks with industrial standards to ensure protection from fraud, unauthorized disclosure, modification, or compromise of data. Yes, personal data is to be transmitted using firmly approved encrypted systems and in no way is it to be transmitted via email. Yes, the hardened images are secure from any malicious leak or unauthorized access. These hardened images do not contain any authentication credentials. Yes, our network communication is encrypted with highly restricted protocols to ensure maximum security. No, the cryptographic keys, including data encryption and SSL certificates are managed by Xoxoday for optimal security of sensitive data. We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security Yes. We have implemented the Information Classification Policy We use a split key mechanism to ensure that every client's key is unique. • We perform annual key rotation. • Keys are generated using KMS service whenever needed. • We store keys in KMS. Attached the Encryption policy Name of the folder - EN01 Encryption policy Every client's key is unique. Yes. Our tech team manages this. We have encrypted the data while in transit and at rest.We use TLS1.2 encryption for Data at transit and AES256 Data at rest. We store keys in KMS. Yes. Backup data is also encrypted. The data in transit will be always be encrypted. Yes. We use google workspace and all the conversations are TLS encrypted. Passwords are encrypted all the time. We use logical data isolation with the help of company specific encryption keys. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256. Backup, passwords are protected. We use encryption. We have the ability to logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant's data. our network environment is designed and configured to restrict any communication and connection between the tenant's environment. We have a multi-layered network architecture with role-based access control. All the confidential/PI data are encrypted at rest and in transit with a split key mechanism to ensure that every client's key is unique. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. We use TLS1.3 encryption for Data at transit We logically segregate the tenant's data, and it is segregated with a client-specific key for proper handling and security reasons. We use TLS1.3 encryption while data in transit and AES256 while data at rest Yes, our logic to physically separate tenant systems is made possible by assigning each tenant's data a client-specific key that is uniquely encrypted for maximum security. We use TLS1.3 encryption while data in transit and AES256 while data at rest We use logical data isolation with the help of company specific encryption keys. All data volume is encrypted with AES 256-bit encryption to prevent any external snooping or unauthorized access in the multi-tenant environment. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. By default the users will not have access to our customer information or PII. These PII or Sensitive information will be visible only to authorized users and only to the extent needed to perform activities. We do not share or transfer any of the customer data with any other parties. We do not provide access to the PII/SPII to any personnel who do not need the access and implemented the role based access control mechanism. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. All the confidential/PI data are encrypted at rest and in transit with a split key mechanism to ensure that every client's key is unique. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest Data backups are done on daily basis and in a secured way on AWS. This has been tested on regular basis. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Yes. The data at rest encrypted in the cloud. We use AES256 while data at rest. Attached the evidence. We use TLS1.3 encryption while data in transit and AES256 while data at rest Each tenant data is uniquely encrypted using client specific key. We use AES 256 bit encryption for data at rest to ensure maximum security measures. our network communication is encrypted with highly restricted protocols to ensure maximum security. the cryptographic keys, including data encryption and SSL certificates are managed by Xoxoday for optimal security of sensitive data. The passwords are also stored after encryption for maximum security of data Yes. All the data at rest is encrypted using AES-256-bit standards and all the data in transit encryption is HTTPS with TLS 1.2 we logically segregate the tenant's data and the application.Each tenant data is uniquely encrypted using client specific key. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. We are compliant with EU GDPR and CPRA (California Privacy Rights Act) We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behavior. Our network environment is designed and configured to restrict any communication and connection between the tenant's environment and our corporate network. We use logical data isolation with the help of company-specific encryption keys. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. We are EU GDPR Compliant and CPRA Certified. The data isolated between customers. We use logical data isolation with the help of company specific encryption keys. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256 The data is stored on AWS and The IDs and passwords are stored after encryption for maximum security of data We also conduct Network layer vulnerability and applicatioin layer vulnerability scan. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256 Yes. Data is encrypted. Each tenant data is uniquely encrypted using client specific key Yes. We provide importance to user's privacy. We use AES 256-bit encryption. We have a multi-layered network architecture with role-based access control. All the confidential/PI data are encrypted at rest and in transit with a split key mechanism to ensure that every client's key is unique. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access. Since we are SAAS product, we maintain backup and restore all the customer data by ourselves. We use AES 256 encryption for data at rest. We have a multi AZ deployment with periodic backup for our DR. We use logical data isolation with the help of company specific encryption keys. Data in non production environment is not updated with the production data. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256 Yes, our network communication is encrypted with highly restricted protocols to ensure maximum security. We use AES 256 bit encryption for data at rest to ensure maximum security measures. Yes. The data anonymization implemented. We have enabled security settings with strong encryption for authentication and transmission. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest Our employees only have access to the data that is necessary for the completion of the business activity which they are involved in. We have role based access system to make sure that only the authorised individual have an access to the required information. We review the role provisioning, deprovisioning, and recertification on a periodical basis and also audited by the external auditor. Our IT Team Review an access controls and approve as per the procedure. Any changes in the access levels of the users will be as per the role based logical access. We encrypt our secretes and store them in a private respository and servers. All the network communication for network communication is encrypted to industry standards. We use logical data isolation with the help of company specific encryption keys. Data in non-production environment is not updated with the production data. We generate separate test data at transit - TLS1.2 encryption, Data at rest - AES256 Yes We do very limited modification or changes wherever necessary. We have implemented the Encryption policy. We have defined generation, storage, archival, retrieval, distribution, retirement and destruction of keys. Attached the Encryption policy. All information are classified as Restricted and encrypted. The data is segregated with a client-specific key for proper handling and representation. All the data including the account credentials, Backup data are encrypted in transit and at rest. All the the customer data stored on our application also be encrypted for maximum security. We have implemented the security controls. We use TLS1.3 encryption for Data at transit and AES256 Data at rest for maximum security.We store password hashed. We have SHA512 hash with unique salt for every password We make sure that we follow the Industry best practices and security standard to make sure that we secure the information asset. Backup is encrypted and stored on cloud. We use logical data isolation with the help of company specific encryption keys We use logical data isolation with the help of company specific encryption keys. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256. We have the ability to logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant's data. our network environment is designed and configured to restrict any communication and connection between the tenant's environment. Yes. We comply with all the applicable new laws and regulations. We also have a service provider who helps us with regards to Information security, compliance and certifications etc.. We have identified the upcoming CPRA and implemented the controls and achieved the CPRA Attestation with the help of the external auditor. Attached the CPRA Attestation report. Yes. The communications are secure. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. We store password hashed. We have HA512 hash with unique salt for every password Yes. We use encrypted channel Yes We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. We store password hashed. We have HA512 hash with unique salt for every password Each tenant data is uniquely encrypted using a client specific key. All data volume is encrypted with AES 256-bit encryption to prevent any external snooping or unauthorized access in the multi-tenant environment Corporate data cannot be accessed by other clients of the service provider Data is encrypted during transmission, at rest (database and storage), and at backup We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access. Attached the Encryption Policy. We have the ability to logically segment or encrypt customer data. our network environment is designed and configured to restrict any communication and connection between the tenant's environment and our corporate network.our logic to physically separate tenant systems is made possible by assigning each tenant's data a client-specific key that is uniquely encrypted for maximum security. We do field level encryption for PII and user generated content. This encryption has a unique encryption key for each client. In addition we also do disk level encryption for the entire stored data. We have implements cryptographic mechanisms to prevent unauthorized disclosure and modification of information at rest. We use AES 256 bit encryption for data at rest to ensure maximum security measures. Attached the encryption policy. Sensitive data is encrypted and not stored in logs. Compliant. Cryptographic keys are protected. Compliant. The cryptographic keys, including data encryption and SSL certificates, are managed by Xoxoday for optimal security of sensitive data. Each tenant's data is uniquely encrypted using client specific key. NA. We do not store any other Sensitive personal information. The PII(name, email ID, phone#) are encrypted. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. The application and system backup data is encrypted We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. The back up data is encrypted and only authorised individuals will have access. Test data and backup data is seperated from the production servers. There is no integration with Infosys services/systems. The network Architecture diagram has been shared to show the TLS communication. Yes, we use AES 256-bit encryption. All the network communication for network communication is encrypted with the industry standards All data volume is encrypted with AES 256-bit encryption to prevent any external snooping or unauthorized access in the multi-tenant environment We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. All the PII Are encrypted. # Data Management Source: https://help-plum.xoxoday.com/faq/security-compliance/data-management Find answers to frequently asked questions about Plum's data management practices, including retention and lifecycle policies. Yes, the payment card data is masked and encrypted to ensure that the access only lies in the hands of authorized individuals. We use AES 256-bit encryption for data at rest for securing digital identities. The only user data stored within the system is their personal information - names, emails and contact numbers. This data is not put to any use by Xoxoday and resides within the system. The data can be deleted upon the tenant's request. Your data is completely secure. Third parties have no access to the given data. Yes, as stated above, your data is completely encrypted and secure, hence no critical information shall be revealed to the third parties. No. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records. Yes, our web assets, email records, and end-points are sealed with data loss prevention techniques. Yes, our technicalities are built in tandem with the customer data retention policies. No, we only rely on our ironclad infrastructure to ensure maximum security of data. The Xoxoday platform operates on the cloud, which means there are no removable storage devices in question. Our data cleansing process goes through an organized purge. Once the data is purged, it's purged from all places. There are user roles available for privileged and authorized members, access to which is provided via oAuth-2.0. Identities of users are verified on the events they access any resources. A support ticket has to be raised to the customer support team, after which the de-provisioning of privileged credentials will be taken care of in the back-end. The accounts with highest privilege are authenticated and managed via oAuth-2.0, which can be used to implement secure access to confidential data. No, roles of high privilege are allocated to a chosen few so that it doesn't break the segregation of duties. In case of an emergency, tenants can raise a request to the customer support personnel or the key account manager. The privileged access shall be given from the back-end promptly. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Yes, mutual authentication exists for strong authentication via AES 256-bit encryption. * Infrastructure logs are collected using AWS Audit Trail * Application-relatedlogs are collected in our Elastic Search server and retained in long-term cloud storage. No. Since we are a multi-tenant system, our logs contain information of all the tenants. We cannot isolate a single customer's information from our logs. Administrative logs are part of Cloud Dashboard and are regularly reviewed. Yes, we have multiple internet service providers for uninterrupted coverage and maximum uptime. There are gateways in place to defer DDoS attacks. No, historical data cannot be provided due to its confidentiality. We don't face any downtime and keep our service uninterrupted even in the events of upgrades and patches. Yes, in case there's a need for a forensic investigation, we can accommodate time and make it happen. Yes. We comply with this requirement, we follow multi-layer application architecture to isolate database access. Yes. We follow a defined quality change control and testing as per the Organization's policies and procedures. Yes. We follow a data classification policy and access control policy to provide access to the individuals based on data type, value, sensitivity, and criticality to the organization. Yes, We comply with this requirement. All data has been designated with stewardship, with assigned responsibilities defined, documented, and communicated as per the compliance requirements. Yes. We make sure that we follow access control policy and data protection policy to make sure that only authorized individual has access to the required data. And we have controls such as antivirus, file integrity monitoring, and log monitoring as per the compliance requirements. Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role based access requirements. Furthermore, while defining job roles and designing access roles, privileges leading to conflicts of interests are to be avoided. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access events. We have implemented the Role based access control machanism. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. We have implemented the Media protection procedure and Data retension & Disposal policy to make sure that we dispose the data securely. Yes. All are separate. We do not use. We not disclose or share any of the clients data. They do not have access. Yes. Segregation is done. Yes, we have implemented the physical security and only authorised individual can have access. We have also deployed security guards for maximum security. At least 180 days Yes, we do not allow any personal storgae devices. Yes, we will delete the data upon termination of the contract of request of the end users. The data will be entered by the end users and will be deleted upon the termination of the contract. Upon termination of the contract we confirm the data deletion. We securely dispose the data upon termination of the contract and confirm you within a specified period of timeline. We have implemented the Data Retention and Disposal Policy. Attached the document. We do not store customer information in any equipments, all the information will be stored on AWS Cloud virtual platform. We make sure that all the any data stored in any electronic devices are deleted before disposing of the equipments. NO The secure deletion standard like DoD 5220.22-M ECE is being followed and we provide a certificate that the data was properly sanitized from all computing resources and portable storage media We have implemented the data loss prevention techniques to make sure that the data is not lost permanently. It's a part of our data loss prevention techniques our web assets, email records, and end-points are sealed with data loss prevention techniques even when the endpoint is disconnected from corporate network Since we are into SAAS business we purge the data upon termination of the contracts or request by the customer. As per the compliance requirements we will delete the data upon a request from the customer. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. We do not use any of our customer data for testing. We collect only the name and email from the customer as a mandatory PII and these data stored on AWS - Singapore region. We always transparently inform the customer about the data storage location. No.We do not use our customer data for any of these purposes. We adhere to Data Retention and Disposal Policy and make sure that the personal information of the data subject will be deleted upon requests or termination of the contract. We have implemented the Data Loss Prevention techniques and Backup of data will be taken on regular basis automatically on AWS Platform. The data backup is also encrypted and there are no possibilities of loosing the data stored. The data can be deleted upon the tenant's request or termination of the contract. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. The data can be deleted upon the tenant's request or termination of the contract. We conduct the code review and get the necessary approvals from authorised personnel before releasing the new versions or developments. This is part of the code review process wherein the reviewer checks the utility and security of the 3rd party library. NA. We do not store any Health information or PHI. 7Years. But we delete the data upon customer request as per the GDPR. The employees Name, Email ID, DOB, designation will be involved. And other information posted on the groups will be involved. Cardholder data is not involved. Yes, our web assets, email records, and end-points are sealed with data loss prevention techniques. We can delete the customer data upon their request or after the termination of the contract. Our data cleansing process goes through an organized purge. Once the data is purged, it's purged from all places We do not use any data from our production environment for testing purposes. Our testing and production environment is on a different account. Its logically segregated for maximum security. We do not use any data from our production environment for testing purposes. We treat this as sensitive and confidential We securely delete the data upon termination of the contract Our data cleaning process goes through an organized purge. We will delete the data upon termination of the contract and confirm you. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. our web application, email records, and end-points are sealed with data loss prevention techniques. We have the capability to do it immediately. our products comply with all the industrial benchmarks and standards when it comes to the Software Development Life-cycle (SDLC). All software development procedures are supervised and monitored by Xoxoday so that they include: • security requirements • independent security review of the environment by a certified individual • code reviews Quality monitoring, evaluation, and acceptance criteria for information systems, upgrades, and new versions shall be established and documented for the clients' reference. We have implemented policies and procedures as per ISMS and GDPR requirements. We also conduct periodical Internal and external Audit by the third party Auditor. We have deployed our application on Cloud Virtual platform for maximum security. We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We conduct periodical Vulnerability assessment and Penetration Testing from the Inductry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications. We use logical data isolation with the help of company specific encryption keys. Data in non production environment is not updated with the production data. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256 As per the Information security policy and Data protection policy only the authorised individual have an access to the data through internal approving and ticketing system. Upon request or termincation of the contract we delete the data and confirm. Since we are a SaaS solution, PII is collected through our application and stored on AWS virtual platform cloud. We do not provide access to anybody except an authorised individual of our product teams. we logically segregate the tenant's data and the application.Each tenant data is uniquely encrypted using client specific key. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. NA. We do not handles the card holder data. Yes. OTP will get generate before making the payment. We have the Data security Controls in place. We have established the Data Management System and Information Security Management system to ensure that the data is managed during the conduct of business in a safe and secure manner in delivering the business values to the interested parties. Nreach Online Services Pvt ltd, respects the individual right to their personal information and is committed to use minimum personal data with transparency, accuracy & protection of confidentiality, integrity, availability, privacy, authenticity & trustworthiness, nonrepudiation, accountability and auditability of the data received, stored, processed and destroyed for business purposes. Atatched the Xoxoday GDPR Data Security Policy We do not transfer any data to any external parties. We are equipped to detect and mitigate Threats, DDOS attacks, session hijack, login spoofs or any other data extraction strategies. We deleted the data upon termination of the contract or if received the request from the customers/users. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. NA. We do not process any PHI. NA. We do not process any PHI. We do not share or disclose any PII to the third parties. We do not store PHI. Not application. All the data enters via our application. We do not process any PHI. We process the PII(name, email ID, phone#) and all are encrypted. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. Attached the Network architecture diagram and data flow. We will be deleting the data securely as per the Data retension and data disposal policy Yes, our policies and procedures are established as per implemented mechanisms for secure disposal and removal of data from every storage media. By this, it rests assured that the data can't be recovered by any computer forensic means. We assure secure data disposal when storage is decommissioned or when the contract comes to an end." Yes, we follow all the technical guidelines for development of our code and applications that come under the Open Web Application Security Project. We collect the data only through our application. There have been no incidences of security breaches resulting in the failure of core systems. We are equipped to detect and mitigate Advanced Persistent Threats or DDOS. We use AWS Cloud watch for monitoring the configuration and infrastructure changes. This will identify several types of denial of service (DoS) attacks The data can be deleted upon the tenant's request or termination of the contract. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. NA. We do not transmit data from one location to another. Our web assets, email records, and endpoints are sealed with data loss prevention techniques. We delete the customer data upon termination of the contract or request from the data subject. Yes. We confirm once the data is securely deleted from all the sources. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. We delete the customer data upon termination of the contract or on request of the data subject. # Data Security Source: https://help-plum.xoxoday.com/faq/security-compliance/data-security Find answers to frequently asked questions about the technical safeguards Plum uses to keep customer data secure. [Open document](https://drive.google.com/file/d/1W5QQnsnixFirx-xjZ1KRhPOA7Bi3cMRf/view) [Open document](https://drive.google.com/file/d/1okA7QhhKPHrrO_eSUrGd19yHhqpZRnOI/view?usp=sharing) [Open document](https://drive.google.com/file/d/1zsggds3GYgDOAMOE-bBT2vX1EH5R9E4A/view) [Open document](https://drive.google.com/file/d/1W5QQnsnixFirx-xjZ1KRhPOA7Bi3cMRf/view) [Open document](https://drive.google.com/file/d/1zyr_8lViSEbl3YlClOJFe4BmqJgdO_hU/view?usp=sharing) [Open document](https://drive.google.com/file/d/1S4C7STlV8n9xUKaNOY__hEMerLQbkqus/view?usp=sharing) [Open document](https://drive.google.com/file/d/1AUHfaBYe5lLXsbyRzP4mLMHh4LNsFY2e/view?usp=sharing) [Open document](https://drive.google.com/file/d/1KaECkPolkGh10EHfIpkUgntHn7-eK2X1/view?usp=sharing) # Finance Compliance Source: https://help-plum.xoxoday.com/faq/security-compliance/finance-compliance Find answers to frequently asked questions about Plum's finance compliance practices and internal financial controls. [Open document](https://drive.google.com/file/d/1BdeOUJl-14jww0Dkm3uLHtnLRjKIYlag/view?usp=sharing) # Governance, Risk and Data Compliance Source: https://help-plum.xoxoday.com/faq/security-compliance/governance-risk-data-compliance Find answers to frequently asked questions about Plum's governance, risk management, and data compliance practices. Yes, there are established policies and procedures for labeling, handling, storing, transmitting, retention/disposal, and security of TCCC data and objects which contain data, per the TCCC Information Classification Standard and Protection Measures. Yes, there are established policies and procedures for label inheritance of TCCC data and objects which contain data, per the TCCC Information Classification Standard and Protection Measures. Mechanisms for label inheritance shall be implemented for objects that act as aggregate containers for data. Yes, we adhere to the retention policy that the tenant sends out for optimal collaboration and smooth user experience with Xoxoday's products and services. Your data is of the utmost importance. All the security mechanisms and policies are established and implemented in such ways that data leak can be prevented, in transit as well as at rest. Yes, the policy, process, and procedure is implemented to ensure proper segregation of duties. These can be asked for and delivered upon tenants' requests. In the event of user-role conflict of interest, technical controls shall be implemented to mitigate risk (if any) from unauthorized/unintentional modification/misuse of organizations' information assets. Yes, our products comply with all the industrial benchmarks and standards when it comes to the Software Development Life-cycle (SDLC). All software development procedures are supervised and monitored by Xoxoday so that they include: * security requirements * independent security review of the environment by a certified individual * code reviewsQuality monitoring, evaluation, and acceptance criteria for information systems, upgrades, and new versions shall be established and documented for the clients' reference. Yes, our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase. Yes, an independent security review is conducted by certified professionals to look for any security vulnerabilities in order to solve them before deploying to production. Yes, our products comply with all the industrial benchmarks and standards when it comes to the Software Development Life-cycle (SDLC) security standard. Yes, changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates and modifications. Any change in roles, rights, or responsibilities shall be documented for a seamless experience. We have a consistent and unified framework for business continuity planning, disaster recovery, plan development. All the appropriate communications shall be established, documented, and adopted to ensure consistency in business continuity. This includes protection against natural and man-made disasters (e.g. fire, flood, earthquake, war, volcanic activity, biological hazard, civil unrest, mudslide, tectonic activity, utility services outages, etc.). Our hosting options are limited to Xoxoday's jurisdiction and are backed by prominent business continuity plans. Hence, we don't find the need to provide geographically diverse hosting options. The capability to transfer infrastructure service failover to other providers is not provided to the clients. Business continuity plans shall be subject to test at least annually or upon significant organizational or environmental changes to ensure continuing effectiveness. Along with an aligned enterprise-wide framework, we perform independent reviews through industry professionals along with formal risk assessments. These are done at least annually or at planned intervals to determine the likelihood and impact of all identified risks. With qualitative/quantitative methods ensuring our compliances with policies, procedures, and standards, we stick to the best standards. Yes, our stringent checks and tests are conducted annually to keep up the cloud service infrastructure hygiene as per the industrial standards. Annual audits are processed both internally and externally. The audit results can be sent over to tenants upon request. Yes, the tenants can request for penetration results and get the reports from our end. No, we do not process your payment card data for any reason other than billing purposes. Yes, we are compliant with the Indian IT Act of 2000. There is no such process available from our end. We will terminate the contract as per rules and statutes. Meanwhile your data will be stored with us and won't be given back to you. However, if the tenant wants the data to be erased, it can be done so upon request. Yes, we store data that's required for seamless rewarding and recognition. We conduct regular audits to ensure safety of data like employees' names, emails, employee numbers, etc. are used for verification and rewarding purposes. Xoxoday's information and cyber-security team keeps a watchful eye on all potential sources of threats and areas of compromise when it comes to information security. Roles are systematically defined for information security measures to tactfully align all operations, preventing any security breaches. Employees must agree with the acceptable usage policy of peripherals and devices to prevent malicious activities from the inside and out. Our environment has all the capabilities to be SOC-2 Type-II compliant but the certification is yet to come through. It shall be updated soon. No, our environment is not CSA-certified. Xoxoday keeps track of all security requirements with respect to legislations, statutes, and contracts. They are documented in all steps. We have our own procedure for control of documents and records that ensures compliance related to intellectual property rights and use of proprietary software. Our record management criteria checks all boxes of legislative, regulatory, contractual and business requirements. With different metrics tracking cyber-security measures, Xoxoday keeps the effectiveness in check with regular monitoring. Xoxoday's Human Resource operation procedure takes all measures of employee confidentiality into consideration. Yes, Xoxoday performs a thorough background check on every employee before they get onboard. The Non Disclosure Agreement ensures that the information is secure even after the contract is terminated. Yes, our Xoxoday Store vouchers are procured from third-party vendors. These vouchers are shared with the tenants in order to be showcased to users of Xoxoday platform. No, the third parties and vendors we deal with our confidential to Xoxoday. Hence, this list cannot be shared. Yes, there's a third-party security policy present to safeguard the interests of Xoxoday's tenants as well as the end users. Yes, our third party security policy deems it clear to comply with security obligations and we monitor their compliance regularly. Yes, we have a detailed risk management procedure in place to address situational issues like change of services being provided to tenants. No, our customer requests are addressed by the Xoxoday customer support team for maximum efficiency. Yes, Xoxoday's brand protection caters to any malicious interruptions and fallacies as they are addressed in prompt time. Yes, with media platforms being the biggest pedestal for information sharing, we keep an eye out for any brand protection issues. Yes, in the event of a rapid spike/slump in network traffic or host activity, Xoxoday analyzes the traffic to detect and prevent unauthorized or erratic behavior. Yes, in order to ensure airtight security of data, we have a mandatory and sessional privacy training and awareness module. The Cloud Security Alliance (CSA) is the world's leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. Yes, Please visit the link to view the registry - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday) Important features of CSA STAR LEVL – 1 are listed below * Operating in a low-risk environment * Wanting to offer increased transparency around the security controls they have in place. * Looking for a cost-effective way to improve trust and transparency. Yes, we ensure the same as part of our code review, static code analysis, and Web Application Firewall. Yes, We comply with these requirements. Our Cloud Security Platform, (CSP) Amazon Web Services (AWS) provides these securities to our data centers. Production data shall not be replicated or used in non-production environments. We do not use LIVE data in any other environment. We comply with the requirement. We take prior authorization from the concerned authority as per the Media protection procedure before relocation or transfer of hardware, software, or data to an offsite premises. As per Mobile Security Compatibility compliance requirements we have a documented application validation process to test for mobile device, operating system, and application compatibility issues. The California Privacy Rights Act (CPRA) is a state-wide data privacy bill that amends and expands the existing California Consumer Privacy Act (CCPA). The CPRA works as an addendum to the CCPA, strengthening data privacy rights for California residents, tightening business regulations, and establishing the California Privacy Protection Agency (CPPA) as lead enforcer and supervisor. Yes. We are compliant with CPRA, and Our solution will continue to offer full compliance with the new and updated data privacy regime. Yes. We support our consumers to exercise their rights as per the CPRA. Yes. We have implemented all the privacy controls and audited the same with the help of external Auditors. Yes. Please reach out to our sales representative/Xoxoday POC to have access to the CPRA report. No. We do not collect any data from any users across the globe who are not 18 years old. Yes. The data subject can authorize an agent (an "Authorized Agent") to exercise their rights. To do this, the data subject must provide your Authorized Agent with written permission to do, and we may request a copy of this written permission from your Authorized Agent when they make a request to exercise the rights. You may submit a Valid Request by emailing [cs@xoxoday.com](mailto:cs@xoxoday.com). No. We will not sell, rent, or share Personal Data with third parties outside of our company. But Personal Data may be provided where we are required to do so by any privacy laws. SOC 2 compliance is part of the AICPA Service Organization Control reporting platform. The goal of SOC 2 is to evaluate organization security and internal controls around security, availability, processing integrity, confidentiality, and privacy. SOC 2 Compliances are developed by the American Institute of CPAs (AICPA), it defines criteria for managing customer data based on five "trust service principles"—security, availability, processing integrity, confidentiality, and privacy. Yes. Xoxoday is SOC 2 certified organization. We have implemented all the required SOC 2 controls and got them Audited with the help of Certified Public Accountants (CPA). Amazon Web Services (AWS) has achieved SOC 1, SOC 2, and SOC 3 reports. These reports detail the AWS controls environment and implemented controls for AICPA Trust Services Criteria (TSC) and can be leveraged as part of a cloud customer security program. AWS SOC-covered cloud services are audited periodically against the SOC reporting framework. You may reach out to our sales representative/Xoxoday POC to have access to the SOC 2 report. Laika Compliance LLC performs the SOC 2 audit for Xoxoday. The SOC 2 Type I report is valid for one year following the date the report was issued. Yes. SOC 2 is an internationally recognized standard. The SOC 2 report and certification involve an independent audit by a third party. Yes. We do conduct the SOC 2 Audit on an annual basis. The Auditor has validated and tested all the applicable SOC 2 controls as per the compliance requirements. We do not process (Collect/Store) Protected Health Information (PHI). Yes. Xoxoday is compliant with Health Insurance Portability and Accountability Act (HIPAA). Yes. Please reach out to our sales representative/Xoxoday POC to have access to the HIPAA Audit report. Yes. We have implemented the Data Subject Access Rights Procedure to make sure that all the data subjects will have the opportunities to exercise their rights as per the privacy laws. The secure deletion standard like DoD 5220.22-M ECE is being followed and we provide a certificate that the data was properly sanitized from all computing resources and portable storage media. Yes. Xoxoday is GDPR Compliant. We have implemented the Data Subject Access Rights Procedure as per the GDPR and made all the data subject rights available as per the data protection laws. This procedure sets out the key features regarding handling or responding to requests for access to personal data made by data subjects, their representatives or other interested parties. Yes. We validate the compliance requirements of the Sub-processor and obtain the Compliance certificates and audit reports such as – ISO 27001:2013, SOC 2 Type II, ISO 27017, ISO 27701, ISO 27018, Cloud Security Alliance Controls, etc. We conduct the independent Audits for - ISO 27001:2013, SOC 2 Type I, CPRA/CCPA, HIPAA, VA/PT Assessments. Xoxoday maintains a disaster recovery program to ensure services remain available or are easily recoverable in the case of a disaster. Customers can stay up-to-date on availability issues through a publicly available status website covering scheduled maintenance and service incident history. The BCP and DR Plans are tested and reviewed every year. The Xoxoday BCP and DR plans are reviewed and audited as part of ISO 27001 standards and SOC 2 Type II covering availability as one of the trust service principles. Users are not having admin access to their computer machines and only IT Support admins can install or uninstall the softwares. CTOs and Production heads are responsible for safeguarding the customers data. Only authorised individual will have access to the production environment. We delete the customer data upon request/termination of the contract and confirm the secure deletion. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. We clasify the Information assets into Confidential, Restricted , Internal and Public etc.. We maintain the records of all our assets. we logically segregate the tenant's data, and it is segregated with a client-specific key for proper handling and security reasons. We have restricted the ports for all the users as per Xoxoday IT Policy The password needs to be minimum 8 characters long and should contain at least one capital letter, special characters among '# \$ % \* &' and 1 digit Maximum Password Age – 45 days Minimum Password Age – 1 day Computer machines will lockout in 15 mins from the time it became inactive. Yes. Only authorised individual have access. We use best practices and industry standards to achieve compliance with industry-accepted general security and privacy frameworks. We use enterprise-class security features and conduct comprehensive audits of our applications, systems, and networks to protect customer and business data. Our customers rest easy knowing their information is safe, their interactions are secure, and their businesses are protected. Please click here to know about Xoxoday Security framework - [https://www.xoxoday.com/security](https://www.xoxoday.com/security) We are compliant. We monitor the system performance. Yes. We maintain current architecture diagrams that include data flows between security domains/zones All operating systems are hardened as per Xoxoday hardening guidelines. We are compliant. We have deployed our applications on AWS Virtual platform cloud. Please click here for SLA - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view) Appropriate roles and responsibilities have been defined and documented. Finance, Leagl, Admin, Infosec departments are active part of it. Since its SaaS platform is not applicable. Yes. we conduct the testing on frequent basis to comply with the requirements. Yes. Its compliant with ISO 27001 and SOC 2 trust service principles. Yes. We mitigate all the risk identified. We inform the customer if there is any incidents as per the security and privacy laws. Yes. We do conduct an internal Audit. Yes. Privacy and security is a part of the Master Service agreements. Xoxoday is compliant with GDPR, HIPAA, CCPA/CPRA privacy laws. And we inform the customer if there is any data breaches as per the compliance requirements. Yes. We provide report on SLA. We do conduct an External Audit with the help of the independent auditor. Yes. we conduct the assessment on annual basis. AWS is a sub-processor as we are storing data on AWS VPC. And they are AWS SOC 2, ISO 27001, ISO 27017 and ISO 27018 certified We monitor the compliances of sub-processor on frequent basis. We continuosly train employees on privacy and security. Yes. We have member in our organisation with dedicated information security duties. Xoxoday's primary security focus is to safeguard our customers or users data. This is the reason that Xoxoday has invested in the appropriate resources and controls to protect and service our customers. All our employees are having the unique log in IDs. We have installed the firewall for maximum securty and configured to restrict unauthorized traffic All are configured according to security standards as part of the build process Its part of our Internal and external Audits and validated by the indeendent auditors. We have implemented the access control policy and access will be provided only upon need and approval basis. Attached the access control policy. We have track of the changes. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. We have installed Smoke detectors and Fire extinguishers for physical security. security incidents reviewed to capture the root cause. We are SOC 2 compliant and we have engaged Laika Compliance LLC, an independent assessor firm, to conduct a SOC 2 Type 1 and SOC 2 Type 2 examination for the Xoxoday Platform against the Security and Confidentiality Trust Services Categories. Attached the ISO 27001:2013 certificate. We provide Software as a Service.(SAAS). We are ISO 27001 certified and GDPR compliant. Attached the document. We are ISO 27001 certified and GDPR compliant. Attached the document. Since it's a SaaS prodcut and deployed on cloud virtual platform only authorised individual have an access to the our production environment on need and approval basis. We inform the client to revoke access. We use Google workspace and have secure mode of sharing the data. We can manage all the enpoints centrally. We have implemented the security measures to manage the risks introduced during the use of Organization's information assets used for managing Personally Identifiable Information. We have a formal risk assessment process and conduct the risk assessment annually. All the contractors/vendors have signed the NDA and contracts All the necessary clauses has been included in the agreements with regards to Confidentiality, liabilities, termination etc Yes. We do conduct the Risk Assessment every year. Yes. We have implemented the Data security and Information clasification policy. Attached the same. Yes. They have signed for the agreements. We have a biometric systems and access cards. only authorised individual can have access. We have deployed Sensors for fire detection and fire extinguishers to detect and protect from the fire. Yes, we will notify Yes. Our Customer support team will notify. Yes. We create an email accounts only after the approval from reporting managers. We have not outsourced and does not create any email ids Yes. IT Team is responsible. Yes. We have a Email Security Policy and attached the same Yes, we have implemented the security controls for email with the help of Google workspace and installed the end point security for all the laptops of the employees. All the incoming and outgoing attachments are scanned. Yes. Yes, We have implemented the Acceptable Usage Policy and have restricted for usage and access to internet. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. Since our application is deployed on AWS cloud we will ensure the best uptime in the insudtry. Yes. All the changes takes place as per the change management policy implemented. Yes. We have software register and only approved and licensed softwares will be used. Yes, all are up to date. Yes, we have capacity planning and monitor the hard disk space, RAM, CPU etc. All the employees laptop is secured with Bitdefender end point security software Yes Yes. Taken into consideration Annually Yes. Attached the same. We do consider all of these, addition to that we also validate the controls in place with regards to cloud security, BCP, Uptime etc. AWS is ISO 27001, SOC 2 Type II certified and complied with CSA start level 2. Please click here for more details about AWS Compliance Programs - [https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/) Yes. We have an agreement. We have implemented policies and procedures as per ISMS and GDPR requirements. We also conduct periodical Internal and external Audit by the third party Auditor. We have deployed our application on Cloud Virtual platform for maximum security. We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We conduct periodical Vulnerability assessment and Penetration Testing from the Inductry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications. Xoxoday and AWS both are ISO 27001:2013 certified and implemented the change management procedure. We ensure that we follow the policies and procedures with regards to any changes to be made. Yes. AWS is ISO 27017, ISO 27001:2013, ISO 2018, SOC 2 certified. Yes. Attached the AWS ISO 27001 certificate Yes. Tested our BCP plan We ensure that we maintain confidentiality, integrity, availability and privacy of data collected, processes, stored through implementing policies and procedures. And we do conduct the internal and external Audits periodically to make sure that all the controls are working effeectively. Yes Yes Since we have logically segregated the data and ISO 27001 certified and GDPR compliant we do not disclose or provide any of the the customer data. Yes. Audited by the independent Auditor and all the aspects of Privacy, information security, BCP, DR, Production, VAPT has been validated. NO Production Site - No.17, Bhagyalakshmi Square, 2nd Floor, Sector 3, HSR Layout, Bangalore -560102 We have deployed our application on AWS Singapore. Since we have deployed our application on AWS cloud they only provide DR Services. No other location We provide our application to the customer. We have 230+ employees. 100+ employees are involved in the production/devolopment and we have a sepearate team for IT Support and Information security. We have provided separate computers to each employees. Altogether we are having around 250 computer machines. Our application is deployed on AWS cloud virtual platform. We are ISO27001;2013 certified and GDPR compliant.Attached the ISO 27001:2013 certificate. We are SOC 2 compliant and in the last phase of final Audit. Attached the engagement letter that we have with our external Auditors. Xoxoday is ISO 27001:2013 certified, GDPR compliant and SOC 2 type I certified organization and have all the required technical and organizational controls in place and auditred during the internal and external audits. We are ISO 27001 Certified organization. We make sure that all the required records are maintained and compliant with the requirements. Attached the Security Incident Reporting & Response Procedure and Incident Management Procedure We have implemented the Information classification Policy to protect against unauthorised access, disclosure, modification, or other misuse. All our assets are labelled as per the requirement. Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. A strong identification and authentication system and logging systems are deployed and provide a centralized control to administer, monitor and review all critical access. We have a role-based access system through access control policy to make sure that only the authorised individual has access to the required information. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. The approvers are either the Product Heads or respective function Heads are their authorized delegates. We have the Fire alarams, Smoke detectors, UPS, Temperature controler, Air conditioner, etc.. for protecting against the environmental hazards. Yes, all our - both full-time and on-contract are bound by an agreement of non-disclosure and a confidentiality agreement as a condition of employment to protect the customers and tenant's information. We use the CCTV cameras to monitor the building on a 24\_7\_365 basis. All the enterances, exit, restricted areas are under surveilance for security reasons. Yes. We have the Information security team. We are compliant In accordance with Data Protection Laws, we make available to Controller on request in a timely manner such information as is necessary to demonstrate compliance by Processor with its obligations under Data Protection Laws. Upon Controller's written request and subject to the confidentiality obligations set forth in the Agreement, we will make available to Controller a copy of Nreach the most recent third-party audits or certifications, as applicable. We do not agree for the Surprise audits. We have the Buiness continuity and Disaster Recovery Plan in place. These controls has been tested at least annually as per the compliacne requirements. Attached the policies for your referrence. We have the Crisis management is in place. Attache the same. We have provided an option to work from home/remotely due to this pandamic with necessary infrastructure and security. Business continuity plan has been tested on annual basis and audited during the internal and external audits. Atatched the business continuity policy and plan. Generic IDs are not used [Please click here for SLA - https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view) We have the ability to delete the data upon request by the data subject or termination of the contract. Attached the data retension and disposal policy. We have implemented the Business continuity policy and we have the ability to resume our operation from potential threats, Pandemic, flood, fire, earthquake etc. Due this pandemic/WFH situation, VPN access has been enabled with 2FA For such authorized individuals, for ensuring business continuity. We have the required controls in place for working from home or remotely due to this pandemic situation. Its a part of our Business continuity plan and IT Support Head, HR Head, CTO, Infosec Head will be involved in the preparedness activities. We have provided WFH option to all the employees to get protected from COVID 19. We have provided WFH option to all the employees to get protected from COVID 19. We test the Business continuity plan on annual basis. It was tested in the month of Aug 2021 for the last time. It has been well defined in the in the Business continuity policy and plans. Attached the same for your referrence. We inform our customer on any crisis and if that is effecting on our customers. Xoxoday is a data processor. NO. We obtain consent before such activities from the customer. We have the DPA and appropriate controls in place – We are compliant. ISO 27001;2013, SOC 2 Type I Certified and GDPR compliant. YES. We have implemented the Business continuity plans and tested them annually. No. But we are in the process of getting the insurance from the Insurance company. We conduct the internal and External audits on a periodical basis as per the compliance requirements and obtain Audit reports and certifications. We provide the same with the customers. NO. We are not subjected to any actions as such. application by Xoxoday, the RnR platform is a cloud-based SaaS platform hosted on VPC infrastructure of AWS. The data centers are hosted completely in isolation so that the access is limited and controlled. Each instance (EC2 Instance) under fortified VPC network is further conglomeration of Docker Container Web Services and APIs and application layer running on top of it. This helps in managing various aspects and features of application without affecting the functioning of each other and achieving a modular architecture to work as plug and play model. Amazon Cloud Watch is implemented to enable monitoring of the functioning of the application. We have Web application firewall (WAF), IDS/IPS, AWS Guardduty, and the data has been encrypted for security reasons. Attached the Architecture diagram. Xoxoday is ISO 27001:2013 certified and GDPR compliant. Xoxoday is ISO 27001:2013 certified and GDPR compliant. And we follow ISO 27001, NIST, CSA standards and best practices. We have Web application firewall (WAF), IDS/IPS, AWS Guardduty, Coudflare and the data has been encrypted for security reasons. We conduct code reviews as per the compliance requirements. We also conduct the Vulnerability assessment and penetration testing on annual basis with the help of the third party authorised vendor. Attached the latest VAPT certificate and ISO 27001 certificate. Attached the ISO 27001:2013 certificate and 1st Year Surveilance audit report. We did not have any non-confirmities. We are compliant with the data privacy and security requirements. We are having the controls in place with regards to Cyber security, Risk management, crisis management, business continuity, Network security, application security etc. Attached the Business continuity management and Cyber Crisis Management Plan, incident management procedures, SDLC etc. Attached the Business continuity plan and procedure. We test the BCP controls on annual basis as per the compliance requirements and it has been auditted during the internal and external audits. Xoxoday is ISO 27001:2013 certified, CSA START Level 1 and GDPR compliant. And we follow ISO 27001, NIST, CSA standards and best practices. We have Web application firewall (WAF), IDS/IPS, AWS Guardduty, Coudflare and the data has been encrypted for security reasons. We conduct code reviews as per the compliance requirements. We also conduct the Vulnerability assessment and penetration testing on annual basis with the help of the third party authorised vendor. Attached the below policies and procedures - 1. Encryption Policy 2. Password Management Policy 3. IT Policy 4. Information Classification Policy 5. Threat and Vulnerability Management 6. Cyber Crisis Management Plan 7. Backup Recovery Procedure 8. Access Control Procedure 9. Incident Management Procedure 10. Change Management Procedure Data centers are designed to anticipate and tolerate failure while maintaining service levels. In case of failure, automated processes move traffic away from the affected area. These are tested on annual basis. AWS is also ISO 27001, ISO 27017, ISO 27701, ISO 27018, SOC 2 compliant organizatin. Please click here for more details - [https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/) Please click here to know more about AWS security - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/) Please click here to know more about Xoxoday Service level agreement - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view) Please click here to know more about Xoxoday Service level agreement - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view) Please click here to know more about data governance - [https://www.xoxoday.com/gdpr](https://www.xoxoday.com/gdpr) Attached the Risk Management Procedure We have plan for having the cyber insurance. - In progress. Each employee, when inducted, signs a confidentiality agreement and acceptable use policy, after which they undergo training in information security, privacy, and compliance. Furthermore, we evaluate their understanding through tests and quizzes to determine which topics they need further training in. We provide training on specific aspects of security that they may require based on their roles. We have implemented the Information security policy and Disciplinary policy. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently. Please click here to know more about the Application SLA - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view?usp=sharing](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view?usp=sharing) We review and get an approval from the management on annual basis as per the compliance requirements. We have installed End point security on all the computers and monitored and updated on regular basis. Yes. Our tenants can report the Bugs and security vulnerabilities to [cs@xoxoday.com](mailto:cs@xoxoday.com) We also have Bug Bounty Program at Xoxoday and please click here to know more about - [https://www.xoxoday.com/bug-bounty](https://www.xoxoday.com/bug-bounty) Since application is a SaaS platform and deployed on AWS virtual platform cloud NA. We have the full time employees. We conduct the review and update the policies, procedures etc..and take an approval from the management on annual basis as per the compliance requirements. We also communicate all the policies and procesures to all the employees, contractors through HRMS platform. We do not allow to access the infrastructure hosting. All the information security policy and standards been approved by senior management. We have installed the antivirus on all the workstations and servers. Customer data security is an essential part of our product, processes, and team culture. Our facilities, processes and systems are reliable, robust, and tested by reputed quality control and data security organizations. We continuously look for opportunities to make improvements in the dynamic technology landscape and give you a highly secure, scalable system to provide a great experience. Attached the GDPR - Data security policy. We have installed Bidefender endpoint security and restricted the access of external hard drives, USB etc to have restriction on data transfer. we use file integrity and network intrusion detection (IDS) tools to help facilitate timely detection, investigation by root cause analysis, and response to incidents We do not use. Annually We have conducted the BCP test on 6th Aug 2021. Attached the Business continuity policy. We have installed Smoke detectors and Fire extinguishers for physical security. Attached the incident management procedure. All our policies are reveiwed annuaaly and approved by the top level management. security incidents reviewed to capture the root cause. Attached the Security Incident Reporting and Response Procedure Classification of Incidents are done. Attached the Incident Management Procedure No Security breaches till date. We are SOC 2 compliant and we have engaged Laika Compliance LLC, an independent assessor firm, to conduct a SOC 2 Type 1 and SOC 2 Type 2 examination for the Xoxoday Platform against the Security and Confidentiality Trust Services Categories. Attached the engagement letter. Attached the ISO 27001:2013 certificate. We make sure that they have adequate controls in place and meet the security standard. We are ISO 27001 certified and GDPR compliant. Attached the document. We review these to make sure the all the controls in place. We provide access only upon need and approval basis. We use Google workspace and have secure mode of sharing the data. We can manage all the enpoints centrally. Attached the Risk Management Procedure We have a formal risk assessment process and conduct the risk assessment annually. All the contractors/vendors have signed the NDA and contracts All the necessary clauses has been included in the agreements with regards to Confidentiality, liabilities, termination etc The SaaS solution is deployed on Public cloud. Yes Yes. We are using Bitdefender endpoint security. Yes. We use for security reasons Our employees will not have access by default. The data will be accessed only upon need an approval basis. The access is controlled through the AWS Identity and Access Management system that also enforces two-factor authentication We collect only 3 types of the personal Information such as Name, email ID, phone#. , personal data is to be transmitted using firmly approved encrypted systems. We have implemented the role based acccess control to make sure that the acccess has been granted to only authorised individual. Yes. Yes. We inform the client about any security incidents. Yes. Attached Incident management policy and SLA Yes Yes We are compliant. Yes, We are ISO 27001:2013 certified. Attached the certificate. We are SOC 2 Type 1 compliant. The audit has been completed and auditor is working on the Draft audit report. We will be able to share once the report is finalized. NA. But AWS Virtual platform cloud is ISO 27017 and 27018 certified and attached the report. NA. We do not handles the card holder data. the customer will be using the application product and all the information will be entered only through our application. The data sharing between vendor and the customer will take place only through application product. There will be no manual data sharing or transfer. PII will be entered through application and stored it on AWS cloud virtual platform. We store Name, email ID and phone number of the users. We do not have any sub-contractors. We have deployed our application on AWS Virtual platform cloud. And AWS is ISO 27001, SOC 2, ISO 27017, ISO 27018, ISO 27701, CSA Compliant etc.. We have deployed our application on AWS Virtual Platform cloud. application is a cloud based application. We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. All the confidential/PI data are encrypted at rest and in transit with a split key mechanism to ensure that every client's key is unique We do not decrypt the data until and unless if there any specific request from the customer. Xoxoday endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week ("Agreed Hours of Service"). Uptime is measured based on the monthly average of availability, rounded down to the nearest minute. Please click here to know about Xoxoday SLA - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view) Xoxoday has a formal Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) defined and implemented to enable people and process support during any crisis or business interruptions. The BCP and DR Plan is tested and reviewed on a yearly basis as per the compliance requirements. The BCP and DR plan of Xoxoday is reviewed and audited as part of ISO 27001 standards and SOC 2 Audits by the independent auditor. Attached the Business Continuity Plans (BCP) and Disaster Recovery Plan (DRP) documents. Since it's a SaaS platform, there are no process as such. Attached the below mentioned coompliance certifications - Attached the Audit reports. 1. ISO 27001 certificate 3. VAPT Certificates 4. VAPT Audit reports 5. SOC 2 Audit reports. 6. GDPR Data Privacy Impact assessment report 7. California Privacy Rights Act (CPRA) attestation report. 8. CSA STAR LEVEL 1 compliant - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday) We conduct these audit on annual basis and we will share it upon request. We always provide our best service to resolve security incidents / outages. Attached the Service Level Agreement (SLA) Xoxoday is committed to ensuring the integrity, confidentiality, availability, and security of its physical and information assets and maintaining privacy when serving the customers and organization's needs while meeting appropriate legal, statutory, and regulatory requirements. To provide adequate protection for information assets, Xoxoday has built the Information Security Management System (ISMS), enabling everyone to follow these policies diligently, consistently, and impartially. Xoxoday will implement procedures and controls at all levels to protect the confidentiality and integrity of information stored and processed on its systems and ensure that information is available only to authorized individuals as and when required. Please click here to know more about Xoxoday Security - [https://www.xoxoday.com/security](https://www.xoxoday.com/security) We have deployed our application on AWS Virtual platform cloud - Singapore region. We are GDPR compliant. And we have an agreement and Standard contractual clauses (SCC) as per GDPR Compliance requirements. NO NO No. There were no Personal Data Breaches. Xoxoday is committed to ensuring the integrity, confidentiality, availability, and security of its physical and information assets and maintaining privacy when serving the customers and organization's needs while meeting appropriate legal, statutory, and regulatory requirements. To provide adequate protection for information assets, Xoxoday has built the Information Security Management System (ISMS), enabling everyone to follow these policies diligently, consistently, and impartially. Xoxoday will implement procedures and controls at all levels to protect the confidentiality and integrity of information stored and processed on its systems and ensure that information is available only to authorized individuals as and when required. Attached the below documents - 1. ISO 27001 Certificate 2. SOC 2 Audit report. 3. California Privacy Rights Act (CPRA) attestation report. 4. VAPT Certificates 5. GDPR DPIA Assessment report. 6. CSA START LEVEL 1 Compliant - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday) the customer can request the Xoxoday POC for these reports and we will provide the latest Audit reports upon request. We are storing all the customer data on AWS Virtual platform cloud – Singapore region and consider AWS as a Sub-Processor as per EU GDPR. AWS is ISO 27001, SOC 2, ISO 27017, ISO 27018, CSA STAR, ISO 27701 certified organization. Please click here to know about AWS Compliance offerings - [https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/) Scope and functionalities are the part of the agreement. Please click here for SLA - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view) We do not offer any credits/ penalties. We have implemented all the technical and organisational measures to ensure the integrity, confidentiality, availability, and security of its physical and information assets and maintain privacy when serving the customers and organization's needs while meeting appropriate legal, statutory, and regulatory requirements. To provide adequate protection for information assets, Xoxoday has built the Information Security Management System (ISMS), enabling everyone to follow these policies diligently, consistently, and impartially. [ISO 27001 certificate VAPT Certificate SOC 2 Audit reports. California Privacy Rights Act (CPRA) attestation report. CSA STAR LEVEL 1 compliant - https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday We have shared these certifications and Audit reports.](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday) We do not process the data for other purposes than the one specified in the contract, We do not share the data with third parties. But we store it on AWS Virtual platform cloud and we consider AWS as a Sub-processor. We do not disclose any of our customers personal information to any third parties. We reserve the right to disclose PI if required by law or if we reasonably believe that use or disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or comply with a law, court order, or legal process. We reject any non-legally binding requests for disclosure. We process only the Name, phone# and Email ID as mandatory information. We process the information as per the terms of use - [https://www.xoxoday.com/terms-of-use](https://www.xoxoday.com/terms-of-use) We are storing all the customer data on AWS Virtual platform cloud and we operate or provide services from Bangalore, India. We inform the customer of any changes in regards to changes in sub-processors. Xoxoday Terms & conditions - [https://www.xoxoday.com/terms-of-use](https://www.xoxoday.com/terms-of-use) Yes, the cloud provider does have a right to suspend services for specific reasons; more detailed in Section 3.3 of the Master Services Agreement. Section 3.3(a) read along with Section 2 of the MSA The Contract is subject to the laws of India. For disputes arising under this contract, courts of Delhi has an exclusive jurisdiction. Arbitration & Conciliation Act, 1996 We conduct the periodical Risk assessment. and it has been audited during the internal and external audits. We also provide SLA performance report to the customer on need basis. we have the capability to respond to security alerts, and report security vulnerabilities and information security incidents within 24 hours of discovering them [We also have Bug Bounty program - https://www.xoxoday.com/bug-bounty](https://www.xoxoday.com/bug-bounty) We train our employees on their role and responsibilities and also comminicate before joining the organizatin application is an all-in-one employee engagement and motivation platform that offers Rewards & Recognition, Pulse Surveys, 1-on-1 Feedback, Social Intranet and People Analytics in one powerful solution. Information security department is responsible for security initiatives and the Head of the Information security reports to the Board of Director of the company. The policies and procedures have been created, reviewed and approved by the Top level management of the company. The information security policies have been uploaded on KEKA HRMS Application and communicated to all the employees. Attached the screenshot for your reference. Attached the Risk Management Procedure. Attached the internal audit report. Your data is of the utmost importance. All the security mechanisms and policies are established and implemented in such ways that data leak can be prevented, in transit as well as at rest. We have installed Bitdefender endpoint security in all the endpoints. Bitdefender is based on a layered next-gen endpoint protection platform with the industry's best prevention, detection and blocking capabilities, using proven machine learning techniques, behavioural analysis and continuous monitoring of running processes. We have the capability to wipe out the data remotely for all endpoints including BYOD devices. Attached the ISO 27001:2013 certificate and Statement of applicability. We provide tpliance certifications upon request. We use the Software Development Life Cycle (SDLC) process. It is aligned with ISO 27001;2013 and SOC 2 frameworks. During the development and testing security related requirements are specially considered. We have SDLC Policy as per ISMS requirements and we follow General Coding Practice. For example - We Conduct data validation on a trusted system, All cryptographic functions used to protect secrets from the application user. We can also provide uptime status on a need basis. We have proper forensic procedures for data collection and analysis for incident responses Yes, in case specific incidents arise for particular tenants, our logging and monitoring framework allows isolation of incidents. Xoxoday endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week. Uptime is measured based on the monthly average of availability. We do not offer any penalty. Attached the SLA Attached the below documents - 1. ISO 27001:2013 certificate 2. VA/PT Certificate 3. VA/PT Executive report 4. application Architecture Diagram 5. We have deployed our aplication on AWS Virtual platform Cloud and attached AWS Compliance certificates - ISO 27001, ISO 27017 & ISO 27018. 5. application SLA Customer Support is available on all working days (Mon - Fri) between 3.30 AM GMT to 1:30 PM GMT. Xoxoday is – ISO 27001:2013 certified CPRA (California Privacy Rights Act) EU GDPR Compliant CSA STAR LEVEL 1 Compliant – Click here Vulnerability Assessment and Penetration Testing (VAPT) Attached these above certificates and Reports. The backups are automated and taken on a daily basis. We delete the data upon receiving the request from the customer/end users/termination of the contract. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. We have an ELK setup in place to ensure data monitoring in the most optimal manner. The audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. As per the SDLC Policy we follow several distinct stages, including planning, design, building, testing, code review, deployment and maintenance etc. Our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase. It would depend on the criticality of the investigation and the type of service subscribed. Our team will be able to provide the ETA as soon as they receive the request from you and start acting immediately. Yes. You can check this information from the user management option available for Admin console. You can reach out to us with the help of the help center or can write an email to customer support team Yes. We maintain and record the Audit logs and complying with various compliance requirements. Yes. You may reach out to our support team anytime for requesting these records and they would be able to help you out on this requirement. It would depend on the criticality of the investigation and the type of service subscribed. Our team will be able to provide the ETA as soon as they receive the request from you and start acting immediately. Yes. We deployed our application on AWS and AWS provides the data backup service as well. Yes. We are ISO 27001:2013 certified and GDPR Compliant. We have implemented the risk assessment procedure and conduct the risk assessment annually as per the compliance requirements.Risk assessment is used to identify the risks encountered by the information-processing facilities (or individual system components). The aim is to estimate the impact and probability of a threat occurrence. The risk assessment procedure is having Risk, Likelihood and Impact. The risk ranking is done based on the Residual Risk Rating such as High, medium and low. Attached the Risk Management Procedure for your reference. Risk Management Procedure has been used to validate the security compliance of AWS. AWS Compliance certifications and attestations are assessed by a third-party independent auditor and result in a certification, audit report, or attestation of compliance. AWS is ISO 27001, SOC 2 Type II certified and complied with CSA start level 2. Please click here for more details about AWS Compliance Programs - [https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/) Yes. We can use the risk assessment framework adopted by NSE for cloud service risk assessment.. Please provide the same. We comply with this requirement. The risk assessment procedure has defined the Risk Acceptance Criteria, Benefits, Components, Impact Rating, Risk Treatment, Risk Acceptance etc and all the controls identified in our risk assessment as per the industrial standard like ISO, SOC2, NIST, GDPR etc. Sure. We are ISO 27001;2013 and GDPR compliant. We have policies and procedures in place with all the required compliance controls. We comply with this requirement. We conduct annual audit by the independent auditors to test the controls in place with regards to Information Security management system(ISMS) and also for testing the service organization controls(SOC)covering the principles of Security, Availability, Confidentiality, and Privacy. AWS is also SOC 2 certified. Sure. Attached the ISO certificate and we are in the Audit process for SOC 2. we will provide the same once the audit is completed. We are ISO 27001;2013 certified, GDPR compliant and in the process of SOC 2 audit. We make sure that our customer data is safe and secure and meet all the compliance requirements and industry best practices. Xoxoday has built the Information Security Management System (ISMS) which includes the respective policies to be followed in a diligent, consistent, and impartial manner. Our legal team would review and agree the terms and conditions. We agree. NSE can review. Our legal team would review and agree the terms and conditions. We will inform NSE if there is any breach. The data isolated between customers. We use logical data isolation with the help of company specific encryption keys.We use TLS1.2 encryption for Data in transit and AES256 for Data at rest We agree. We have implemented the data breach notification procedure. We agree. We will notify NSE. We agree.Currently, we do not have any plans as such. All the data will be stored on AWS cloud We have the disposal policy in place and implemented mechanisms for secure disposal and removal of data. We agree. We will delete the data upon termination of the contract or request and confirm. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. We have implemented Asset Management Procedure in place and maintain all the records of IT Assets like, hardware, software, licenses, accessories etc. We review and update the inventory as per the Asset management policy. The database server, application server or storage devices hosting NSE's data & information is not made available publicly. We isolate our machines, network and storage with respect to the AWS Standards in order to keep it safe and secure Yes, one can write to us at our 24\*7 support team at [cs@xoxoday.com](mailto:cs@xoxoday.com) We help the clinets in setting up from both admin and end user side, and traiing is also provided on how application can be used for hasslefree awards distribution We provide trainging over internet , if possible we provide telephonic assistance also. Yes we provide "on demand training" , this incur no additional cost to the company We have a 24\*7 available support team, once a ticket is generated , It is assigned to one of the cs team executive and we intent to solve the issue within next 24hrs. Xoxoday employees and third party would have an access. We provide acess on case to case basis as per the Information security and access control policy. We also have role based access system to meet the compliance requirements of the data security . The data is hosted on Amazon Web Services (AWS) We do conduct employees and contractors background verification as per the compliance requirements before onboarding process. We will onboard them only after passing the background verification. We are ISO 27001:2013 certified organization. We conduct periodical review of the access provided and make the necessary chages as per the Role based access management and access control policy. We also conduct Internal and external audits in a timely manner. Our Information security compliance policies and procedures are established and implemented to enforce two-factor authentication We are ISO 27001:2013 certified organization The User access are monitored and recorded internally as per the compliance requirement and Access Control Procedures. Yes we have implemented intrusion detection tools, we ensure timely detection and investigation in a prompt manner. Yes. file integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation. Yes. Implemented SIEM Yes. All the controls are audited annually. Yes, We will share the Data protection policy. Access control policy and Information security policies Size of the team is 5 and all are having 5+ years of experience personal data is stored are registered databases that comply to all necessary inputs of a standard inventory repository and its transit scrambled for maximum security. We use AWS Platform for storing the data. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records. As per the Information security policy and Data protection policy only the authorised individual have an access to the data through internal approving and ticketing system. No. Planned downtime will not be calculated uptime No. Planned downtime will not count against the SLA We have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working. We test it annually once as per the compliance requirements. Xoxoday's architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows. We have Business Continuity Policy and Business Continuity Management Procedure in place and tested periodically. And also our Policies has been reviwed and Audited annually. Yes. We have implemented IDS/IPS, Firewall and our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting Yes. We have procedures in place to support Government We have the clauses for suppporting local government and law enforcement requesting customer data in data protection policy. We will share the copy of it. We have deployed our application on Amaon web services (AWS) AWS is designed to help us build secure, high-performing, resilient, and efficient infrastructure for our applications. AWS is also ISO 27001:2013 and SOC 2 type II Certified and provide all applicable security to the data center. Yes. We have industry approved vendor called Appknox for Vulnerability assessment anf Penetration Testing. Appknox performs Static, Dynamic, API, and as well as Behavioral Analysis. And they helps to detect and address security vulnerabilities. We collect only personal information through our application. We collect name, email ID and mobile numbers. Yes. We have capabilities to anonymize data. By Anonymization users are able to make use of sensitive information without having access to the identifiable data items. And its used within a secure environment with employee access on a need to know basis. No. we do not have it in hard copy Yes. We conduct vendor Risk assessment and also external Auditor validate the critical vendor documentations during the annual and Internal Audit. Yes. We have Information Security Program Yes. We review Information Security Policies every year. Yes. We have Information security risk management program Yes. Our management is supportive and evaluate, Recommend and take action on security risks Yes, we have Information security team and the Infosec head is reporting to Chief Operating Officer of Xoxoday. Yes Yes. Please visit here for more details - [https://www.xoxoday.com/bug-bounty](https://www.xoxoday.com/bug-bounty) Yes. All the endpoint laptops that connect directly to production networks centrally managed All the employees laptop is secured with Bitdefender end point security software. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory. No. sensitive or private data never reside on endpoint devices. This is enforced throgh access control policy. We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. Yes. Our incient response plan is tested every year as per the ISMS requirements. We follow SDLC policy during the design phase of devolopment. See SDLC procedure attached We have SDLC procedure and Information System Acquisition Development and Maintenance Procedure. Devolopers are trained on the Secure Coding Practices as soon as they joined our organization We conduct vendor risk assessment and collect all the required security policies, procedures, VAPT reports, ISO 27001, SOC 2 reports. And also our internal and exteranal auditors validate the security controls of our crtical vendors during the Audit. NO NA. We do not have custom-built software Yes Internal Audit has been conducted by the inhouse Infosec and ISMS Lead Auditor. All the projects, business processes and ISMS controls has been included in the scope and opportunity of improvements has been communicated to all the respective teams with the remideiation plan. And the frequency of the Internal audit is annually. We have the external Auditor for ISMS Audit. All the projects, business processes and ISMS controls has been included in the scope and opportunity of improvements has been communicated to all the respective teams with the remideiation plan. And the frequency of the external audit is annually. See ISOIEC 270012013 Certificate and Internal Audit report attached. NA. We do not use for own purposes Yes Yes. All the employees and third party service providers are required to sign Confidentiality Agreements to protect customer information as per ISMS compliance requirements. We have dedicated IT Team and Admin team who looks after the hardware security and, we have implemented the security controls as per the ISO 27001:2013 and SOC 2 Compliance requirements. We are hosting our application on AWS, and they are providing physical security to our data centre. We have Asset Management Procedure in place to identify, classify, label, and handle the Information and Information assets according to their criticality and sensitivity. We have Media protection procedure to handle the locally stored data as per the Information security compliance requirements. As per the Physical and Environmental Security policy we have security guards and CCTV Camera's to safeguard the office building and also to provide an access to the building only for the authorized individuals. We also have Media protection policy which also defines on how to handle the Paper documents as per the compliance requirements. Physical documents are handled with at most care and followed the policies and procedures of an organisation to make sure that the data is protected. We have Physical and Environmental Security policy and Vendor management guidelines in place and working effectively. We have implemented controls on Physical entry, Securing offices, rooms, facilities, Working in secure areas, Delivery and Loading areas etc. Only the authorised individuals will get an access upon verification. And we also conduct periodical verification of the effectiveness of these controls periodically through internal and external Audit. We provide access to the outsiders or suppliers on approval and escorting mechanism of vendor management guidelines by issuing the access cards. All our assets are classified, labelled, and maintained in the register by our IT Team. Access granted only to, authorized individuals. We have locked environment for our hardware's which would store the data. We also have implemented the Media protection procedure to protect the data which are stored physically. Yes. Backups are stored in a safe place. We have backup Recovery Procedure and implemented the controls to protect the organization information asset from the damages that may be caused due to failure of hardware system, corruption of software, breaches leading to data destruction and or not being able to retrieve and use. We predominantly work on cloud-based infrastructure and the teams may consider adoption of Amazon Web Services which provides the Backup and Restore services to build scalable, durable and secure data-protection solutions. AWS claims the following benefits and the teams may evaluate the benefits to the respective context that may lead to realize the following outcomes: 1. Data Type and Durability 2. Flexibility and Scalability 3. Security and Compliance The following AWS based offering for the following use cases offered by AWS may be considered based on the contractual needs of the subject under consideration: 1. Hybrid Cloud Backup 2. Data Lifecycle Management 3. Tape Replacement 4. Global Data Resiliency 5. Data Backup 6. Archive & Compliance We are ISO 27001:2013 certified and GDPR compliant organization. We have Information security policy and Data security policies in place with regards to data protection. We make sure that the below principle of data security has been followed as per the compliance requirements. 1. Fairness and lawfulness When personal data processed by us, we make sure that the individual rights of the data subjects must be protected. We will ensure that the personal data is collected and processed in a legal and fair manner. 2. Confidentiality - Restriction to a specific purpose We make sure that the any processing of personal data should be lawful, fair, and transparent. Personal data will be processed only for the purpose that was defined before the data was collected. Subsequent changes to the purpose are only possible to a limited extent and require substantiation. 3. Transparency We make sure that we maintain the transparency with regards to the data collected, stored and disposed. We also provide rights to data subjects as per the GDPR compliance requirements. For ex - Right to Rectification, Right to Portability and Right to be Forgotten. 4. Integrity and data security Personal data is subjected to the data secrecy. We have controls on confidentiality, Integrity and data security. We follow secured suitable organizational and technical measures to make sure that the data is protected from an unauthorized access, illegal processing or distribution, as well as accidental loss, modification or destruction etc. Sensitive data - We do Inform involved parties about how we will process their data Inform involved parties about who has access to their information Have provisions in cases of lost, corrupted, or compromised data Allow involved parties to request that we modify, erase, reduce or correct data contained in our databases. Sensitive data - We do not Communicated informally. Stored for more than a specified amount of time. Distribute to any party other than the ones agreed upon by the data's owner (exempting legitimate requests from law enforcement authorities. In addition to ways of handling the data the company has direct obligations towards people to whom the data belongs. We have controls in place to protect the information or to maintain privacy. We conduct Data Privacy impact assessment and Audits periodically as per the compliance requirements. We have Personally Identifiable Information Policy, Data Security policy, Data Subject Access Rights Procedure, Data Retention and Disposal Policy as per GDPR compliance. We conduct periodic vendor risk assessment. Information security documents are validated by theiInternal and external auditors during the assessments. Yes. We have an access control policy. The policy is attached for reference. Only authorised employees will have access to the data. Yes. Xoxoday is ISO/IEC 27001:2013 certified organization. See certificate attached. Yes. We have a well-defined policy for roles and responsibilities. We have communicated each employee about their responsibilities across the organization. We do maintain appropriate contracts with relevant authorities and ensure that applicable regulations are complied with Yes. We provide these rights to the data subject as per GDPR Yes. We conduct internal and external audits and all the applicable controls have been validated as per the compliance requirements. Yes We have a media handling procedure. See attached for reference. No. We do not transfer the data outside our organization. Yes. See Infrastructure Change Control Procedure attached. Yes. Security inceidents will be reported by our Information security team or customer support team within 48 hours. We have implemented physical security controls as per the compliance requirements. We have CCTV, access cards, security guards for monitoring and only authorised individual have access. Segregation is done for production and non-production or Testing environments. We maintain the test accounts seperately and delete or terminate the accounts immediately once the testing is completed. Only Admins have an access to create these tests accounts on need and approval basis. We have implemented the Roles and Resposibilities policy and defined the Duties of all the system users and segragated based on the defined roles. Only authorised individual will have an access to the Information system on need and approval basis. We maintain these records for Audit purposes. We have controls in place to monitor the user access system. We have implemented Role based access management system through access control policy. Our application also supports Role based access control system to make sure that only authorised individual will have an access to the Information system on need and approval basis. We maintain these records for Audit purposes. We are Compliant. We monitor these controls on a periodical basis and also during the internal and external Audits. Successful and failed login attempts will be logged, we use privileged accounts are used only for system administration activities,we remove default credentials and use the new credentials for all our systems. We use Multifactor authentication menthods to make sure that only authenticated individual have an access to the Information system wherever strong authentication is required. We use Biomentric verification and access cards methods for physical security purposes. We have these controls in place. We have a restriction for Physical access, monitor these access periodically and validate to make sure that only the authorised individual have an access. The credentilas has been comminocated via secured mode to make sure that confidentiality is maintained. We are Compliant.These controls are audited during the internal and external Audits. We are Compliant.Only authorised individual will have an access. We are cothe customerant. We maintain the records of Audit logs. We have restricted the access of external harddrives, USB etc for all the systems through Active directory and End point security. We have the security controls in place. We have installed the firewalls to monitor and control the incoming and outgoing network traffic based on predetermined security rules. It helps us to establishes a barrier between a trusted network and an untrusted network. We have implemented the asset management procedure to identify, classify, label and handle the Information and Information assets according to their criticality and sensitivity. We have labeled the aseets in order to identify and make sure that the access control permissions are maintained. we have implemented intrusion detection and prevention tools, we ensure timely detection and investigation in a prompt manner. These are integrated with security operations/SIEM solutions. We take an approval from the concerned authority before procuring the equipment or routing connections and test the same before installing it. All the network devices are securely configured and we always make sure that we monitor the same on regular basis and take appropriate action on any detections. We use vendor supplied softwares without any changes wherever feasible, if all the security controls are in place. We consider these factors before making these changes to the softwares. Yes, we test the changes made on testing environment before moving it to a production environment. Only authorised individual have an acces to the approved information assets. we are compliant. We document or have a track of all the changes made to protect the information system. We are compliant and have these controls in place. We have the appropriate clauses in the agreements wherever necessary. We provide guidance for using our products appropriately and take all the possible benefits. We have the controls in place. All the Critical patches will be deployed immediately We inform our customers on the vulnerabilities wherever is required from the compliance perspective. Our product is free from dormant malicious programmes We test the systems before deploying into operational environment. We have implemented the System Devolopment Life Cycle procedures and all the testing of new features are documented. We conduct security assessments before accepting the products and take appropriate approval to make sure that all the security requirements are met. All the test results are documented. We record these in the Risk register and documented before purchasing the product. We make sure that these are met before acquiring and products. The customer responsible staff can confirm upon validation of the security requirements. All the design and implemetation has been documented. We conduct the security Risk assessment in order to identify and mitigate the risks. We have kept Testing and production environment seperately. We do not use any data from our production environment for testing purposes. All our contracts or agreeements are having appropriate clauses with regards to security compliance, privacy, Audit requirements etc. we use only licensed softwares or assets We are compliant. We maintain these records for Audit purposes. We have not outsourced. Attached the Information Security Manual. It prescribes the policies that govern the management and administration of the Information Security Management System (ISMS) for application.It specifies the scope and the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving the information security controls. We have not subcontracted or outsourced any of services with regards to the product. We have documented the Transfer of Information and it's a part of our Information security policy We do not transfer the data. But if its necessary it will be done only upon the approval of the management. We have documented the Transfer of Information and it's a part of our Information security policy We do not transfer the data. But we follow these compliance requirements if there are any data transfers. We have implemented the Information security and Data security policies in order to make sure that we secure our organizational and customers information. We maintain these records for Audit purposes. We monitor and audit the logs. We are complied. We have controls in place to make sure that Information system is protected. We conduct the Risk assessment to identify and mitigate the risks involved. We use Google workspace as email solution and adequate security features has been enabled to make sure that Information system is protected. We do not connect.NA We make sure that all the controls and compensatory controls are in place in order to protect against the Security threats. We have implemeted the risk management procedure and defined the Risk Treatment, Risk Treatment, Risk Mitigation, and Risk transfer etc We have implemeted the risk management procedure and defined the Risk Treatment, Risk Treatment, Risk Mitigation, and Risk transfer etc We implement the Compensating security controls wherever measures cannot be applied due to technical or operational infeasibility. We maintain these records for Audit purposes. It's a part of our Internal and external Audits. We make sure that these controls are in place and security has not been degraded below the accepted level. We also validate these controls during our internal and external Audits. We have implemented the role based access system and change management policy in order to make sure that we provide an access to an individual only upon need and approval basis. All the changes has been tracked and maintained the records for audit purposes. We have a up to date records of all the assets used. We make sure that we follow the Industry best practices and security standard to make sure that we secure the information asset. We make sure that we follow the existing security controls and implement the compensatory controls to make sure that the information system is secure. We have implemented the control. We conduct the Risk assessment to identify and mitigate the risks involved. Compliant.We review and validate these controls on a periodical basis and These are part of an Internal and external Audits. Compliant.We review and validate these controls on a periodical basis. We maintain these records for Audit purposes. We have the required security controls in place. We do not use outdated computer hardware, software, technology, services or practices We upgrade the systems make sure that do not use outdated computer hardware, software, technology, services or practices We have installed the end point security software on all the computers and servers to keep the computer and personal information protected. We have installed the end point security software on all the computers and servers to keep the computer and personal information protected. We are compliant. We have enabled these features. We have installed end point security softwares to safeguard from attack scripts, viruses, worms, Trojan horses, backdoors and malicious active content. We also conduct periodical scanning in order to make sure that all the information assets are safe. These are centrally managed and have control on all the end points. It is available on need to know basis We make sure the Vulnerability assessment has been conducted for our products as per the compliance requirements. We are compliant. the customer Sensitive information will not be exposed to the general public. We document and maintain all the security issues. We are complaint. We are compliant. We have clasified, labeled our assets and periodically monitored. All the logs and realtime trafic is monitored. Implemented. We are compliant. These are all part of CSP agreement. We have these controls in place as a part of our Business continuity plan. We have these controls in place as a part of our Business continuity plan. It has been tested periodically and part of our internal and external Audit. We have conducted the risk assessment as per the industrial standard. Agreed. We will sign the NDA SLA can be documented and agreed by the both the party. Only authorised individual have an acces to the approved information assets. We allow our customer to audit but atlease 30 days prior notice with the scope of the audit needs to be communicated Its documented as per the Risk management procedure. We have all the details in SLA We can make our audit reports available We maintain appropriate reports and records, to monitor and measure the compliance with the security requirements. We make sure that we follow the risk management procedure and take these factors into consideration. We have these in place and tested annually. We have these in place and tested annually. Our BCP/DR plan supports this. We review these on annual basis We have cmmunicated to all the internal and external parties. It's a part of Business continuity documents and attached the same for your reference. The BCP Test and lessons learned has been documented. It's a part of BCP documents and we review and update when changes takes place. These are part of internal and external audits We have implemented the Corrective Action Procedure. We have implemented the Corrective Action Procedure. We review rhe corrective action taken. We conduc the security assessments by the Internal and external auditors We share the data with our Internal and external auditors We make sure the Assessments and Audits will be conducted and reported independently. All the Sensitive information shall be handled as per Policies and procedures implemented. We have defined it in our compliance policy and Corrective Action Procedure We allow our customer to audit or assess but atlease 30 days prior notice with the scope of the audit needs to be communicated We continuously monitor and improve Information security framework to make sure that we safegurd the Information and all the controls are in place. We make sure that we brings these improvements to Information security systems from the incidents reported and audit observations etc We have implemented the corrective action plan procedure and review the policies and procedures on annual basis. It can be included in the agreement and our legal team will review and confirm Statement of work will have a details of product/service to be provided We can include the service levels in the agreement. We are not currently having an options for service credits/liquidated damages, if SLA are not met. We make sure that we have all the controls in place. We will do this as part of the agreement We are a multi tenant SAAS system and all our logs will contain data of all customers. We will have our own log monitoring and security analysis. Attached the BCP/DR documents We end point security in place We allow our customer to audit, but atlease 30 days prior notice with the scope of the audit needs to be communicated We have deployed our application on Amazon web services (AWS) Virtual platform cloud. AWS provides data center security to our application. AWS is ISO 27001;2013, ISO 27017, ISO 27018, SOC 2 certified organization. Xoxoday is also ISO 27001:2013 and GDPR compliant organization. Only the authorised individual have an access as per Access control policy. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access. Xoxoday's architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows. Since our services are delivered via. Web, the upgrades and updates to the services are seamless and usually do not involve any actions from the end-users. We try to release our product hotfixes once every week & major features once every month. Yes. Annually once. Yes. We are ISO 27001:2013 and GDPR Compliant. We are also compliant with SOC 2 type 1 and on the last phase of Audit. We will share the report once we have it from the Auditor. Attached the ISO 27001 certificate and engagement letter that we have for SOC 2 Audit. We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it's linked with the SSO/Active Directory All the employees initially inform the IT Support team through ticketing systemb the Infosec manager and Final level will be DPO and the management. The time of support ranges depends on the level of service. RTO and RPO is - 6 mins our products comply with all the industrial benchmarks and standards when it comes to the Software Development Life-cycle (SDLC). All software development procedures are supervised and monitored by Xoxoday so that they include: security requirements independent security review of the environment by a certified individual code reviews Quality monitoring, evaluation, and acceptance criteria for information systems, upgrades, and new versions shall be established and documented for the clients' reference. The data centers are hosted completely in isolation so that the access is limited and controlled. Load balancer allows shifting incremental load and can auto scale based on data load experienced by application. Each instance (EC2 Instance) under fortified VPC network is further conglomeration of Docker Container Web Services and APIs and application layer running on top of it. This helps in managing various aspects and features of application without affecting the functioning of each other and achieving a modular architecture to work as plug and play model. Amazon Cloud Watch is implemented to enable monitoring of the functioning of the application. The data is encrypted using 256-encryption based SSL certificate. To manage security of data Xoxoday plans a quarterly VAPT based security audit of application. We have implemented policies and procedures as per ISMS and GDPR requirements. We also conduct periodical Internal and external Audit by the third party Auditor. We have deployed our application on Cloud Virtual platform for maximum security. We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We conduct periodical Vulnerability assessment and Penetration Testing from the Inductry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications. We use logical data isolation with the help of company specific encryption keys. Data in non production environment is not updated with the production data. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256 As per the Information security policy and Data protection policy only the authorised individual have an access to the data through internal approving and ticketing system. We comply with Information security compliance - ISO 27001;2013, SOC 2 and GDPR Our product is ISO 27001 and GDPR compliant and have the features. We have health checks along with Self healing mechanisms in place 99.99% We use logical data isolation with the help of company specific encryption keys. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256. We have the ability to logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant's data. our network environment is designed and configured to restrict any communication and connection between the tenant's environment. Yes. We have the controls in place. We have blocked connecting Hard disk, USB, CD ROM etc to computers and all the devices are centrally managed. The data is only stored on our application and its deployed on AWS Cloud. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records We are a SAAS solution. We are cloud hosted. We use a variety of tools and plugins integrated with Prometheus & Cloudwatch along with health checks for facilitating our uptime/service availability Xoxoday's architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows. active-passive Yes. we have implemented the cookies policy Yes, we have the access controls Yes Yes, we have the access controls Yes. Users can updated their information Xoxoday - application platform has been integrated with Darwinbox with the objective of creating a reward system for employees. Organizations that are using DarwinBox will not only be able to automate their HR processes but can also reward employees to keep them motivated and engaged. Xoxoday application offers a unified rewarding platform that helps organizations build a winning organizational culture through reward and recognition programs that have a global catalog consisting of products and experiences from more than 700+ brands. Please click here to know more - [https://xoxoday.gitbook.io/application/developer-resources/integrations/darwinbox-+-application](https://xoxoday.gitbook.io/application/developer-resources/integrations/darwinbox-+-application) Yes. Xoxoday's primary security focus is to safeguard our customers or users' data. This is the reason that Xoxoday has invested in the appropriate resources and controls to protect and service our customers. We have an Infosec Manager who is responsible for Information security and reports to the Board of Directors of the company. All the job descriptions, role and responsibilities has been documented as per the compliance requirements. Xoxoday has developed a comprehensive set of security policies covering a range of topics. These policies are shared with and made available to all employees and contractors with access to Xoxoday information assets. Each employee, when inducted, signs a confidentiality agreement and acceptable use policy, after which they undergo training in information security, privacy, and compliance. Furthermore, we evaluate their understanding through tests and quizzes to determine which topics they need further training in. We provide training on specific aspects of security that they may require based on their roles. We spread awareness about the Information security among the employees through posters in public areas, emails, training and orientations etc.. Yes. All new hires are required to sign Non-Disclosure and Confidentiality agreements. The Employee expressly agrees that he/she shall not use Confidential Information provided by the Company in the development or delivery or for personal gain from providing any products or services for his/her own account or for the account of any third party. The NDA signed will be valid till the termination from an employement. Yes, We have implemented the process for termination from an employement. Once the employee is terminated all the access will be revoked, IDs are disabled, assets are returned and recorded as a part of the exit clearance. We have implemented the access control procedure and all the access will be revoked upon termination or transfer of an emplyees as per the compliance requirements. Anti-Virus is deployed in all systems and servers for protection against virus and malware. We use Bitdefender end point security for protecting the systems from virus and this has been updated on daily basis and centrally managed. 1. Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com) to raise a ticket, if you happen to notice any potential security issue whilst meeting all the required criteria in our policy. 2. The validation of the reported issue in terms of severity & authenticity will be done by our security team in around 90 days. 3. Post validation, steps will be taken to fix the security issues in accordance with our security policies. 4. The owner of the ticket will be informed once the issue is resolved. Security Severity has been categorized as High, Medium and Low. Once the reported vulnerability is closed we will conform the same. Reports can be generated by the admins through the application. If there are any additional support needed, our customer support team would be able to help and guide on generating report. We do not use any in-house devoloped applications. We have deployed our application on AWS cloud virtual platform. And AWS is SOC 2, ISO 27001, ISO 27017 and ISO 27701 certified organization. Shared the certificates. [Please click here to know more about API Documentation - https://xoxoday.gitbook.io/application/user-guide/for-admins-1/xoxo-links/xoxo-link-apis https://xoxoday.gitbook.io/application/developer-resources/storefront-integration/api-endpoints](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis) We have implemented the Web application firewall, IDs/IPs and amazon guard duty etc for maximum security. OAuth2 is used to authorize all API requests. We also conduct code review to make sure that the APIs are secure. Yes. Our employees are having required education and certifications to perform the job. We do conduct Internal and external Audit very year Yes, It's a part og our ISMS training. Attached the training calender as an advace. Xoxoday is compliant with - ISO 27001:2013, CPRA (California Privacy Rights Act), SOC 2 Type I, CSA STAR Level 1 and GDPR(General Data Protection Regulation). Attached the below mentioned documents. 1. Xoxoday ISOIEC 270012013 Certificate 2. Xoxoday SOC 2 Type 1 Report 2021 3. Xoxoday VAPT Certificate (Conducted by 3rd party vendor) 4. Xoxoday application VAPT Report (Conducted by 3rd party vendor) 5. Xoxoday CPRA Attestation Report 6. CSA STAR LEVEL 1 Compliant - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday) We have deployed our application on AWS Virtual platform cloud. The AWS Compliance Program helps to understand the robust controls in place at AWS to maintain security and compliance in the cloud. Attached the below compliance certificates and Audit reports – 1. Amazon Web Services ISO 27001 Certificate 2. AWS ISO 27017\_certification 3. AWS ISO 27018\_certification 4. AWS SOC 2 Report 5. AWS SOC 2 Type I Privacy Report 6. AWS CSA STAR Certificate Yes. We follow ISO 27001:2013, SOC-2 and GDPR We are ISO 27001:2013 certified and GDPR Compliant. Yes. We are ISO 27001:2013 certified and GDPR Compliant. We are also complied with Cloud Security Alliance (CSA) STAR level 1. Its SAAS Solution and available 24\*7 It's a web application. And it can be presented over the calls like MS Teams, Zoom, Google meet etc. Yes. We have an integration with other applications and provide secure communications. Yes Yes. Files will be transferred securely. Yes. The solutions integrated with other solutions like Zoho CRM, HubSpot, Darwin box, SurveyMonkey, Freshdesk etc NA. It's a SAAS Solution and does not require. The data will be in our control. And AWS Cloud provide service for deploying our application. AWS is also ISO 27001 and SOC 2 certified organization and adhered to the data governance. It's a part of our Risk assessment and we validate the compliance requirements of AWS cloud virtual platform annually. We have implemented all the required Infosec Policies and procedures as per ISO 27001:2013, GDPR and SOC-2 We perform Internal Audit and external Audits annually. We also conduct Security assessments and testing like Vulnerability assessment and Penetration testing every six months. Yes. We communicate these assessment results to clients on a yearly basis. We have the arrangements in place. Storage Period would be as per regulatory conditions. Personal data can be deleted based on a formal written request. Xoxoday would delete the data within 30 days of receiving the request. We will delete the data of the customers upon the termination of the contract and Our data cleansing process goes through an organized purge. Once the data is purged, it's purged from all places We have implemented all the SOC controls and in the last phase of Audit. We would be able to provide SOC 2 Type I report in next 2-3 weeks We have BCP/DR Policy as per the Infosec compliance requirements and we conduct the BCP test annually. See Business Continuity Management Procedure attached. See attached Incident Management Procedure attached Yes. An independent security third party audit been completed by "TUV NORD". The last last day of Audit was 29th June 2021 We have establised the Information security management systemIt specifies the scope and the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving the information security management system (ISMS) at Xoxoday. Xoxoday is committed to ensure Integrity, Confidentiality, Availability and Security of its Physical and Information Assets and also maintaining privacy for serving the needs of the customers and organization while meeting appropriate legal, statutory and regulatory requirements. Attached the Information Security Management System Manual. We have the Data security Controls in place. We have implemented IDS/IPS, Firewall and our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting. We have Cloudflare web application firewall for maximum security of data. We have implemented the role based access control system to make sure that the data os available only to an authorised individual. Nreach Online Services Pvt ltd, respects the individual right to their personal information and is committed to use minimum personal data with transparency, accuracy & protection of confidentiality, integrity, availability, privacy, authenticity & trustworthiness, nonrepudiation, accountability and auditability of the data received, stored, processed and destroyed for business purposes. Atatched the Xoxoday GDPR Data Security Policy We are compliant. We collect the data only throigh our application. We have role based access system to make sure that only the authorised individual have an access to the required information All the devices and emails are having adequate security controls. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. We have installed the firewalls to monitor and control the incoming and outgoing network traffic based on predetermined security rules. It helps us to establishes a barrier between a trusted network and an untrusted network. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory for more security. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.We have SDLC Policy as per ISMS requirements and we follow General Coding Practice. For example - We Conduct data validation on a trusted system, All cryptographic functions used to protect secrets from the application user.We also have Implemented least privilege; restrict users to only the functionality, data and system information that is required to perform their tasks. Yes. We have Implemented the SPF/ DKIM/ DMARC effectively. We are compliant. We have implemented the Password Management Policy We store password hashed. We have SHA512 hash with unique salt for every password. The password needs to be minimum 8 characters long and should contain at least one capital letter, special characters among '# \$ % \* &' and 1 digit. Maximum Password Age is 45 days. User IDs and passwords transmit through stringent checks in an encrypted format that complies with the current Technical Security Baseline Standards. All the user can set their own password from the very first login attempt. Passwords once used cannot be reused with the password history technique in order to disallow the reuse of old passwords. [AWS is ISO 27001, ISO 27017, ISO 27701, SOC 2, PCI DSS Level 1 certified organization. Please click here for more information about AWS Audit and certification - https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/) We inform Fincare if these regulatory authories agreed to inform. Yes. 30 days prior notice and scope of the Audit needs to communicated. We are a multi tenant SAAS system and all our logs will contain data of all customers. We will have our own log monitoring and security analysis. Its a SAAS product and we use We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Yes Yes [We store data on AWS Singapore.AWS is ISO 27001, ISO 27017, ISO 27701, SOC 2, PCI DSS Level 1 certified organization. Please click here for more information about AWS Audit and certification - https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/) We do not own the data centers. We deploy our application on AWS cloud virtual platform. [We store data on AWS Singapore.AWS is ISO 27001, ISO 27017, ISO 27701, SOC 2, PCI DSS Level 1 certified organization. Please click here for more information about AWS Audit and certification - https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/) Attached the ISO27001:2013 certificate. We do not collect and store any Payment card details. PCI DSS is not applicable for us. We inform the client if there is any changes of the design that impacts security posture of the system. We take steps to securely develop and test against security threats to ensure the safety of our customer data. We maintain a Secure development Lifecycle, in which training our developers and performing design and code reviews takes a primary role. In addition, Xoxoday employs third-party security experts to perform detailed penetration tests on different applications. application is ISO 27001, GDPR, CPRA/CCPA, CSA STAR certified. Our technical team maintains these records. We consuct the code review as per the compliance requirements and maintain the code repository. Attached the SDLC Proedures. Compliant. Since application is a SaaS Platform this would be not applicable. Since application is a SaaS Platform this would be not applicable. Since application is a SaaS Platform this would be not applicable. We are compliant with the requiremenrts. We do not transfer manually. NA And we use Google workspace for emailing solution. cryptographic keys are protected. Compliant. We do not store any PHI. The PII(name, email ID, phone#) are encrypted. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. We store only the PII(name, email ID, phone#) and does not store/process PHI & PCI. We are compliant with ISO 27001, CCPA/CPRA, EU GDPR, CSA etc. Attached these compliance certificates/audit reports. Yes, all the mechanisms related to security and policies are implemented to facilitate timely decision and investigation by root-cause analysis. These incidences are analyzed with network intrusion detection (IDS) tools. The information used for authentication is securely stored and transmitted. We store password hashed. We have SHA512 hash with unique salt for every password Not applicable since application is a SaaS platform. At Xoxoday we use Google workspace and activated the MDM features. application also has iOS and Androind mobile applications. This feature can be configured with the help of the MDM Solution that the customer use. At Xoxoday we use Google workspace and activated the MDM features. Compliant. We have segreated the roles and assign the responsibilities to our employees. Since its a Cloud hosted SaaS platform deploying of the application on cloud and server scannings are under the scope of Xoxoday. We use Web application firewall (WAF) and pfSense firewall for security reasons. 1. The Cloudflare Web Application Firewall (Cloudflare WAF) checks incoming web requests and filters undesired traffic based on the set of rules. 2. pfSense helps to monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on a defined set of security rules. At xoxoday we monitor and maintain the logs. The Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. At Xoxoday we have implemented the Active directory and the system will get locked if its inactive for more than 15 mins and re-autentication would require. We have the process in place for standardized approach to structured exception and error handling across all layers. At Xoxoday the validation has been done during the development and testing and we are compliant with the requirements. At Xoxoday Security and compliance requirements are considered during the development stage and we are ISO 27001, CPRA, CSA STAR level 1, GDPR compliant. We have implemented the controls to monitor the application and safegurd from the attacks. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. Since application is SaaS Platform it would be not applicable. We have implemented the Software Development Life Cycle (SDLC) procedure and attached the same for your reference. Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing. We remidiate or fixes the issues identified during the VA/PT assessment and make sure that the application is free from the vulnerabilities. Since it's a SaaS platform and deployed on AWS cloud virtual platform Singapore region. All the data will be stored on AWS VPC. Xoxoday is ISO 27001:2013 certified. An ISMS is a framework of policies and procedures that includes all legal, physical and technical controls involved in an organisation's information risk management processes with the aim of keeping information secure. With ISO's robust information security management system (ISMS) in place, you gain the additional reassurance that a full spectrum of security best practices is implemented across the organization Our Goal is to protect three aspects of information - Confidentiality: only the authorized persons have the right to access information. Integrity: only the authorized persons can change the information. Availability: the information must be accessible to authorized persons whenever it is needed. We have implemented the Access control policy to control the upload, download, viewing and modification AV Scans takes place every week and users also can scan it whenever they can scan the machine. We have prescheduled the scanning once in a week. We are using linux operating system which is inherently secure along with security practices like web application firewall etc We make sure that the customer data is well segregated and compartmantalized No Breaches taken place. We are having Robust Information security compliance framework and we are ISO 27001:2013 and GDPR complied. We follow all the applicable infosec compliance requirements to comply with the regulations We conduct the Risk assessment and compliance review on annual basis as per the compliance requirements. Yes. All the compliance and audit findings has been mitigated. All the vulnerabilities identified during the assessment has been fixed. We use Bitdefender end point security and installed on servers and development machines. Its updated on regular basis. Our roles and job duties are segregated through role-based access to ensure maximum security. Access to data and systems are based on the principles of least privilege for access. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access events. Its restricted and not available to the public. We follow the best practices ans servers are hardened for security reasons. We have implemented the Identity access management (IAM) and follow the Access control policy. At Xoxoday we follow the password policy. We have deployed our application on AWS Virtual platform cloud - Singapore region. RTO and RPO is 60 Minutes. We have implemented the Incident Management Procedure and attached the same for your reference. Since application is a SaaS product and the customer can use the product and services as soon as subscribed for application product usage. the customer will have the legal rights to use the Product. We do not change the terms frequently. We will provide 30 days' notice period for any changes of terms. We notify Client in case of any unauthorized disclosure of or breach of any confidentiality obligation of Xoxoday with respect to Confidential Information, data or information of Client and Xoxoday shall take all necessary and required steps and measures to mitigate such unauthorized disclosure or breach and shall co-operate with Client , at Xoxoday 's cost, to mitigate or control the loss or liability arising out of such disclosure or breach and to retrieve such data or information. Yes. have an active SLA in place that identifies minimum performance of the Product. We have the SLA in place. application endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week. Uptime is measured based on the monthly average of availability. We would be able to provide a report on need basis. No penalties are associated with SLA. We monitor the service continuously and make sure that the product and service is available to use all the time. We have a documented Business Continuity and Disaster Recovery Plan defined and implemented to enable people and process support during any crisis or business interruptions. Since our services are delivered via. Web, the upgrades and updates to the services are seamless and usually do not involve any actions from the end-users. Yes. Our architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows. If there is any major activity and the service will be unavailable, the Maintenance hours were communicated well in advance at least 3-4 day by application. Termination clause will be the part of Master Service agreement and both the parties can review and agree during entering into an agreement. Since it's a SaaS product, this is not applicable. Termination clause will be the part of Master Service agreement and both the parties can review and agree before entering into an agreement. Yes. changes to the production environment or development are documented, tested, and approved prior to implementation or any new releases. We conduct internal reviews and audited by the external auditors for our security standard certification. We conduct periodical Vulnerability assessment and Penetration Testing from the Industry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications. the customer data will stored on AWS virtual platform cloud Singapore. There is no impact on security. At Xoxoday we have implemented the Cyber Crisis Management Plan to provide and support capability for reporting and responding to cyber security incidents, to eliminate or minimize impacts of such incidents No. We monitor the logs on regular basis with regards to network, file and server, and security system. To provide more information, the infrastructure logs are collected using AWS Audit Trail and Application related logs are collected in our Elastic Search server and retained in long term cloud storage. No. Since we are a multi-tenant system, our logs contain information of all the tenants. We cannot isolate a single customer's information from our logs. At Xoxoday the Audit logs reviewed on a regular basis for security events. audit logs are set up, reviewed by our Technical team and logs are recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. We are GDPR Compliant. Our information security team and Customer support team will inform the POC of Client via email communication with Preliminary Incident Synopsis and Root Cause Analysis report (RCA) including the details of Business Impact, Issue Description, Root Cause, and Corrective Actions. Yes. We have implemented the incident response plan and it complies with industry standards ISO 27001:2013, SOC-2, GDPR. We are ISO 27001:2013 certified and attached the certificate. Yes, there are established policies and procedures for label inheritance of TCCC data and objects which contain data, per the TCCC Information Classification Standard and Protection Measures. Mechanisms for label inheritance shall be implemented for objects that act as aggregate containers for data. Yes, we adhere to the retention policy that the tenant sends out for optimal collaboration and smooth user experience with Xoxoday's products and services. Your data is of the utmost importance. All the security mechanisms and policies are established and implemented in such ways that data leak can be prevented, in transit as well as at rest. Yes, the policy, process, and procedure is implemented to ensure proper segregation of duties. These can be asked for and delivered upon tenants' requests. In the event of user-role conflict of interest, technical controls shall be implemented to mitigate risk (if any) from unauthorized/unintentional modification/misuse of organizations' information assets. Yes, our products comply with all the industrial benchmarks and standards when it comes to the Software Development Life-cycle (SDLC). All software development procedures are supervised and monitored by Xoxoday so that they include: * security requirements * independent security review of the environment by a certified individual * code reviewsQuality monitoring, evaluation, and acceptance criteria for information systems, upgrades, and new versions shall be established and documented for the clients' reference. Yes, our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase. Yes, an independent security review is conducted by certified professionals to look for any security vulnerabilities in order to solve them before deploying to production. Yes, our products comply with all the industrial benchmarks and standards when it comes to the Software Development Life-cycle (SDLC) security standard. Yes, changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates and modifications. Any change in roles, rights, or responsibilities shall be documented for a seamless experience. We have a consistent and unified framework for business continuity planning, disaster recovery, plan development. All the appropriate communications shall be established, documented, and adopted to ensure consistency in business continuity. This includes protection against natural and man-made disasters (e.g. fire, flood, earthquake, war, volcanic activity, biological hazard, civil unrest, mudslide, tectonic activity, utility services outages, etc.). Our hosting options are limited to Xoxoday's jurisdiction and are backed by prominent business continuity plans. Hence, we don't find the need to provide geographically diverse hosting options. The capability to transfer infrastructure service failover to other providers is not provided to the clients. Business continuity plans shall be subject to test at least annually or upon significant organizational or environmental changes to ensure continuing effectiveness. Along with an aligned enterprise-wide framework, we perform independent reviews through industry professionals along with formal risk assessments. These are done at least annually or at planned intervals to determine the likelihood and impact of all identified risks. With qualitative/quantitative methods ensuring our compliances with policies, procedures, and standards, we stick to the best standards. Yes, our stringent checks and tests are conducted annually to keep up the cloud service infrastructure hygiene as per the industrial standards. Annual audits are processed both internally and externally. The audit results can be sent over to tenants upon request. Yes, the tenants can request for penetration results and get the reports from our end. No, we do not process your payment card data for any reason other than billing purposes. Yes, we are compliant with the Indian IT Act of 2000. There is no such process available from our end. We will terminate the contract as per rules and statutes. Meanwhile your data will be stored with us and won't be given back to you. However, if the tenant wants the data to be erased, it can be done so upon request. Yes, we store data that's required for seamless rewarding and recognition. We conduct regular audits to ensure safety of data like employees' names, emails, employee numbers, etc. are used for verification and rewarding purposes. Xoxoday's information and cyber-security team keeps a watchful eye on all potential sources of threats and areas of compromise when it comes to information security. Roles are systematically defined for information security measures to tactfully align all operations, preventing any security breaches. Employees must agree with the acceptable usage policy of peripherals and devices to prevent malicious activities from the inside and out. Our environment has all the capabilities to be SOC-2 Type-II compliant but the certification is yet to come through. It shall be updated soon. No, our environment is not CSA-certified. Xoxoday keeps track of all security requirements with respect to legislations, statutes, and contracts. They are documented in all steps. We have our own procedure for control of documents and records that ensures compliance related to intellectual property rights and use of proprietary software. Our record management criteria checks all boxes of legislative, regulatory, contractual and business requirements. With different metrics tracking cyber-security measures, Xoxoday keeps the effectiveness in check with regular monitoring. Xoxoday's Human Resource operation procedure takes all measures of employee confidentiality into consideration. Yes, Xoxoday performs a thorough background check on every employee before they get onboard. The Non Disclosure Agreement ensures that the information is secure even after the contract is terminated. Yes, our Xoxoday Store vouchers are procured from third-party vendors. These vouchers are shared with the tenants in order to be showcased to users of Xoxoday platform. No, the third parties and vendors we deal with our confidential to Xoxoday. Hence, this list cannot be shared. Yes, there's a third-party security policy present to safeguard the interests of Xoxoday's tenants as well as the end users. Yes, our third party security policy deems it clear to comply with security obligations and we monitor their compliance regularly. Yes, we have a detailed risk management procedure in place to address situational issues like change of services being provided to tenants. No, our customer requests are addressed by the Xoxoday customer support team for maximum efficiency. Yes, Xoxoday's brand protection caters to any malicious interruptions and fallacies as they are addressed in prompt time. Yes, with media platforms being the biggest pedestal for information sharing, we keep an eye out for any brand protection issues. Yes, in the event of a rapid spike/slump in network traffic or host activity, Xoxoday analyzes the traffic to detect and prevent unauthorized or erratic behavior. Yes, in order to ensure airtight security of data, we have a mandatory and sessional privacy training and awareness module. The Cloud Security Alliance (CSA) is the world's leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. Yes, Please visit the link to view the registry - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday) Important features of CSA STAR LEVL – 1 are listed below * Operating in a low-risk environment * Wanting to offer increased transparency around the security controls they have in place. * Looking for a cost-effective way to improve trust and transparency. Yes, we ensure the same as part of our code review, static code analysis, and Web Application Firewall. Yes, We comply with these requirements. Our Cloud Security Platform, (CSP) Amazon Web Services (AWS) provides these securities to our data centers. Production data shall not be replicated or used in non-production environments. We do not use LIVE data in any other environment. We comply with the requirement. We take prior authorization from the concerned authority as per the Media protection procedure before relocation or transfer of hardware, software, or data to an offsite premises. As per Mobile Security Compatibility compliance requirements we have a documented application validation process to test for mobile device, operating system, and application compatibility issues. The California Privacy Rights Act (CPRA) is a state-wide data privacy bill that amends and expands the existing California Consumer Privacy Act (CCPA). The CPRA works as an addendum to the CCPA, strengthening data privacy rights for California residents, tightening business regulations, and establishing the California Privacy Protection Agency (CPPA) as lead enforcer and supervisor. Yes. We are compliant with CPRA, and Our solution will continue to offer full compliance with the new and updated data privacy regime. Yes. We support our consumers to exercise their rights as per the CPRA. Yes. We have implemented all the privacy controls and audited the same with the help of external Auditors. Yes. Please reach out to our sales representative/Xoxoday POC to have access to the CPRA report. No. We do not collect any data from any users across the globe who are not 18 years old. Yes. The data subject can authorize an agent (an "Authorized Agent") to exercise their rights. To do this, the data subject must provide your Authorized Agent with written permission to do, and we may request a copy of this written permission from your Authorized Agent when they make a request to exercise the rights. You may submit a Valid Request by emailing [cs@xoxoday.com](mailto:cs@xoxoday.com). No. We will not sell, rent, or share Personal Data with third parties outside of our company. But Personal Data may be provided where we are required to do so by any privacy laws. SOC 2 compliance is part of the AICPA Service Organization Control reporting platform. The goal of SOC 2 is to evaluate organization security and internal controls around security, availability, processing integrity, confidentiality, and privacy. SOC 2 Compliances are developed by the American Institute of CPAs (AICPA), it defines criteria for managing customer data based on five "trust service principles"—security, availability, processing integrity, confidentiality, and privacy. Yes. Xoxoday is SOC 2 certified organization. We have implemented all the required SOC 2 controls and got them Audited with the help of Certified Public Accountants (CPA). Amazon Web Services (AWS) has achieved SOC 1, SOC 2, and SOC 3 reports. These reports detail the AWS controls environment and implemented controls for AICPA Trust Services Criteria (TSC) and can be leveraged as part of a cloud customer security program. AWS SOC-covered cloud services are audited periodically against the SOC reporting framework. You may reach out to our sales representative/Xoxoday POC to have access to the SOC 2 report. Laika Compliance LLC performs the SOC 2 audit for Xoxoday. The SOC 2 Type I report is valid for one year following the date the report was issued. Yes. SOC 2 is an internationally recognized standard. The SOC 2 report and certification involve an independent audit by a third party. Yes. We do conduct the SOC 2 Audit on an annual basis. The Auditor has validated and tested all the applicable SOC 2 controls as per the compliance requirements. We do not process (Collect/Store) Protected Health Information (PHI). Yes. Xoxoday is compliant with Health Insurance Portability and Accountability Act (HIPAA). Yes. Please reach out to our sales representative/Xoxoday POC to have access to the HIPAA Audit report. Yes. We have implemented the Data Subject Access Rights Procedure to make sure that all the data subjects will have the opportunities to exercise their rights as per the privacy laws. The secure deletion standard like DoD 5220.22-M ECE is being followed and we provide a certificate that the data was properly sanitized from all computing resources and portable storage media. Yes. Xoxoday is GDPR Compliant. We have implemented the Data Subject Access Rights Procedure as per the GDPR and made all the data subject rights available as per the data protection laws. This procedure sets out the key features regarding handling or responding to requests for access to personal data made by data subjects, their representatives or other interested parties. Yes. We validate the compliance requirements of the Sub-processor and obtain the Compliance certificates and audit reports such as – ISO 27001:2013, SOC 2 Type II, ISO 27017, ISO 27701, ISO 27018, Cloud Security Alliance Controls, etc. We conduct the independent Audits for - ISO 27001:2013, SOC 2 Type I, CPRA/CCPA, HIPAA, VA/PT Assessments. Xoxoday maintains a disaster recovery program to ensure services remain available or are easily recoverable in the case of a disaster. Customers can stay up-to-date on availability issues through a publicly available status website covering scheduled maintenance and service incident history. The BCP and DR Plans are tested and reviewed every year. The Xoxoday BCP and DR plans are reviewed and audited as part of ISO 27001 standards and SOC 2 Type II covering availability as one of the trust service principles. Users are not having admin access to their computer machines and only IT Support admins can install or uninstall the softwares. CTOs and Production heads are responsible for safeguarding the customers data. Only authorised individual will have access to the production environment. We delete the customer data upon request/termination of the contract and confirm the secure deletion. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. We clasify the Information assets into Confidential, Restricted , Internal and Public etc.. We maintain the records of all our assets. we logically segregate the tenant's data, and it is segregated with a client-specific key for proper handling and security reasons. We have restricted the ports for all the users as per Xoxoday IT Policy The password needs to be minimum 8 characters long and should contain at least one capital letter, special characters among '# \$ % \* &' and 1 digit Maximum Password Age – 45 days Minimum Password Age – 1 day Computer machines will lockout in 15 mins from the time it became inactive. Yes. Only authorised individual have access. We use best practices and industry standards to achieve compliance with industry-accepted general security and privacy frameworks. We use enterprise-class security features and conduct comprehensive audits of our applications, systems, and networks to protect customer and business data. Our customers rest easy knowing their information is safe, their interactions are secure, and their businesses are protected. Please click here to know about Xoxoday Security framework - [https://www.xoxoday.com/security](https://www.xoxoday.com/security) We are compliant. We monitor the system performance. Yes. We maintain current architecture diagrams that include data flows between security domains/zones All operating systems are hardened as per Xoxoday hardening guidelines. We are compliant. We have deployed our applications on AWS Virtual platform cloud. Please click here for SLA - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view) Appropriate roles and responsibilities have been defined and documented. Finance, Leagl, Admin, Infosec departments are active part of it. Since its SaaS platform is not applicable. Yes. we conduct the testing on frequent basis to comply with the requirements. Yes. Its compliant with ISO 27001 and SOC 2 trust service principles. Yes. We mitigate all the risk identified. We inform the customer if there is any incidents as per the security and privacy laws. Yes. We do conduct an internal Audit. Yes. Privacy and security is a part of the Master Service agreements. Xoxoday is compliant with GDPR, HIPAA, CCPA/CPRA privacy laws. And we inform the customer if there is any data breaches as per the compliance requirements. Yes. We provide report on SLA. We do conduct an External Audit with the help of the independent auditor. Yes. we conduct the assessment on annual basis. AWS is a sub-processor as we are storing data on AWS VPC. And they are AWS SOC 2, ISO 27001, ISO 27017 and ISO 27018 certified We monitor the compliances of sub-processor on frequent basis. We continuosly train employees on privacy and security. Yes. We have member in our organisation with dedicated information security duties. Xoxoday's primary security focus is to safeguard our customers or users data. This is the reason that Xoxoday has invested in the appropriate resources and controls to protect and service our customers. All our employees are having the unique log in IDs. We have installed the firewall for maximum securty and configured to restrict unauthorized traffic All are configured according to security standards as part of the build process Its part of our Internal and external Audits and validated by the indeendent auditors. We have implemented the access control policy and access will be provided only upon need and approval basis. Attached the access control policy. We have track of the changes. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. We have installed Smoke detectors and Fire extinguishers for physical security. security incidents reviewed to capture the root cause. We are SOC 2 compliant and we have engaged Laika Compliance LLC, an independent assessor firm, to conduct a SOC 2 Type 1 and SOC 2 Type 2 examination for the Xoxoday Platform against the Security and Confidentiality Trust Services Categories. Attached the ISO 27001:2013 certificate. We provide Software as a Service.(SAAS). We are ISO 27001 certified and GDPR compliant. Attached the document. We are ISO 27001 certified and GDPR compliant. Attached the document. Since it's a SaaS prodcut and deployed on cloud virtual platform only authorised individual have an access to the our production environment on need and approval basis. We inform the client to revoke access. We use Google workspace and have secure mode of sharing the data. We can manage all the enpoints centrally. We have implemented the security measures to manage the risks introduced during the use of Organization's information assets used for managing Personally Identifiable Information. We have a formal risk assessment process and conduct the risk assessment annually. All the contractors/vendors have signed the NDA and contracts All the necessary clauses has been included in the agreements with regards to Confidentiality, liabilities, termination etc Yes. We do conduct the Risk Assessment every year. Yes. We have implemented the Data security and Information clasification policy. Attached the same. Yes. They have signed for the agreements. We have a biometric systems and access cards. only authorised individual can have access. We have deployed Sensors for fire detection and fire extinguishers to detect and protect from the fire. Yes, we will notify Yes. Our Customer support team will notify. Yes. We create an email accounts only after the approval from reporting managers. We have not outsourced and does not create any email ids Yes. IT Team is responsible. Yes. We have a Email Security Policy and attached the same Yes, we have implemented the security controls for email with the help of Google workspace and installed the end point security for all the laptops of the employees. All the incoming and outgoing attachments are scanned. Yes. Yes, We have implemented the Acceptable Usage Policy and have restricted for usage and access to internet. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. Since our application is deployed on AWS cloud we will ensure the best uptime in the insudtry. Yes. All the changes takes place as per the change management policy implemented. Yes. We have software register and only approved and licensed softwares will be used. Yes, all are up to date. Yes, we have capacity planning and monitor the hard disk space, RAM, CPU etc. All the employees laptop is secured with Bitdefender end point security software Yes Yes. Taken into consideration Annually Yes. Attached the same. We do consider all of these, addition to that we also validate the controls in place with regards to cloud security, BCP, Uptime etc. AWS is ISO 27001, SOC 2 Type II certified and complied with CSA start level 2. Please click here for more details about AWS Compliance Programs - [https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/) Yes. We have an agreement. We have implemented policies and procedures as per ISMS and GDPR requirements. We also conduct periodical Internal and external Audit by the third party Auditor. We have deployed our application on Cloud Virtual platform for maximum security. We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We conduct periodical Vulnerability assessment and Penetration Testing from the Inductry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications. Xoxoday and AWS both are ISO 27001:2013 certified and implemented the change management procedure. We ensure that we follow the policies and procedures with regards to any changes to be made. Yes. AWS is ISO 27017, ISO 27001:2013, ISO 2018, SOC 2 certified. Yes. Attached the AWS ISO 27001 certificate Yes. Tested our BCP plan We ensure that we maintain confidentiality, integrity, availability and privacy of data collected, processes, stored through implementing policies and procedures. And we do conduct the internal and external Audits periodically to make sure that all the controls are working effeectively. Yes Yes Since we have logically segregated the data and ISO 27001 certified and GDPR compliant we do not disclose or provide any of the the customer data. Yes. Audited by the independent Auditor and all the aspects of Privacy, information security, BCP, DR, Production, VAPT has been validated. NO Production Site - No.17, Bhagyalakshmi Square, 2nd Floor, Sector 3, HSR Layout, Bangalore -560102 We have deployed our application on AWS Singapore. Since we have deployed our application on AWS cloud they only provide DR Services. No other location We provide our application to the customer. We have 230+ employees. 100+ employees are involved in the production/devolopment and we have a sepearate team for IT Support and Information security. We have provided separate computers to each employees. Altogether we are having around 250 computer machines. Our application is deployed on AWS cloud virtual platform. We are ISO27001;2013 certified and GDPR compliant.Attached the ISO 27001:2013 certificate. We are SOC 2 compliant and in the last phase of final Audit. Attached the engagement letter that we have with our external Auditors. Xoxoday is ISO 27001:2013 certified, GDPR compliant and SOC 2 type I certified organization and have all the required technical and organizational controls in place and auditred during the internal and external audits. We are ISO 27001 Certified organization. We make sure that all the required records are maintained and compliant with the requirements. Attached the Security Incident Reporting & Response Procedure and Incident Management Procedure We have implemented the Information classification Policy to protect against unauthorised access, disclosure, modification, or other misuse. All our assets are labelled as per the requirement. Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. A strong identification and authentication system and logging systems are deployed and provide a centralized control to administer, monitor and review all critical access. We have a role-based access system through access control policy to make sure that only the authorised individual has access to the required information. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. The approvers are either the Product Heads or respective function Heads are their authorized delegates. We have the Fire alarams, Smoke detectors, UPS, Temperature controler, Air conditioner, etc.. for protecting against the environmental hazards. Yes, all our - both full-time and on-contract are bound by an agreement of non-disclosure and a confidentiality agreement as a condition of employment to protect the customers and tenant's information. We use the CCTV cameras to monitor the building on a 24\_7\_365 basis. All the enterances, exit, restricted areas are under surveilance for security reasons. Yes. We have the Information security team. We are compliant In accordance with Data Protection Laws, we make available to Controller on request in a timely manner such information as is necessary to demonstrate compliance by Processor with its obligations under Data Protection Laws. Upon Controller's written request and subject to the confidentiality obligations set forth in the Agreement, we will make available to Controller a copy of Nreach the most recent third-party audits or certifications, as applicable. We do not agree for the Surprise audits. We have the Buiness continuity and Disaster Recovery Plan in place. These controls has been tested at least annually as per the compliacne requirements. Attached the policies for your referrence. We have the Crisis management is in place. Attache the same. We have provided an option to work from home/remotely due to this pandamic with necessary infrastructure and security. Business continuity plan has been tested on annual basis and audited during the internal and external audits. Atatched the business continuity policy and plan. Generic IDs are not used [Please click here for SLA - https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view) We have the ability to delete the data upon request by the data subject or termination of the contract. Attached the data retension and disposal policy. We have implemented the Business continuity policy and we have the ability to resume our operation from potential threats, Pandemic, flood, fire, earthquake etc. Due this pandemic/WFH situation, VPN access has been enabled with 2FA For such authorized individuals, for ensuring business continuity. We have the required controls in place for working from home or remotely due to this pandemic situation. Its a part of our Business continuity plan and IT Support Head, HR Head, CTO, Infosec Head will be involved in the preparedness activities. We have provided WFH option to all the employees to get protected from COVID 19. We have provided WFH option to all the employees to get protected from COVID 19. We test the Business continuity plan on annual basis. It was tested in the month of Aug 2021 for the last time. It has been well defined in the in the Business continuity policy and plans. Attached the same for your referrence. We inform our customer on any crisis and if that is effecting on our customers. Xoxoday is a data processor. NO. We obtain consent before such activities from the customer. We have the DPA and appropriate controls in place – We are compliant. ISO 27001;2013, SOC 2 Type I Certified and GDPR compliant. YES. We have implemented the Business continuity plans and tested them annually. No. But we are in the process of getting the insurance from the Insurance company. We conduct the internal and External audits on a periodical basis as per the compliance requirements and obtain Audit reports and certifications. We provide the same with the customers. NO. We are not subjected to any actions as such. application by Xoxoday, the RnR platform is a cloud-based SaaS platform hosted on VPC infrastructure of AWS. The data centers are hosted completely in isolation so that the access is limited and controlled. Each instance (EC2 Instance) under fortified VPC network is further conglomeration of Docker Container Web Services and APIs and application layer running on top of it. This helps in managing various aspects and features of application without affecting the functioning of each other and achieving a modular architecture to work as plug and play model. Amazon Cloud Watch is implemented to enable monitoring of the functioning of the application. We have Web application firewall (WAF), IDS/IPS, AWS Guardduty, and the data has been encrypted for security reasons. Attached the Architecture diagram. Xoxoday is ISO 27001:2013 certified and GDPR compliant. Xoxoday is ISO 27001:2013 certified and GDPR compliant. And we follow ISO 27001, NIST, CSA standards and best practices. We have Web application firewall (WAF), IDS/IPS, AWS Guardduty, Coudflare and the data has been encrypted for security reasons. We conduct code reviews as per the compliance requirements. We also conduct the Vulnerability assessment and penetration testing on annual basis with the help of the third party authorised vendor. Attached the latest VAPT certificate and ISO 27001 certificate. Attached the ISO 27001:2013 certificate and 1st Year Surveilance audit report. We did not have any non-confirmities. We are compliant with the data privacy and security requirements. We are having the controls in place with regards to Cyber security, Risk management, crisis management, business continuity, Network security, application security etc. Attached the Business continuity management and Cyber Crisis Management Plan, incident management procedures, SDLC etc. Attached the Business continuity plan and procedure. We test the BCP controls on annual basis as per the compliance requirements and it has been auditted during the internal and external audits. Xoxoday is ISO 27001:2013 certified, CSA START Level 1 and GDPR compliant. And we follow ISO 27001, NIST, CSA standards and best practices. We have Web application firewall (WAF), IDS/IPS, AWS Guardduty, Coudflare and the data has been encrypted for security reasons. We conduct code reviews as per the compliance requirements. We also conduct the Vulnerability assessment and penetration testing on annual basis with the help of the third party authorised vendor. Attached the below policies and procedures - 1. Encryption Policy 2. Password Management Policy 3. IT Policy 4. Information Classification Policy 5. Threat and Vulnerability Management 6. Cyber Crisis Management Plan 7. Backup Recovery Procedure 8. Access Control Procedure 9. Incident Management Procedure 10. Change Management Procedure Data centers are designed to anticipate and tolerate failure while maintaining service levels. In case of failure, automated processes move traffic away from the affected area. These are tested on annual basis. AWS is also ISO 27001, ISO 27017, ISO 27701, ISO 27018, SOC 2 compliant organizatin. Please click here for more details - [https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/) Please click here to know more about AWS security - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/) Please click here to know more about Xoxoday Service level agreement - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view) Please click here to know more about Xoxoday Service level agreement - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view) Please click here to know more about data governance - [https://www.xoxoday.com/gdpr](https://www.xoxoday.com/gdpr) Attached the Risk Management Procedure We have plan for having the cyber insurance. - In progress. Each employee, when inducted, signs a confidentiality agreement and acceptable use policy, after which they undergo training in information security, privacy, and compliance. Furthermore, we evaluate their understanding through tests and quizzes to determine which topics they need further training in. We provide training on specific aspects of security that they may require based on their roles. We have implemented the Information security policy and Disciplinary policy. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently. Please click here to know more about the Application SLA - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view?usp=sharing](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view?usp=sharing) We review and get an approval from the management on annual basis as per the compliance requirements. We have installed End point security on all the computers and monitored and updated on regular basis. Yes. Our tenants can report the Bugs and security vulnerabilities to [cs@xoxoday.com](mailto:cs@xoxoday.com) We also have Bug Bounty Program at Xoxoday and please click here to know more about - [https://www.xoxoday.com/bug-bounty](https://www.xoxoday.com/bug-bounty) Since application is a SaaS platform and deployed on AWS virtual platform cloud NA. We have the full time employees. We conduct the review and update the policies, procedures etc..and take an approval from the management on annual basis as per the compliance requirements. We also communicate all the policies and procesures to all the employees, contractors through HRMS platform. We do not allow to access the infrastructure hosting. All the information security policy and standards been approved by senior management. We have installed the antivirus on all the workstations and servers. Customer data security is an essential part of our product, processes, and team culture. Our facilities, processes and systems are reliable, robust, and tested by reputed quality control and data security organizations. We continuously look for opportunities to make improvements in the dynamic technology landscape and give you a highly secure, scalable system to provide a great experience. Attached the GDPR - Data security policy. We have installed Bidefender endpoint security and restricted the access of external hard drives, USB etc to have restriction on data transfer. we use file integrity and network intrusion detection (IDS) tools to help facilitate timely detection, investigation by root cause analysis, and response to incidents We do not use. Annually We have conducted the BCP test on 6th Aug 2021. Attached the Business continuity policy. We have installed Smoke detectors and Fire extinguishers for physical security. Attached the incident management procedure. All our policies are reveiwed annuaaly and approved by the top level management. security incidents reviewed to capture the root cause. Attached the Security Incident Reporting and Response Procedure Classification of Incidents are done. Attached the Incident Management Procedure No Security breaches till date. We are SOC 2 compliant and we have engaged Laika Compliance LLC, an independent assessor firm, to conduct a SOC 2 Type 1 and SOC 2 Type 2 examination for the Xoxoday Platform against the Security and Confidentiality Trust Services Categories. Attached the engagement letter. Attached the ISO 27001:2013 certificate. We make sure that they have adequate controls in place and meet the security standard. We are ISO 27001 certified and GDPR compliant. Attached the document. We review these to make sure the all the controls in place. We provide access only upon need and approval basis. We use Google workspace and have secure mode of sharing the data. We can manage all the enpoints centrally. Attached the Risk Management Procedure We have a formal risk assessment process and conduct the risk assessment annually. All the contractors/vendors have signed the NDA and contracts All the necessary clauses has been included in the agreements with regards to Confidentiality, liabilities, termination etc The SaaS solution is deployed on Public cloud. Yes Yes. We are using Bitdefender endpoint security. Yes. We use for security reasons Our employees will not have access by default. The data will be accessed only upon need an approval basis. The access is controlled through the AWS Identity and Access Management system that also enforces two-factor authentication We collect only 3 types of the personal Information such as Name, email ID, phone#. , personal data is to be transmitted using firmly approved encrypted systems. We have implemented the role based acccess control to make sure that the acccess has been granted to only authorised individual. Yes. Yes. We inform the client about any security incidents. Yes. Attached Incident management policy and SLA Yes Yes We are compliant. Yes, We are ISO 27001:2013 certified. Attached the certificate. We are SOC 2 Type 1 compliant. The audit has been completed and auditor is working on the Draft audit report. We will be able to share once the report is finalized. NA. But AWS Virtual platform cloud is ISO 27017 and 27018 certified and attached the report. NA. We do not handles the card holder data. the customer will be using the application product and all the information will be entered only through our application. The data sharing between vendor and the customer will take place only through application product. There will be no manual data sharing or transfer. PII will be entered through application and stored it on AWS cloud virtual platform. We store Name, email ID and phone number of the users. We do not have any sub-contractors. We have deployed our application on AWS Virtual platform cloud. And AWS is ISO 27001, SOC 2, ISO 27017, ISO 27018, ISO 27701, CSA Compliant etc.. We have deployed our application on AWS Virtual Platform cloud. application is a cloud based application. We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. All the confidential/PI data are encrypted at rest and in transit with a split key mechanism to ensure that every client's key is unique We do not decrypt the data until and unless if there any specific request from the customer. Xoxoday endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week ("Agreed Hours of Service"). Uptime is measured based on the monthly average of availability, rounded down to the nearest minute. Please click here to know about Xoxoday SLA - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view) Xoxoday has a formal Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) defined and implemented to enable people and process support during any crisis or business interruptions. The BCP and DR Plan is tested and reviewed on a yearly basis as per the compliance requirements. The BCP and DR plan of Xoxoday is reviewed and audited as part of ISO 27001 standards and SOC 2 Audits by the independent auditor. Attached the Business Continuity Plans (BCP) and Disaster Recovery Plan (DRP) documents. Since it's a SaaS platform, there are no process as such. Attached the below mentioned coompliance certifications - Attached the Audit reports. 1. ISO 27001 certificate 3. VAPT Certificates 4. VAPT Audit reports 5. SOC 2 Audit reports. 6. GDPR Data Privacy Impact assessment report 7. California Privacy Rights Act (CPRA) attestation report. 8. CSA STAR LEVEL 1 compliant - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday) We conduct these audit on annual basis and we will share it upon request. We always provide our best service to resolve security incidents / outages. Attached the Service Level Agreement (SLA) Xoxoday is committed to ensuring the integrity, confidentiality, availability, and security of its physical and information assets and maintaining privacy when serving the customers and organization's needs while meeting appropriate legal, statutory, and regulatory requirements. To provide adequate protection for information assets, Xoxoday has built the Information Security Management System (ISMS), enabling everyone to follow these policies diligently, consistently, and impartially. Xoxoday will implement procedures and controls at all levels to protect the confidentiality and integrity of information stored and processed on its systems and ensure that information is available only to authorized individuals as and when required. Please click here to know more about Xoxoday Security - [https://www.xoxoday.com/security](https://www.xoxoday.com/security) We have deployed our application on AWS Virtual platform cloud - Singapore region. We are GDPR compliant. And we have an agreement and Standard contractual clauses (SCC) as per GDPR Compliance requirements. NO NO No. There were no Personal Data Breaches. Xoxoday is committed to ensuring the integrity, confidentiality, availability, and security of its physical and information assets and maintaining privacy when serving the customers and organization's needs while meeting appropriate legal, statutory, and regulatory requirements. To provide adequate protection for information assets, Xoxoday has built the Information Security Management System (ISMS), enabling everyone to follow these policies diligently, consistently, and impartially. Xoxoday will implement procedures and controls at all levels to protect the confidentiality and integrity of information stored and processed on its systems and ensure that information is available only to authorized individuals as and when required. Attached the below documents - 1. ISO 27001 Certificate 2. SOC 2 Audit report. 3. California Privacy Rights Act (CPRA) attestation report. 4. VAPT Certificates 5. GDPR DPIA Assessment report. 6. CSA START LEVEL 1 Compliant - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday) the customer can request the Xoxoday POC for these reports and we will provide the latest Audit reports upon request. We are storing all the customer data on AWS Virtual platform cloud – Singapore region and consider AWS as a Sub-Processor as per EU GDPR. AWS is ISO 27001, SOC 2, ISO 27017, ISO 27018, CSA STAR, ISO 27701 certified organization. Please click here to know about AWS Compliance offerings - [https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/) Scope and functionalities are the part of the agreement. Please click here for SLA - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view) We do not offer any credits/ penalties. We have implemented all the technical and organisational measures to ensure the integrity, confidentiality, availability, and security of its physical and information assets and maintain privacy when serving the customers and organization's needs while meeting appropriate legal, statutory, and regulatory requirements. To provide adequate protection for information assets, Xoxoday has built the Information Security Management System (ISMS), enabling everyone to follow these policies diligently, consistently, and impartially. [ISO 27001 certificate VAPT Certificate SOC 2 Audit reports. California Privacy Rights Act (CPRA) attestation report. CSA STAR LEVEL 1 compliant - https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday We have shared these certifications and Audit reports.](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday) We do not process the data for other purposes than the one specified in the contract, We do not share the data with third parties. But we store it on AWS Virtual platform cloud and we consider AWS as a Sub-processor. We do not disclose any of our customers personal information to any third parties. We reserve the right to disclose PI if required by law or if we reasonably believe that use or disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or comply with a law, court order, or legal process. We reject any non-legally binding requests for disclosure. We process only the Name, phone# and Email ID as mandatory information. We process the information as per the terms of use - [https://www.xoxoday.com/terms-of-use](https://www.xoxoday.com/terms-of-use) We are storing all the customer data on AWS Virtual platform cloud and we operate or provide services from Bangalore, India. We inform the customer of any changes in regards to changes in sub-processors. Xoxoday Terms & conditions - [https://www.xoxoday.com/terms-of-use](https://www.xoxoday.com/terms-of-use) Yes, the cloud provider does have a right to suspend services for specific reasons; more detailed in Section 3.3 of the Master Services Agreement. Section 3.3(a) read along with Section 2 of the MSA The Contract is subject to the laws of India. For disputes arising under this contract, courts of Delhi has an exclusive jurisdiction. Arbitration & Conciliation Act, 1996 We conduct the periodical Risk assessment. and it has been audited during the internal and external audits. We also provide SLA performance report to the customer on need basis. we have the capability to respond to security alerts, and report security vulnerabilities and information security incidents within 24 hours of discovering them [We also have Bug Bounty program - https://www.xoxoday.com/bug-bounty](https://www.xoxoday.com/bug-bounty) We train our employees on their role and responsibilities and also comminicate before joining the organizatin application is an all-in-one employee engagement and motivation platform that offers Rewards & Recognition, Pulse Surveys, 1-on-1 Feedback, Social Intranet and People Analytics in one powerful solution. Information security department is responsible for security initiatives and the Head of the Information security reports to the Board of Director of the company. The policies and procedures have been created, reviewed and approved by the Top level management of the company. The information security policies have been uploaded on KEKA HRMS Application and communicated to all the employees. Attached the screenshot for your reference. Attached the Risk Management Procedure. Attached the internal audit report. Your data is of the utmost importance. All the security mechanisms and policies are established and implemented in such ways that data leak can be prevented, in transit as well as at rest. We have installed Bitdefender endpoint security in all the endpoints. Bitdefender is based on a layered next-gen endpoint protection platform with the industry's best prevention, detection and blocking capabilities, using proven machine learning techniques, behavioural analysis and continuous monitoring of running processes. We have the capability to wipe out the data remotely for all endpoints including BYOD devices. Attached the ISO 27001:2013 certificate and Statement of applicability. We provide tpliance certifications upon request. We use the Software Development Life Cycle (SDLC) process. It is aligned with ISO 27001;2013 and SOC 2 frameworks. During the development and testing security related requirements are specially considered. We have SDLC Policy as per ISMS requirements and we follow General Coding Practice. For example - We Conduct data validation on a trusted system, All cryptographic functions used to protect secrets from the application user. We can also provide uptime status on a need basis. We have proper forensic procedures for data collection and analysis for incident responses Yes, in case specific incidents arise for particular tenants, our logging and monitoring framework allows isolation of incidents. Xoxoday endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week. Uptime is measured based on the monthly average of availability. We do not offer any penalty. Attached the SLA Attached the below documents - 1. ISO 27001:2013 certificate 2. VA/PT Certificate 3. VA/PT Executive report 4. application Architecture Diagram 5. We have deployed our aplication on AWS Virtual platform Cloud and attached AWS Compliance certificates - ISO 27001, ISO 27017 & ISO 27018. 5. application SLA Customer Support is available on all working days (Mon - Fri) between 3.30 AM GMT to 1:30 PM GMT. Xoxoday is – ISO 27001:2013 certified CPRA (California Privacy Rights Act) EU GDPR Compliant CSA STAR LEVEL 1 Compliant – Click here Vulnerability Assessment and Penetration Testing (VAPT) Attached these above certificates and Reports. The backups are automated and taken on a daily basis. We delete the data upon receiving the request from the customer/end users/termination of the contract. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. We have an ELK setup in place to ensure data monitoring in the most optimal manner. The audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. As per the SDLC Policy we follow several distinct stages, including planning, design, building, testing, code review, deployment and maintenance etc. Our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase. It would depend on the criticality of the investigation and the type of service subscribed. Our team will be able to provide the ETA as soon as they receive the request from you and start acting immediately. Yes. You can check this information from the user management option available for Admin console. You can reach out to us with the help of the help center or can write an email to customer support team Yes. We maintain and record the Audit logs and complying with various compliance requirements. Yes. You may reach out to our support team anytime for requesting these records and they would be able to help you out on this requirement. It would depend on the criticality of the investigation and the type of service subscribed. Our team will be able to provide the ETA as soon as they receive the request from you and start acting immediately. Yes. We deployed our application on AWS and AWS provides the data backup service as well. Yes. We are ISO 27001:2013 certified and GDPR Compliant. We have implemented the risk assessment procedure and conduct the risk assessment annually as per the compliance requirements.Risk assessment is used to identify the risks encountered by the information-processing facilities (or individual system components). The aim is to estimate the impact and probability of a threat occurrence. The risk assessment procedure is having Risk, Likelihood and Impact. The risk ranking is done based on the Residual Risk Rating such as High, medium and low. Attached the Risk Management Procedure for your reference. Risk Management Procedure has been used to validate the security compliance of AWS. AWS Compliance certifications and attestations are assessed by a third-party independent auditor and result in a certification, audit report, or attestation of compliance. AWS is ISO 27001, SOC 2 Type II certified and complied with CSA start level 2. Please click here for more details about AWS Compliance Programs - [https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/) Yes. We can use the risk assessment framework adopted by NSE for cloud service risk assessment.. Please provide the same. We comply with this requirement. The risk assessment procedure has defined the Risk Acceptance Criteria, Benefits, Components, Impact Rating, Risk Treatment, Risk Acceptance etc and all the controls identified in our risk assessment as per the industrial standard like ISO, SOC2, NIST, GDPR etc. Sure. We are ISO 27001;2013 and GDPR compliant. We have policies and procedures in place with all the required compliance controls. We comply with this requirement. We conduct annual audit by the independent auditors to test the controls in place with regards to Information Security management system(ISMS) and also for testing the service organization controls(SOC)covering the principles of Security, Availability, Confidentiality, and Privacy. AWS is also SOC 2 certified. Sure. Attached the ISO certificate and we are in the Audit process for SOC 2. we will provide the same once the audit is completed. We are ISO 27001;2013 certified, GDPR compliant and in the process of SOC 2 audit. We make sure that our customer data is safe and secure and meet all the compliance requirements and industry best practices. Xoxoday has built the Information Security Management System (ISMS) which includes the respective policies to be followed in a diligent, consistent, and impartial manner. Our legal team would review and agree the terms and conditions. We agree. NSE can review. Our legal team would review and agree the terms and conditions. We will inform NSE if there is any breach. The data isolated between customers. We use logical data isolation with the help of company specific encryption keys.We use TLS1.2 encryption for Data in transit and AES256 for Data at rest We agree. We have implemented the data breach notification procedure. We agree. We will notify NSE. We agree.Currently, we do not have any plans as such. All the data will be stored on AWS cloud We have the disposal policy in place and implemented mechanisms for secure disposal and removal of data. We agree. We will delete the data upon termination of the contract or request and confirm. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. We have implemented Asset Management Procedure in place and maintain all the records of IT Assets like, hardware, software, licenses, accessories etc. We review and update the inventory as per the Asset management policy. The database server, application server or storage devices hosting NSE's data & information is not made available publicly. We isolate our machines, network and storage with respect to the AWS Standards in order to keep it safe and secure Yes, one can write to us at our 24\*7 support team at [cs@xoxoday.com](mailto:cs@xoxoday.com) We help the clinets in setting up from both admin and end user side, and traiing is also provided on how application can be used for hasslefree awards distribution We provide trainging over internet , if possible we provide telephonic assistance also. Yes we provide "on demand training" , this incur no additional cost to the company We have a 24\*7 available support team, once a ticket is generated , It is assigned to one of the cs team executive and we intent to solve the issue within next 24hrs. Xoxoday employees and third party would have an access. We provide acess on case to case basis as per the Information security and access control policy. We also have role based access system to meet the compliance requirements of the data security . The data is hosted on Amazon Web Services (AWS) We do conduct employees and contractors background verification as per the compliance requirements before onboarding process. We will onboard them only after passing the background verification. We are ISO 27001:2013 certified organization. We conduct periodical review of the access provided and make the necessary chages as per the Role based access management and access control policy. We also conduct Internal and external audits in a timely manner. Our Information security compliance policies and procedures are established and implemented to enforce two-factor authentication We are ISO 27001:2013 certified organization The User access are monitored and recorded internally as per the compliance requirement and Access Control Procedures. Yes we have implemented intrusion detection tools, we ensure timely detection and investigation in a prompt manner. Yes. file integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation. Yes. Implemented SIEM Yes. All the controls are audited annually. Yes, We will share the Data protection policy. Access control policy and Information security policies Size of the team is 5 and all are having 5+ years of experience personal data is stored are registered databases that comply to all necessary inputs of a standard inventory repository and its transit scrambled for maximum security. We use AWS Platform for storing the data. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records. As per the Information security policy and Data protection policy only the authorised individual have an access to the data through internal approving and ticketing system. No. Planned downtime will not be calculated uptime No. Planned downtime will not count against the SLA We have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working. We test it annually once as per the compliance requirements. Xoxoday's architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows. We have Business Continuity Policy and Business Continuity Management Procedure in place and tested periodically. And also our Policies has been reviwed and Audited annually. Yes. We have implemented IDS/IPS, Firewall and our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting Yes. We have procedures in place to support Government We have the clauses for suppporting local government and law enforcement requesting customer data in data protection policy. We will share the copy of it. We have deployed our application on Amaon web services (AWS) AWS is designed to help us build secure, high-performing, resilient, and efficient infrastructure for our applications. AWS is also ISO 27001:2013 and SOC 2 type II Certified and provide all applicable security to the data center. Yes. We have industry approved vendor called Appknox for Vulnerability assessment anf Penetration Testing. Appknox performs Static, Dynamic, API, and as well as Behavioral Analysis. And they helps to detect and address security vulnerabilities. We collect only personal information through our application. We collect name, email ID and mobile numbers. Yes. We have capabilities to anonymize data. By Anonymization users are able to make use of sensitive information without having access to the identifiable data items. And its used within a secure environment with employee access on a need to know basis. No. we do not have it in hard copy Yes. We conduct vendor Risk assessment and also external Auditor validate the critical vendor documentations during the annual and Internal Audit. Yes. We have Information Security Program Yes. We review Information Security Policies every year. Yes. We have Information security risk management program Yes. Our management is supportive and evaluate, Recommend and take action on security risks Yes, we have Information security team and the Infosec head is reporting to Chief Operating Officer of Xoxoday. Yes Yes. Please visit here for more details - [https://www.xoxoday.com/bug-bounty](https://www.xoxoday.com/bug-bounty) Yes. All the endpoint laptops that connect directly to production networks centrally managed All the employees laptop is secured with Bitdefender end point security software. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory. No. sensitive or private data never reside on endpoint devices. This is enforced throgh access control policy. We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. Yes. Our incient response plan is tested every year as per the ISMS requirements. We follow SDLC policy during the design phase of devolopment. See SDLC procedure attached We have SDLC procedure and Information System Acquisition Development and Maintenance Procedure. Devolopers are trained on the Secure Coding Practices as soon as they joined our organization We conduct vendor risk assessment and collect all the required security policies, procedures, VAPT reports, ISO 27001, SOC 2 reports. And also our internal and exteranal auditors validate the security controls of our crtical vendors during the Audit. NO NA. We do not have custom-built software Yes Internal Audit has been conducted by the inhouse Infosec and ISMS Lead Auditor. All the projects, business processes and ISMS controls has been included in the scope and opportunity of improvements has been communicated to all the respective teams with the remideiation plan. And the frequency of the Internal audit is annually. We have the external Auditor for ISMS Audit. All the projects, business processes and ISMS controls has been included in the scope and opportunity of improvements has been communicated to all the respective teams with the remideiation plan. And the frequency of the external audit is annually. See ISOIEC 270012013 Certificate and Internal Audit report attached. NA. We do not use for own purposes Yes Yes. All the employees and third party service providers are required to sign Confidentiality Agreements to protect customer information as per ISMS compliance requirements. We have dedicated IT Team and Admin team who looks after the hardware security and, we have implemented the security controls as per the ISO 27001:2013 and SOC 2 Compliance requirements. We are hosting our application on AWS, and they are providing physical security to our data centre. We have Asset Management Procedure in place to identify, classify, label, and handle the Information and Information assets according to their criticality and sensitivity. We have Media protection procedure to handle the locally stored data as per the Information security compliance requirements. As per the Physical and Environmental Security policy we have security guards and CCTV Camera's to safeguard the office building and also to provide an access to the building only for the authorized individuals. We also have Media protection policy which also defines on how to handle the Paper documents as per the compliance requirements. Physical documents are handled with at most care and followed the policies and procedures of an organisation to make sure that the data is protected. We have Physical and Environmental Security policy and Vendor management guidelines in place and working effectively. We have implemented controls on Physical entry, Securing offices, rooms, facilities, Working in secure areas, Delivery and Loading areas etc. Only the authorised individuals will get an access upon verification. And we also conduct periodical verification of the effectiveness of these controls periodically through internal and external Audit. We provide access to the outsiders or suppliers on approval and escorting mechanism of vendor management guidelines by issuing the access cards. All our assets are classified, labelled, and maintained in the register by our IT Team. Access granted only to, authorized individuals. We have locked environment for our hardware's which would store the data. We also have implemented the Media protection procedure to protect the data which are stored physically. Yes. Backups are stored in a safe place. We have backup Recovery Procedure and implemented the controls to protect the organization information asset from the damages that may be caused due to failure of hardware system, corruption of software, breaches leading to data destruction and or not being able to retrieve and use. We predominantly work on cloud-based infrastructure and the teams may consider adoption of Amazon Web Services which provides the Backup and Restore services to build scalable, durable and secure data-protection solutions. AWS claims the following benefits and the teams may evaluate the benefits to the respective context that may lead to realize the following outcomes: 1. Data Type and Durability 2. Flexibility and Scalability 3. Security and Compliance The following AWS based offering for the following use cases offered by AWS may be considered based on the contractual needs of the subject under consideration: 1. Hybrid Cloud Backup 2. Data Lifecycle Management 3. Tape Replacement 4. Global Data Resiliency 5. Data Backup 6. Archive & Compliance We are ISO 27001:2013 certified and GDPR compliant organization. We have Information security policy and Data security policies in place with regards to data protection. We make sure that the below principle of data security has been followed as per the compliance requirements. 1. Fairness and lawfulness When personal data processed by us, we make sure that the individual rights of the data subjects must be protected. We will ensure that the personal data is collected and processed in a legal and fair manner. 2. Confidentiality - Restriction to a specific purpose We make sure that the any processing of personal data should be lawful, fair, and transparent. Personal data will be processed only for the purpose that was defined before the data was collected. Subsequent changes to the purpose are only possible to a limited extent and require substantiation. 3. Transparency We make sure that we maintain the transparency with regards to the data collected, stored and disposed. We also provide rights to data subjects as per the GDPR compliance requirements. For ex - Right to Rectification, Right to Portability and Right to be Forgotten. 4. Integrity and data security Personal data is subjected to the data secrecy. We have controls on confidentiality, Integrity and data security. We follow secured suitable organizational and technical measures to make sure that the data is protected from an unauthorized access, illegal processing or distribution, as well as accidental loss, modification or destruction etc. Sensitive data - We do Inform involved parties about how we will process their data Inform involved parties about who has access to their information Have provisions in cases of lost, corrupted, or compromised data Allow involved parties to request that we modify, erase, reduce or correct data contained in our databases. Sensitive data - We do not Communicated informally. Stored for more than a specified amount of time. Distribute to any party other than the ones agreed upon by the data's owner (exempting legitimate requests from law enforcement authorities. In addition to ways of handling the data the company has direct obligations towards people to whom the data belongs. We have controls in place to protect the information or to maintain privacy. We conduct Data Privacy impact assessment and Audits periodically as per the compliance requirements. We have Personally Identifiable Information Policy, Data Security policy, Data Subject Access Rights Procedure, Data Retention and Disposal Policy as per GDPR compliance. We conduct periodic vendor risk assessment. Information security documents are validated by theiInternal and external auditors during the assessments. Yes. We have an access control policy. The policy is attached for reference. Only authorised employees will have access to the data. Yes. Xoxoday is ISO/IEC 27001:2013 certified organization. See certificate attached. Yes. We have a well-defined policy for roles and responsibilities. We have communicated each employee about their responsibilities across the organization. We do maintain appropriate contracts with relevant authorities and ensure that applicable regulations are complied with Yes. We provide these rights to the data subject as per GDPR Yes. We conduct internal and external audits and all the applicable controls have been validated as per the compliance requirements. Yes We have a media handling procedure. See attached for reference. No. We do not transfer the data outside our organization. Yes. See Infrastructure Change Control Procedure attached. Yes. Security inceidents will be reported by our Information security team or customer support team within 48 hours. We have implemented physical security controls as per the compliance requirements. We have CCTV, access cards, security guards for monitoring and only authorised individual have access. Segregation is done for production and non-production or Testing environments. We maintain the test accounts seperately and delete or terminate the accounts immediately once the testing is completed. Only Admins have an access to create these tests accounts on need and approval basis. We have implemented the Roles and Resposibilities policy and defined the Duties of all the system users and segragated based on the defined roles. Only authorised individual will have an access to the Information system on need and approval basis. We maintain these records for Audit purposes. We have controls in place to monitor the user access system. We have implemented Role based access management system through access control policy. Our application also supports Role based access control system to make sure that only authorised individual will have an access to the Information system on need and approval basis. We maintain these records for Audit purposes. We are Compliant. We monitor these controls on a periodical basis and also during the internal and external Audits. Successful and failed login attempts will be logged, we use privileged accounts are used only for system administration activities,we remove default credentials and use the new credentials for all our systems. We use Multifactor authentication menthods to make sure that only authenticated individual have an access to the Information system wherever strong authentication is required. We use Biomentric verification and access cards methods for physical security purposes. We have these controls in place. We have a restriction for Physical access, monitor these access periodically and validate to make sure that only the authorised individual have an access. The credentilas has been comminocated via secured mode to make sure that confidentiality is maintained. We are Compliant.These controls are audited during the internal and external Audits. We are Compliant.Only authorised individual will have an access. We are cothe customerant. We maintain the records of Audit logs. We have restricted the access of external harddrives, USB etc for all the systems through Active directory and End point security. We have the security controls in place. We have installed the firewalls to monitor and control the incoming and outgoing network traffic based on predetermined security rules. It helps us to establishes a barrier between a trusted network and an untrusted network. We have implemented the asset management procedure to identify, classify, label and handle the Information and Information assets according to their criticality and sensitivity. We have labeled the aseets in order to identify and make sure that the access control permissions are maintained. we have implemented intrusion detection and prevention tools, we ensure timely detection and investigation in a prompt manner. These are integrated with security operations/SIEM solutions. We take an approval from the concerned authority before procuring the equipment or routing connections and test the same before installing it. All the network devices are securely configured and we always make sure that we monitor the same on regular basis and take appropriate action on any detections. We use vendor supplied softwares without any changes wherever feasible, if all the security controls are in place. We consider these factors before making these changes to the softwares. Yes, we test the changes made on testing environment before moving it to a production environment. Only authorised individual have an acces to the approved information assets. we are compliant. We document or have a track of all the changes made to protect the information system. We are compliant and have these controls in place. We have the appropriate clauses in the agreements wherever necessary. We provide guidance for using our products appropriately and take all the possible benefits. We have the controls in place. All the Critical patches will be deployed immediately We inform our customers on the vulnerabilities wherever is required from the compliance perspective. Our product is free from dormant malicious programmes We test the systems before deploying into operational environment. We have implemented the System Devolopment Life Cycle procedures and all the testing of new features are documented. We conduct security assessments before accepting the products and take appropriate approval to make sure that all the security requirements are met. All the test results are documented. We record these in the Risk register and documented before purchasing the product. We make sure that these are met before acquiring and products. The customer responsible staff can confirm upon validation of the security requirements. All the design and implemetation has been documented. We conduct the security Risk assessment in order to identify and mitigate the risks. We have kept Testing and production environment seperately. We do not use any data from our production environment for testing purposes. All our contracts or agreeements are having appropriate clauses with regards to security compliance, privacy, Audit requirements etc. we use only licensed softwares or assets We are compliant. We maintain these records for Audit purposes. We have not outsourced. Attached the Information Security Manual. It prescribes the policies that govern the management and administration of the Information Security Management System (ISMS) for application.It specifies the scope and the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving the information security controls. We have not subcontracted or outsourced any of services with regards to the product. We have documented the Transfer of Information and it's a part of our Information security policy We do not transfer the data. But if its necessary it will be done only upon the approval of the management. We have documented the Transfer of Information and it's a part of our Information security policy We do not transfer the data. But we follow these compliance requirements if there are any data transfers. We have implemented the Information security and Data security policies in order to make sure that we secure our organizational and customers information. We maintain these records for Audit purposes. We monitor and audit the logs. We are complied. We have controls in place to make sure that Information system is protected. We conduct the Risk assessment to identify and mitigate the risks involved. We use Google workspace as email solution and adequate security features has been enabled to make sure that Information system is protected. We do not connect.NA We make sure that all the controls and compensatory controls are in place in order to protect against the Security threats. We have implemeted the risk management procedure and defined the Risk Treatment, Risk Treatment, Risk Mitigation, and Risk transfer etc We have implemeted the risk management procedure and defined the Risk Treatment, Risk Treatment, Risk Mitigation, and Risk transfer etc We implement the Compensating security controls wherever measures cannot be applied due to technical or operational infeasibility. We maintain these records for Audit purposes. It's a part of our Internal and external Audits. We make sure that these controls are in place and security has not been degraded below the accepted level. We also validate these controls during our internal and external Audits. We have implemented the role based access system and change management policy in order to make sure that we provide an access to an individual only upon need and approval basis. All the changes has been tracked and maintained the records for audit purposes. We have a up to date records of all the assets used. We make sure that we follow the Industry best practices and security standard to make sure that we secure the information asset. We make sure that we follow the existing security controls and implement the compensatory controls to make sure that the information system is secure. We have implemented the control. We conduct the Risk assessment to identify and mitigate the risks involved. Compliant.We review and validate these controls on a periodical basis and These are part of an Internal and external Audits. Compliant.We review and validate these controls on a periodical basis. We maintain these records for Audit purposes. We have the required security controls in place. We do not use outdated computer hardware, software, technology, services or practices We upgrade the systems make sure that do not use outdated computer hardware, software, technology, services or practices We have installed the end point security software on all the computers and servers to keep the computer and personal information protected. We have installed the end point security software on all the computers and servers to keep the computer and personal information protected. We are compliant. We have enabled these features. We have installed end point security softwares to safeguard from attack scripts, viruses, worms, Trojan horses, backdoors and malicious active content. We also conduct periodical scanning in order to make sure that all the information assets are safe. These are centrally managed and have control on all the end points. It is available on need to know basis We make sure the Vulnerability assessment has been conducted for our products as per the compliance requirements. We are compliant. the customer Sensitive information will not be exposed to the general public. We document and maintain all the security issues. We are complaint. We are compliant. We have clasified, labeled our assets and periodically monitored. All the logs and realtime trafic is monitored. Implemented. We are compliant. These are all part of CSP agreement. We have these controls in place as a part of our Business continuity plan. We have these controls in place as a part of our Business continuity plan. It has been tested periodically and part of our internal and external Audit. We have conducted the risk assessment as per the industrial standard. Agreed. We will sign the NDA SLA can be documented and agreed by the both the party. Only authorised individual have an acces to the approved information assets. We allow our customer to audit but atlease 30 days prior notice with the scope of the audit needs to be communicated Its documented as per the Risk management procedure. We have all the details in SLA We can make our audit reports available We maintain appropriate reports and records, to monitor and measure the compliance with the security requirements. We make sure that we follow the risk management procedure and take these factors into consideration. We have these in place and tested annually. We have these in place and tested annually. Our BCP/DR plan supports this. We review these on annual basis We have cmmunicated to all the internal and external parties. It's a part of Business continuity documents and attached the same for your reference. The BCP Test and lessons learned has been documented. It's a part of BCP documents and we review and update when changes takes place. These are part of internal and external audits We have implemented the Corrective Action Procedure. We have implemented the Corrective Action Procedure. We review rhe corrective action taken. We conduc the security assessments by the Internal and external auditors We share the data with our Internal and external auditors We make sure the Assessments and Audits will be conducted and reported independently. All the Sensitive information shall be handled as per Policies and procedures implemented. We have defined it in our compliance policy and Corrective Action Procedure We allow our customer to audit or assess but atlease 30 days prior notice with the scope of the audit needs to be communicated We continuously monitor and improve Information security framework to make sure that we safegurd the Information and all the controls are in place. We make sure that we brings these improvements to Information security systems from the incidents reported and audit observations etc We have implemented the corrective action plan procedure and review the policies and procedures on annual basis. It can be included in the agreement and our legal team will review and confirm Statement of work will have a details of product/service to be provided We can include the service levels in the agreement. We are not currently having an options for service credits/liquidated damages, if SLA are not met. We make sure that we have all the controls in place. We will do this as part of the agreement We are a multi tenant SAAS system and all our logs will contain data of all customers. We will have our own log monitoring and security analysis. Attached the BCP/DR documents We end point security in place We allow our customer to audit, but atlease 30 days prior notice with the scope of the audit needs to be communicated We have deployed our application on Amazon web services (AWS) Virtual platform cloud. AWS provides data center security to our application. AWS is ISO 27001;2013, ISO 27017, ISO 27018, SOC 2 certified organization. Xoxoday is also ISO 27001:2013 and GDPR compliant organization. Only the authorised individual have an access as per Access control policy. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access. Xoxoday's architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows. Since our services are delivered via. Web, the upgrades and updates to the services are seamless and usually do not involve any actions from the end-users. We try to release our product hotfixes once every week & major features once every month. Yes. Annually once. Yes. We are ISO 27001:2013 and GDPR Compliant. We are also compliant with SOC 2 type 1 and on the last phase of Audit. We will share the report once we have it from the Auditor. Attached the ISO 27001 certificate and engagement letter that we have for SOC 2 Audit. We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it's linked with the SSO/Active Directory All the employees initially inform the IT Support team through ticketing systemb the Infosec manager and Final level will be DPO and the management. The time of support ranges depends on the level of service. RTO and RPO is - 6 mins our products comply with all the industrial benchmarks and standards when it comes to the Software Development Life-cycle (SDLC). All software development procedures are supervised and monitored by Xoxoday so that they include: security requirements independent security review of the environment by a certified individual code reviews Quality monitoring, evaluation, and acceptance criteria for information systems, upgrades, and new versions shall be established and documented for the clients' reference. The data centers are hosted completely in isolation so that the access is limited and controlled. Load balancer allows shifting incremental load and can auto scale based on data load experienced by application. Each instance (EC2 Instance) under fortified VPC network is further conglomeration of Docker Container Web Services and APIs and application layer running on top of it. This helps in managing various aspects and features of application without affecting the functioning of each other and achieving a modular architecture to work as plug and play model. Amazon Cloud Watch is implemented to enable monitoring of the functioning of the application. The data is encrypted using 256-encryption based SSL certificate. To manage security of data Xoxoday plans a quarterly VAPT based security audit of application. We have implemented policies and procedures as per ISMS and GDPR requirements. We also conduct periodical Internal and external Audit by the third party Auditor. We have deployed our application on Cloud Virtual platform for maximum security. We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We conduct periodical Vulnerability assessment and Penetration Testing from the Inductry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications. We use logical data isolation with the help of company specific encryption keys. Data in non production environment is not updated with the production data. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256 As per the Information security policy and Data protection policy only the authorised individual have an access to the data through internal approving and ticketing system. We comply with Information security compliance - ISO 27001;2013, SOC 2 and GDPR Our product is ISO 27001 and GDPR compliant and have the features. We have health checks along with Self healing mechanisms in place 99.99% We use logical data isolation with the help of company specific encryption keys. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256. We have the ability to logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant's data. our network environment is designed and configured to restrict any communication and connection between the tenant's environment. Yes. We have the controls in place. We have blocked connecting Hard disk, USB, CD ROM etc to computers and all the devices are centrally managed. The data is only stored on our application and its deployed on AWS Cloud. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records We are a SAAS solution. We are cloud hosted. We use a variety of tools and plugins integrated with Prometheus & Cloudwatch along with health checks for facilitating our uptime/service availability Xoxoday's architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows. active-passive Yes. we have implemented the cookies policy Yes, we have the access controls Yes Yes, we have the access controls Yes. Users can updated their information Xoxoday - application platform has been integrated with Darwinbox with the objective of creating a reward system for employees. Organizations that are using DarwinBox will not only be able to automate their HR processes but can also reward employees to keep them motivated and engaged. Xoxoday application offers a unified rewarding platform that helps organizations build a winning organizational culture through reward and recognition programs that have a global catalog consisting of products and experiences from more than 700+ brands. Please click here to know more - [https://xoxoday.gitbook.io/application/developer-resources/integrations/darwinbox-+-application](https://xoxoday.gitbook.io/application/developer-resources/integrations/darwinbox-+-application) Yes. Xoxoday's primary security focus is to safeguard our customers or users' data. This is the reason that Xoxoday has invested in the appropriate resources and controls to protect and service our customers. We have an Infosec Manager who is responsible for Information security and reports to the Board of Directors of the company. All the job descriptions, role and responsibilities has been documented as per the compliance requirements. Xoxoday has developed a comprehensive set of security policies covering a range of topics. These policies are shared with and made available to all employees and contractors with access to Xoxoday information assets. Each employee, when inducted, signs a confidentiality agreement and acceptable use policy, after which they undergo training in information security, privacy, and compliance. Furthermore, we evaluate their understanding through tests and quizzes to determine which topics they need further training in. We provide training on specific aspects of security that they may require based on their roles. We spread awareness about the Information security among the employees through posters in public areas, emails, training and orientations etc.. Yes. All new hires are required to sign Non-Disclosure and Confidentiality agreements. The Employee expressly agrees that he/she shall not use Confidential Information provided by the Company in the development or delivery or for personal gain from providing any products or services for his/her own account or for the account of any third party. The NDA signed will be valid till the termination from an employement. Yes, We have implemented the process for termination from an employement. Once the employee is terminated all the access will be revoked, IDs are disabled, assets are returned and recorded as a part of the exit clearance. We have implemented the access control procedure and all the access will be revoked upon termination or transfer of an emplyees as per the compliance requirements. Anti-Virus is deployed in all systems and servers for protection against virus and malware. We use Bitdefender end point security for protecting the systems from virus and this has been updated on daily basis and centrally managed. 1. Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com) to raise a ticket, if you happen to notice any potential security issue whilst meeting all the required criteria in our policy. 2. The validation of the reported issue in terms of severity & authenticity will be done by our security team in around 90 days. 3. Post validation, steps will be taken to fix the security issues in accordance with our security policies. 4. The owner of the ticket will be informed once the issue is resolved. Security Severity has been categorized as High, Medium and Low. Once the reported vulnerability is closed we will conform the same. Reports can be generated by the admins through the application. If there are any additional support needed, our customer support team would be able to help and guide on generating report. We do not use any in-house devoloped applications. We have deployed our application on AWS cloud virtual platform. And AWS is SOC 2, ISO 27001, ISO 27017 and ISO 27701 certified organization. Shared the certificates. [Please click here to know more about API Documentation - https://xoxoday.gitbook.io/application/user-guide/for-admins-1/xoxo-links/xoxo-link-apis https://xoxoday.gitbook.io/application/developer-resources/storefront-integration/api-endpoints](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis) We have implemented the Web application firewall, IDs/IPs and amazon guard duty etc for maximum security. OAuth2 is used to authorize all API requests. We also conduct code review to make sure that the APIs are secure. Yes. Our employees are having required education and certifications to perform the job. We do conduct Internal and external Audit very year Yes, It's a part og our ISMS training. Attached the training calender as an advace. Xoxoday is compliant with - ISO 27001:2013, CPRA (California Privacy Rights Act), SOC 2 Type I, CSA STAR Level 1 and GDPR(General Data Protection Regulation). Attached the below mentioned documents. 1. Xoxoday ISOIEC 270012013 Certificate 2. Xoxoday SOC 2 Type 1 Report 2021 3. Xoxoday VAPT Certificate (Conducted by 3rd party vendor) 4. Xoxoday application VAPT Report (Conducted by 3rd party vendor) 5. Xoxoday CPRA Attestation Report 6. CSA STAR LEVEL 1 Compliant - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday) We have deployed our application on AWS Virtual platform cloud. The AWS Compliance Program helps to understand the robust controls in place at AWS to maintain security and compliance in the cloud. Attached the below compliance certificates and Audit reports – 1. Amazon Web Services ISO 27001 Certificate 2. AWS ISO 27017\_certification 3. AWS ISO 27018\_certification 4. AWS SOC 2 Report 5. AWS SOC 2 Type I Privacy Report 6. AWS CSA STAR Certificate Yes. We follow ISO 27001:2013, SOC-2 and GDPR We are ISO 27001:2013 certified and GDPR Compliant. Yes. We are ISO 27001:2013 certified and GDPR Compliant. We are also complied with Cloud Security Alliance (CSA) STAR level 1. Its SAAS Solution and available 24\*7 It's a web application. And it can be presented over the calls like MS Teams, Zoom, Google meet etc. Yes. We have an integration with other applications and provide secure communications. Yes Yes. Files will be transferred securely. Yes. The solutions integrated with other solutions like Zoho CRM, HubSpot, Darwin box, SurveyMonkey, Freshdesk etc NA. It's a SAAS Solution and does not require. The data will be in our control. And AWS Cloud provide service for deploying our application. AWS is also ISO 27001 and SOC 2 certified organization and adhered to the data governance. It's a part of our Risk assessment and we validate the compliance requirements of AWS cloud virtual platform annually. We have implemented all the required Infosec Policies and procedures as per ISO 27001:2013, GDPR and SOC-2 We perform Internal Audit and external Audits annually. We also conduct Security assessments and testing like Vulnerability assessment and Penetration testing every six months. Yes. We communicate these assessment results to clients on a yearly basis. We have the arrangements in place. Storage Period would be as per regulatory conditions. Personal data can be deleted based on a formal written request. Xoxoday would delete the data within 30 days of receiving the request. We will delete the data of the customers upon the termination of the contract and Our data cleansing process goes through an organized purge. Once the data is purged, it's purged from all places We have implemented all the SOC controls and in the last phase of Audit. We would be able to provide SOC 2 Type I report in next 2-3 weeks We have BCP/DR Policy as per the Infosec compliance requirements and we conduct the BCP test annually. See Business Continuity Management Procedure attached. See attached Incident Management Procedure attached Yes. An independent security third party audit been completed by "TUV NORD". The last last day of Audit was 29th June 2021 We have establised the Information security management systemIt specifies the scope and the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving the information security management system (ISMS) at Xoxoday. Xoxoday is committed to ensure Integrity, Confidentiality, Availability and Security of its Physical and Information Assets and also maintaining privacy for serving the needs of the customers and organization while meeting appropriate legal, statutory and regulatory requirements. Attached the Information Security Management System Manual. We have the Data security Controls in place. We have implemented IDS/IPS, Firewall and our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting. We have Cloudflare web application firewall for maximum security of data. We have implemented the role based access control system to make sure that the data os available only to an authorised individual. Nreach Online Services Pvt ltd, respects the individual right to their personal information and is committed to use minimum personal data with transparency, accuracy & protection of confidentiality, integrity, availability, privacy, authenticity & trustworthiness, nonrepudiation, accountability and auditability of the data received, stored, processed and destroyed for business purposes. Atatched the Xoxoday GDPR Data Security Policy We are compliant. We collect the data only throigh our application. We have role based access system to make sure that only the authorised individual have an access to the required information All the devices and emails are having adequate security controls. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. We have installed the firewalls to monitor and control the incoming and outgoing network traffic based on predetermined security rules. It helps us to establishes a barrier between a trusted network and an untrusted network. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory for more security. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.We have SDLC Policy as per ISMS requirements and we follow General Coding Practice. For example - We Conduct data validation on a trusted system, All cryptographic functions used to protect secrets from the application user.We also have Implemented least privilege; restrict users to only the functionality, data and system information that is required to perform their tasks. Yes. We have Implemented the SPF/ DKIM/ DMARC effectively. We are compliant. We have implemented the Password Management Policy We store password hashed. We have SHA512 hash with unique salt for every password. The password needs to be minimum 8 characters long and should contain at least one capital letter, special characters among '# \$ % \* &' and 1 digit. Maximum Password Age is 45 days. User IDs and passwords transmit through stringent checks in an encrypted format that complies with the current Technical Security Baseline Standards. All the user can set their own password from the very first login attempt. Passwords once used cannot be reused with the password history technique in order to disallow the reuse of old passwords. [AWS is ISO 27001, ISO 27017, ISO 27701, SOC 2, PCI DSS Level 1 certified organization. Please click here for more information about AWS Audit and certification - https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/) We inform Fincare if these regulatory authories agreed to inform. Yes. 30 days prior notice and scope of the Audit needs to communicated. We are a multi tenant SAAS system and all our logs will contain data of all customers. We will have our own log monitoring and security analysis. Its a SAAS product and we use We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Yes Yes [We store data on AWS Singapore.AWS is ISO 27001, ISO 27017, ISO 27701, SOC 2, PCI DSS Level 1 certified organization. Please click here for more information about AWS Audit and certification - https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/) We do not own the data centers. We deploy our application on AWS cloud virtual platform. [We store data on AWS Singapore.AWS is ISO 27001, ISO 27017, ISO 27701, SOC 2, PCI DSS Level 1 certified organization. Please click here for more information about AWS Audit and certification - https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/) Attached the ISO27001:2013 certificate. We do not collect and store any Payment card details. PCI DSS is not applicable for us. We inform the client if there is any changes of the design that impacts security posture of the system. We take steps to securely develop and test against security threats to ensure the safety of our customer data. We maintain a Secure development Lifecycle, in which training our developers and performing design and code reviews takes a primary role. In addition, Xoxoday employs third-party security experts to perform detailed penetration tests on different applications. application is ISO 27001, GDPR, CPRA/CCPA, CSA STAR certified. Our technical team maintains these records. We consuct the code review as per the compliance requirements and maintain the code repository. Attached the SDLC Proedures. Compliant. Since application is a SaaS Platform this would be not applicable. Since application is a SaaS Platform this would be not applicable. Since application is a SaaS Platform this would be not applicable. We are compliant with the requiremenrts. We do not transfer manually. NA And we use Google workspace for emailing solution. cryptographic keys are protected. Compliant. We do not store any PHI. The PII(name, email ID, phone#) are encrypted. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. We store only the PII(name, email ID, phone#) and does not store/process PHI & PCI. We are compliant with ISO 27001, CCPA/CPRA, EU GDPR, CSA etc. Attached these compliance certificates/audit reports. Yes, all the mechanisms related to security and policies are implemented to facilitate timely decision and investigation by root-cause analysis. These incidences are analyzed with network intrusion detection (IDS) tools. The information used for authentication is securely stored and transmitted. We store password hashed. We have SHA512 hash with unique salt for every password Not applicable since application is a SaaS platform. At Xoxoday we use Google workspace and activated the MDM features. application also has iOS and Androind mobile applications. This feature can be configured with the help of the MDM Solution that the customer use. At Xoxoday we use Google workspace and activated the MDM features. Compliant. We have segreated the roles and assign the responsibilities to our employees. Since its a Cloud hosted SaaS platform deploying of the application on cloud and server scannings are under the scope of Xoxoday. We use Web application firewall (WAF) and pfSense firewall for security reasons. 1. The Cloudflare Web Application Firewall (Cloudflare WAF) checks incoming web requests and filters undesired traffic based on the set of rules. 2. pfSense helps to monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on a defined set of security rules. At xoxoday we monitor and maintain the logs. The Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. At Xoxoday we have implemented the Active directory and the system will get locked if its inactive for more than 15 mins and re-autentication would require. We have the process in place for standardized approach to structured exception and error handling across all layers. At Xoxoday the validation has been done during the development and testing and we are compliant with the requirements. At Xoxoday Security and compliance requirements are considered during the development stage and we are ISO 27001, CPRA, CSA STAR level 1, GDPR compliant. We have implemented the controls to monitor the application and safegurd from the attacks. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. Since application is SaaS Platform it would be not applicable. We have implemented the Software Development Life Cycle (SDLC) procedure and attached the same for your reference. Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing. We remidiate or fixes the issues identified during the VA/PT assessment and make sure that the application is free from the vulnerabilities. Since it's a SaaS platform and deployed on AWS cloud virtual platform Singapore region. All the data will be stored on AWS VPC. Xoxoday is ISO 27001:2013 certified. An ISMS is a framework of policies and procedures that includes all legal, physical and technical controls involved in an organisation's information risk management processes with the aim of keeping information secure. With ISO's robust information security management system (ISMS) in place, you gain the additional reassurance that a full spectrum of security best practices is implemented across the organization Our Goal is to protect three aspects of information - Confidentiality: only the authorized persons have the right to access information. Integrity: only the authorized persons can change the information. Availability: the information must be accessible to authorized persons whenever it is needed. We have implemented the Access control policy to control the upload, download, viewing and modification AV Scans takes place every week and users also can scan it whenever they can scan the machine. We have prescheduled the scanning once in a week. We are using linux operating system which is inherently secure along with security practices like web application firewall etc We make sure that the customer data is well segregated and compartmantalized No Breaches taken place. We are having Robust Information security compliance framework and we are ISO 27001:2013 and GDPR complied. We follow all the applicable infosec compliance requirements to comply with the regulations We conduct the Risk assessment and compliance review on annual basis as per the compliance requirements. Yes. All the compliance and audit findings has been mitigated. All the vulnerabilities identified during the assessment has been fixed. We use Bitdefender end point security and installed on servers and development machines. Its updated on regular basis. Our roles and job duties are segregated through role-based access to ensure maximum security. Access to data and systems are based on the principles of least privilege for access. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access events. Its restricted and not available to the public. We follow the best practices ans servers are hardened for security reasons. We have implemented the Identity access management (IAM) and follow the Access control policy. At Xoxoday we follow the password policy. We have deployed our application on AWS Virtual platform cloud - Singapore region. RTO and RPO is 60 Minutes. We have implemented the Incident Management Procedure and attached the same for your reference. Since application is a SaaS product and the customer can use the product and services as soon as subscribed for application product usage. the customer will have the legal rights to use the Product. We do not change the terms frequently. We will provide 30 days' notice period for any changes of terms. We notify Client in case of any unauthorized disclosure of or breach of any confidentiality obligation of Xoxoday with respect to Confidential Information, data or information of Client and Xoxoday shall take all necessary and required steps and measures to mitigate such unauthorized disclosure or breach and shall co-operate with Client , at Xoxoday 's cost, to mitigate or control the loss or liability arising out of such disclosure or breach and to retrieve such data or information. Yes. have an active SLA in place that identifies minimum performance of the Product. We have the SLA in place. application endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week. Uptime is measured based on the monthly average of availability. We would be able to provide a report on need basis. No penalties are associated with SLA. We monitor the service continuously and make sure that the product and service is available to use all the time. We have a documented Business Continuity and Disaster Recovery Plan defined and implemented to enable people and process support during any crisis or business interruptions. Since our services are delivered via. Web, the upgrades and updates to the services are seamless and usually do not involve any actions from the end-users. Yes. Our architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows. If there is any major activity and the service will be unavailable, the Maintenance hours were communicated well in advance at least 3-4 day by application. Termination clause will be the part of Master Service agreement and both the parties can review and agree during entering into an agreement. Since it's a SaaS product, this is not applicable. Termination clause will be the part of Master Service agreement and both the parties can review and agree before entering into an agreement. Yes. changes to the production environment or development are documented, tested, and approved prior to implementation or any new releases. We conduct internal reviews and audited by the external auditors for our security standard certification. We conduct periodical Vulnerability assessment and Penetration Testing from the Industry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications. the customer data will stored on AWS virtual platform cloud Singapore. There is no impact on security. At Xoxoday we have implemented the Cyber Crisis Management Plan to provide and support capability for reporting and responding to cyber security incidents, to eliminate or minimize impacts of such incidents No. We monitor the logs on regular basis with regards to network, file and server, and security system. To provide more information, the infrastructure logs are collected using AWS Audit Trail and Application related logs are collected in our Elastic Search server and retained in long term cloud storage. No. Since we are a multi-tenant system, our logs contain information of all the tenants. We cannot isolate a single customer's information from our logs. At Xoxoday the Audit logs reviewed on a regular basis for security events. audit logs are set up, reviewed by our Technical team and logs are recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. We are GDPR Compliant. Our information security team and Customer support team will inform the POC of Client via email communication with Preliminary Incident Synopsis and Root Cause Analysis report (RCA) including the details of Business Impact, Issue Description, Root Cause, and Corrective Actions. Yes. We have implemented the incident response plan and it complies with industry standards ISO 27001:2013, SOC-2, GDPR. We are ISO 27001:2013 certified and attached the certificate. # HR Compliance Source: https://help-plum.xoxoday.com/faq/security-compliance/hr-compliance Find answers to frequently asked questions about Plum's HR compliance practices and internal employment-related policies. Each employee undergoes a process of background verification. We hire reputed external agencies to perform this check on our behalf. We do this to verify their criminal records, previous employment records, if any, and educational background. Until this check is performed, the employee is not assigned tasks that may pose risks to users. There will be exception and it applies to all the employees, contractors, vendors, and others who may have access to your systems. Yes, we conduct background verification of all the employees Yes. We conduct Background verification criminal history checks for all candidates for employment, contractors and third party vendors Yes. We have the procedure for exit clearance and we will remove all the access provided and take all the assets back from the employees. We do conduct employees and contractors background verification as per the compliance requirements As a part of onboarding process all the employees are mandated to sign a non-disclosure agreement As part of the employee on-boarding process, all new joinees are provided with awareness training on information security and privacy requirements at Freshworks. Annually a refresher training is conducted for all the employees. In addition, on a need basis, role-based information security and data privacy training are provided to different teams. The disciplinary process has been documented and communicated to the employees. As a part of on boarding process we also have taken Information security declaration form from all the employees and made it mandatory. All the employees are aware that in case of any breach the desciplinary action will be taken against them, User registration and de-registration process is a part of Onboarding and Offboarding. We have provided WFH option to all our employees and also we follow hygiene practices at work and educating employees on the importance controlling infections at work by adopting correct hygiene practices We have taken a approriate measures and stopped travelling due to an outbreak. All the employees are working from home and issued guidelines to get protected from the current situation. We are compliant. We are compliant. YES. We conduct the mandatory background verification. Each employee undergoes a process of background verification. We hire reputed external agencies to perform this check on our behalf. We do this to verify their criminal records, previous employment records if any, and educational background. Until this check is performed, the employee is not assigned tasks that may pose risks to users. All new hires are required to sign Non-Disclosure and Confidentiality agreements. The Employee expressly agrees that he/she shall not use Confidential Information provided by the Company in the development or delivery or for personal gain from providing any products or services for his/her own account or for the account of any third party. Yes. We conduct the background verification of all our employees. We performs background checks for all the employees in accordance with law. The background check includes criminal, education, and employment verification etc. We conduct ISMS training for all the employees. The frequency of the training will be annually. Yes. We conduct the background verification of all the employees. We provide mandatory security and awareness training to all our employees and spread awareness about the information security accrross the organization. Yes. Our employees are having required education and certifications to perform the job. Each employee, when inducted, signs a confidentiality agreement and acceptable use policy, after which they undergo training in information security, privacy, and compliance. Furthermore, we evaluate their understanding through tests and quizzes to determine which topics they need further training in. We provide training on specific aspects of security that they may require based on their roles. All our engineers and other employees who suports application service are having appropriate education and skillset to perform the job.Each employee undergoes a process of background verification. We hire reputed external agencies to perform this check on our behalf. We do this to verify their criminal records, previous employment records, if any, and educational background. Until this check is performed, the employee is not assigned tasks that may pose risks to users. Yes Yes. All the employees and third party service providers are required to sign Confidentiality Agreements to protect customer information as per ISMS compliance requirements. We conduct Background verification of the vendors before onboarding. We have implemented Supplier Management Procedure, and this is applicable to all suppliers delivering various products and services with respect to delivery functions and support functions including Finance, Legal, Human Resources, IT Infrastructure. We are having contracts or agreements and non-disclosure agreements with all our suppliers Xoxoday monitors supplier services and compliance requirements and review each supplier annually with respect to the services delivered by the supplier. The review frequency could be changed based on the criticality of the services provided. Validation of suppliers related documentations are also part of our internal and external Audits. It's a part of our recruitment process. Attached the Background Verification Procedure Each employee undergoes a process of background verification. We hire reputed external agencies to perform this check on our behalf. We do this to verify their criminal records, previous employment records if any, and educational background. Until this check is performed, the employee is not assigned tasks that may pose risks to users. Yes. We have a Recruitment policy. Yes. We conduct background verification of all the employees before onboarding. Each employee, when inducted, signs a confidentiality agreement and acceptable use policy, after which they undergo training in information security, privacy, and compliance. Furthermore, we evaluate their understanding through tests and quizzes to determine which topics they need further training in. We provide training on specific aspects of security that they may require based on their roles. We also conduct the annual training for all the employees thereafter. Yes. We have communicated to all the employees and conducting periodical Awareness training to spread awareness and the employees are well aware of Incident reporting system. # Identity and Access Management Source: https://help-plum.xoxoday.com/faq/security-compliance/identity-and-access-management Find answers to frequently asked questions about Plum's identity and access management practices and internal security controls. Yes, our policies and procedures are established and implemented to enforce two-factor authentication for privileged account management/authentication while accessing tenant data/systems. Yes, systems must be configured to log all successful and unsuccessful login attempts by accounts with privileged access. These authentication logs must be retained for a minimum of 180 days and in accordance with the Company's records retention guidelines. Yes, users can re-authenticate a change in credentials and we comply to any attempted change in authentication information. No, we do not present login notices to users before they log in as the users are redirected through SAP SuccessFactors. Yes, there is a protocol in place to ensure that no information beyond an unsuccessful login attempt goes through prior to a successful login. Yes, our partnerships with a wide array of integration partners ensure existing customer based Single Sign On (SSO) capability for all users to seamlessly use Xoxoday's products. With an easy DIY setup, your SSO solution would be plugged in and ready to go. Please refer to our list of integrations to know more. Yes, our identity federation standards include SAML 2.0, SPML, WS-Federation and more as means of authenticating and authorizing users with airtight security protocol. We isolate our machines, network and storage with respect to the AWS Standards in order to keep it safe and secure. No, tenants are only allowed to use our secure protocols and procedures to prevent cracks and folds in data handling. Yes, we do support our clients' and tenants' access review policies. Our password setting requirements comply with all factors to ensure that strong passwords are created. Passwords should be of a minimum length and contain special characters, capitalized letters, and alpha-numeric combinations. No, customers/tenants must comply with Xoxoday's account lockout and password polices that have been incorporated for maximum security. No, the user can set their own password from the very first login attempt. No. As Xoxoday's products use single sign on (SSO), the users can login via their suite email and credentials. Yes, audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. Yes, to ensure the maximum safety and authority of data in right hands, the physical and logical adult log access of users can only be accessed by authorized personnel. No, logs are automatically audited, but are not integrated with tenant's security ops. In case the tenant requests for logs, they can shared when asked for by the clients. Yes, regular audit logs are stored with Xoxoday and retained for future references. The event logs are stores in a bucket wherein nobody can access them without an approval from the high authorities i.e. the Chief Technical Officer. Yes, all the mechanisms related to security and policies are implemented to facilitate timely decision and investigation by root-cause analysis. These incidences are analyzed with network intrusion detection (IDS) tools. Please refer to: "Threat & Vulnerabilities Management Procedures". Yes, in case specific incidents arise for particular tenants, our logging and monitoring framework allows isolation of incidents. Yes, there are measures to limit the access of tenant's data from non-authorized devices. Please refer to "Access Control Procedures". No. In case the accounts are deactivated or dormant, they would still be in the Xoxoday's domain. The admin would have to manually reach out and disable the accounts that they wish to declare dormant or inactive. Yes. Passwords once used cannot be reused with the password history technique in order to disallow the reuse of old passwords. Please refer to "Password Management Policy". Yes, with access control limit, super admins and admins can give out access to authorized individuals as per requests raised by them in order to handle their platform as well as the personal data accordingly. Yes, the role of "admin" and "super admin" holds the high regards and these roles can process the personal data of users as per their choice with the access control limit capability. Yes, personal data is stored are registered databases that comply to all necessary inputs of a standard inventory repository. Yes, all the given credentials are safely stored in a TCCC-approved centralized system in order to securely process the personal data. Yes, our roles and job duties are segregated through role-based access to ensure maximum security of tenants' databases. Yes, in case an incident occurs with respect to inappropriate access of data, we shall share the reports. Yes, we do support measures to enforce strong multifactor authentication when it comes to accessing highly restricted data. No, the data can be accessed by Xoxoday's authorized personnel to serve you better with maximum security. We have AWS Identity and Access Management (IAM). Access to data and systems is based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. A strong identification and authentication system and logging systems are deployed and provide centralized control to administer, monitor, and review all critical access events. AWS is responsible for providing physical security to the data center as we have deployed our application on AWS. AWS provides physical data center access only to approved employees. All employees who need data center access must first apply for access and provide a valid business justification. These requests are granted based on the principle of least privilege, where requests must specify to which layer of the data center the individual needs access and are time-bound. Requests are reviewed and approved by authorized personnel, and access is revoked after the requested time expires. Once granted admittance, individuals are restricted to areas specified in their permissions. Third-party access - Third-party access is requested by approved AWS employees, who must apply for third-party access and provide a valid business justification. These requests are granted based on the principle of least privilege, where requests must specify to which layer of the data center the individual needs access, and are time-bound. These requests are approved by authorized personnel, and access is revoked after request time expires. Yes, we have implemented the process for termination from employment. Once the employee is terminated all the access will be revoked, IDs are disabled, assets are returned and recorded as a part of the exit clearance. We have implemented the access control procedure and all the access will be revoked upon termination or transfer of an employee as per the compliance requirements. Yes. We use a cloud-hosted VPN with strict access controls to allow our employees to access the official network. Yes, We have implemented the security operations center to monitor, prevent, detect, investigate, and respond to cyber threats around the clock. We have AWS Identity and Access Management (IAM). Access to data and systems is based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. Furthermore, while defining job roles and designing access roles, privileges leading to conflicts of interests are to be avoided. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access events. our identity federation standards include SAML 2.0, SPML, WS-Federation and more as means of authenticating and authorizing users with airtight security protocol We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. Wireless access is allowed and handled with high quality routers, password protection and restriction on internet usage etc. All our employees are having a unique email IDs and we have implemented the role based access control. Our product team will create an account for the admin users and the password can be changed immediately. Yes, we have the exit procedure and all the access provided to an employee will be removed or deleted. Yes. We review the access provided every month and the SPOC will be our system administrator. Yes. We have defined the number of unsuccessful attempts. After 3 unsuccessful logins the account will get locked. Yes, we have the different levels of access. For Ex - Admin, users. Yes. Every 90 days We will get an email for resetting the password. Once we click on it it will take us to a different window and provide an option to change or reset the password. We use only internet connection through wifi and only after the approval process IT Team will provide an access. Yes. We have all these controls. We have restricted access to shared folders, USB or external drives, Internet access and privileges access. Yes. We have a track of all these information and we will remove the access once the empoyee left the organization. Yes, we have different level of access like Admin and users and its configured in a secured manner. It's an application and it supports SSO and Active directory. Time our period that we configure in SSO/AD would apply. Yes. We have segregated the areas. We have implemented the controls for having the access only to an authorised individuals for production area. Yes, we have the controls. Yes. We have segregated the users. Sharing device is not allowed. All the permisson needs to be taken from the IT Team. Not provided these access to the employees. We have different levels of users and only upon approval and need basis will get access. At Xoxoday for all the critical applications the 2FA has been enabled. only Xoxoday authorised individual will have an access All the computer machines are restricted with Access to CDs, USB or any other hard drives. We do not grant access for security reasons. The secured areas are restricted and does not have access with electronic devices or mobiles. These areas are physically locked and periodically reviewed as a part of internal and external audits. Also these restricted area are secured with CCTV cameras and monitored 24\*7 for security reasons. We have implemented the access control procedure and we revoke the access rights of the employees when not needed or termination from the employment. Access granted and revoked will be reviewed regularly and validated during the internal and external audits. Access to the systems are based on the principles of least privilege for access. All the users have restrictions on installing and uninstalling the application/softwares, they are not provided with Admin access. Admin access will be with the the IT support head and will not be available for the normal users. We remove the access immediately after termination of an employees as a part of exit procedures. We inform the BSLI incase of any involuntary termination of an employee working on client account within a reasonable timeframe We have implemented the role based access control policy. We regularly monitor the user access controls and make neccessary reconciliation for security reasons. Our employees are provided access for corporate emails. But we have restricted for accessing other email service provider, sending the PII on emails, sending an email to personal email Ids etc for maximum security. All our employees are not provided with access to the client data. Only authorised individual will have access on need and approval basis. The approvers are either the Product Heads or CTO. Content Filtering Solution in place for cotrolled access to Internet and all the logs are monitored. We have the documented procedure in place for user access management. Attached the Access Control Procedure. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need to know basis and support segregation of duties. Access to data and systems are based on the principles of least privilege for access and need to know basis. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. Only authorised individual will have access on need and approval basis. The approvers are either the Product Heads or CTO. We provide option of work from home/remotely to our employees. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory. All the computer machines are restricted with Access to CDs, USB or any other hard drives. We do not grant access for security reasons. We have Changed default credentials and turned off services that are not needed. MFA has been enabled to make sure that only authorised individuals have access. We have implemented Cloudflare web application firewall, IDS, Guard Duty etc in order to prevent DDOS-type attacks. (Attached the evidence of Cloudflare web application firewall, IDS, VA/PT reports, guard Duty etc) We have implemented the role-based access control system and Only authorized users have access to the servers. logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long-term cloud storage. mechanisms are implemented to detect, address, and stabilize vulnerabilities We also have implemented the backup plan. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. Data backups are done daily and in a secured way in AWS. All the systems are secured with Bitdefender end point security, VPN, Active directory, Firewall etc for maximum security. All the sensitive areas are restricted and authorized personnel only can have access. Our facility is having Biometric access system and all the logs are maintained and periodically reviewed. We also have visitors management guidelines and All visitors and contractors are required to present identification and are signed in and continually escorted by authorized staff. AWS Identity and Access Management (IAM) enables us to manage access to AWS services and resources securely we don't provide multi-factor authentication. As of now, there's oAuth2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins. We have 3 types of roles - User, Admin and Super Admin. Based on the roles and responsibility these access can be provided on need and and approval basis. [Manage accounts - Manage Super Admin/Admins - https://xoxoday.gitbook.io/application/user-guide/for-admins-1/getting-started/settings/manage-super-admin-admins#can-the-super-admin-disable-his-her-own-account-if-no-how-is-the-scenario-of-the-exit-of-a-super-admin-handled](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/getting-started/settings/manage-super-admin-admins#can-the-super-admin-disable-his-her-own-account-if-no-how-is-the-scenario-of-the-exit-of-a-super-admin-handled) Xoxoday application platform collects PII like Name, email ID and Phone number of the employees those who will be using this platform. Xoxoday is ISO 27001:2013 certified, GDPR compliant and SOC 2 type I certified organization and have all the required technical and organizational controls in place and auditred during the internal and external audits. We have implemented the role-based access control system and Only authorized users have access to the servers. We use Amazon IAM for Identity access management. logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long-term cloud storage. mechanisms are implemented to detect, address, and stabilize vulnerabilities We also have implemented the backup plan. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. Data backups are done daily and in a secured way in AWS. Our network is protected through the use of key cloud security services, integration with our Cloudflare edge protection networks, regular audits, and network intelligence technologies, which monitor and/or block known malicious traffic and network attacks. Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a Vulnerability assessment and penetration testing. Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role based access requirements. Furthermore, while defining job roles and designing access roles, privileges leading to conflicts of interests are to be avoided. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access. We conduct the access control review on frequent basis and revoke all the access provided for exit employees. We have unique user IDs for all and does not use generic user IDs.Access to data and systems are based on the principles of least privilege for access. We conduct the access control review on frequent basis and revoke all the access provided for exit employees. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need to know basis and support segregation of duties. Privileges relating to Administration of user access privileges and role configurations are different from the authorized approver that approves access requests. The approvers are either the Product Heads or respective function Heads are their authorized delegates. Attached the Access control procedure. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need to know basis and support segregation of duties. All our employees are having the unique log in IDs. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. We provide application web application. Admins can control the application and will have an access to alerts and security events. We inform the the customer to revoke access. We have the alerting system in place and we perfom the scaning immediately in order to reduce the risk. They do not have access. Yes. We have role-based access system through access control policy to make sure that only the authorised individual has access to the required information. All the Access to data and systems are based on the principles of least privilege for access. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. The approvers are either the Product Heads or respective function Heads are their authorized delegates. Yes, We have the necessary controls in place in order to protec the information according to the data classification. For ex - Identity access management (IAM) Yes. We have a SIEM in pance for monitoring and maintaining logs over security incidents from various components. [Please click here to know more about admin acceess, Login, SSO Logins - https://xoxoday.gitbook.io/application/user-guide/for-admins-1/getting-started](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/getting-started) Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access. We have role-based access system through access control policy to make sure that only the authorised individual has access to the required information. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles Only authorised individual would access on need and approval basis. We also use SSO. All our employees are using official email IDs We have implemented Role based Access control policy and only authorised individual will have access upon need and approval basis. Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role based access requirements. Furthermore, while defining job roles and designing access roles, privileges leading to conflicts of interests are to be avoided. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it's linked with the SSO/Active Directory. We monitor and review these privileged access provided and do the necessary reconciliation as per the Access control policy implemented. 1. Xoxoday application has a rich set of integrations with HRMS, HRIS, CRM, Survey, Marketing automation, SSO, SAML tools like SAP SuccessFactors, Zoho People, Darwin Box, Hubspot, Freshworks, Zapier, Hubspot, Type Form, Survey Monkey, Survey Gizmo, SAML 2.0, etc 2. SSO SSO Redirection - The client has to generate temporary token for SSO and redirect the user to Xoxoday with this temporary token. Please click here - [https://xoxoday.gitbook.io/application/developer-resources/storefront-integration/api-endpoints/sso-redirection#sso-token-from-company-session](https://xoxoday.gitbook.io/application/developer-resources/storefront-integration/api-endpoints/sso-redirection#sso-token-from-company-session) Access to our production environment is allowed only via Xoxoday corporate network and access is allowed only to authorized individuals of the infrastructure and engineering team. Given the pandemic/WFH situation, VPN access has been enabled with 2FA For such authorized individuals, for ensuring business continuity. All our admins accounts has been sealed with MFA. and also we use AWS IAM for managing privileged identities. We revoke the access once the tasks is performed or terminated from the organization as per the access control policy and part of the HR Exit clearance. Yes. access revocation process synchronized throughout all the systems. Attached the Access control policy. We have implemented the Role-Based Access Control (RBAC) An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need to know basis and support segregation of duties. Privileges relating to Administration of user access privileges and role configurations are different from the authorized approver that approves access requests. The approvers are either the Product Heads or respective function Heads are their authorized delegates. We review the access rights on monthly basis. Attached the access control policy. We have implemented the incident management procedure and attached the same. We communicate with Preliminary Incident Synopsis and Root Cause Analysis report (RCA) including the details of Business Impact, Issue Description, Root Cause, and Corrective Actions. We use logical data isolation with the help of company specific encryption keys. We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. The incidents in other tenants would have no effect on the customer's services. We are adhered to ISO 27001:2013, GDPR, CPRA, SOC 2, CSA STAR and VA/PT - Shared these certifications and Audit reports. We have implemented the Access control policy and shared the same for your reference. All our admins' accounts have been sealed with MFA. and also, we use AWS IAM for managing privileged identities. All our Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long-term cloud storage. The audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. application support many SSO options such as - Google workspace. Azure AD, OKTA SSO, Onelogin, Ping Identity, Centrify etc.. There are four access roles: Super Admin, General Admin, Manager and Employee. Manage the level of access for each role through the access controls page application is a web application and also supports Android and iOS apps. application is supported by a comprehensive web application that can be accessed via desktop and mobile browsers on all compatible devices. For ex -Google chrome, Internet explorer, Microsoft edge etc.. The access control mechanism like RBAC is built in the application. We have a Super Admin, Admin, and user's account. Please click here to know more about SSO integration - [https://www.application.io/integrations](https://www.application.io/integrations) It supports Azure AD, Google workspace, Okta SSO, One login, Ping identity SSO, Centrify etc.. Its supports Azure AD integration. No. it does not. Once SSO is enabled, the users are not presented with any password options. Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. A strong identification and authentication system and logging systems are deployed and provide a centralized control to administer, monitor and review all critical access. We have a role-based access system through access control policy to make sure that only the authorised individual has access to the required information. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. The approvers are either the Product Heads or respective function Heads are their authorized delegates. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team, and it's linked with the SSO/Active Directory In addition to that we also use Encryption, Firewall, Bitdefender end point security etc. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team, and it's linked with the SSO/Active Directory We have implemented the Web application firewall, IDs/IPs and amazon guard duty etc for maximum security. OAuth2 is used to authorize all API requests. We also conduct code review to make sure that the APIs are secure. Yes. application supports SSO like Okta SSO, Onelogin SSO, Ping Identity SSO, Centrify etc.. Please click here to know more about application SSO - [https://www.application.io/integrations?tab=tab-sso](https://www.application.io/integrations?tab=tab-sso) Our identity federation standards include SAML 2.0, SPML, WS-Federation It Supports MS Azure active directory. No. We store password hashed. We have SHA512 hash with unique salt for every password No. 2FA is not required for logging into the application. We only support SSO with the help of SAML2.0 protocol. Yes. It supports SSO and OKTA Integration Yes. The account owner will receive an email notification and all the activities are logged. The account owner will receive an email notification and immediately and user can act on it. We have enabled password reset process. It identifies from the domain name of the email ID. We can Change the password of the application account by navigate to Setting in the Quick Access menu. 2FA is not supported. Yes. We have defined accessibility features, role-based permissions, access control and can Manage user access to various account functionality based on organizational needs. When SSO (via SAML2.0) is enabled login via password will be technically prohibited Yes. Users can provide complex password to make sure that the account is secure. Yes. We have enabled Multi factor authentication. Our application also support multi factor authentication. We have implemented the access control policy to make sure that only the authorised individual have an access to the data. You may suggest if anything needs to be added as per NSE access control policy. Super admin have complete control of the platform and can configure everything. We have the controls in place. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. We have controls in place to monitor the user access system. We have implemented Role based access management system through access control policy. We also conduct internal review, Audit and external Audit from the third party auditors to make sure that we are complying with the requirements. Yes, our identity federation standards include SAML 2.0, SPML, WS-Federation and more as means of authenticating and authorizing users with airtight security protocol. We use Freshdesk and Jira for Authorizing access. We have role based access system to make sure that only the authorised individual have an access to the required information. We also have Access Control Procedure as per the compliance requirements. Yes. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory. Yes. We have enabled MFA for maximum security Yes Yes. We have access control policy and change manangement policy in place. Our IT team periodically review the access granted to all the users and take necessary actions. Revocation of access and Asset submission is part of our exit procedure upon termination from the employment. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory. We use AES 256-bit encryption for data at rest for securing digital identities We store password hashed. We have SHA512 hash with unique salt for every password The cryptographic keys, including data encryption and SSL certificates are managed by Xoxoday for optimal security of sensitive data. Each tenant data is uniquely encrypted using client specific key. We use AES 256 bit encryption for data at rest to ensure maximum security measures. Yes Yes Yes Yes API Keys are stored in high availability ephemeral storage and not in any disc. Yes Yes Yes. We follow role-based access system. We have implemented an access control policy and it will restrict access of the authorised individuals only. At least 8 characters 45 days 5 attempts Yes Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in long-term cloud storage All users have benn assigned a unique user account. We have implemeted the Access control Policy and all the system components, network files, sensitive data will be accessed my the unique user accounts. All users have benn assigned a unique user account. And will not be reused by other people in the future. Admins will have a Centralised directory and can manage the users. For ex - Creation and deletion of the users. We are Compliant. We have implemented the Network Access Control and Security Procedure. We are diligently controlling access to computer resources, enforcing policies, Firewall, Switches etc We review the access controls on periodical basis and make sure that only authorised individual will have an access to the Information system. We grant privileges only upon the need and approval basis as per the access control policy. We review the access controls on periodical basis and make sure that only authorised individual will have an access to the Information system We have the monitoring system in place. Unauthorised access or attempts will be detected and prevented We have implemented the role based access control system. Only approved users will have an access to the Business application. We have controls in place to monitor the user access system. We have implemented Role based access management system through access control policy. We are compliant. Only authorised individual have an acces. We are compliant We use 2FA wherever is required to safeguard the information system. We grant an access to the vendor whenever is necessary on approval basis and access will be revoked upon the tasks completion. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory for more security. We have granted the logical access to the third parties upon approval and Agreement in place. We have disabled all the access for security purposes. The access will be provided only on need and approval basis for a specific period of time. We are compliant. We have role based access system to make sure that only the authorised individual have an access to the required information All the devices and emails are having adequate security controls. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.We have SDLC Policy as per ISMS requirements and we follow General Coding Practice. For example - We Conduct data validation on a trusted system, All cryptographic functions used to protect secrets from the application user.We also have Implemented least privilege; restrict users to only the functionality, data and system information that is required to perform their tasks. We have installed the firewalls to monitor and control the incoming and outgoing network traffic based on predetermined security rules. It helps us to establishes a barrier between a trusted network and an untrusted network. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory for more security. we can provide limited access to different vendors or systems. We are compliant. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. We have implemented the Network Access Control and Security Procedure. Network services are provided in house. We maintain the records for the service levels and reviewed during the internal and external Audits. We always make sure that components are configured to the most restrictive mode. We provide access to our employees to only required amount of functionalities for any software applications.We uninstall the softwares or disable the features wherever is not required. We have disabled all the access for security purposes. We review these access frequently. We are compliant. We are compliant. Physical access to equipment has been restricted to only necessary and authorised personnel We are compliant. Only authorised individual have an acces to the approved information assets. We provide access to authorised individual on approval basis Our application doesn't have a 2FA for admin functions. We have role based access system to make sure that only the authorised individual have an access to the required information. Yes. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. As per the access control policy our application controls the access of an unauthorised individual through diference levels of users like Admin, super admin and users. Yes. We are complied. We have the access control policy and password policies. We have access control polic and only the authorosed individual have an access to the PII on need and approval basis. We also review these access granted on monthly basis. We have access control system in place and only the authorised individual have an access. Attached the procedure for your reference. application supports SSO. our identity federation standards include SAML 2.0, SPML, WS-Federation,Google SSO Login and more as means of authenticating and authorizing users with airtight security protocol The application have robust authentication methods. We are integrated SAML 2.0 with SAP SuccessFactors, we also support OAuth 2.0 for seamless authentication. Yes -SSO Yes. We also fix the issues identified and conduct the test once again for confirmation of fixes. Our partnerships with a wide array of integration partners ensure existing customer based Single Sign On (SSO) capability for all users to seamlessly use Xoxoday's products. With an easy DIY setup, your SSO solution would be plugged in and ready to go. Yes. We have physical access controls in place and only authorised individuals will have access. We have provided the access cards to all the employees and installed biometric machines at all the entry and exit areas. We have also installed the CCTV cameras in our building and will be monitored 24\*7 for maximum security. We have implemented the access control policy and only authorised individual will have access to the systems/application. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need to know basis and support segregation of duties Access to the production environment is restricted to a limited set of authorized users based on their job responsibilities. Users from the development and testing or QA teams do not have access to the production environment. Access to migrate changes is limited to designated and authorized individuals. Access to the production environment is approved by the Product Owner and the systems of the authorized users are registered and authenticated during login. The access is controlled through the AWS Identity and Access Management system that also enforces two-factor authentication. Yes. The list of users who have admin access have been maintained through AD, IAM, HRMS etc..and reviewed periodically and during the internal and external audits. Mobile devices are not allowed for production use. Yes. All the sensitive information has been encrypted. All the data at rest also has been encrypted for maximum security. Yes. All the software installation restricted for desktops, laptops and servers. Users does not have permission to install any software or make any changes. Yes. Access to source application code restricted. Application code has been stored in the code repository and have access only to the authorised individuals. We have implemented SDLC Policy as per ISMS requirements and we follow General Coding Practice. For example - We Conduct data validation on a trusted system, All cryptographic functions used to protect secrets from the application user. We also have Implemented least privilege; restrict users to only the functionality, data and system information that is required to perform their tasks we follow all the technical guidelines for development of our code and applications that come under the Open Web Application Security Project. Yes. All our users uses unique IDs. There are no shared accounts. Yes. We have implemented the access control policy and we review the use accounts on frequent basis for both admin and normal users. Only authorised individual would access on need and approval basis. We also use SSO. All our employees are using official email IDs We have implemented Role based Access control policy and only authorised individual will have access upon need and approval basis. Yes. We have role-based access system through access control policy to make sure that only the authorised individual has access to the required information. All the Access to data and systems are based on the principles of least privilege for access. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. The approvers are either the Product Heads or respective function Heads are their authorized delegates. Our employees will not have access by default. The data will be accessed only upon need an approval basis. The access is controlled through the AWS Identity and Access Management system that also enforces two-factor authentication Yes. No, we don't provide multi-factor authentication. As of now, there's oAuth2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins. Yes, We have the necessary controls in place in order to protec the information according to the data classification. For ex - Identity access management (IAM) Yes. Yes. We have implemented the physical access control and logical access control to protect the personal data. We have security guards, CCTV cameras, access cards etc for monitoring purposes. We use logical data isolation with the help of company specific encryption keys. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256 Only authorised individual will have an access. Yes. The administrator has the privileged access and can add or terminate the users. Admins have complete control of the platform and can configure the addition and deletion of the users through the admin console. Yes. application comes with a full set of integration with various platforms like AD. No. We do not use 3rd party application framework It's a SAAS Solution and can login in the multiple system by using the Single user ID/Password. Yes, there is a protocol in place to ensure that no information beyond an unsuccessful login attempt goes through prior to a successful login. Yes. We have this mechanism. Yes. solution disable the User ID automatically if the unsuccessful attempts exceeds the maximum of trial Yes Yes. Its not shown in the screen or sent via email. Password will be reset upon the email confirmation through password reset link. Once we click on the reset my password.it will redirected to the platform and ask us to Set a new password for our account. Password will be reset upon the email confirmation through password reset link. Once we click on the reset my password.it will redirected to the platform and ask us to Set a new password for our account We have enabled the role-based access system to provide an access to only authorized individuals. Yes. It can be managed centrally. The platform will get locked out as configured in AD or SSO ect No. Its linked with the Email IDs Yes. We can set up an account with the help of unique email IDs Yes It supports Email and Mobile phone Authentication. JSON-based token is available for maximum security direct-email logins. We have implemented the role-based access system to make sure that only the authorized individual have access to the required information. We have more than 100 employees for the application product including support functions. Few important positions those who are involved in Infosec and IT Security Functions Chief Operating Officer Vice president - application DevOps Head - application Product Head - application Infosec Manager IT Head We have Access Control Procedure and role based access system to make sure that only the authorised individual has access to the required information. application collaborated with the tools like MS Teams, Slack and HRMS tools like Gusto, Keka, SAP Successfactor, BambooHr, Ramco HRMS, people strong, Zohopeople and darwinbox. Users can also login via G Suite, Azure AD, Okta SSO, One login SSO, Ping identity SSO and Centrify. We have 4 user access roles - Super admin, General Admin, Manager and Employee. application collaborated with the tools like MS Teams, Slack and HRMS tools like Gusto, Keka, SAP Successfactor, BambooHr, Ramco HRMS, people strong, Zohopeople and darwinbox. Users can also login via G Suite, Azure AD, Okta SSO, One login SSO, Ping identity SSO and Centrify. Yes. we have the Physical security controls in place. Attached the Physical and Environmental Security Procedure. All the Fincare data will be stored on AWS Cloud virtual platform and will not store anything locally. The purpose of this procedure is to prevent unauthorized physical access, damage, interference, theft or compromise to assets owned or controlled by Nreach Online Services Private Limited. Yes. We have the Access control policy to make sure that the data os available only to an authorised individual.. Attached the Access control policy. Yes. Attached the Access control policy No.. it does not. Once SSO is enabled, the users are not presented with any password options. Super Admin (CTO) and Devops team are the custodians of the key. [application supports Single Sign-On (SSO). Please click here to know more - https://www.application.io/integrations?tab=tab-sso](https://www.empuls.io/integrations?tab=tab-sso) Since empluls is SaaS platform this can be configured with the help of the Active directory so that the users who are inactive for more than 15 mins can re-login. Yes. Account can be created, disabled and password can be reset. Password is masked during the entry. We store password hashed. We have SHA512 hash with unique salt for every password. [application has four different user access levels, namely Super Admin, General Admin, Manager, User. Please click here to know more - https://help.application.io/platform-management/platform-settings/access-controls](https://help.empuls.io/platform-management/platform-settings/access-controls) [application has four different user access levels, namely Super Admin, General Admin, Manager, User. Please click here to know more - https://help.application.io/platform-management/platform-settings/access-controls Xoxoday is ISO 27001:2013, GDPR, CCPA/CPRA and CSA STAR Level 1 compliant organization. We take appropriate consent for collecting the PII (Name, Email ID, Phone#) as per the privacy laws. Xoxoday GDPR - https://www.xoxoday.com/gdpr Xoxoday Privacy - https://www.xoxoday.com/privacy-policy](https://help.empuls.io/platform-management/platform-settings/access-controls) Since empluls is SaaS platform this can be configured with the help of the Active directory. Yes. This can be configured and users can reset the password. Admins will have a centralised controls on the platform and will have access for creation/deletion of the users as per the requirements. Please click here to know more - [https://help.application.io/platform-management/platform-settings/access-controls](https://help.application.io/platform-management/platform-settings/access-controls) Admins will have a centralised controls on the platform and will have access for creation/deletion of the users as per the requirements. Please click here to know more - [https://help.application.io/platform-management/platform-settings/access-controls](https://help.application.io/platform-management/platform-settings/access-controls) application has four different user access levels, namely Super Admin, General Admin, Manager, User. Please click here to know more - [https://help.application.io/platform-management/platform-settings/access-controls](https://help.application.io/platform-management/platform-settings/access-controls) Application can be used only by the authorised individuals. We have implemented the oAuth2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins. At Xoxoday, the access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role based access requirements. A strong identification and authentication system(AWS IAM) and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access events. Yes the application have robust authentication methods. The users can re-authenticate a change in credentials and we comply to any attempted change in authentication information. our identity federation standards include SAML 2.0, SPML, WS-Federation and more as means of authenticating and authorizing users with airtight security protocol. At Xoxoday we review the access controls on frequent basis. We remove/revoke the access of the users upon termination or the access is not required and maintain these records for Audit purposes. At Xoxoday we review the access controls on frequent basis. Compliant. Attached the Access control policy. Yes. The customer will have control on the Application as they will be having the Super admin access. Yes. The users can access the mobile application only upon successful login. We provide remote support using the client remote access tools. [application has four different user access levels, namely Super Admin, General Admin, Manager, User. Please click here to know more - https://help.application.io/platform-management/platform-settings/access-controls](https://help.empuls.io/platform-management/platform-settings/access-controls) We have implemented the Role based access control machanism. Attached the Access control policy. We have the controls in place on who access the information and what level of access needs to be provided etc.. At Xoxoday we have implemented the Identity access management and all the applications are authenticated before login. We conduct the code review and get an approval from the CTO before releasing any new versions or updates. At Xoxoday we have implemented the Identity access management and all the applications are authenticated before login. Compliant. Only authorised individuals can have access to the application with the help of the valid credentials. No. Its not accessed via direct internet connection. Access to our production environment is allowed only via our corporate network and access is allowed only to authorized individuals. We use a cloud hosted VPN with strict access controls. VPN access has been enabled with 2FA For such authorized individuals. We have Role-based access control (RBAC) system and make sure that only the autorized individual have an access to the data. And we review these access provisoining regularly and deactive the users access as per the change management policy. No. We do not use generic IDs to access data application application has four different user access levels, namely Super Admin, General Admin, Manager, User. Super Admins are the default admins of application. They are also the Group Admins of Townhall. Super Admins can view what access permissions are available to various user access levels using Access Control settings. Super Admins can also delegate access for various features and tasks to General Admin, Manager & User. Within Xoxoday, Access to data and systems are based on the principles of least privilege for access. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access events. We have implimeneted the Access Control policy and follow the role based access control system. And all the access has been reviewed and make the necessary adjustments. The roles and access rights are reviewed during the internal and external Audits as well. Our partnerships with a wide array of integration partners ensure existing customer based Single Sign On (SSO) capability for all users to seamlessly use Xoxoday's products. With an easy DIY setup, your SSO solution would be plugged in and ready to go. our identity federation standards include SAML 2.0 At Xoxoday we have enabled MFA for all the critical roles and privilege accounts for maximum security. At Xoxoday user accounts will lockout after 5 unsuccessful failure login attempts. At Xoxoday all the users enforced to change the password for every 90 days. We store password hashed. We have SHA512 hash with unique salt for every password. We have implemented the Identity access management and follow the Access control policy. At Xoxoday we follow the password policy. We have implemented the Identity access management and follow the Access control policy. At Xoxoday we follow the password policy. Attached the same for your reference. Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access. We have role-based access system through access control policy to make sure that only the authorised individual has access to the required information. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. The approvers are either the Product Heads or respective function Heads are their authorized delegates. We logically segregate the the customer environment from other clients, each customer is uniquely identified by a tenant ID. It is segregated with a client-specific key for proper handling and security reasons. The application is engineered and verified to ensure that it always fetches data only for the logged-in tenant. Per this design, no customer has access to another customer's data. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. Privileges relating to Administration of user access privileges and role configurations are different from the authorized approver that approves access requests. The approvers are either the Product Heads or respective function Heads are their authorized delegates. Developers do not have access to the production environment. Access to the production environment is restricted to a limited set of authorized users based on their job responsibilities Within Xoxoday Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. Furthermore, while defining job roles and designing access roles, privileges leading to conflicts of interests are to be avoided. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access. We use Active directory and SSO for authentication purposes. [No, we don't provide multi-factor authentication. As of now, there's oAuth2.0 and SAML-based tokens Please click here to know more about Single Sign-On - https://www.application.io/integrations?tab=tab-sso](https://www.empuls.io/integrations?tab=tab-sso) Within Xoxoday Access to data and systems are based on the principles of least privilege for access. Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. Privileges relating to Administration of user access privileges and role configurations are different from the authorized approver that approves access requests. The approvers are either the department heads or the management. At Xoxoday only authorised personnel from our technical team will have access. For Ex – CTO/production head, Devops Lead etc.. The event logs are stores in a bucket wherein nobody can access them without an approval from the high authorities i.e. the Chief Technical Officer. # Information Security Source: https://help-plum.xoxoday.com/faq/security-compliance/information-security Find answers to frequently asked questions about the information security practices and standards Plum follows. [Open document](https://drive.google.com/file/d/1l23BTr1RStFZq_QmF-5V2vpS06cBJnHb/view?usp=sharing) [Open document](https://drive.google.com/file/d/1oww6vB7PxwXGafO33h0jG-T1VlD0Wm8q/view?usp=sharing) [Open document](https://drive.google.com/file/d/1WxUI_BnLLbeNzQHtWgkgLFqzhuZxIwax/view?usp=sharing) [Open document](https://drive.google.com/file/d/1P_7-nKbRI8AIWUgm66Q9aUsYr83nN85r/view?usp=sharing) [Open document](https://drive.google.com/file/d/10UXddHd9CxaCO6OLyqEM5PC1iGS2vFEz/view?usp=sharing) [Open document](https://drive.google.com/file/d/1bRjJvB4gDqvkp-WY_NlwTNL35K-Y6_YS/view?usp=sharing) [Open document](https://drive.google.com/file/d/1LQsURIqAmb8waKgI5DJac2D5hUVDNjua/view?usp=sharing) [Open document](https://drive.google.com/file/d/10JIrklIh9EzHWYQYLUvw-oDoTd3THwY2/view?usp=sharing) [Open document](https://drive.google.com/file/d/1PpWRocTmV2CKzZPvVf-9b60qi0Pe3Gx3/view?usp=sharing) [Open document](https://drive.google.com/file/d/1pzfi-zYodRujjPR5RzktjqyE4LME2jT_/view?usp=sharing) [Open document](https://drive.google.com/file/d/18qj9Cu55TuMileF7ppUJTNqfklabZFAX/view?usp=sharing) [Open document](https://drive.google.com/file/d/1FLNuR6I5uy3DHyuH6joR6v5KvlP-_aI-/view?usp=sharing) [Open document](https://drive.google.com/file/d/17eIpv1sBhYTS8mqLPlf1OuZYAkvGmBxo/view?usp=sharing) [Open document](https://drive.google.com/file/d/1BgY8w7K2gaxg2zlVcYaIc32VbdclBuCz/view?usp=sharing) [Open document](https://drive.google.com/file/d/1ajHzFdqttTek0APJhj9Z5bWr9QS6q6N_/view?usp=sharing) [Open document](https://drive.google.com/file/d/1d25BY9fxNhLUb6GmoDtrQ8WDPYtRf3Lh/view?usp=sharing) [Open document](https://drive.google.com/file/d/1ZFnMWlz_RtvrbYQbXxnQV4N7HNmT-MKn/view?usp=sharing) [Open document](https://drive.google.com/drive/u/0/folders/1q1hVwUQ0fEYzFZFXMatHn3UIeIOXM7tU/) [Open document](https://drive.google.com/file/d/1n02SoROiB1L3V27dFGd4G1vszZneoAr0/view?usp=sharing) [Open document](https://drive.google.com/file/d/1OZcypu7cVjHjwVFLnI5XY9zYKqjklMcq/view?usp=sharing) [Open document](https://drive.google.com/file/d/1FlyOOf8Nf6_eNgXFnnII8KZzyzVarCmc/view?usp=sharing) [Open document](https://drive.google.com/file/d/1FSl84TJ1kd-LWSQgs62609I5Xwz9KSyj/view?usp=sharing) # Others Source: https://help-plum.xoxoday.com/faq/security-compliance/others Find answers to additional security and compliance questions about the Plum platform that aren't covered elsewhere in this FAQ. Plum is GDPR compliant. At Xoxoday, we ensure that the data is gathered, stored, and handled with respect to individual rights. We have raised awareness among our employees and other stakeholders on how to handle the data appropriately. Our employees understand the importance of GDPR and information security. Xoxoday has an information security policy that is published and communicated to all suppliers and employees (including contractors and other relevant external parties). Xoxoday has ensured that the Information security policies have established the direction of the organization and align to best leading practices (e.g., ISO-27001, ISO-22307, CoBIT), regulatory, federal/state, and international laws where applicable. Yes, at Xoxoday, we have a formal disciplinary or sanction policy established for employees who have violated security policies and controls. Employees are made aware of what action might be taken in the event of a violation and stated as such in the policies and controls. A detailed disciplinary process and policy are also in place. At Xoxoday, we use JIRA for Project Management, and abiding by the Information security policy is mandatory and has been followed in all the projects. Every code change is reviewed by the tech lead or architect responsible for the project. During the review process, the reviewer is responsible for identifying possible security issues. Yes, Xoxoday has a Mobile device policy. At Xoxoday, the mobile device policy takes into account the risks of working with mobile devices in unprotected environments and the controls to be implemented for preventing data transmitted/stored in the mobile device, and much more. Yes at Xoxoday, we do have an 'Information Security Policy' in place. Information Classification is included in the organization's processes, and be consistent and coherent across the organization. Results of classification indicate the value of assets depending on their sensitivity and criticality to the organization, e.g. in terms of confidentiality, integrity, and availability. Results of classification are updated in accordance with changes in their value, sensitivity, and criticality through their life-cycle. Formal procedures for the secure disposal of media are also established to minimize the risk of confidential information leakage to unauthorized persons. The procedures for the secure disposal of media containing confidential information are proportional to the sensitivity of that information. Yes, we do have an 'Information Security Policy' in place and formal procedures for the secure disposal of media are established to minimize the risk of confidential information leakage to unauthorized persons. The procedures for the secure disposal of media containing confidential information are proportional to the sensitivity of that information. Our application has role-based access controls and the menu's screens are made accessible accordingly. AES 256 bit encryption for PI data. SHA256 with unique salt for Hashing passwords. Yes, Xoxoday does have tested Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP), the data would be stored at AWS Singapore. During security audit/VAPT review, these incidents are identified. Yes, this process is widely communicated to all the employees and stakeholders. Yes, on Xoxoday, we do conduct Quarterly VAPT. Yes, at Xoxoday, we perform quarterly VAPT and have static code analysis via SonarQube Policies, procedures, and standards have been established and maintained to protect information and physical media in transit, and are referenced in such transfer agreements. Also, there is a clause on securing business information and protection of confidential information in the NDA's signed by the external parties. As part of the ISO audit, IS Systems audit is also covered and yes the audit process ensures business disruption is minimized. We have a quarterly VAPT performed on the entire application by a third-party security auditor. At Xoxoday, we ensure that the data is gathered, stored, and handled with respect to individual rights. We have raised awareness among our employees and other stakeholders on how to handle the data appropriately. Our employees understand the importance of GDPR and information security. Our controls are placed based on the data protection impact assessment (DIPA). All personal data is encrypted on Xoxoday. We take data and security very seriously. We are ISO 27001, GDPR, and SOC compliant. More details about our [security](https://www.xoxoday.com/security) and [privacy policy](https://www.xoxoday.com/privacy-policy) in the links aforementioned. You can also know more about our compliance [**here**](/faqs/security-compliance/privacy-and-security). We may use the information we collect from you when you register, make a purchase, sign up for our newsletter, respond to a survey or marketing communication, surf the website, or use certain other site features in the following ways: * To personalize your experience and to allow us to deliver the type of content and product offerings in which you are most interested. * To improve our website in order to better serve you. * To allow us to better service you in responding to your customer service requests. * To ask for ratings and reviews of services or products. * To follow up with them after correspondence (live chat, email, or phone inquiries). We take data and security very seriously. We are ISO 27001, GDPR and SOC compliant. More details about our [security](https://www.xoxoday.com/security) and [privacy policy](https://www.xoxoday.com/privacy-policy) are [here](/faqs/security-compliance/privacy-and-security). We ensure that ensure production data shall not be replicated or used in non-production environments. Physical segregation is done for production and non-production environments. Yes. We are compliant with CPRA (California Privacy Rights Act), GDPR (General Data Protection Regulation) and HIPAA (Health Insurance Portability and Accountability Act) Implemented the data security Policy and Data Subject Access Rights Procedure. In accordance with Data Protection Laws, we make available to Controller on request in a timely manner such information as is necessary to demonstrate compliance by Processor with its obligations under Data Protection Laws. Upon Controller's written request and subject to the confidentiality obligations set forth in the Agreement, we will make available to Controller a copy of Nreach the most recent third-party audits or certifications, as applicable. Privacy Policy - [https://www.xoxoday.com/privacy-policy](https://www.xoxoday.com/privacy-policy) Attached the - Data Protection Policy, Data Security policy, Data Subject Access Rights Procedure, Data Breach Notification Procedure. Attached the data security Policy and Data Subject Access Rights Procedure. Please visit here for Privacy policy - [https://www.xoxoday.com/privacy-policy](https://www.xoxoday.com/privacy-policy) Yes. Please visit - [https://www.xoxoday.com/privacy-policy](https://www.xoxoday.com/privacy-policy) Yes, the policy, process, and procedure is implemented to ensure proper segregation of duties. our roles and job duties are segregated through role-based access to ensure maximum security of tenants' databases Attached the Xoxoday Privacy Policy. Please click here for the external privacy statement - [https://www.xoxoday.com/privacy-policy](https://www.xoxoday.com/privacy-policy). Yes. We do maintain the records as per the Data privacy compliance requirements. Yes. we maintain the list as per the Privacy laws and review it. We provide access only to authorised individual as per Role based access and access control policy. Yes. we follow the privacy gidelines when collecting, storing, or processing Personal Data via electronic, audio, visual or print media. We are complied with this requirements. We have review and monitor machanism to make sure that only the authorised individual have an access and the objectives of the privacy commitments are met. Yes. we provide them a Information security and Privacy training. The frequency of the training is once in a year or as soon as they onboarded. Yes. We have applicable data privacy clauses in the contracts. We continuosly monitor the efficiency and effectiveness of implemented security controls frequently during the internal and external audits. # Policies & Procedures Source: https://help-plum.xoxoday.com/faq/security-compliance/policies-procedures Find answers to frequently asked questions about the internal security policies and procedures that govern Plum's operations. We have the disciplinary process in place for Non-compliance with Information security Policy and we have communicated and made aware of the consequences for non-compliance. We have the employee termination process in place. We have implemented the information security policy and Hardening Guidelines. We have implemented the Data Retention and Disposal Policy and attached the same for your referrence. • Storage Period would be as per regulatory conditions. • Personal data can be deleted based on a formal written request, with justification. • Xoxoday would delete the data within 30 days of receiving the request. All our Privacy and security policies are reviewed every year and approved by the management. At Xoxoday we have developed a Risk Management Framework as part of the Information Security Management System (ISMS) in accordance with ISO/IEC 27001:2013 standard and SOC II attestation. The information security team assesses security risks annually and on an ongoing basis when major changes occur or when industry changes occur. Yes. We have implemented the Data Encryption policy Yes. We have the policies and procesures in place as per the compliane requirements. Yes. classification inclusive of all media types. Yes. we have implemented the Media handling procedures. We follow Xoxoday media handling procedure. Yes. It's a part of Media handling procedure and Information security policy implemented. Yes. we have implemented the Data Retention and Disposal Policy. Yes. We have a written Information security policy. These policies are reviewed anually or whenever changes made to it and approved by the management as per the compliance requirements. Yes. We have implemented the Password Management Policy All the information security policy and standards been approved by senior management. Yes. Xoxoday is ISO 27001:2013, SOC 2, CCPA/CPRA, HIPAA, CSA START, GDPR certified organization. We have implemented the access control policy and access will be provided only upon need and approval basis. Attached the access control policy. We focus on the security while producting the softwares. It's a part of our system devolopment life cycle. We have implemented the BYOD policy and all our employees follow the Xoxoday Information security and IT Policies. Yes. we have implemented the access control policy. We have implemented the Risk Management Procedure Yes. Its approved by the management and communicated to all the employees. Yes. Aattached the Information security policy, Roles and responsibilities policies. Yes. All the policies have been reviewed at regular intervals. Yes. We have implemented the role based access control mechanism and only authorised individual will get access. Yes, we have the policies and procedures in place and we will notify the customer if there is any changes took place in terms of security and privacy. Yes. We have a Change Management process and approved by the management. Yes. We have implemented the change management procedure. Yes. We implemented the the change management procedure. Yes. We have implemented the Data clasification policy. Yes. We have the data retension and disposal policy. We will have the data till you use our platform and will be deleted upon termnination of the contracts and will confirm. 1 year Yes. We have implemented data security policy and have controls in place to monitor the processing of personal information. Since we have deployed our application of AWS cloud only authorised individual have an access. Yes. We have the incident management response team and roles and responsibilities has been clearly defined. As per our policies and procedure we condut Root Cause Analysis report (RCA) including the details of Business Impact, Issue Description, Root Cause, and Corrective Actions. Yes. We have communicated on this to a concerned parties. Yes, we segregated the duties. Yes, our policies and procedures are established and implemented to enforce two-factor authentication for privileged account management/authentication while accessing tenant data/systems. We have segregated the teams according to their roles and responsibilites. We have the SDLC Procedure and attached the same for your reference. We have defined rules and guidelines for secure development of software and systems. Yes. We have implemented the media protection procedure. Yes. We have BCP policy and procedures in place and test it every year. At Xoxoday we have implemented the password management policy. Attached the same for your referrence. We have deployed password security controls accross the organization for maximum security. Attached the Change Management Procedure. All the chnages to production environment is recorded and followed the change management procedure. We have implemented the Asset classification policy. Attached the policy for your referrence. We have the policies in place and audited during the internal and external audits. We have the policies with regards to Access control, Ceyptography, Anti virus protection, Back up and recovery etc.. Yes. We have implemented the Acceptable Usage Policy Yes. We have implemented Clear Screen and Clear Desk Policy All the information security policies has been reviewed annually or upon any changes to the policies. All the management review and approvals has been recorded. Attached the Business continuity documents. Data backups are done daily and in a secured way in AWS. Attached the Backup Recovery Procedure. Attache the Information Security Policy and Data Security policy. Attached the policies with regards to - IT, Virtual Private Network, Threat and vulnerabilities, Virus management, patch management, access control, logging and monitoring etc. Attached the below mentioned policies - 1. Cloud Computing Security Policy 2. Encryption Policy 3. Password Management Policy 4. Threat and Vulnerability Management 5. Infrastructure Change Control Procedure 6. Virtual Private Network Policy 7. Information Classification Policy 8. Cyber Crisis Management Plan 9. Network Access Control and Security Procedure 10. Information System Acquisition Development and Maintenance Procedure The policy, process, and procedure is implemented to ensure proper segregation of duties. Attached the Roles Responsibilities\_Authorities Policy. Yes, all the mechanisms related to security and policies are implemented to facilitate timely decision and investigation by root-cause analysis. These incidences are analyzed with network intrusion detection (IDS) tools. We have implemented the change management procedure. Attached the Change Management Procedure Attached the Security Incident Reporting \_ Response Procedure Yes. We have a written Information security policy. Attached the same for your reference. These policies are reviewed anually or whenever changes made to it and approved by the management as per the compliance requirements. We have implemented the change management Procedure. All the IT changes takes place as per the Change management procedure. Attached the same for your reference. Attached the IT policy. We also have communicated these to all the employees to spread awareness among them. We have implemented the access control policy and access will be provided only upon need and approval basis. Attached the access control policy. Attached the Business continuity policy. Attached the Business continuity plan It's a part of our system devolopment life cycle. Attached the policy. Attached the Change management process. Attached the Supplier Management Procedure We have implemented the BYOD policy. Attached the same for your reference. Attached the Change management process. Please find attached Data Protection Policy and Data Retention and Disposal Policy Data privay and Data protection is a part of our Infoarmation security awareness training. Yes. Attached the Information Classification Policy We have Business Continuity Policy and Business Continuity Management Procedure in place and tested periodically. And also, our Policies has been reviewed and Audited annually. Attached the Business continuity policy, plan and procedures. We have test the BCP every 12 months and this has been reviewed as a part of Internal and external Audits. Attached the Information security Policy Attached the business continuity documents. Attached the Information Security Policy and Risk Management Procedure Yes, We have implemented the change management procedure and atatched the same for your referrence. The changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates and modifications. 1. We have implimented the systems development life cycle (SDLC) and atatched the same for your referrence. 2. Our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase. 3. We also conduct vulnerability and penetration testing and fix the identified observations. 4. Upon passing all the security and quality checks the new version of the product will be released. Xoxoday has a formal Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) defined and implemented to enable people and process support during any crisis or business interruptions. The BCP and DR Plan is tested and reviewed on a yearly basis as per the compliance requirements. We provide applicable compliance Policies/Procedures, Audit/attestation reports, certifications etc.. on need basis. Attached the Change Management Procedure Attached the Security Incident Reporting & Response Procedure. We have Business Continuity Policy and Business Continuity Management Procedure in place and tested periodically. And also, our Policies have been reviewed and Audited annually. Attached the Business continuity policy, plan and procedures. We have tested the BCP every 12 months and this has been reviewed as a part of Internal and external Audits. As per the compliance requirement and Business continuity policy we test the BCP plan every 12 months or upon significant organizational or environmental changes. We conduct the BCP/DR Test on an annual basis as per the compliance requirements and audited during the internal and external audits. Our RTO & RPO is 60 minutes, Attached to the BCP/DR Policy. Data backups are done daily and in a secured way in AWS. We also do test to comply with the business continuity plan. Yes. We have Business continuity plan. We communicate as per the BCP or the agreements or contracts Yes. We have Media handling procedure. Sure. We will provide the same. Yes We adhere to all the policies and procedures of the organization. Yes. We have disciplinary policy Yes. See Acceptable Use Policy attached. We adhere to all the policies and procedures of the organization. Yes. We have disciplinary policy We are ISO 27001:2013 and GDPR Compliant organization. We have policies and procedures in place to comply with all the requirements and working effectively. We have Information security policy, Mobile Device Management Policy, Encryption Policy, Password Management Policy, Risk Management Procedure, Email Security Policy, Access control policy etc as per the compliance requirements. We also have implemented end point security in all our computers and servers to make sure that the data stored are safe, secure, and Protecting against non-human sources of risks. Yes. We have a well-defined policy for roles and responsibilities. We have communicated each employee about their responsibilities across the organization. We do maintain appropriate contracts with relevant authorities and ensure that applicable regulations are complied with Yes. We have an access control policy. The policy is attached for reference. Only authorised employees will have access to the data. Authorised Xoxoday employees only will have access controlled per the relevant policies attached Yes Yes We store password hashed. We have SHA512 hash with unique salt for every password We have implemented the Password Management Policy. Only verified or authorised users can reset the password. No one can reset the password on behalf of somebody. We also follow the best practices for Password Protection and incorporated the same in the Password Management Policy. All the changes takes place as per the change management procedure. We have implemented the SDLC policy and made applicable to all the development and maintenance services, architecture, software and systems that are part of the Information Security Management System. Implemeted the asset management policy We are compliant. Attached the SDLC procedure. We folow General Coding Practice, test the information security features, Vulnerability scanning, Penetration Testing etc and mitigate all the risks identified. We have implemented the Media protection procedures in order to make surer that the data is protected if we store it in any external drives. We have implemented the Media protection procedures in order to make surer that the data is protected. We have asset management policy and Media protection procedure to track the customer maintain the records. It's a part of of Asset management policy. We have implemented the change management procedure We have implemented the change management procedure Capacity management has been well defined in our IT Policy It's a part of our change management and IT Policy. We have Implemented the Physical security Policy and allowed access to only an authorised individual. We have protected all the area as per the physical security Policy and allowed access to only an authorised individual. We have implemented the Security Incident Reporting & Response Procedure Attached the application Change management procedure Our RPO/RTO is 6 mins. Attached the Business continuity documents The BCP Test and lessons learned has been documented. We have implemented the Incident Management Procedure and attached the same for your reference Its part of our Incident Management Procedure We report the incidents Attached our Incident management procedure. Yes. We have Policies and procedures in place. Our application also support for adding and removing users. We have implemented policies and procedure with regards to DR. Since we have deployed our application on AWS cloud they only provide DR Services. Yes. We have Policies and procedures in place. Our application also support for adding and removing users. Yes. We have an Information Classification Policy and attached the same for your referrence. Information classification policy is primarily concerned with the management of information to ensure that sensitive information is handled well with respect to the threat it poses to an organization. It also demonstrates how gathered data is being used and structured within an organization to allow authorized personnel to get the right pieces of information at the right time, while also ensuring that only those who are authorized can view or access information. Sensitive data has been categorised as Confidential, Restricted, Internal, Public etc.. Yes. We have implemented the Acceptable Usage Policy and attached the same for your referrence. The policy outline the usage of Email, Computer Resources, Internet, Clean Desk and Clean Screen, Punitive actions, General guidelines etc.. We have a formal processess in place for security policies review and approval by the top level management as per the compliance requirements. Yes. Xoxoday has developed a Risk Management Framework as part of the Information Security Management System (ISMS) in accordance with ISO/IEC 27001:2013 standard and SOC II compliance. The information security team assesses security risks annually and on an ongoing basis when major changes occur or when industry changes occur. Xoxoday Risk management process includes Risk Treatment, Mitigating Actions, Action Owners, Action Due Dates, Risk Acceptance, Risk Mitigation, Risk Avoiding, Risk Transfer, exceptins etc.. We also conduct the Risk assessment on annual basis and this has been audited as a part of an internal and external Audits. Yes. Attached the Physical and Environmental Security Procedure. Yes. All the repair/modification or installation will be as per the change management procedure upon appropriate approvals. Whenever there is a requirement for additions or changes impacting security of the site, approval shall be taken from the site, Physical Security team prior to implementation. Attached the Physical and Environmental Security Procedure Yes. Data backups are done daily and in a secured way in AWS. All the data backup will be stored on AWS virtual platform cloud. We also have implemented the Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working. Out DR/BCP plans are reviewed and approved by the management and tested on annual basis as per the compliance requirements. DR/BCP controls are validated during the internal and external audits. We have Data Retention and Disposal Policy. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. Data backups are done on daily and in a secured way in AWS. Attached the Backup Recovery Procedure. Yes Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access. We have role-based access system through access control policy to make sure that only the authorised individual has access to the required information. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles Attached the Information security Policy Yes. we have implemented the Business Continuity Plan to ensure that the data is managed during the conduct of business in a safe and secure manner in delivering the business values to the interested parties. Attached the BCP/DR policies and procedures. Yes. we have Acceptable usage policy to outline the acceptable use of Information Security at Xoxoday.This policy applies to all employees – part time or full time, temporary or permanent, service providers with in-house engineers or consultants, contractors, and other workers at Xoxoday, including all personnel affiliated with third parties. This policy applies to all Information Security that is owned or leased by Xoxoday. Attached the Acceptable Usage Policy Attached the Security Incident Reporting & Response Procedure and ncident Management Procedure We adhered to the change management procedure and all the changes to the production systems will be upon review and approval of Chief Technology Officer (CTO) Attached change management procedures. We have implemented the change management policy and all the changes to the platform takes palce as per the compliance process. At Xoxoday we have a documented Business Continuity and Disaster Recovery Plan defined and implemented to enable people and process support during any crisis or business interruptions. Appropriate roles and responsibilities have been defined and documented as part of the BC plan. At Xoxoday the BCP and DR Plan is tested and reviewed on a yearly basis. The BCP and DR plan of Xoxoday is reviewed and audited as part of internal and external audits. We have implemente the Software Development Life Cycle (SDLC) procedures and attached the same for your reference. We have controls on external file sharing. Sure. We will provide our Incident Management Procedure Attached the Cyber Crisis Management Plan We adhered to the change management procedure and all the changes to the production systems will be upon review and approval of Chief Technology Officer (CTO) Attached the data classificaiton policy. Yes. A formal Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) defined and implemented to enable people and process support during any crisis or business interruptions. Yes. At Xoxoday we have implemented the Physical and Environmental Security Procedure. Physical entries have been restricted based on the role of the personnel within the organization. The restriction will be enforced using electronic locks with access through access cards and biometric machines. Third-party Access - The entrance premise of Xoxoday has been manned by security guards on a 24-hour basis. The guards shall verify all the visitors and direct them to the reception and provide temporary access cards. At the reception, the concerned employee shall be intimated, and he/she will escort the visitor on premises always. CCTVs has been placed at strategic points inside the facility Reception lobby, Entry and exit doors of the Xoxoday office, Entry and exit to parking areas, delivery, and dispatch areas etc. and monitored 24x7x365. Our information security team and Customer support team will inform the POC of Client via email communication with Preliminary Incident Synopsis and Root Cause Analysis report (RCA) including the details of Business Impact, Issue Description, Root Cause, and Corrective Actions Attached the Incident Management Procedure We have implemented the Business Continuity Policy and Business Continuity Management Procedure and BCP controls has been tested annually as per the compliance requirements and reviewed during the internal and external audits. We have implemented the Identity access management and follow the Access control policy. # Privacy Compliance Source: https://help-plum.xoxoday.com/faq/security-compliance/privacy-compliance Find answers to frequently asked questions about Plum's privacy compliance practices and how customer data is protected. ## GDPR We have implemented all the technical and organisational measures (TOM) Yes. we have implemented the Data Subject Access Rights Procedure Yes. The Data Processing Agreements is in place. Yes. The Data Processing Agreements is in place. Yes. we conduct the Data Privacy Impact Assessments on annual basis and there are no high risk involved in handling the PII formal data breach notification process is in place. Customer data security is an essential part of our product, processes, and team culture. Our facilities, processes and systems are reliable, robust, and tested by reputed quality control and data security organizations. We continuously look for opportunities to make improvements in the dynamic technology landscape and give you a highly secure, scalable system to provide a great experience. We have implemented many technical controls to safeguard the customer data. For example - Cloudflare Web application firewall (WAF), AWS Guard Duty threat detection services, Amazon CloudWatch, IDS/IPS etc. We are GDPR compliant. Implemented the Data security and Personally Identifiable Information Policy We have implemented the Data Subject Access Rights Procedure. In accordance with Data Protection Laws, we make available to Controller on request in a timely manner such information as is necessary to demonstrate compliance by Processor with its obligations under Data Protection Laws. Upon Controller's written request and subject to the confidentiality obligations set forth in the Agreement, we will make available to Controller a copy of Nreach the most recent third-party audits or certifications, as applicable. We do not agree for the Surprise audits. Yes. It's a part of the agreement. We have implemented the GDPR Xoxoday is the data processor. Xoxoday is GDPR Compliant. We have implemented the Data Subject Access Rights Procedure as per the GDPR and make all the data subject rights available as per the data protection laws. This procedure sets out the key features regarding handling or responding to requests for access to personal data made by data subjects, their representatives or other interested parties. We validate the compliance requirements of the Sub-processor and obtain the Compliance certificates and audit reports such as – ISO 27001:2013, SOC 2 Type II, ISO 27017, ISO 27701, ISO 27018, Cloud Security Alliance Controls etc.. We have implemented the Data Subject Access Rights Procedure to make sure that all the data subjects will have the opportunities to exercise their rights as per the privacy laws. Attached the Xoxoday Data Subject Access Rights Procedure. We provide Software as a Service.(SAAS). We are ISO 27001 certified and GDPR compliant. Attached the document. We are GDPR compliant. And atatched the Data security and Personally Identifiable Information Policy Attached the Data Subject Access Rights Procedure. Please visit here for Privacy policy - [https://www.xoxoday.com/privacy-policy](https://www.xoxoday.com/privacy-policy) We are GDPR Complaint and respect the data subjet access rights. We erase or delete the data upon request of the data subject or on the request of the customer upon termination of the contract. We have Data Retention and Disposal Policy. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. Attached the Data Retention and Disposal Policy. We have Data Retention and Disposal Policy. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. Xoxoday is Compliant with EU GDPR. We are compliant with GDPR. We inform the customer within 48 hours, if there are any data breach as per the compliance requirements. At Xoxoday we have appointed the DPO. Please click here to know more about Xoxoday GDPR - [https://www.xoxoday.com/gdpr](https://www.xoxoday.com/gdpr) Over 2 millions of customers across the globe trust us with their data security. We back ourselves up with robust data security and privacy practices that form an integral part of our product engineering and service delivery principles. Our comprehensive GDPR program is supported by key privacy principles -- Accountability, Privacy by Design and Default, Data Minimization, Subject Access Rights, among others. Technology and operations related to the business are subject to regular sensitization programs. Please click here to know more about Xoxoday GDPR - [https://www.xoxoday.com/gdpr](https://www.xoxoday.com/gdpr) We have implemented the Data Subject Access Rights procedure (DSAR) 1. Personal data can be deleted based on a formal written request, with justification. 2. Xoxoday would delete the data within 30 days of receiving the request Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. Attahed the Data Subject Access Rights procedure (DSAR) Xoxoday is GDPR Compliant and shared the Data Protection Impact Assessment (DPIA) We are not required to submit the report to the Data Protection authority. Xoxoday is compliant with GDPR We offer EU Standard Contractual Clauses. We support end users to Exercise their Rights as per the GDPR compliance requirements. We are compliant with GDPR. We inform the customer within 48 hours, if there are any data breaches as per the compliance requirements. In accordance with Data Protection Laws, we make necessary documents, Audit reports and certifications available to Controllers on request in a timely manner such information as is necessary to demonstrate compliance by Processor with its obligations under Data Protection Laws. Upon Controller's written request and subject to the confidentiality obligations set forth in the Agreement, Xoxoday will make available to Controller a copy of Nreach then most recent third-party audits or certifications, as applicable. We adhere to Data Retention and Disposal Policy and make sure that the personal information of the data subject will be deleted upon requests or termination of the contract. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. We offer standard contractual clauses (SCC) or binding corporate rules to regulate transfers of data to non-adequate third countries. We adhere to Data Retention and Disposal Policy and make sure that the personal information of the data subject will be deleted upon requests or termination of the contract. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. Attached the GDPR Data Protection Policy and Data Security Policy [GDPR compliance - https://www.xoxoday.com/gdpr Privacy policy - https://www.xoxoday.com/privacy-policy](https://www.xoxoday.com/gdpr) [Link - https://www.xoxoday.com/gdpr Note - if you are using Xoxoday products and have agreed to our terms of service, you do not need to sign an additional Data Processing Addendum.](https://www.xoxoday.com/gdpr) AWS - We have deployed our application on AWS Virtual platform cloud. And AWS is GDPR, ISO 27001, SOC 2 certified organization. We collect names, email IDs and Phone numbers. These are the mandatory information required to use the application platform. Yes. We are GDPR Compliant The application is deployed on AWS virtual platform cloud. We are a data processor as per GDPR and all the information is collected only throgh our application. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access. Notify data controllers within 48 hours of the breach or within stipulated time as agreed with the data controller Yes Yes Yes Yes. We have appointed DPO No. The EU-U.S. Privacy Shield Framework is no longer a valid mechanism to comply with EU data protection requirements when transferring personal data from the European Union to the United States. Please visit here for more details - [https://www.privacyshield.gov/Program-Overview](https://www.privacyshield.gov/Program-Overview) See Security Incident Reporting & Response Procedure attached We are GDPR Compliant. Our information security team and Customer support team will inform the POC of the customer via email communication with Preliminary Incident Synopsis and Root Cause Analysis report (RCA) including the details of Business Impact, Issue Description, Root Cause, and Corrective Actions. Yes. We have formally defined criteria for notifying a client during an incident that might impact the security of their data or systems. We notify within 72 hours as per EU-GDPR Data Protection Training and Awareness – Indicate what awareness-raising controls are carried out with regards to colleagues We conduct Information security and Data protection awareness training as soon as new employees joined the organization and annually once for the old employees. The training material includes the below concepts – Information Security Objective How to handle and protect PII What is ISO 27001:2013 Confidentiality, Integrity, Availability and Privacy. Business and cyber security PDCA – Continual improvement General guidelines for security Visitor management Security guidelines Guidelines while using Xoxoday provided devices Password guidelines Email related guidelines Social media related guidelines Phishing attack and its types Information storage related guidelines Incident Management Business continuity management We have implemented Security Incident Reporting & Response Procedure and tested annually. We also have Data Breach Notification Procedure as per the GDPR compliance requirements. We will share the supporting documents with regards to data breach notification and Incident management procedures. Yes. We provide these rights to the data subject as per GDPR We inform our customer in 48 hours if in case any security breaches as per the GDPR regulation. We have implemented policies and procedures as per ISMS and GDPR requirements. We also conduct periodical Internal and external Audit by the third party Auditor. We have deployed our application on Cloud Virtual platform for maximum security. We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We conduct periodical Vulnerability assessment and Penetration Testing from the Inductry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications. We use logical data isolation with the help of company specific encryption keys. Data in non production environment is not updated with the production data. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256 As per the Information security policy and Data protection policy only the authorised individual have an access to the data through internal approving and ticketing system. Yes. Attached the data retension and disposal policy. Yes. we are GDPR compliant. We have procedure in place to provide services to data subject. We do not share the PII with any third parties. We are GDPR Complaint and respect the data subjet access rights. We erase or delete the data upon request of the data subject or on the request of the customer upon termination of the contract. We have Data Retention and Disposal Policy. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. Attached the Data Retention and Disposal Policy. We restrict the processing of data as per the contract signed. We are GDPR compliant. we have implemented the Data Breach Notification Procedure. Our information security team and Customer support team will inform the customer via email communication with Preliminary Incident Synopsis and Root Cause Analysis report (RCA) including the details of Business Impact, Issue Description, Root Cause, and Corrective Actions. We have provided the features to withdraw consent or exercise the right for the end users. Attached the Data subject access rights procedures Yes. We collect the data through our application application. As per the GDPR we are the data processor. No. Since it's a SAAS product we are having EU customers who are using our application application. Employees. No. We collect the data through this application and store it. We do not use or transfer or share the PII Yes. Its posted on our website and they can exercise their rights as per the law. Yes. We do take consent from the data subjects. We Dispose the data Upon the expiry of the data retention as per the agreements, or when the data subject exercises their right to have their personal data erased, the personal data shall be deleted. We do not use personal information for Marketing or Advertisement. NA. We do not use personal information for Marketing or Advertisement. No. But we have deployed our application on AWS cloud virtual platform for maximum security. we are the data processor. We are GDPR compliant. Yes. We are GDPR Compliant and we have a data retention and disposal policy. We assure secure data disposal when storage is decommissioned or when the contract comes to an end. We also provide rights to the users to request for data deletion. GDPR Policy - [https://www.xoxoday.com/gdpr](https://www.xoxoday.com/gdpr) We will be deleting the customer data upon termination of the contracts. Our data cleansing process goes through an organized purge. Once the data is purged, it's purged from all places or completely wiped out. We are GDPR Compliant. And we would be notifying Nova Professional Services of an incident or data breach within 72 hours. We will make sure that we will be fully informed of incident response and investigation. We are ISo 27001;2013 certified and GDPR compliant. We also conduct internal review, Audit and external Audit from the third party auditors to make sure that we are complying with the requirements. we Notify data controllers within 48 hours of the breach or within stipulated time as agreed with the data controller throgh email. Yes. We provide service to the data subject as per the GDP Compliance requirements. They can rectify, erase or restrict processing of their personal data. Xooxday is GDPR Compliant. We collect the data which are only required. We collect the PII - Name, Email ID and Phone/ ## CCPA/CPRA We are compliant with EU GDPR and CPRA (California Privacy Rights Act) We are EU GDPR Compliant and CPRA Certified. Yes. We comply with all the applicable new laws and regulations. We also have a service provider who helps us with regards to Information security, compliance and certifications etc.. We have identified the upcoming CPRA and implemented the controls and achieved the CPRA Attestation with the help of the external auditor.. # Security Operations Source: https://help-plum.xoxoday.com/faq/security-compliance/security-operations Find answers to frequently asked questions about Plum's security operations, monitoring, and incident response practices. Our security systems are airtight and so far we haven't suffered any security breaches. Yes, we have a repository of security incident information if needed for all the affected customers. This information can be accessed electronically. We have an ELK setup in place to ensure data monitoring in the most optimal manner. No, content monitoring and filtration is not done to detect inappropriate data flows. Yes, only the authorized personnel are allowed in points of ingress and egress in order to isolate access of data storage and process. Data backups are done daily and in a secured way in AWS No, the backup and retention of data lies in the hands of Xoxoday. Data is stored in the event that a future need arises for looking into the database. Yes, the data is stored in our secure database and is transit scrambled for maximum security. Our tenants' data is excruciatingly confidential and is never used for testing or staging purposes. Yes, we promptly notify the KO-CIRT for immediate counter-actions and defense mechanisms in case of confirmed security incidents. Yes, please go through our "Information Security Management System Manual" for a complete understanding. Our ISMP is annually reviewed and updated if required. Please go through the links below to access our policies: Information Security Policy Privacy Policy Privacy Policy Yes, it's crucial for our providers to adhere with the Information Security & Privacy Policy of the organization. Yes, we follow all the technical guidelines for development of our code and applications that come under the Open Web Application Security Project. Yes, we remediate and address all requirements with respect to security, contracts, and regulative purposes for customer access to data and information systems. No, we don't provide multi-factor authentication. As of now, there's oAuth2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins. Yes, Xoxoday's architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows. Yes, our event management systems merge the data sources to maintain a log data within the SIEM. This helps in proper analysis and driving out alerts if need be in case of contingency. Yes, our documented security incident response plan logs, monitors, and collects relevant security event data for the purpose of investigation. Yes, information security incidents, if any, shall be quantified in type, volume, and impact of such incidents. Yes, systems must be configured to log all successful and unsuccessful login attempts by accounts with privileged access. These authentication logs must be retained for a minimum of 180 days and in accordance with the Company's records retention guidelines. Yes, with host and network intrusion detection tools, we ensure timely detection and investigation in a prompt manner. No, all of Xoxoday's servers are with Amazon Web Services, Singapore and that is where the outbound traffic is routed through. Cyber threats, if any, are managed internally by the tech team. Yes we have a regular audit on threats for applicability and exposure to our environment. Yes we update your cyber security program based on proactive or reactive threat intelligence feeds Xoxoday's holistic presence keeps our tech team updated with the latest news from multiple sources when it comes to any technological developments or threats. Yes, physical segregation is done for production and non-production environments. # Security Operations & Technical Capabilities and Support Source: https://help-plum.xoxoday.com/faq/security-compliance/security-operations-technical-capabilities-and-support Find answers to frequently asked questions about the technical capabilities and support behind Plum's security operations. Yes, we have proper forensic procedures in place that includes chain-of-custody management processes and controls. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently. Yes, in our cloud audit program, we analyze and address all the requirements put forth by the tenant to ensure maximum satisfaction. Yes, we have proper forensic procedures for data collection and analysis for incident responses. Yes, we can freeze data from a specific time without freezing other data if need be. Yes. Tenant data is enforced and attested in case it comes to light in legal subpoenas. The Xoxoday Platform is developed on microservices architecture because the independent applications and deployed on the AWS virtual platform cloud. No, our product is supported by a comprehensive web application that can be accessed via desktop and mobile browsers on all compatible devices. Our platform can be white-listed to match the look and feel of the tenant's platform. The emails are also customizable for a personal touch. Reports with respect to rewarding and beyond can be accessed through the platform. The customization is done on the platform level, manually by the super admin. Yes, Xoxoday Plum comes with a full set of integration with various platforms for enriched utility and maximum output from the platform. Yes, Xoxoday Plum comes with a full set of integration with various platforms for enriched utility and maximum output from the platform. No, we keep it with one data center for maximum safety, privacy, and security of database of our tenants. Reports and analysis can be extracted from the platform. These reports give detailed insights with respect to what's being the reward and recognition input and output throughout the concerned period. In case reports are needed apart from the predefined ones, they can be shared with the tenants in a spreadsheet. Xoxoday's customer support team is available at all times to address any queries and support with respect to advisory and technical operations. Each tenant data is uniquely encrypted using client specific key. We use AES 256 bit encryption for data at rest to ensure maximum security measures. Yes, hardware security modules are used to protect these keys, and the key access lies with the Chief Technical Office. We use the Key Management Service by AWS to manage all the keys. In the event that keys get compromised, they can be recovered through the Key Management Service. Yes, in the event of service interruption, the prior notification will count for downtime. The time of support ranges between six to forty-eight hours. This depends on the level of service and the gravity of incidents. No, there is no penalty clause attached in the event of a performance failure. We are a SAAS company hence we do not have in built APIs, we maintain quarterly/yearly audit logs. No we do not integrate with the above third party tools We maintain the logging of applications and alerts by ourselves. We cannot be integrated with the bank system, According to our company policy we do not share the logs with any third party. Yes the application have robust authentication methods. We are integrated SAML 2.0 with SAP SuccessFactors, we also support OAuth 2.0 for seamless authentication. Yes we do report pen test and SOC findings Our applications are compatible with desktops, tablets and Mobiles, No additional components are required. Since we are SAAS product, we maintain backup and restore all the customer data by ourselves. We use AES 256 encryption for data at rest. We have a multi AZ deployment with periodic backup for our DR. DR is active-active. We use logical data isolation with the help of company-specific encryption keys. Data in non production environment is not updated with the production data. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256 We are a SAAS solution, and hosting is handled by us. No instances needed from the client. We use Public cloud for hosting (AWS Singapore) 6 Hours RTO and 6 Hours RPO, Yes upon request we can share latest DR strategy test results. No there aren't any FLASH component installed in our web app. This solution doesn't require any such API integration. The solution is seamlessly integrated with the SAP SuccessFactors solution already. We only have 2 roles. Super admin and user. Super admin have complete control of the platform and can configure everything. SCB Admin staff will become the super admins. Xoxoday will not be sharing logs with SCB as we have multi-tenant information in the logs. If there is a significant downtime or disruption of service, we will provide an alert notification to SCB Web Content Accessibility Guidelines (WCAG) defines how to make Web content more accessible to people with disabilities. Accessibility involves a wide range of disabilities, including visual, auditory, physical, speech, cognitive, language, learning, and neurological disabilities. Yes. We always give our best to make sure that our applications are developed as per WCAG guidelines and helping differently-abled people across the globe. Yes. We ensure that people with disabilities can use our websites and applications without any difficulties. Our website and products are having very simple options with very good visibility of the content. Yes. We always consider the WCAG guidelines for helping differently-abled people. Yes. We periodically review and do all the necessary changes to our website and applications as per the guidelines. # Solution Development Source: https://help-plum.xoxoday.com/faq/security-compliance/solution-development Find answers to frequently asked questions about the secure solution development lifecycle Plum follows for its products. Yes, our network environment is designed and configured to restrict any communication and connection between the tenant's environment and our corporate network. Yes, our logic to physically separate tenant systems is made possible by assigning each tenant's data a client-specific key that is uniquely encrypted for maximum security. Yes, all the resources that are needed for the configuration, installation, and operation of information systems are made available to the authorized personnel for their perusal. No, we have a holistic computing environment which uses logical methods of isolation to keep the tenant's data secure. Yes, we logically segregate the tenant's data and the application. Yes, physical segregation is done for production and non-production environments. As per the SDLC process, we have defined General Coding Practice and some salient points are - * We use parameterized queries. * All PI data need will be encrypted * All our communications will be over secure channels only and many more. No. All the deployments will take place only upon QA Process. Backups are automated and tested/reviewed on a weekly basis. Recovery process has been tested during the annual BCP test to make sure that implemented controls are working effectively. All the customer data backup has been stored on AWS/MS Azure Virtual platform cloud and all the data at rest has been encrypted. Information security and Technology Team will be responsible for evaluating the incident and appropriately initiating the escalation process and holds the overall responsibility to monitor the activity and facilitate any action. If the problem requires further investigation, IT will assign the ticket to the appropriate Support Groups and escalate it CTO. We use a split key mechanism to ensure that every client's key is unique. * We perform annual key rotations. * Keys are generated using the KMS service whenever needed. * We store keys in KMS. We have implemented the systems development life cycle (SDLC) Procedure. Our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase. We also conduct vulnerability and penetration testing and fix the identified observations. Upon passing all the security and quality checks the new version of the product will be released. # Tax Compliance Source: https://help-plum.xoxoday.com/faq/security-compliance/tax-compliance Find answers to frequently asked questions about Plum's tax compliance practices and the documentation it maintains. Disclaimer: This is for informative purposes only and should not be construed as professional, financial, or legal advice. The information does not constitute or form part of, and should not be construed as, a direct indication from the designated countries' tax authorities. For updated information, please visit the official tax website of your country's government/tax authority. ## USA In the United States, every person is allowed a tax-free benefit of up to \$25 per year. This is valid for every employee irrespective of the federal, local, or state laws. A Federal Income Tax (22%) + Social Security (7.65%) + Local/State Tax (if applicable) is applied on the amount above \$25. The employer can either record a high value of benefits and withhold the tax, or trim it from the amount being given to the employee. The Internal Revenue Service USA ## UK In the United Kingdom, an amount of £50 goes tax-free in the name of small benefits for every person through the year. If the amount goes over the exemption limit or is issued as a voucher exchangeable for cash, it will be taxed on the employee's end under "Other Earnings". There are certain exemptions, the list of which can be checked out here ([https://www.gov.uk/hmrc-internal-manuals/national-insurance-manual/nim02416](https://www.gov.uk/hmrc-internal-manuals/national-insurance-manual/nim02416)). Trivial benefits are non-taxable, provided that: * it costs the employer £50 or less to provide * it isn't cash or a cash voucher * it isn't a reward for employees' work or performance * it isn't in terms of their contract [https://www.gov.uk/expenses-and-benefits-trivial-benefits](https://www.gov.uk/expenses-and-benefits-trivial-benefits) ## Ireland The Irish tax authorities exempt a handsome total of €500 per person through the year in the name of small benefits. If the SBE limits are crossed, the taxation would be according to the rules and regulations of the Irish tax authority. The amount is only deemed to be tax-free in case it is gifted in terms of vouchers and benefits. Long Service Awards are not taxable at all as much as €50 per every year of service. The Revenue Commissioners, Ireland>> [https://www.revenue.ie/en/employing-people/benefit-in-kind-for-employers/other-benefits/service-and-performance-schemes-and-awards.aspx](https://www.revenue.ie/en/employing-people/benefit-in-kind-for-employers/other-benefits/service-and-performance-schemes-and-awards.aspx) ## India Gifts up to Rs. 5,000 in the aggregate per financial year would be tax-exempt in the hands of the employees. The excess value of gifts over and above Rs. 5000/- would be taxed as a perquisite in the hands of the employees. The Gift value is added to the CTC (Cost to the Company) of the employee for calculation of Income-tax. Income Tax ## Poland In Poland, any purchase of gifts that ZFŚS aka the National Revenue Administration of Poland finances is tax-free. The amount would be wholesomely taxed. Purchase gifts partly from the ZFŚS and partly from current assets won't make it tax-free—no matter how much the amount is. This fund houses a separate bank account for every worker and has an employee's and employer's contribution to it. The ZFŚS is allocated to leisure, healthcare, entertainment, sports, recreation along with other expenses. Any purchase of gifts that ZFŚS finance is tax-free. GOV.PL>>[https://www.gov.pl/web/national-revenue-administration/about-us](https://www.gov.pl/web/national-revenue-administration/about-us) ## France In France, an exemption of €169 is given for every person through the year, provided that it's spent on activities other than food and fuel. Provided that the amount goes about the SBE limit, it shall be fully taxed under the French Tax statutes. When the gifts are given for an event that marks a significant milestone, e.g. wedding, birth, retirement, Mother's Day, or Father's Day, etc. If the gift voucher given for the event (s)mentioned above, one can not redeem it for food or fuel (the voucher's value should still be €169 per event and calendar year). Cultural events that promote the country's colors and traditions are also exempted. The Ministry of Economy & Finance>> [https://www.impots.gouv.fr/portail/](https://www.impots.gouv.fr/portail/) ## Netherlands With an amount of €2207 for every employee through the year, the Dutch authorities have a generic gift tax statute for all its citizens. The Dutch tax authority identifies tax slabs on gifts according to the value of donations. For donations ranging between €0 to €126,723, the tax rate is 30% on the gift value. Meanwhile, for donations with a value that goes above €126.723, the tax rate is 40% on the gift value. In a general sense, there's no separate clause for the Dutch corporations signifying the gift tax rules for employees, so we are going to focus on what it says altogether. The Dutch Tax Authority>> [https://www.belastingdienst.nl/wps/wcm/connect/en/individuals/individuals](https://www.belastingdienst.nl/wps/wcm/connect/en/individuals/individuals) ## Norway NOK1000 - that is the maximum an employee can get per year while being exempted from any kind of taxation under the small benefits exemption. All gifts to employees over this amount and without special occasions and taxable. All gifts to employees over this amount and without special occasions and taxable. In the case of long service rewards,gifts up to NOK8,000 in value can be given for long service in the business.The first reward for long service opens up after 20 years of service, and after that in every 10 years. Gifts up to NOK4,000 can be given in case when the recipient gets married, reaches the age of fifty (and ten years thereafter), and when the recipient retires. The same amount of reward unlocks when the business reaches a jubilee landmark, i.e. 25 years, 50 years, and soon. It's a condition that to get tax exemptions, the gifts must be non-cash. Gift vouchers are acceptable. The Ministry of Economy & Finance>> [https://www.impots.gouv.fr/portail/](https://www.impots.gouv.fr/portail/) ## Spain Spanish Tax Authorities give a relaxation of up to €299 for every gift through the year per employee. There are certain benefits besides it, like meal vouchers worth up to €11 per day, nursery vouchers, public transport vouchers within certain limits, medical insurance premiums up to a maximum annual amount of EUR500 per family member covered, etc. that are exempted from tax. Agencia Tributaria>> [https://www.agenciatributaria.es/AEAT.internet/en\_gb/Inicio.shtml](https://www.agenciatributaria.es/AEAT.internet/en_gb/Inicio.shtml) ## Germany The EStG states a total of \$44 for every emplpoyee per month that can go tax free. All gifts to employees over this amount and without special occasions and taxable. As per Section 8, (para two; clause 11) of the German Income Tax Act (EStG), tax and social security contributions are exempted up to € 44 a month. Section 19.6 (para one) of the German Income Tax Law (LStR) exempt from tax and social security contributions up to€60 for special personal occasions. BZSt>> [https://www.bzst.de/EN/Home/home\_node.html](https://www.bzst.de/EN/Home/home_node.html) ## Denmark With an amount of DKK1100 for every employee for a year, the Danish tax authorities has a threshold for gift vouchers and other non-cash gifts. The gifts going beyond this limit are taxable to the given slabs. Skattestyrelsen, the Danish tax authority signifies that gift vouchers and other non-cash gifts aren't taxable up to DKK1,100 in case they are unrelated to the employees' jobs. Benefits related to employees' jobs have a more relaxed threshold, and they are tax-exempt until their value exceeds DKK5,600. SKAT.DK>> [https://skat.dk/skat.aspx?oid=2244343](https://skat.dk/skat.aspx?oid=2244343) ## Singapore No corporate gift tax is charged on presents worth under the value of SGD200. As for the values exceeding SGD200, it would only be taxed in case of a single gift value surpassing the limit. However, multiple gifts can given under the value of SGD200 without being taxed. If the nature of benefit or gift is that of bereavement, i.e. on the occasion of loss, then it's exempted from any tax. Such gifts are never taxable, even if their value exceeds S\$200. Do note that the above rules apply to cash and non-cash gifts. [https://www.iras.gov.sg/IRASHome/Businesses/Employers/Tax-Treatment-of-Employee-Remuneration/Gifts/](https://www.iras.gov.sg/IRASHome/Businesses/Employers/Tax-Treatment-of-Employee-Remuneration/Gifts/) ## Malaysia Normally, gift vouchers are not taxable in the hands of the employee unless they are of a recurring nature and are provided in circumstances where the employee expects such gifts as part of his remuneration. In case the Gift Vouchers are part of the remuneration, it will be taxed at the hand of the employee. The small benefit exemptions aren't applicable, however, on long service or festivities. The value of gift vouchers would be taxed on the recipient's gross income. [http://www.hasil.gov.my/index.php?bt\_lgv=2](http://www.hasil.gov.my/index.php?bt_lgv=2) ## Philippines Any gifts below P5000 are exempted from taxation. These gifts, however, are advisable to be crossed only on special occasions and festivities. Any gift above P5000 would be considered as a fringe benefit and will be taxed. [https://www.bir.gov.ph/](https://www.bir.gov.ph/) # Training and Awareness Source: https://help-plum.xoxoday.com/faq/security-compliance/training-and-awareness Find answers to frequently asked questions about the security training and awareness programs Plum runs for its employees. Yes, our personnel - both full-time and on-contract are bound by an agreement of non-disclosure and a confidentiality agreement as a condition of employment to protect the customers and tenant's information. Yes, all the employees and personnel pass through induction and job training, along with contractors and third-party users for their share of information security controls. Yes, all personnel are well-trained with awareness programs annually. We conduct the Infosec Awareness training as soon as employee joined the organization and on annual basis. Each employee, when inducted, signs a confidentiality agreement and acceptable use policy, after which they undergo training in information security, privacy, and compliance. Furthermore, we evaluate their understanding through tests and quizzes to determine which topics they need further training in. We provide training on specific aspects of security that they may require based on their roles. We conduct ISMS training for all the employees. Attached the IT policy. We also have communicated these to all the employees to spread awareness among them. We conduct ISMS training for all the employees. The frequency of the training will be annually. Data privay and Data protection is a part of our Infoarmation security awareness training. Yes. We conduct ISMS training for newly joined employees and existing employees. Yes. We do conduct security awareness training for all the employees as soon as they joined the organization and also annually as per the ISMS requirements. We conduct annual ISMS training for all the employees as per the compliance requirements We provide mandatory security and awareness training to all our employees and spread awareness about the information security accrross the organization. Yes. We conduct Infosec awareness training as soon as the new employees join the organization and annually once for all the existing employees. Yes. We have eduated all our employees throgh training on Data privacy compliance. The Production or devolopment team always make sure that the new devolopments made will be complied with the data privacy requirements. We also educate our Production or devolopment on the recent updates throgh necessary trainings. # Vulnerability and Threat Management Source: https://help-plum.xoxoday.com/faq/security-compliance/vulnerability-and-threat-management Find answers to frequently asked questions about Plum's vulnerability scanning and threat management practices. Yes, policies and procedures are established and mechanisms are implemented to detect, address, and stabilize vulnerabilities in a timeframe that matches the Security Patch Management Standards. Yes, Xoxoday's products are supported by leading anti-malware programs. These are connected with our cloud service offerings and are a part of all our systems. Yes, we perform periodic scans of operating systems and databases along with server applications for vulnerability and configuration compliance. This is done by using suitable vulnerability management tools as per the industry standards. Yes, we ensure that there is no breach in network layers with vulnerability scans as per the industrial standards. Yes, to check the hygiene of application layer, our vulnerability scans are done as prescribed by the industrial standard. Yes, tenants can request for vulnerability scan reports. Yes, in order to detect any unauthorized changes in the data or system configuration, we have a procedure in place for host/file integrity monitoring. No, our periodic vulnerability scans are conducted just the right number of times to ensure the prominence of security measures and protection of the operating system layer. No, our periodic vulnerability scans are conducted just the right number of times to ensure prominence of security measures and protection of the database layer. No, our periodic vulnerability scans are conducted just the right number of times to ensure the prominence of security measures and protection of the application layer. Yes, vulnerability scans and penetration tests are conducted periodically by third parties and external services to test our security measures. Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com) to raise a ticket, if you happen to notice any potential security issue whilst meeting all the required criteria in our policy. The validation of the reported issue in terms of severity & authenticity will be done by our security team in around 90 days. Post validation, steps will be taken to fix the security issues in accordance with our security policies. The owner of the ticket will be informed once the issue is resolved. Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing. We have fixed all the issues identified during the VAPT Audit and rescanned it once again to make sure that all the vulnerabilities are remideiated. Post confirmation of these fixes we got the final VAPT Certificate for our product. Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing. 60 days. We conduct the VA/PT on annual basis as per the compliance requirements. Manual and third party tools are used for this assessment. Yes. We have the capabilities to patch the vulnerabilities. We conduct VAPT on annual basis. we follow all the technical guidelines for development of our code and applications that come under the Open Web Application Security Project. And also we conduct VAPT Assessment for our application and remidiate the findings we perform periodic scans of operating systems and databases along with server applications for vulnerability and configuration compliance. This is done by using suitable vulnerability management tools as per the industry standards. our periodic vulnerability scans are conducted just the right number of times to ensure prominence of security measures and protection of the database layer. We have implemented the Threat and Vulnerability Management procedures. We close the identified vulnerabilities or fixes the issues. We conduct code reviews, VA-PT assessments, Log monitoring, Incident reportings etc and these controls are monitored and reviewed during the internal and external parties. Attached the latest VAPT Certificate. Attached the letest VAPT Certificate. Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing. Attached the Threat and Vulnerability Management and Patch Management Procedure. We conduct the Vulnerability assessment and penetration testing for maximum security. We conduct on yearly basis as per the compliance requirements. Attached the Threat and Vulnerability Management Policy. Yes. As part of every build, the third-party libraries are scanned for security vulnerability. Our software will be free from all the vulnerabilities. Attached the independent third party performed a Penetration Test report. We conduct the periodical vulnerability and penetration testing as per the compliance requirements which includes Static, Dynamic, API, Manual etc.. We perform the VA/PT on an annual basis as per the compliance requirements. Attached the VA/PT report and certificate. We do conduct Vulnerability and Penetration testing from the Authorized vendor. We comply with the requirements. We also conduct periodical Vulnerability assessment and penetration testing with the help of the authorised third party vendor. We conduct internal review and audited by the exteranal auditors for our security standard certification and VAPT assessment We conduct periodical Vulnerability assessment and Penetration Testing from the Inductry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications. Exhaustive Vulnerability Assessment and Penetration Testing has been conducted along with business logic testing based on OWASP framework which incorporates 120+ test cases like Access Controls, Authentication and Session Management, Cross-site Request Forgery, Cross-site Scripting, Cryptography and Insecure Storage, Data Validation, Information Leakage and Error Handling, Malicious Execution etc. We have conducted Vulnerability assessment and penetration testing with the help of Industry approved third party vendor. We conduct VAPT for every six months. During the testing, if any observations found by the auditor our team will work on those Audit observations and fix the issues. See Threat and Vulnerabilities Management procedure attached. Periodic scans has been performed on all network assets deployed on Xoxoday by the third party vendor. The critical vulnerabilities are fixed immediately within a span of 5 days. We have the third party vendor called Appknox for scanning the vulnerabilities. They use Appknox tool(Mannual and Automated) for vulnerability management See Threat and Vulnerabilities Management procedure attached. Periodic scans has been performed for application and the identified observation has been fixed by our engineering team. We have the third party vendor called Appknox for scanning the vulnerabilities. They use Appknox tool(Mannual and Automated) for vulnerability management We have Access control policy, and we follow Role based access system and review the access provided periodically to eliminate the risk and make sure that only the Authorised individual have access to avoid risk. We have implemented the controls with regards to avoiding source of Risk and to make sure that we prevent an unauthorised access of the data. We have implemented end point security in all the computers and servers to prevent the unauthorised access. We have Patch Management Procedure and Logging and Monitoring Procedure in place as per the compliance requirements. We also conduct periodical Vulnerability and penetration testing for identifying the source of risk and implement controls for mitigating the risk. Yes. We update the patched and conduct the vulnerability assessment and penetration testing and remidiate the risks identified. We have implemented the Incident Management Procedure and VAPT Audit periodically. Attached the latest VAPT Certificate. We have implemented the Threat and Vulnerabilities Management procedures is to proactively expose security flaws and correct them before a malicious attacker can leverage the same weaknesses and cause irrecoverable damages. We have implemented the Threat and Vulnerabilities Management procedures. We conduc the Vulnerabilities assessment and fixes the issue identified during the assessments. We conduct the Vulnerability assessment for our application during the testing and prior to deployment. We conduct Vulnerability assessment and penetration testing during the testing and before deployment. And we make sure that all the issues has been fixed and mitigated security vulnerabilities. We conduct Vulnerability assessment and penetration testing for our application in order to make sure that issues has been fixed and mitigated security vulnerabilities. We conduct Vulnerability assessment and Penetration testing in order to make sure that we identify the vulnerabilities and fixes the issue or mitigate the risk involved. We have deployed our application on AWS cluod virtual platform and hardened in order to secure a system by reducing its surface of vulnerability. We continuously monitor the Vulnerabilities and fixes the issue on a periodical basis. We also update the patches regularly to eliminate the security risk. We make sure that we identify the vulnerabilities and fixes the issues in order to make sure that Information system is secure and free from vulnerabilities. We conduct periodical vulnerability and penetration testing and fixes the issue identified and make sure that all the risk associated with these vulnerabilities are identified. We have implemented the Threat and Vulnerability Management to identify and eliminate problems that could lead to a breach of confidentiality, availability, or the integrity of application data resources and to ensure adequate protection of client data. The treatment of vulnerabilities consists of the definition and implementation of controls and measures to eliminate vulnerabilities We have implemented the Threat and Vulnerability Management to identify and eliminate problems that could lead to a breach of confidentiality, availability, or the integrity of application data resources and to ensure adequate protection of client data. Vulnerabilities will be categorized as Critical, High, Medium, Low and Information. We remidiate all the vulnerabilities identified. We have implemented the Threat and Vulnerability Management to identify and eliminate problems that could lead to a breach of confidentiality, availability, or the integrity of application data resources and to ensure adequate protection of client data. We monitor the vulnerabilities identified and remidiate it. We follow this as a part of Threat and Vulnerabilities Management procedure. We do not share the vulnerabilities to any unauthorised individual. We conduct Vulnerability assessment and penetration testing periodically and we can make this available for the customer on need to knoe basis. We inform on our potential vulnerabilities and non-compliance issues aand make sure that we mitifate these issues We conduct Penetration testing with the help of industry approved thord party vendor Yes. We conduct third party Vulnerability assessment. Attached the certificate for your reference. Yes. We also fix the issues identified and conduct the test once again for confirmation of fixes. We will delete the data upon termination of the contract and confirm you. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a Vulnerability assessment and penetration testing. We conduct the VA/PT on annual basis and Attached the latest certificate. Security patches are rated as Critical, High, Medium and Low. Critical patches will be deployed immediately High patches will get deployed within 5 days Medium Patches will get deployed within 15 day Low will get deployed in 25 days. Attached the Threat and Vulnerabilities Management program. Attached the latest VAPT Certificate Attached the VA/PT Executive report and Certificate issued upon remediation of all the vulnerabilities identified during the third party assessment. VA/PT has been consucted with the help of the third party VAPT auditor. The name of the vendor is Appknox. We conduct VPAT for every six months and shared the latest VAPT Certificate. Attached the Infrastructure Architecture diagram where all the security components are included. Attached the VAPT certificate and Cloud Computing Security Policy Attached the Executive summary of VAPT report Yes. As part of every build, the third party libraries are scanned for security vulnerability. Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing. We are compliant with this requirements. Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing as per the compliance requirements. Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing. Attached the VAPT Certificate and executive report. All the vulnerabilities has been fixed. We conduct the VAPT Assessment with the help of the authorised vendor and compliant with the requirement. We conduct Vulnerability assessment and penetration testing from the Authorised vendor, and the identified Vulnerabilities will be closed in a timely manner. The treatment of vulnerabilities consists of the definition and implementation of controls and measures to eliminate vulnerabilities (e.g. applying a patch to the affect system) or to prevent the vulnerabilities from being exploited (e.g. deactivating a service or disallowing a firewall connection). Vulnerabilities will be categorized as Critical, High, Medium, Low and Information. We inform the Infosys Immediatly if any critical Vulnerability to be reported. All are fixed and there are no open Vulnerabilities. The testing is conducted and vulnerabilities has been mitigated before any releases. We conduct Vulnerability assessment and Penetration testing as per the compliance requirements. The date of the most recent certificate is 01st March, 2021. Attached the vulnerability assessments/penetration tests report. # Account Settings Source: https://help-plum.xoxoday.com/faqs/for-admins/account-management-faqs Find answers to frequently asked questions about managing your Plum account settings, admin users, and wallet balance. *Get answers to questions on account management, user management, gift cards, the storefront, and gifting programs on Xoxoday Plum.* ## User Management Yes. The Xoxoday customer rewards platform enables the management of multi-departmental reward programs. Admins can create department-specific configurations such as goals, budgets, roles, and performance metrics. Each team can independently manage its reward programs while leveraging shared platform features like real-time reports and budget tracking. Yes, the Xoxoday customer rewards platform includes a robust admin portal that enables authorized personnel to access on-demand, real-time reports. These reports can be viewed, customized, and downloaded instantly, supporting a wide range of audit, compliance, and operational tracking requirements. Features such as filtered views, saved report templates, and exportable formats (e.g., CSV, XLSX) enhance data accessibility for ongoing program optimization and transparency. Yes, the system offers complete activity logging with time-stamping capabilities for all user actions. Each transaction is tied to an individual user profile, enabling auditability, compliance tracking, and robust administrative control. This is essential for financial transparency and operational accountability. Yes. All Xoxoday solutions maintain precise timestamping and user-level activity tracking for accountability and compliance: * **Global rewards marketplace and payout platform** — Tracks reward issuance, catalog changes, and redemption approvals in real time. * **Employee engagement and recognition platform** — Logs recognition events, budget updates, and survey deployments with exact timestamps. * **Sales commission and incentive management system** — Records commission plan changes, payout processing, and performance updates with user attribution. * **Customer loyalty management solution** — Captures member enrolments, points accruals, and redemption events with user and time logs. * **Merchant-funded offers and promotion engine** — Tracks merchant offer activations, validations, and campaign edits with full audit trails. ## Gift cards Yes, the Xoxoday gift card marketplace supports role-based distribution, allowing designated administrators to send gift cards to recipients regardless of who initially placed the order. Once the cards are delivered via secure links to the recipient's email, they can be activated and redeemed independently. This flexibility supports decentralized reward distribution within large organizations. ## Storefront: a global reward marketplace Yes, the Xoxoday rewards catalog includes access to a worldwide network of airport lounges. Users can redeem their points to enjoy premium airport lounge experiences, which include Wi-Fi, refreshments, relaxation areas, and other business traveler amenities. The Xoxoday gift card marketplace includes intuitive search and filter functionalities that empower customers to browse by category, product type, point eligibility, and preferences. This streamlined navigation enhances the overall user experience, helping users find exactly what they're looking for across a diverse range of digital and physical reward options. The AI copilot further helps customers with insightful product recommendations and queries. Travel insurance is generally included in the booking you make via our partners. We also provide an option to choose an insurance from our options while booking. Yes, the Xoxoday reward marketplace includes premium experiences such as hotel loyalty memberships (e.g., IHG, Hilton Honors, Radisson Rewards) and global subscription services such as Netflix, Spotify, and Amazon Prime. Availability may vary by region, and we continue to expand our catalog based on geographic feasibility. Clients will be notified when new options become available in their local reward environment. These benefits are generally handled directly by airlines to ensure personalized service. However, the platform provides an option to redeem on airmiles to upgrade your bookings. At present, complimentary baggage check-in benefits are not available in the Xoxoday gift card marketplace. Airlines often handle such privileges directly to maintain control over customer service standards. The Xoxoday rewards, incentives, and payout platform provides access to one of the world's most comprehensive closed-loop gift card networks via its AI-powered global rewards marketplace. These merchant-specific cards are redeemable exclusively with the issuing brand, making them ideal for targeted reward experiences. **Availability of closed-loop gift cards** — Clients benefit from: * 10,000+ brand-specific gift card options * Coverage in 100+ countries * 30+ major reward categories to meet diverse user needs **Top closed-loop gift card categories:** * Retail & shopping (e.g., Amazon, Walmart, Flipkart) * Dining & food delivery (e.g., Starbucks, Uber Eats, Swiggy) * Travel & hospitality (e.g., Airbnb, Booking.com) * Entertainment & gaming (e.g., Netflix, Spotify, Xbox, Steam) * Fashion & lifestyle (e.g., Nike, H\&M, Sephora) * Digital subscriptions & utilities (e.g., Google Play, Apple, mobile top-ups) * Charity & donations (1000+ nonprofit options) * Financial products (e.g., Visa/Mastercard prepaid cards) **Custom catalog additions** — Clients can request new closed-loop gift card partners during onboarding or later via customer support. The Xoxoday team evaluates requests based on: * Regional demand and popularity * Brand integration and compliance * Procurement and fulfillment feasibility If approved, new partners can be added to the client's private catalog or made available platform-wide based on relevance and viability. The Xoxoday rewards marketplace offers both digital and physical gift cards to meet the diverse needs of businesses and recipients globally. **Card types offered:**- **Digital gift cards** — Delivered instantly via email, SMS, or WhatsApp; ideal for scalable campaigns. * **Physical gift cards**— Available in bulk or individually; suitable for events or regions with limited digital adoption.**Catalog scale and customization:** * Access to 10M+ reward options across 30+ categories in 100+ countries. * No upper limits on the number or type of brands; supports 50,000+ daily transactions. * Businesses can customize catalogs by geography, audience segment, redemption value, or campaign purpose. **Popular global brands included:** * Amazon, Walmart, Target, Kroger * 21,000+ other trusted global and local brands, regularly updated for relevance and seasonal promotions. This extensive offering ensures global scale, personalization, and seamless reward delivery. The platform can support premium experiences like invite-only memberships and private events. These are offered based on client demand, subject to third-party approvals and potential additional costs, enabling high-value, exclusive loyalty and recognition programs. Yes, the Xoxoday rewards, incentives, and payout platform provides an online catalog accessible to departments for ordering gift cards. Workflow approval can be configured to ensure that requests follow internal governance policies. The catalog includes the same comprehensive closed-loop gift card options, covering 30+ categories in 100+ countries, and supports custom partner additions as needed. The Xoxoday reward marketplace supports a comprehensive range of redemption categories to suit diverse business needs: * Digital vouchers such as gift cards across retail, dining, travel, wellness, and more * Prepaid digital cards from major card issuers, available across geographies * Digital services including subscriptions, mobile top-ups, and digital utilities * Branded merchandise spanning electronics, fashion, lifestyle products, and more * OEM products such as accessories, gadgets, and device-related tools All these categories are part of the standard catalog offering in the Xoxoday gift card marketplace, covering 30+ categories in 100+ countries. The Xoxoday reward marketplace features a fully integrated digital rewards catalog, offering a wide portfolio of multi-brand vouchers. End users can redeem rewards from a curated selection of e-vouchers and gift cards across 30+ categories, including travel, food, lifestyle, and more. This comprehensive and user-friendly interface ensures an intuitive redemption journey. Explore the catalog: [stores.xoxoday.com/marketplace/rewards-api-catalogue](https://stores.xoxoday.com/marketplace/rewards-api-catalogue). Yes, the Xoxoday gift card marketplace includes a built-in currency conversion feature. Loyalty points and payments are automatically converted to the user's local currency based on real-time exchange rates, ensuring seamless global reward fulfillment and user convenience. Yes, users can filter rewards by merchant, product type, keywords, location, price, and popularity. They can also mark favorites and view results based on those preferences, making catalog navigation simple and efficient. We differentiate through the breadth, flexibility, and global scale of our digital reward infrastructure. Key points include: * 1M+ reward options across 100+ countries * Multiple delivery modes: email, SMS, API, and storefront * Customizable storefronts and branded experiences * Multi-lingual, multi-currency rewards catalog * Data privacy and regional deployment * Value for money and low total cost of ownership * Dedicated enterprise support with SLAs Xoxoday rewards marketplace supports a wide array of global airline loyalty programs for airmiles and airpoints. Yes. The Xoxoday customer rewards platform supports custom vendor onboarding and partner management. The platform allows you to add products from your vendors. ## Gifting program Yes, the Xoxoday customer incentive software allows you to configure redemption limits at the customer group level. This includes setting maximum redemption thresholds per transaction or restricting access based on the user's loyalty tier. These rules can be aligned with your broader loyalty program strategy. For feedback or questions, reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Campaigns Source: https://help-plum.xoxoday.com/faqs/for-admins/campaigns-faqs Find answers to frequently asked questions about creating, editing, and managing your reward campaigns in Plum. *Get quick answers to questions on running campaigns on Xoxoday Plum.* ## Dashboard Yes. The Xoxoday reward payout platform includes a centralized dashboard for administrators to oversee all active and past campaigns. * Provides real-time status updates: issued, redeemed, pending, or failed gift cards * Offers recipient-level insights and program-wide analytics * Streamlines campaign management and simplifies tracking of usage, performance, and budget compliance across initiatives ## Gifting Program Yes. The Xoxoday customer incentive software supports end-to-end execution of marketing campaigns and promotions tied to gift cards. * Distribute both digital and physical cards via the gift card marketplace * Personalize campaigns and automate reward delivery * Track redemptions through a real-time analytics dashboard * Send reminders or nudges to users to boost engagement The Xoxoday reward marketplace allows businesses to create and manage custom catalogs linked to specific customer groups. * Eligibility can be based on location, loyalty tier, or account type * Ensures only qualified users can access certain rewards * Supports targeted reward delivery through the customer rewards platform Xoxoday customer incentive software powers referral programs by automatically rewarding users for successful referrals. * Built-in referral tracking and reward automation * Rewards can include points, gift cards, or bonus credits * Supports both B2B and B2C audiences * Drives customer acquisition and loyalty through meaningful incentives Yes, the Xoxoday gifting platform supports a wide range of digital reward use cases, including gifting for employees and students, processing reimbursements, managing athletic stipends, and mileage-related rewards. It also accommodates similar custom remuneration projects through its robust configuration options and integrations. These features are adaptable to academic, administrative, and research environments, making the platform highly versatile for university-wide use. Our admin portal provides a self-service platform for distributing rewards, allowing administrators to log in and send rewards either in bulk or individually. Bulk uploads support lists of up to 10,000 recipients in a single file. Administrators can download cards in bulk to their email address through the portal or via API. ## Reporting Yes, the customer rewards platform includes gamification tools like leaderboards that rank participants based on performance, points earned, or other defined KPIs. These visual metrics help foster healthy competition and increased participation. Leaderboards can be segmented by region, team, or cohort and are particularly effective in sales, channel partner, and customer engagement programs. Combined with rewards from the Xoxoday gift card marketplace, this feature maximizes user motivation. ## Dashboard Yes. The Xoxoday reward payout platform includes a centralized dashboard for administrators to oversee all active and past campaigns. * Provides real-time status updates: issued, redeemed, pending, or failed gift cards * Offers recipient-level insights and program-wide analytics * Streamlines campaign management and simplifies tracking of usage, performance, and budget compliance across initiatives ## Gifting Program Yes. The Xoxoday customer incentive software supports end-to-end execution of marketing campaigns and promotions tied to gift cards. * Distribute both digital and physical cards via the gift card marketplace * Personalize campaigns and automate reward delivery * Track redemptions through a real-time analytics dashboard * Send reminders or nudges to users to boost engagement The Xoxoday reward marketplace allows businesses to create and manage custom catalogs linked to specific customer groups. * Eligibility can be based on location, loyalty tier, or account type * Ensures only qualified users can access certain rewards * Supports targeted reward delivery through the customer rewards platform Xoxoday customer incentive software powers referral programs by automatically rewarding users for successful referrals. * Built-in referral tracking and reward automation * Rewards can include points, gift cards, or bonus credits * Supports both B2B and B2C audiences * Drives customer acquisition and loyalty through meaningful incentives Yes, the Xoxoday gifting platform supports a wide range of digital reward use cases, including gifting for employees and students, processing reimbursements, managing athletic stipends, and mileage-related rewards. It also accommodates similar custom remuneration projects through its robust configuration options and integrations. These features are adaptable to academic, administrative, and research environments, making the platform highly versatile for university-wide use. Our admin portal provides a self-service platform for distributing rewards, allowing administrators to log in and send rewards either in bulk or individually. Bulk uploads support lists of up to 10,000 recipients in a single file. Administrators can download cards in bulk to their email address through the portal or via API. ## Reporting Yes, the customer rewards platform includes gamification tools like leaderboards that rank participants based on performance, points earned, or other defined KPIs. These visual metrics help foster healthy competition and increased participation. Leaderboards can be segmented by region, team, or cohort and are particularly effective in sales, channel partner, and customer engagement programs. Combined with rewards from the Xoxoday gift card marketplace, this feature maximizes user motivation. ## Gamificationamification The Xoxoday customer incentive software includes gamification tools that turn passive users into active participants, fostering deeper engagement and loyalty. * Interactive challenges, themed campaigns, and behavioral triggers (e.g., service milestones, driving habits) * Custom digital badges, points-based rewards, and seasonal quests * Leaderboards, milestone-based unlocks, and social sharing features * Campaign refresh mechanisms aligned with monthly or seasonal themes * Gamification analytics to track participation rates, app dwell time, badge completion, and social influence These features create a dynamic, experience-driven loyalty environment beyond simple transactional engagement. The Xoxoday customer incentive software includes gamification tools that turn passive users into active participants, fostering deeper engagement and loyalty. * Interactive challenges, themed campaigns, and behavioral triggers (e.g., service milestones, driving habits) * Custom digital badges, points-based rewards, and seasonal quests * Leaderboards, milestone-based unlocks, and social sharing features * Campaign refresh mechanisms aligned with monthly or seasonal themes * Gamification analytics to track participation rates, app dwell time, badge completion, and social influence These features create a dynamic, experience-driven loyalty environment beyond simple transactional engagement. # Customize Communication Source: https://help-plum.xoxoday.com/faqs/for-admins/customize-reward-communication Find answers to common questions on customizing the reward communication, such as emails and messages, sent to recipients through Plum. *Get quick answers to questions on customizing reward communication on Plum.* ## Communication The communication module, part of the Xoxoday reward payout platform, enables seamless and timely multi-channel messaging to keep users informed and engaged. It supports both promotional and transactional messaging formats and integrates across: * **Email:** for personalized promotions, surveys, and transactional updates * **SMS:** for brief, time-sensitive communications like reminders or confirmations * **Messaging apps (e.g., WhatsApp):** for interactive campaigns, push notifications, and engagement flows This omnichannel communication framework ensures consistent brand messaging, improves open rates, and supports personalized customer journeys triggered by real-time behavior or events. Yes, the Xoxoday reward payout platform allows organizations to customize gift cards with their company logo, brand colors, and messaging. This branding enhances recipient experience and reinforces your identity. Customization may incur additional fees and lead times, depending on the complexity and scale of the request. Yes, through the Xoxoday customer incentive software, you can easily personalize messages that accompany gift card deliveries via email, SMS, or other supported formats. These custom messages allow for tailored communication that aligns with campaign goals or occasions. The Xoxoday reward payout platform supports automated, data-driven communication workflows to deliver tailored messages via email, SMS, and in-app notifications. Messages can be personalized based on user milestones, available rewards, expiring points, or seasonal offers. This helps create a consistent engagement loop, keeping users informed and motivated throughout their rewards journey. These communications can be white-labeled and aligned with your brand voice. The Xoxoday platform includes a multi-channel engagement suite to deliver personalized, timely, and consistent messaging throughout the customer lifecycle. **Communication Tools Across Channels** * Email: Transactional and promotional emails with customizable templates * SMS & WhatsApp: Time-sensitive updates with rich media support * Push Notifications: In-app or mobile prompts for real-time updates * In-App Messaging: Banners and widgets for contextual nudges * Social Integrations: Export lists for targeted ad campaigns on platforms like Facebook **Campaign Management & Personalization** * Automation workflows (e.g., welcome journeys, tier milestone celebrations) * Dynamic personalization with member data such as points, names, or personalized offers * Multi-language support for local engagement **Marketing Support Services** * Assistance with campaign planning, creative design, loyalty calendar management, and promotions * End-to-end catalog updates and merchant partnership management **Integration with Marketing Tech Stack** * Loyalty triggers (e.g., birthdays, tier upgrades) synced with CRM, email, or SMS tools via APIs or native integrations * Enables unified, omnichannel member experiences **Use Case Examples** * Onboarding journeys (Day 0/7/14) * Tier achievements – Automated rewards and congratulations * Birthday campaigns – Personalized monthly promotions * Reactivation – Limited-time incentives for dormant users * Partner offers – Geo-targeted promotional messages By combining technology and marketing expertise, the platform ensures communications are relevant, measurable, and high-performing. Yes. With our Custom Branding feature, you can tailor the user experience by applying your company's colors, fonts, and logos across all emails, landing pages, and the marketplace. You can customize every aspect of your reward emails, including subject lines, sender names, salutations, logos, sending domains, and banner images. Additionally, you can create unique landing pages for your rewards by personalizing content, logos, and banner images. # Getting started Source: https://help-plum.xoxoday.com/faqs/for-admins/getting-started-for-admins-faqs Find answers to frequently asked questions about getting started with Plum as an admin, from setup to your first reward. *Get quick answers to questions on Plum* ## Set up process The steps are as followed: **Step 1:** Initial Consultation: Detailed requirement gathering covering incentive types, program goals, and regional scope. **Step 2:** Contract Finalization: Commercial agreement, compliance verification, and account security approvals. **Step 3:** Admin Account Creation: Creation of the primary admin account with defined roles and permissions. **Step 4:** Platform Configuration: Customization of reward catalogs, branding, languages, currencies, payout modes, and taxation rules. **Step 5:** Regional Enablement: Activation of services across 55+ countries in all major continents: * North America – United States, Canada * South America – Brazil, Argentina, Chile * Europe – United Kingdom, Germany, France, Spain, Italy, Netherlands, etc. * Asia – India, Singapore, UAE, Japan, China, Indonesia, etc. * Africa – South Africa, Nigeria, Kenya * Oceania – Australia, New Zealand **Step 6:** Integration & Testing: API, SSO, and payment gateway setup with sandbox testing. **Step 7:** Go-Live: Platform launch, assignment of the Relationship Manager, and user onboarding. This process ensures full operational readiness, security compliance, and localization for each target market. ## Security Requirement Yes. Every client is assigned a dedicated Relationship Manager (RM) or Customer Success Manager (CSM) to ensure smooth implementation, adoption, and ongoing support. The RM acts as the primary point of contact for escalations, program reviews, and best-practice recommendations. ## Implementation & Roll out Xoxoday follows a structured, customer-centric implementation methodology across all its Platforms to ensure seamless program rollout and long-term success. The approach is collaborative, phased, and designed to minimize disruption while maximizing adoption. * **Pre-Implementation:** This stage involves foundational readiness checks such as reviewing the Statement of Work (SOW), obtaining required InfoSec clearance, finalizing the Master Services Agreement (MSA), establishing payment and subscription terms, and transitioning ownership from the sales team to the implementation team. * **Requirements Gathering & Discovery:** At this stage, we work closely with client stakeholders to capture program goals, success metrics, and specific requirements. This includes understanding user segments, reward policies, technical dependencies, and branding preferences to form the blueprint of the engagement program. * **Planning & Configuration:** A joint launch team is established, and timelines are finalized. The platform is configured based on business rules, policies, and workflows. This includes integration with critical enterprise systems such as HRIS, SSO, ERP, CRM, and communication tools. * **Customization & Integration:** The platform is customized with client-specific branding, logos, color palettes, and program elements to ensure a consistent user experience. Technical integrations are validated to enable smooth data flows and reward automation across channels. * **Testing & Validation:** Before launch, rigorous user acceptance testing (UAT) is conducted to ensure the platform is functioning as expected. This includes testing user journeys, redemption workflows, system integrations, and reporting dashboards. * **Launch & Change Management:** A formal go-live is executed with supporting communication and engagement strategies. Training materials, FAQs, and guides are provided to drive user adoption and ensure all stakeholders are aligned for a smooth rollout. * **Post-Deployment Support & Success Reviews:** Following launch, clients receive dedicated support through account managers and customer success teams. Regular reviews, monthly, quarterly, and annual, are conducted to monitor adoption, measure KPIs, and align with evolving business needs. Continuous feedback loops and proactive recommendations ensure that the program remains effective and delivers ROI. By following this phased methodology, Xoxoday ensures that each customer engagement rewards program is launched smoothly, tailored to business requirements, and continually optimized for success. ## Gifting Program The Xoxoday customer rewards platform offers multiple levers to optimize spend and improve operational ease: * Volume & tiered discounts – Benefit from pricing advantages when purchasing at scale. * Digital-first rewards – Reduce costs tied to packaging, logistics, and physical distribution. * Bulk ordering & automation – Use self-serve bulk issuance, API integrations, and wallet-based payments for faster, low-touch reward distribution. * Customizable reporting – Configure custom fields, generate real-time insights, and track redemptions and spend for greater visibility and accountability. Together, these features streamline workflows, improve delivery speed, and maximize ROI on your rewards program. Yes, a consumer reward platform can deliver highly personalized reward experiences by using rule-based automation or machine learning models. It can track user activity, preferences, transaction history, and frequency of engagement to curate personalized reward recommendations. Through the Xoxoday solution, administrators can display curated catalog options that resonate with user profiles—resulting in higher redemption satisfaction and stronger program engagement. ## Gifting Catalog The Xoxoday reward marketplace supports a broad range of reward capabilities beyond traditional gift cards, including: * Distribution of gift cards to employees, students, or research participants * Reimbursements and expense allowances * Support for athletic stipends and fringe benefits * Management of mileage or lifestyle reimbursements * Custom remuneration workflows tailored to organizational needs Designed as a holistic consumer reward platform, Xoxoday can handle diverse use cases across engagement, recognition, and financial compensation. ## Customer Service While a toll-free number is available for platform support during standard business hours, all core functions such as deactivating gift cards, verifying their status, and reissuing them can be seamlessly handled via the self-service admin panel on the Xoxoday reward payout platform. The dashboard displays delivery status, recipient engagement (email/SMS), and options to cancel or resend rewards. ## Invoice The Xoxoday reward payout platform provides flexible and transparent invoicing options tailored to organizational needs. Invoices are typically generated during wallet top-ups initiated by the business. Once payment is processed, the wallet balance is instantly updated, and confirmation is shared with the finance team. Itemized invoices, listing transaction details such as quantity, unit costs, reward type, and applicable service fees, can be provided in accordance with pre-approved invoice templates or customized formats preferred by the organization. This ensures detailed financial visibility and simplifies reconciliation. The Xoxoday customer rewards platform can support invoice generation and email delivery to customers upon successful redemption or transaction. These invoices can include detailed transaction information such as date, time, itemized rewards, payment method, and custom narration if scoped appropriately. However, the exact implementation is subject to further technical scoping, customer-specific integration requirements, and platform configuration. For financial institutions like banks, integration via API and secure email delivery mechanisms can be explored. ## Financial Yes, Xoxoday applies a 5% transaction fee on reward redemptions. For example, if a user redeems 100 points for a $100 reward, the organization will be billed $105. This fee supports operational costs including reward processing, delivery logistics, and catalog management. There are no hidden fees for catalog access or customization. Yes, the Xoxoday reward payout platform is designed to distinguish between compensation and reimbursement payments, as well as between human subject rewards and general-purpose payouts such as employee recognition or athletic stipends. This segmentation enhances financial accuracy and supports compliance with tax and privacy policies across different stakeholder groups. ## Record Creation Yes. The Xoxoday reward payout platform supports milestone-based and task-driven payment scheduling. This allows program administrators to automate variable compensation based on criteria such as study phase completion, participant tenure, or activity type. The platform is built to accommodate custom payment logic and workflows aligned with research objectives. ## Wallet management The Xoxoday gift card solution operates on a prepaid wallet model. Organizations can fund their wallet in advance and issue gift cards to recipients based on required denominations. The system deducts the card value from the wallet at the time of issuance, ensuring transparency and control. This flexible funding mechanism supports real-time transactions and can scale according to fluctuating reward needs. You get a notification when the wallet balance hits a low threshold. ## Payments Xoxoday supports a wide array of payout methods tailored to global needs: * UPI and equivalent * Digital wallets like PayPal, Venmo, Zelle (region-specific) * Reloadable gift cards (Visa, Mastercard, etc.) * Direct debit card payouts, and * Bank transfers where supported. These options are part of Xoxoday's multi-country reward catalog. Full details are available at [https://stores.xoxoday.com/marketplace/home](https://stores.xoxoday.com/marketplace/home). Yes. Every transaction processed through the Xoxoday reward payout platform is automatically logged with a precise timestamp and payment amount. This ensures full visibility into the financial flow of rewards, facilitating transparent audits and program accountability. Yes. The platform includes real-time tracking capabilities that capture and display the delivery and redemption status of each reward or payment card. This includes information such as whether the card has been delivered, activated, or redeemed, ensuring payment verification and fraud prevention. ## Process Xoxoday follows a structured, transparent, and industry-aligned process for handling software enhancement requests across all its Platforms. This ensures client feedback is systematically captured, prioritized, and aligned with the long-term product roadmap. * **Submission of Requests:** Enhancement requests can be submitted through the Customer Success Manager (CSM), the support portal, or via account management channels. Each request is logged with details such as business impact, use case, urgency, and expected outcomes. * **Review & Prioritization:** Requests are validated by product teams before being assessed by the Chief Product Officer. Evaluation is based on customer impact, technical feasibility, security implications, and alignment with the product vision. * **Roadmap Planning & Transparency:** Approved requests are incorporated into the product roadmap, with expected timelines communicated back to the customer. Xoxoday emphasizes roadmap transparency, enabling clients to plan adoption in advance. * **Development & Release:** Enhancements are built using agile methodology and CI/CD (continuous integration/continuous deployment) for faster, incremental releases. Each update undergoes rigorous QA testing before deployment, with customers informed via release notes, newsletters, and business reviews. * **Feedback & Iteration:** Post-release, feedback is actively collected to ensure enhancements deliver intended outcomes. This feedback loop ensures continuous refinement and innovation in our product suite. Through this structured approach, combining customer co-creation, agile execution, transparent communication, and impact-driven prioritization, Xoxoday ensures enhancement requests are handled effectively, driving long-term customer success and innovation across all Platforms. Xoxoday has robust capabilities to address enhancement, change, and customization requests across all its platforms. Our approach balances agility with governance, ensuring business needs are met while maintaining platform stability, scalability, and compliance. * **Structured Intake & Assessment:** Requests can be submitted through Customer Success Managers (CSMs), the support portal, or account teams. Each request is assessed for business impact, urgency, and technical feasibility. * **Customization Flexibility:** Platforms are modular and API-first, enabling configuration of workflows, branding, catalog rules, and integrations without heavy development. For unique needs, custom modules, connectors, and extensions can be built while ensuring compatibility with future releases. * **Enhancement & Change Management:** Enhancement requests are reviewed by the Product Management team and prioritized for inclusion in the product roadmap. Changes are delivered using Agile and CI/CD practices, enabling faster iterations and frequent incremental improvements. All updates undergo QA, regression testing, and InfoSec review before deployment. * **Transparency & Communication:** Clients are kept informed through release notes, success reviews, and roadmap discussions. Dedicated CSMs ensure requests are tracked, communicated, and followed up on until resolution. * **Post-Implementation Support:** Once changes or customizations are deployed, user feedback is gathered and performance is monitored through analytics and KPIs. Feedback loops enable continuous refinement to maximize business value. By combining flexible configuration options, structured change management, agile delivery, and transparent communication, Xoxoday ensures enhancement and customization requests are handled efficiently. Xoxoday follows a well-defined Change Management Methodology across all its Platforms to ensure changes are implemented securely, efficiently, and with minimal disruption to customer operations. * **Change Request & Impact Assessment:** Change requests are initiated via the support portal, CSMs, or account management. Each request undergoes an impact assessment covering business value, security, compliance, dependencies, and potential risks. * **Planning & Prioritization:** Approved requests are slotted into release cycles or sprint backlogs, depending on urgency. Prioritization is based on business impact, customer need, technical feasibility, and roadmap alignment. Transparent communication of planned changes ensures clients can anticipate timelines and prepare internal stakeholders. * **Development & Testing:** Changes are developed following Agile methodology and CI/CD practices, enabling incremental, high-quality releases. Rigorous unit testing, regression testing, InfoSec checks, and UAT (User Acceptance Testing) are conducted before deployment. * **Deployment & Rollout:** Deployment follows a staged rollout approach (sandbox → staging → production), ensuring validation at every level. Automated monitoring is in place to detect anomalies, with rollback procedures available in case of unexpected issues. * **Post-Implementation Review & Continuous Feedback:** After rollout, customer feedback and performance metrics are captured to confirm change effectiveness. Release notes and communication updates are shared proactively with customers. Continuous improvement is embedded, ensuring learnings from each change cycle inform future updates. By combining structured intake, agile development, staged rollouts, rigorous testing, and transparent communication, Xoxoday ensures system changes are implemented seamlessly. Yes, the Xoxoday reward platform guarantees 99.9% uptime and delivers high throughput performance across modules. All new releases undergo rigorous performance benchmarking and regression testing before rollout to ensure system stability and reliability. The Xoxoday gift card solution provides a comprehensive admin dashboard with built-in audit and tracking features. Universities can monitor discount structures in real-time, filter data by category, and export detailed reports in formats like Excel and CSV. The reporting module supports advanced filtering by product type, recipient, time range, or department, offering full visibility into pricing accuracy. This ensures that all transactions are verifiable and align with contractual terms. ## Incentive Program Xoxoday streamlines the end-to-end incentive lifecycle through its global reward marketplace. Incentives are sourced from a curated network of brand partners, offering 10M+ options across 100+ countries. IPA files containing recipient details can be processed in bulk via CSV upload or API integrations. Once validated, incentives are delivered instantly through SMS, email, or WhatsApp. Returned or failed deliveries are flagged for retries or admin review. If recipients report any issues (like malfunction or redemption failures), Xoxoday's dedicated support and SLA-backed ticketing system resolves them swiftly, ensuring a seamless experience. The Xoxoday gift card solution offers robust admin capabilities for managing provider incentive programs. Program admins are responsible for wallet recharges and can distribute rewards through Xoxo Points, Xoxo Codes, Xoxo Links, or branded gift cards. The system supports multi-admin access—ideal for distributed teams across geographies. To ensure smooth operations, admins are provided with detailed training kits, documentation, and access to a dedicated Customer Success Manager (CSM) who acts as the single point of contact for all ongoing support and strategic guidance. More on administrative features can be found here: [User Management](/account-administration/user-management/user-management) ## Points based system The Xoxoday customer incentive software allows seamless panelist data management and point allocation. Clients can upload panelist information directly through the self-service dashboard. Incentive rules and allocation can be configured manually or automated using rule-based logic for recurring bi-annual reward cycles. # Integrations Source: https://help-plum.xoxoday.com/faqs/for-admins/integration-faqs Find answers to frequently asked questions about integrating Plum with your CRM, HR, and survey tools and platforms. *Get quick answers to questions relating to integration* Yes, the Xoxoday customer rewards platform supports robust API integrations with platforms like Salesforce, PunchOut, ERP, and Point-of-Sale systems. Custom API connections can also be developed to meet specific system requirements, including those of platforms like Vivint or NRG. Businesses using the Xoxoday reward marketplace can access the full product catalog via secure APIs. These APIs allow for custom configurations and selective catalog displays. While catalog access is API-driven, onboarding new vendors is managed through the backend to ensure quality control, compliance, and proper integration with the platform. Yes. Xoxoday's API suite supports real-time data retrieval on product inventory, pricing updates, and time-sensitive promotional offers. This ensures customers always view the latest catalog information, enhancing trust and driving higher engagement across the Xoxoday gift card solution. The Xoxoday customer incentive software supports real-time synchronization of product inventory and redemption configurations. Businesses can manage digital vouchers, merchandise stock, and availability statuses seamlessly, ensuring accurate catalog experiences for all users. The Xoxoday reward marketplace can be seamlessly integrated with any existing loyalty management system to support both points redemption and earnings. For redemptions, the platform facilitates real-time access to user point balances, updates, and redemptions via APIs. For point earnings, transactional data can be securely shared with the loyalty engine, enabling it to allocate reward points based on purchases made through the marketplace. This integration empowers businesses to deliver a cohesive loyalty experience across all user touchpoints. Yes, the Xoxoday gift card marketplace supports cross-vertical use cases by sharing detailed transaction data via APIs. This data can be utilized by a central loyalty engine to accumulate and manage points from purchases made across different verticals such as telecom, fintech, and travel. The system is flexible and API-first, allowing easy integration with diverse business models. Yes, the Xoxoday customer rewards platform offers partners and vendors access to a dedicated admin portal. Through this portal, partners can manage their product catalogs, update pricing, configure shipping or digital delivery options, and handle fulfillment processes. This self-service capability enables better autonomy and faster go-to-market execution for suppliers while maintaining full visibility and control within the marketplace ecosystem. # Reward Code Source: https://help-plum.xoxoday.com/faqs/for-admins/reward-code-faqs Find answers to frequently asked questions about sending, customizing, and managing your reward codes in Plum. *Get quick answers to questions relating to Reward Code* ## Delivery We have rarely seen incidents on our platform where the delivery of e-vouchers and incorrect codes for redemption are sent to the end users. However, if such incidents occur, Xoxoday offers 24/7 email and chat support ([cs@xoxoday.com](mailto:cs@xoxoday.com)) for all users of the platform. We'll also share a proper escalation matrix with you. Your account manager and customer success teams will also work with you closely to address any issues. For prepaid cards such as Visa or Mastercard, the customer incentive software does not support fund withdrawal once issued. However, for Xoxo reward codes, the funds can be retracted for unused gift cards if you are on the "redemption based plan". ## Reporting The Xoxoday reward payout platform provides a robust self-service analytics and admin dashboard that empowers internal teams with real-time insights and actionable metrics. Features include: * Automated daily, weekly, monthly, and quarterly reports * Reward analytics: total vs. unique redemptions, preferred reward categories * Communication analytics: campaign open and click-through rates across email, SMS, and other channels * Segmentation tools: filters by geography, behavior, reward usage tiers, service touchpoints * Customer satisfaction indicators: Net Promoter Score (NPS), Sales Satisfaction Index (SSI), and Customer Satisfaction Index (CSI) This data-driven dashboard helps teams fine-tune campaign performance, increase redemptions, and deliver targeted experiences. ## Security Requirement The platform prioritizes security in reward distribution. In case of frauds, the system can cancel the reward orders. The system can also block reward codes which are not misused. If the fraud happens on a 3rd party service, we'll have to check with the 3rd party to check possibilities. # Reward Points Source: https://help-plum.xoxoday.com/faqs/for-admins/reward-points-faqs Find answers to frequently asked questions about sending, tracking, and managing your reward points balance in Plum. *Get quick answers to questions relating to Reward Points* ## Points Redemption The Xoxoday incentive management platform supports automated file processing through APIs for real-time or scheduled transfers of points data from CRM tools such as Salesforce to external programs. This allows for a fully integrated and automated rewards experience across systems. Absolutely. The Xoxoday customer rewards platform includes automated workflows that credit points back to the member's account when a redemption request is rejected by the external partner. This ensures accurate balances and a transparent user experience. Yes, once a redemption request is accepted, the Xoxoday reward marketplace automatically deducts the corresponding number of points from the member's balance. This ensures real-time updates and alignment between the redemption activity and point balances. Yes, the Xoxoday consumer reward platform offers configurable redemption denominations for airline loyalty programs or any reward category. This enables clients to define specific point tiers for redemptions, supporting both user flexibility and budget control. ## Rewards Redemption Reward values on Xoxoday's platform are fully configurable to align with your program's budget and objectives. During program design, you can set a preferred point-to-currency ratio. Many clients choose a simple 1:1 ratio (1 point = \$1.00) for transparency, though other ratios like 1:2 can also be applied. Points are not marked up, and there's no breakage in the pay-on-redemption model. The catalog value always matches the points spent, ensuring full transparency and cost-efficient reward distribution. ## Points Redemption - Invoice Credit Yes, the Xoxoday reward payout platform allows full control over redemption rules. Program administrators can set both minimum and maximum limits for how members convert reward points into credits or benefits. When members choose to redeem their points as invoice credit, the equivalent credit amount is automatically applied to their next billing cycle. This credit appears as a line item on the upcoming invoice, providing full transparency and ease of tracking. The Xoxoday customer rewards platform supports such redemption workflows through customizable automation rules and flexible reward configurations. Yes. As part of the redemption workflow on the Xoxoday reward payout platform, members instantly receive an email confirmation once their point redemption is complete. This notification includes the details of the credit applied, the number of points redeemed, and confirmation of the amount that will be adjusted on their next invoice. This real-time communication enhances user trust and ensures a seamless post-redemption experience. Yes. The Xoxoday reward marketplace allows administrators to set up bonus credit promotions linked to specific redemption thresholds. For example, you can configure a rule where users receive an additional \$5 reward when redeeming 5,000 points. These promotions can be tailored for time-limited campaigns, member tiers, or seasonal offers, helping businesses drive engagement and encourage more redemptions. Yes, invoice credits can be configured to apply to the pre-tax amount, depending on the specific integration setup. The Xoxoday reward payout platform can accommodate this requirement through customized billing workflows. For greater flexibility, financial rules such as credit application logic can be defined during the onboarding phase to ensure compliance with local taxation and accounting standards. Yes. The Xoxoday customer incentive software lets administrators define rules so invoice credits apply only to selected product categories. Using configurable reward logic and advanced rule-based segmentation, businesses can restrict credits to specific SKUs or catalog sections—such as electronics, apparel, or seasonal merchandise—helping optimize budget allocation and maximize reward spend efficiency. ## Points Redemption - Travel Credit Yes, the Xoxoday reward payout platform supports secure overnight batch file transfers for points-based reward programs. This allows seamless integration with partner systems and ensures efficient processing of bulk transactions. Yes, the Xoxoday rewards platform supports hand-back file processing to confirm or reject points redemption requests. This feature helps maintain transactional accuracy, reconciliation, and audit readiness in partner-integrated workflows. The Xoxoday incentive management software can automatically credit points back to a member's rewards account when a redemption or reward request is rejected. This ensures data accuracy, improves the user experience, and maintains the integrity of the reward points balance. Yes, with the Xoxoday customer incentive platform, approved points requests are automatically deducted from the member's rewards balance. This deduction process is secure and traceable, ensuring compliance and transparency within your points management program. The Xoxoday reward payout platform provides robust reporting features that can be configured to deliver monthly reports on all points-related activities—such as requested, approved, and rejected redemptions. These reports support audit-readiness, transparency, and informed decision-making. Yes, the Xoxoday customer rewards platform supports robust API integrations to enable automatic file processing of points requests. This ensures a seamless and scalable exchange of data between client systems and the reward infrastructure. ## Gifting Program The Xoxoday rewards platform enables users to participate in various games & contests such as surveys, feedback campaigns, or milestone-based actions to earn points. Submissions are automatically tracked within the platform, and corresponding points are added in real time. The gamification can be chosen by the client. # Send Gift Cards Source: https://help-plum.xoxoday.com/faqs/for-admins/send-gift-cards-faqs Find answers to frequently asked questions about sending digital gift cards to recipients through the Plum platform. *Get quick answers to questions on sending gift cards on Plum* ## Customer Service The Xoxoday reward payout platform deems an order successful only when all quality checks are met: * Correct voucher, denomination, or merchandise is fulfilled * Branded collateral or cover letter (where required) follows approved format and tone * One printed cover letter is included per package, where applicable * Shipping is completed to the exact address provided by the organization If deliveries are incorrect or products damaged, issues are treated as P2 priority with a 4-hour response time and 24-hour resolution window. The Xoxoday customer rewards platform ensures end-to-end order traceability with strong logistics protocols. * Valid Proof of Delivery (POD) is provided for disputed or undelivered orders * If POD is unavailable, a replacement is issued at no extra cost * Issues are prioritized as: * P1: Time-sensitive cases like undelivered items or critical errors * P2: Moderately urgent issues such as incorrect names, vouchers, or denominations * Response time is 4 business hours for both categories, with resolution expected within 8 hours for P1 and 24 hours for P2 ## Gift Card Yes, all gift cards issued through the Xoxoday gift card solution come with a defined expiration period. The duration varies by card type or issuing brand and is communicated upfront at the time of issuance, ensuring recipients have ample time to redeem their rewards. Xoxoday's rewards, incentives, and payout platform enables flexible global reward distribution, including Visa and Mastercard gift cards across 100+ countries. * Visa & Mastercard digital gift cards: No activation fees when issued digitally via the Xoxoday marketplace, ensuring cost efficiency at scale. * Other branded or physical cards: For cards such as American Express, Discover, or physical card formats, activation fees may apply. These fees are determined by the issuing bank and regional regulations, not by Xoxoday. All applicable charges are displayed transparently on the platform when selecting reward types, so businesses have full clarity before issuing. Alongside this, Xoxoday offers real-time tracking, multi-currency support, and a self-serve dashboard to manage issuance, activation, cancellation, and re-delivery. Yes. The Xoxoday reward marketplace's admin interface allows authorized users to: * Deactivate issued gift cards * Track usage and redemption status * Verify remaining balances This centralized control ensures transparency and oversight for large-scale rewards distribution. Vouchers delivered through the Xoxoday reward payout platform typically offer flexible validity, including 12 months or longer. While validity is governed by individual brand partners, most vouchers offer ample redemption windows to ensure a satisfying end-user experience. * Digital rewards: Delivered instantly via email, WhatsApp, or SMS * Physical rewards: Delivered within 2 to 7 days, depending on the delivery location All digital gift cards from the Xoxoday reward marketplace are delivered instantly via email or SMS, ensuring real-time fulfillment with no delays. This makes the solution ideal for time-sensitive campaigns such as on-the-spot rewards, contests, or service recovery gestures. Yes, the Xoxoday gift card solution manages end-to-end fulfillment for physical gift cards, including printing, packaging, and delivery. Orders can be shipped across the 100+ countries with reliable logistics support. This turnkey offering simplifies the physical reward process while maintaining branding and quality standards. For prepaid cards such as Visa or Mastercard, the customer incentive software does not support fund withdrawal once issued. However, for Xoxo reward codes, the funds can be retracted for unused gift cards if you are on the "redemption based plan". Yes, the Xoxoday gift card solution enables administrators to generate gift cards without assigning them to a specific individual at the time of issue. These unassigned cards are delivered via email in bulk to the designated admin in secure format. These cards can be sent in inactive format and can be activated on demand securely. This approach is particularly useful for open campaigns, event-based rewards, or when the final recipient is yet to be determined. The Xoxoday rewards, incentives, and payout platform offers global delivery of physical rewards across 100+ countries with standard and expedited shipping options. * Coverage: Rewards shipped to North America, Europe, APAC, MENA, and LATAM * Reward types: Prepaid Visa/Mastercard gift cards, branded merchandise, swag, and corporate gifting bundles * Tracking: Most shipments are trackable via integrated courier partners **Standard Shipping** * Carriers: Local postal services (USPS, Royal Mail, Canada Post, India Post, etc.) * Delivery times: * North America & Europe: 3–7 business days * APAC & Middle East: 5–10 business days * LATAM & Africa: 7–14 business days (varies by region) * Cost: Included in base fulfillment charges for most reward categories **Expedited Shipping** * Carriers: FedEx, DHL, UPS, Aramex (region-based) * Delivery times: * Major metros (US, UK, EU, India): Next-day or 2-day delivery * Remote/international: 3–5 business days * Cost: Additional, based on volume, country, and weight **Security & SLA** * Tamper-proof packaging for prepaid and branded cards * Delivery confirmation and audit trail via the platform * Insurance for high-value shipments (available on request) ## Points Redemption Yes, the Xoxoday gift card marketplace adheres to merchant-specific denomination constraints. Each brand or merchant in the platform defines their available gift card values, and these denominations are clearly displayed during the selection process to ensure transparency and accuracy for end-users. Yes, the Xoxoday reward marketplace supports full configurability of reward point costs by gift card brand, denomination, and delivery mode (digital or physical). This allows program administrators to tailor the redemption logic to business rules, regional pricing, or marketing objectives, ensuring flexibility and cost control. ## Distribution The Xoxoday customer rewards platform offers omnichannel gift card distribution, enabling delivery via email, SMS, WhatsApp, and in-app notifications. For those preferring tangible rewards, physical gift cards are available and can be shipped directly to recipients. This multichannel approach ensures a seamless and tailored reward delivery experience across digital and physical touchpoints. Admins can send rewards directly to individual email addresses or mobile numbers. This flexibility is ideal for targeted recognition, milestone achievements, or just-in-time incentive distribution. The Xoxoday reward payout platform provides bulk distribution capabilities via both the self-service portal, Spreadsheets and API integrations. Admins can upload a list of recipients and distribute rewards in bulk, or use the API to get these rewards. These links remain accessible until activated by the recipients. There's no restriction on the number of orders per day, making it easy to run large-scale reward campaigns across departments, regions, or audience segments. Yes, the Xoxoday reward payout platform supports both open-loop and closed-loop gift cards. Open-loop cards (such as prepaid Visa and Mastercard) can be used universally, while closed-loop cards are redeemable at specific retail or service brands. This dual offering ensures flexibility in consumer reward experiences across different geographies. ## Gifting Program The Xoxoday rewards, incentives, and payout platform offers a gift card program that stands out for its scale, flexibility, and global coverage. Designed to meet the needs of modern enterprises, it empowers businesses with a seamless, secure, and highly customizable way to reward employees, customers, partners, or research participants. Here's how the program differentiates itself: * **Global gift card catalog with unmatched scale:** Our platform offers access to over 10 million reward choices across 30+ categories, with a strong emphasis on gift cards. It includes 10,000+ brand gift cards — such as Amazon, Walmart, Starbucks, and Visa/Mastercard — available in 100+ countries with support for 55+ currencies and 50+ languages. * **Dual-mode delivery: physical & digital:** The gift card program supports both physical and electronic delivery, ensuring users can choose the mode that best suits their location and preference. * **Real-time reward delivery & status tracking:** Gift cards can be sent instantly via email, SMS, or WhatsApp, with access to a self-service admin dashboard to track delivery and redemption status in real time. Bulk issuance is also supported for up to 10,000 recipients at once. * **Custom branding and localization:** Businesses can fully customize gift card emails, landing pages, and catalogs with brand logos, messages, and localization settings (language, currency, etc.) to ensure a white-labeled, personalized gifting experience. * **Transparent pricing with pay-on-redemption model:** Unlike many providers, Xoxoday uses a transparent pricing structure with no markups on gift card value or shipping, and offers pay-on-redemption billing for point-based programs, minimizing breakage and optimizing spend efficiency. * **Fraud prevention and redemption controls:** Admins can set expiration periods, block specific gift cards, enable approval workflows, and use maker-checker models for high-value distributions. Built-in fraud detection further secures transactions. * **Dedicated account management and global support:** Clients receive a dedicated account manager, access to 24/7 customer support, and optional onboarding and integration assistance. This ensures smooth implementation, timely issue resolution, and scalable program management. These capabilities collectively make the Xoxoday gift card program a highly secure, flexible, and globally scalable rewards solution trusted by over 5000+ businesses, including Fortune 500 enterprises and leading research institutions. Absolutely. The Xoxoday gift card solution is designed for flexible ordering to suit varied use cases. Administrators can issue single cards for individual rewards or execute bulk distributions to thousands of recipients in one go. Cards can be activated and sent instantly via email, SMS, or custom links. This dual-mode ordering capability supports dynamic reward campaigns, whether for a one-off recognition or a large-scale loyalty or engagement program. There are no minimum or maximum order limits. Organizations can issue a single reward or run bulk campaigns for thousands of recipients. The platform is designed to scale seamlessly without constraints. No fixed dollar limit exists. * Gift card denominations are selected within brand-specific ranges displayed during order setup * Virtual prepaid cards support custom denominations (e.g., \$1, ₹2500, £52) * Reward Codes can hold up to 50,000 points each, with up to 15 codes applicable per transaction within the total balance Yes, the incentive software provides full flexibility to load digital prepaid cards in custom denominations as per your requirements. This helps tailor the value of each reward to specific user actions, performance tiers, or campaign milestones. Yes. The platform supports personalized gifting: * Custom messages and delivery scheduling for occasions like birthdays or holidays * Delivery via email, SMS, WhatsApp, or other social channels * Recipient selection from contact directories * Confirmation notifications for senders and email receipts summarizing the transaction * Functionality is configurable based on integration and implementation requirements The Xoxoday gift card marketplace supports global shipping of physical vouchers. Cards can be sent to a designated location as per project instructions, including consolidated delivery to client-appointed audit hubs. There are no additional costs to participants for receiving these rewards. Yes, the gift cards can be uploaded in Apple or Google wallet for easy tracking. The Xoxoday gift card solution maintains a transparent pricing model. There are no hidden fees related to card issuance, inactivity, or reporting. Clients only pay for what is redeemed, with no markup on gift card value or hidden service costs. Yes, the Xoxoday gift card solution offers a real-time dashboard that allows administrators to track every stage of gift card activity. This includes issuance status, redemption history, balance checks, delivery confirmations, and user-level usage insights. The platform ensures transparency and accountability by updating these records dynamically as transactions occur. Yes, the Xoxoday gift card solution enables users to seamlessly share rewards, e-gift cards, and merchandise links with others. These can be sent through multiple digital channels such as WhatsApp, text message, email, or social platforms, directly from the integrated app experience. This functionality enhances social gifting and engagement and can be embedded within any app ecosystem via API or SDK integration. ## Refunds and Returns The Xoxoday gift card solution supports cancellations and refund processing for cancelled or unfulfilled orders. The refunds go to the original payment method which can be reward points or reward codes or credit card/bank through payment gateway. While the Xoxoday gift card solution does not offer guaranteed upfront discounts based solely on expected breakage, organizations can benefit from its pay-on-redemption pricing model, where costs are incurred only for claimed gift cards. Additionally, volume-based pricing tiers and program-specific commercial models may be available depending on usage scale and scope. The treatment of breakage depends on the type of card issued. * For prepaid Visa or Mastercard-type gift cards, unused funds are not recoverable. * For gift cards, the breakage is handled as per the terms of the brand and the country. For unused balances, the terms of the brand define the usage. Through the Xoxoday gift card solution's admin dashboard, authorized personnel can: * Cancel issued rewards * Resend gift cards when needed If the gift card hasn't been accessed or used, the order can usually be reversed, ensuring a smooth and secure process for administrators managing both bulk and individual reward programs. # Cancellation/Refund Source: https://help-plum.xoxoday.com/faqs/for-end-users/cancellation-refund Find answers to frequently asked questions about cancellations and refunds for rewards received through the Plum platform. *FAQ's on cancellation and refunds.* You cannot cancel an experience after booking confirmation is received from Xoxoday. Any modification in the booking will be at the service provider's discretion. Please drop a mail to [cs@xoxoday.com](mailto:cs@xoxoday.com) for any rescheduling/canceling changes. You can also [raise a ticket](https://www.xoxoday.com/support#raise_a_ticket) or Whatsapp us at **+91 8061915050**. Cancellation charges are dependent on the cancellation policy of the experience. It is mentioned while booking the experience. You would be able to change the experience before a confirmation is received. Currently, this feature isn't available online. Please contact at [cs@xoxoday.com](mailto:cs@xoxoday.com) to help you guide through the process. You can also [raise a ticket](https://www.xoxoday.com/support#raise_a_ticket) or Whatsapp us at +91 8061915050. But once you receive the confirmation of your booking, any modifications will be at the service provider's discretion. Yes, the amount will be refunded to your account without any cancellations, if the experience is not available. # Create Support Ticket Source: https://help-plum.xoxoday.com/faqs/for-end-users/create-support-ticket Learn how to create a support ticket as an end user on Plum if you run into any issue with a reward you've received. *How to create customer support ticket for a quick resolution of your query* At Xoxoday, we strive to deliver a superior experience to all our users at all times. However, we understand that at times, the users may be left with unanswered questions or are simply not sure about what to do next. The Plum customer support team is available to resolve all such queries and issues that the customers are facing. ## How to Create a Customer Support Ticket? 1. Navigate to the in-app resource centre. Empuls Resource Center 2. Go to Home --> Raise A Support Ticket. Raise A ticket 3. Fill out the form on the new tickets creation page and submit. Ticket Creation Form Users can also simply drop an email to [support@empuls.io](mailto:support@empuls.io) with the details of their query/issue for a swift resolution. # Delivery related Issues Source: https://help-plum.xoxoday.com/faqs/for-end-users/delivery-related-issues Find answers to frequently asked questions about delivery-related issues for rewards sent through the Plum platform. *Get answers to Delivery FAQ's* Please [raise a ticket](https://www.xoxoday.com/support#raise_a_ticket) or send a mail to [cs@xoxoday.com](mailto:cs@xoxoday.com) or Whatsapp us at +91 080 61915050. We will check and get back to you on the same. Please [raise a ticket](https://www.xoxoday.com/support#raise_a_ticket) or send a mail to [cs@xoxoday.com](mailto:cs@xoxoday.com) or Whatsapp us at +91 8061915050. We will update you in the next 4 business hours. Yes, you may coordinate with the delivery executive at the time of delivery and arrange an alternate person to collect the Gift Box on your behalf. You may provide any address to deliver the gift box, be it residential or otherwise. Once the Gift Box is dispatched from our end, you will be notified with the tracking details on your official mail ID to track the shipment further. # Getting started Source: https://help-plum.xoxoday.com/faqs/for-end-users/getting-started-for-end-users-faqs Find answers to frequently asked questions about getting started as an end user redeeming rewards on the Plum platform. *FAQ's for End Users* The Storefront ([https://stores.xoxoday.com/companyname/](https://stores.xoxoday.com/companyname/)) is accessible in a mobile browser and can be accessed via an Android or an iOS device. For first-time users, please follow the steps below: Go to "stores.xoxoday.com/\[companyname]," click on the login page, and enter your email and password. You will receive an OTP to verify and be successfully signed up. The user has to visit stores.xoxoday.com to redeem the code. Users can redeem the code through guest checkout. You don't have to log in or sign up. [Read more](/getting-started/for-end-users/how-to-redeem/reward-code) here. After logging in to the store, your reward points balance will be shown at the top right corner of the page or under "Xoxo Points" in the profile icon. Choose any gift vouchers or any product from 30+ categories. During checkout, the user will be able to see the points balance and will be asked if he wants to use the points for the order payment. After checking the same, your points can be used for checkout. [Read more](/getting-started/for-end-users/how-to-redeem/redeem-reward-points) here. When you get the email about the reward, click "Redeem Now." You'll be taken to a page listing all of your vouchers. Read more here. No, you cannot redeem Giift points/vouchers for cash. To use your Mastercard/Visa cards, you can pay the excess amount during checkout by selecting the option to pay via "Credit Card" and choosing the card of your choice. For Reward Codes and Rewards links, the user need not log into Plum. Checkout is available for guest login. We generally respond to customer inquiries within 8 business hours. Our customer support timings are as follows: Monday to Friday (9:00 am to 9 pm)\* Saturday to Sunday (9:30 am to 6.30 pm)\* Note: All times are in IST. For queries please raise a ticket at [cs@xoxoday.com](mailto:cs@xoxoday.com) or Whatsapp us at +91 080 61915050. You can check the order status under your Profile. Click on the profile icon and select "Orders." Then, navigate to "Your Orders" to view a list of your orders. Order Status is mentioned right next to the order. (Delivered/Pending). If your order status is pending, please check the Delivery TAT of the Gift voucher mentioned in T\&C of the Brand. Note: The order history can only be checked if the user is registered in Plum and has placed the order by logging into the account and not guest check out. * Go to [https://stores.xoxoday.com/](https://stores.xoxoday.com/) * Now, click on the "Login" button that is present in the top right corner of the page. * Enter your company email address that is associated with Plum. * Now, click on "Verify Email". * Now, enter the password and click on "Login" * After logging in to the Plum Storefront, click on the "Profile" button. * You can edit information from the "Basic Information" section in the dashboard. * Now, change the mobile number in the "Phone" section by clicking on "Edit Information". * Now, click "Confirm" * You will receive an OTP. Please enter the OTP on the screen. * Congratulations, you have successfully changed your mobile number in the storefront. After logging in to the Plum Storefront, you can see your reward points on top-right corner. Yes, we allow multi-lingual support in 10 different languages for the convenience of our end users. Kindly check if the number provided is correct this might happen due to network issues, please retry after some time. If you still face issues, raise a ticket in the help section at the top right corner. You can also email us at [cs@xoxoday.com](mailto:cs@xoxoday.com) or WhatsApp us at +91 080 61915050. Yes, they come with validity, the validity of the offer is limited and subject to change. Conversion rates are the conversion amount of the points that you have received. For example: 1 Point = 1 INR. Yes, "Couple" in this case denotes any two people who can visit and enjoy the experience. Yes, they are identical. You may redeem the experience and gift the same to your family & friends but the booking name has to be provided so that we can inform the service provider in whose name it has to be booked. No, once the booking is confirmed it cannot be canceled or swapped. The Reward points are usually rewarded from your Company and the same cannot be added manually by an individual. Please drop us an email at [cs@xoxoday.com](mailto:cs@xoxoday.com) with the existing mail ID and the reason for the change of mail ID. We will validate the details and update you on the request. Kindly check your spam folder if the reset link is delivered. You can click on reset password after 15 min to check if you are receiving the reset link. If you still have not received the reset link, write to [cs@xoxoday.com](mailto:cs@xoxoday.com) to help you with the query. No, Plum doesn't support cash on delivery right now. In Plum, you pay the price that is mentioned on the checkout page. There are no hidden charges present. To check the validity of xoxo points, please write to [cs@xoxoday.com](mailto:cs@xoxoday.com). Information like date of procurement, amount, quantity can be seen in the history reports on the Plum Admin platform. Yes, we allow custom changes to the company logo. The following steps can be followed to do the same. Settings >> Platform Preference >> Storefront >> Click on company logo >> Upload new image >> Click on upload. Phone support is available for administrators in case of order placement or redemption issues on a case-by-case basis. Placing orders by phone is possible through some custom configurations. The Xoxoday consumer reward platform provides complete support to track events like reward issuance and expiration. These data points can be leveraged by client-owned communication systems to trigger timely user notifications. This setup allows for seamless integration while maintaining flexibility in how end-user communication is managed. Yes, the redemption process within the Xoxoday reward solution can be configured to require two-factor authentication (2FA). Codes can be sent via SMS or email to the registered mobile number or email ID of the designated primary or secondary account holder, ensuring secure and compliant redemption processes. # Gift Box Queries Source: https://help-plum.xoxoday.com/faqs/for-end-users/gift-box-queries Find answers to frequently asked questions about gift box orders and other related queries for Plum end users. No, you do not have to create a new account on Xoxoday. You can log in to your enterprise account, and click to visit the e-store option and select Experiences and Activities you will be redirected to stores.Xoxoday.com and you can proceed to choose and book the experience. Once the Gift Box is dispatched from our end, you will be notified with the tracking details on your official mail ID to track the shipment further. You may receive either a Xoxo voucher in the Gift Box or Xoxo points to your Email ID. The gift box will be dispatched and delivered to you on or before the anniversary date. In case, the employee updates the address after the anniversary date or near the anniversary date, the gift box will be dispatched within 7-8 working days. In case of any queries, you will have to write to [cs@xoxoday.com](mailto:cs@xoxoday.com) with your Employee ID/Official Mail ID. You can also [raise a ticket](https://www.xoxoday.com/support#raise_a_ticket) or Whatsapp us at +91 080 61915050. We will revert to you with the updates on Gift Box Delivery. # Gift Vouchers Source: https://help-plum.xoxoday.com/faqs/for-end-users/gift-vouchers-faqs Find answers to frequently asked questions about redeeming the gift vouchers you've received through the Plum platform. *Get answers to commonly asked questions on Gift Vouchers* * E-gift vouchers are gift vouchers (Ex: Flipkart, Myntra, Lifestyle, etc.,) available on Xoxoday. * You can use Xoxo points to redeem the e-gift vouchers. * Each brand has a different way of redeeming itself. We suggest you go through the "Terms & Conditions" and "How to Use" sections for that particular brand that you wish to redeem and then use your XoxoPoints accordingly. * The order will be delivered to your mail ID instantly. Please check your spam box/junk/promotional/updates folders just in case. * We make it a point to deliver the vouchers instantly, however, if there is a delay from the vendor's side, it might take up to 24 to 48 hours. * If you are still unable to find the voucher, please write to [cs@xoxoday.com](mailto:cs@xoxoday.com) or click on "[Raise a ticket](https://www.xoxoday.com/support#raise_a_ticket)" on the header of this page. You can also WhatsApp us at +91 080 61915050. * Every gift voucher has a specific validity and specific time of delivery. You will be able to find the validity of the voucher and the T\&C of the voucher at the time of purchase. Please note that the validity of the voucher cannot be extended and the vouchers cannot be canceled after delivery to the recipient. * The reward email will have the redirecting link to the brand website if its online, you can use the instruction to redeem the voucher. * Every gift voucher has a specific validity and specific time of delivery. You will be able to find the validity of the voucher and the T\&C of the voucher at the time of purchase. Please note that the validity of the voucher cannot be extended and the vouchers cannot be canceled after delivery to the recipient. Please write to [cs@xoxoday.com](mailto:cs@xoxoday.com) with your official email id and company details. Xoxoday will send you a copy of the voucher code. You can also WhatsApp us at +91 8061915050 or raise a help ticket from the header of this page. * Please check the order status, if the delivered voucher details will be available in your inbox, spam, or Junk folder. * If pending - Please check the **Terms and conditions** for delivery turnaround time. * If you are still struggling to resolve this, please raise a ticket or send a mail to [cs@xoxoday.com](mailto:cs@xoxoday.com) or Whatsapp us at +91 080 61915050. Please drop us an email to [cs@xoxoday.com](mailto:cs@xoxoday.com) with the Order ID & alternate mail ID marking your official mail ID in CC. We will validate the details and re-send them to your alternate mail ID. You can also raise a ticket or Whatsapp us at +91 080 61915050. Please raise a ticket or send a mail to [cs@xoxoday.com](mailto:cs@xoxoday.com) or Whatsapp us at +91 8061915050. We will ensure that this is resolved. Yes, every gift voucher has a specific validity, please check the T\&C while placing the order. No physical vouchers are sent for any gift vouchers. These are the e-vouchers that are sent only to your provided email ID. Most of the vouchers are delivered instantly. There are a few vouchers with the defined TAT (Turn Around Time) and it is mentioned on our website under T\&C. This will help you to know the delivery TAT. Please raise a ticket or send a mail to [cs@xoxoday.com](mailto:cs@xoxoday.com) or Whatsapp us at +91 8061915050. We will update you in the next 24 hours. Currently, we do not support the feature to add xoxo code to your account and use it during the time of checkout. This is something our team is currently working on and will be getting this feature live soon. Yes, xoxo points and xoxo codes are usually valid for one year. You can view all such necessary details in the terms and condition section on the specific gift voucher page. # Performance and Reliability Source: https://help-plum.xoxoday.com/faqs/for-end-users/performance-and-reliability Find answers to frequently asked questions about Plum's platform performance and reliability from an end user's view. *Get quick answers to questions on Performance and Reliability.* Yes. Xoxoday is engineered for scalability and reliability, ensuring smooth performance even during peak events like promotions, campaigns, or seasonal reward cycles. The platform currently supports 10,000+ transactions per minute and uses auto-scaling infrastructure to handle sudden surges without affecting user experience. **How Xoxoday Manages Seasonal Spikes** * **Scalable Architecture:** Built on containerized microservices, async messaging, and caching so each component can scale independently. Stateless services scale horizontally behind AWS Application Load Balancers. Kafka-backed queues absorb "flash-sale" traffic, while Redis caching avoids database hot spots. * **High Availability & Reliability:** Active-active deployments across availability zones ensure continuity. Datastores run with replication, hourly snapshots, and disaster recovery (RTO/RPO of 120 minutes). Target uptime of 99.99%. * **Performance Under Load:** Search & audit handled by managed Elasticsearch; reporting & analytics run on Redshift—keeping transactions fast. WAF and Cloudflare bot protection secure the perimeter against promo-related bot traffic. * **Modern Scaling Practices:** Kubernetes-ready microservices with HPA/VPA pod autoscaling, cluster autoscaler, and safe rollout strategies (blue-green, canary). Rate-limiting, back-pressure, circuit breakers, and exponential backoff prevent overloads during sudden spikes. * **Operational Playbook for Peak Events:** Capacity planning and load testing ahead of campaigns. Pre-scaling hot services and pre-warming caches. Partitioned messaging and tuned concurrency to maximize throughput. Real-time observability with APM and alerting (PagerDuty) for proactive autoscaling. The Xoxoday reward payout platform is designed to scale with institutional needs, supporting high-volume reward distribution and automation. Through the self-service admin portal, administrators can upload reward recipient lists in bulk (up to 10,000 records in a single file) or send individual rewards. Automation capabilities include API-triggered sends, scheduling for time-based rewards, and rule-based workflows. Bulk delivery options via email, SMS, or shareable reward links streamline processes, making it ideal for recurring programs, cohort-based campaigns, or seasonal events. ## Reporting The Xoxoday reward payout platform is designed to scale effortlessly with growing organizations. As a cloud-hosted, enterprise-grade solution, it can handle expanding user bases and higher transaction volumes without impacting performance. The platform supports a global rewards store that can be customized to meet organizational needs, and the catalog team ensures fast onboarding of new products and categories across geographies. While adding new features or integrating with additional tools may require project-based implementation, core functions such as user onboarding, catalog scaling, and reward fulfillment operate autonomously and are built for enterprise-scale performance. The customer incentive software is designed to support flexible event tracking mechanisms. To ensure accurate export of event data to your enterprise data warehouse, our team would need further clarity on event taxonomy, expected data granularity, and data warehouse integration requirements. Xoxoday can work with your IT/data teams to configure a compliant event capture and delivery workflow based on custom needs. ## Integration Yes, transactions initiated through the Xoxoday reward marketplace can be configured to emit loyalty-related events. During the transaction creation process, you can pass an internal reference ID, which can then be included in the event payload and shared with existing or future loyalty systems. This enables a seamless connection between reward actions and loyalty event tracking, enhancing program integration. ## Reward Transaction Yes, the Xoxoday reward payout platform supports automatic logging of all reward transactions into the appropriate ledgers. Each transaction is mapped based on its type—such as wallet recharges, redemptions, or refunds—and reflected accurately in the system. If required, the platform can be configured to reflect transactions across multiple ledgers depending on financial structure or reconciliation needs. Absolutely. The Xoxoday customer incentive software offers a unified ledger view that includes all transaction types—redemptions, refunds, wallet top-ups—making reconciliation seamless. Admins can download these reports directly from the dashboard or retrieve them via API. This structure aligns with conventional MIS and reconciliation workflows, ensuring integration with existing financial protocols. # SMS and WhatsApp Message Pricing Source: https://help-plum.xoxoday.com/faqs/for-end-users/sms-and-whatsapp-message-pricing Find answers to frequently asked questions about SMS and WhatsApp message pricing for reward notifications sent via Plum. \*This document provides an overview of the per-message cost incurred by Xoxoday for sending SMS and WhatsApp notifications related to rewards delivery. The cost varies by country and channel, as outlined below.\* ## SMS Cost (per message) | **Country** | **Per SMS unit cost (USD)** | **Average Cost per message (USD)** | | -------------------- | --------------------------- | ---------------------------------- | | India | \$0.0015 | \$0.0030 | | United States | \$0.0037 | \$0.0088 | | Canada | \$0.0037 | \$0.0097 | | South Africa | \$0.0229 | \$0.0481 | | Maldives | \$0.0488 | \$0.0488 | | Turkey | \$0.0270 | \$0.0514 | | Thailand | \$0.0246 | \$0.0532 | | Qatar | \$0.0477 | \$0.0562 | | Denmark | \$0.0424 | \$0.0635 | | Bahrain | \$0.0234 | \$0.0642 | | United Kingdom | \$0.0288 | \$0.0658 | | Guatemala | \$0.0455 | \$0.0683 | | Australia | \$0.0298 | \$0.0835 | | Brazil | \$0.0303 | \$0.0835 | | South Korea | \$0.0325 | \$0.0858 | | Poland | \$0.0381 | \$0.0890 | | Puerto Rico | \$0.0418 | \$0.0977 | | Singapore | \$0.0353 | \$0.1012 | | Czech Republic | \$0.0548 | \$0.1048 | | Saudi Arabia | \$0.0553 | \$0.1112 | | Malta | \$0.0562 | \$0.1123 | | Costa Rica | \$0.0418 | \$0.1228 | | Kenya | \$0.0562 | \$0.1246 | | China | \$0.0230 | \$0.1257 | | Taiwan | \$0.0427 | \$0.1262 | | Mexico | \$0.0442 | \$0.1298 | | Portugal | \$0.0446 | \$0.1308 | | Croatia | \$0.0513 | \$0.1367 | | Greece | \$0.0548 | \$0.1385 | | Ukraine | \$0.1249 | \$0.1400 | | Sweden | \$0.0557 | \$0.1452 | | Morocco | \$0.0565 | \$0.1471 | | United Arab Emirates | \$0.0596 | \$0.1525 | | Hong Kong | \$0.0539 | \$0.1540 | | Italy | \$0.0603 | \$0.1632 | | Slovakia | \$0.0556 | \$0.1668 | | Finland | \$0.0708 | \$0.1680 | | Japan | \$0.0696 | \$0.1696 | | Switzerland | \$0.0585 | \$0.1708 | | Argentina | \$0.0606 | \$0.1769 | | Austria | \$0.0692 | \$0.1792 | | Ireland | \$0.0640 | \$0.1803 | | Romania | \$0.0625 | \$0.1811 | | Spain | \$0.0637 | \$0.1834 | | France | \$0.0659 | \$0.1841 | | Bolivia | \$0.0640 | \$0.1851 | | Netherlands | \$0.0845 | \$0.2127 | | Malaysia | \$0.0778 | \$0.2142 | | Belgium | \$0.0881 | \$0.2246 | | New Zealand | \$0.0881 | \$0.2307 | | Kuwait | \$0.0814 | \$0.2442 | | Lebanon | \$0.0814 | \$0.2442 | | Germany | \$0.0904 | \$0.2514 | | Israel | \$0.0947 | \$0.2539 | | Pakistan | \$0.1559 | \$0.2560 | | Hungary | \$0.0873 | \$0.2600 | | Bulgaria | \$0.1158 | \$0.2702 | | Nepal | \$0.1133 | \$0.2833 | | Mauritius | \$0.1302 | \$0.2864 | | Oman | \$0.0955 | \$0.2864 | | Egypt | \$0.1040 | \$0.3021 | | Myanmar | \$0.1009 | \$0.3027 | | Vietnam | \$0.1102 | \$0.3202 | | Sri Lanka | \$0.1795 | \$0.3508 | | Jordan | \$0.1337 | \$0.3674 | | Philippines | \$0.1328 | \$0.3941 | | Bangladesh | \$0.1729 | \$0.4593 | | Indonesia | \$0.2490 | \$0.5452 | **Notes:** * SMS costs represent the **per-unit cost** and Average cost per message charged to Xoxoday. * These rates may vary slightly depending on carrier and message length. ## WhatsApp cost (per message) | **Country** | **WhatsApp Cost USD** | | -------------------- | --------------------- | | India | \$0.0020 | | United States | \$0.0116 | | Canada | \$0.0116 | | South Africa | \$0.0068 | | Maldives | \$0.0350 | | Turkey | \$0.0075 | | Thailand | \$0.0350 | | Qatar | \$0.0151 | | Denmark | \$0.0312 | | Bahrain | \$0.0151 | | United Kingdom | \$0.0296 | | Guatemala | \$0.0365 | | Australia | \$0.0350 | | Brazil | \$0.0261 | | South Korea | \$0.0350 | | Poland | \$0.0457 | | Puerto Rico | \$0.0365 | | Singapore | \$0.0350 | | Czech Republic | \$0.0457 | | Saudi Arabia | \$0.0100 | | Malta | \$0.0312 | | Costa Rica | \$0.0365 | | Kenya | \$0.0123 | | China | \$0.0350 | | Taiwan | \$0.0350 | | Mexico | \$0.0200 | | Portugal | \$0.0312 | | Croatia | \$0.0457 | | Greece | \$0.0312 | | Ukraine | \$0.0457 | | Sweden | \$0.0312 | | Morocco | \$0.0123 | | United Arab Emirates | \$0.0134 | | Hong Kong | \$0.0350 | | Italy | \$0.0311 | | Slovakia | \$0.0457 | | Finland | \$0.0312 | | Japan | \$0.0350 | | Switzerland | \$0.0312 | | Argentina | \$0.0303 | | Austria | \$0.0312 | | Ireland | \$0.0312 | | Romania | \$0.0457 | | Spain | \$0.0283 | | France | \$0.0564 | | Bolivia | \$0.0365 | | Netherlands | \$0.0587 | | Malaysia | \$0.0120 | | Belgium | \$0.0312 | | New Zealand | \$0.0350 | | Kuwait | \$0.0151 | | Lebanon | \$0.0151 | | Germany | \$0.0627 | | Israel | \$0.0143 | | Pakistan | \$0.0051 | | Hungary | \$0.0457 | | Bulgaria | \$0.0457 | | Nepal | \$0.0350 | | Mauritius | \$0.0123 | | Oman | \$0.0151 | | Egypt | \$0.0050 | | Myanmar | \$0.0350 | | Vietnam | \$0.0350 | | Sri Lanka | \$0.0350 | | Jordan | \$0.0151 | | Philippines | \$0.0350 | | Bangladesh | \$0.0350 | | Indonesia | \$0.0249 | **Notes:** * WhatsApp cost is **per session message**, billed based on conversation category (utility, marketing, authentication). * Prices are calculated based on Meta's Business API rates and Xoxoday's provider markup. * The cost reflects **average per-message delivery** charges. # For Merchants Source: https://help-plum.xoxoday.com/faqs/offer-management/faqs-offer-management-for-merchants Find answers to frequently asked questions about using Plum's Offers Management portal as a registered merchant. *Get quick answers to questions on Merchant platform* ## Getting Started The Xoxoday offer management solution is an end-to-end digital platform that allows banks, payment providers, and reward platforms to launch, manage, and track merchant-funded offers seamlessly — all in one place. Designed for scalability and speed, it enables businesses to deliver personalised, data-driven promotions to their customers without operational complexity. Built with enterprise-grade architecture, the platform simplifies offer creation, automates validation, and improves customer engagement through real-time analytics and omnichannel distribution. Key highlights of the Xoxoday offer management solution include: * **Comprehensive offer creation:** Merchants can create digital offers, vouchers, and discounts across categories like fixed-value, percentage-based, and product-specific promotions. * **Omnichannel distribution:** Publish and share offers across websites, apps, emails, SMS, and social media with personalised URLs and QR codes. * **Merchant & customer management:** Simplifies onboarding, approval workflows, and redemptions with secure role-based access and store-level PIN validation. * **Smart analytics & reporting:** Access real-time dashboards to monitor redemptions, customer behaviour, and campaign ROI to make data-driven decisions. * **Flexible deployment:** Available as a white-labelled, mobile-responsive solution supporting multi-language and multi-currency environments across 175+ countries. * **Global scalability & security:** With 250+ integrations and enterprise-grade privacy settings, it guarantees seamless compatibility and compliance across diverse markets. Overall, the Xoxoday offer management solution streamlines how organisations deliver and measure promotional campaigns — reducing go-to-market time from weeks to minutes while driving higher engagement, conversions, and customer loyalty. ## Campaign & Offer Management Yes, administrators can create test cohorts of users who receive the campaign offers before the public launch. This allows thorough validation of configurations, rules, and notifications. The pre-live testing environment helps ensure that everything functions smoothly once the campaign goes live, all within the Xoxoday platform for merchant funded offers. Yes, the platform provides robust support for dynamic, event-based notifications. Campaign managers can personalize messages using variables like user name, voucher code, or expiry date. These messages can be sent via SMS, push notifications, or in-app alerts for events like reward claim confirmations, upcoming voucher expirations, or system-level updates. This ensures real-time, relevant communication tailored to each user through Xoxoday's merchant campaign management software. Yes. The platform for merchant funded offers by Xoxoday allows users to fund one or multiple campaigns at the same time. Users can allocate funds to each campaign individually based on their preferences and specify the amount for each. Yes. The merchant payout automation software by Xoxoday provides wallet debit APIs that allow users to initiate fund withdrawals to a nominated bank account. All debit transactions are recorded in the wallet for reconciliation and transparency. Yes. Message template creation is supported, allowing campaign owners to standardize communications. However, prioritizing the delivery queue of messages is not currently available as a built-in feature. If required, this functionality can be developed through custom configuration on the Xoxoday platform for merchant funded offers. Yes. The solution for merchant offer creation by Xoxoday enables businesses to apply pricing models such as subscription, time-based, or usage-based at the campaign or contract level. Once pricing definitions and dependencies are finalized, the system will be configured to support these billing structures. Yes. The platform for merchant funded offers by Xoxoday allows users to build highly customized campaigns. Features include defining campaign periods, setting up recurring schedules (e.g., every day or every few hours), restricting access to exclusive customer segments, targeting specific SKUs or branches, and enabling task-based offer logic. Yes. Grouping campaigns to assign multiple prizes with different claim limits and eligibility rules is supported. Merchants can fully customize their offer templates to align with their brand's visual identity and campaign objectives. The platform enables selection from diverse coupon styles and layouts, allowing businesses to integrate their logo, brand colors, and messaging. It supports multiple offer types — such as fixed-value discounts, percentage-based offers, product-specific promotions, and free-format vouchers — ensuring every campaign looks and feels unique. These configurations can be adjusted instantly from the admin dashboard for greater creative flexibility. The Xoxoday solution enables seamless omnichannel campaign distribution through websites, mobile apps, email, SMS, and social media. With just a few clicks, merchants can launch live campaigns and share personalized URLs or QR codes generated automatically by the system. These features make it easy for customers to discover, claim, and redeem offers both online and in-store, driving engagement and accelerating campaign visibility. The Xoxoday merchant-funded offers platform allows businesses to share promotions directly with their existing customer base and publish them across partner ecosystems to reach new audiences. Once published, offers begin generating high-quality, engaged traffic within hours. With proven mechanics that enhance conversion rates, merchants can leverage audience segmentation and targeting capabilities to maximize visibility and customer acquisition at scale. ## Gift Voucher & Promo Codes The Xoxoday platform for merchant funded offers supports a wide range of use cases for digital gift voucher creation and management. These include: * Creating electronic gift cards for marketplaces and campaigns * Uploading existing gift card voucher codes for use in promotions * Digitalizing physical gift cards or vouchers * Creating new digital gift cards based on inputs from previously issued ones * Configuring flexible validity periods, including rounding validity to month-end * Generating gift voucher codes and integrating with SMS/Email gateways to communicate these codes to customers * Enabling self-upload of voucher code lists * System-generated gift vouchers with preset denominations and code stock * Distributing vouchers via a white-labeled marketplace * Customizing marketplace selections and defining discounts * Sending vouchers via email campaigns * Defining campaign details and customer segments using customer data from retailers The Xoxoday merchant reward program software facilitates bulk generation of gift voucher codes with user-defined denominations, code quantities, and downloadable reports. Additional capabilities include: * Blocking and unblocking gift voucher codes * Extending gift voucher validity * Viewing and editing gift card configurations * Downloading the list of voucher codes * Publishing or unpublishing gift cards directly within the platform Yes, the platform allows users to distribute vouchers in multiple ways: as single items, in bulk batches, or automatically triggered by specific events. This flexibility enables targeted and timely engagement across different customer segments using Xoxoday merchant campaign management software. Yes, the Xoxoday platform for merchant reward programs supports both static and dynamic promo code configurations. Campaign creators can issue common codes for mass distribution or auto-generate unique, single-use codes. Promo codes can be configured to offer fixed discounts, percentage discounts, or product/SKU-specific offers. Additionally, users can apply these codes across specific stores, merchants, or audience groups with customized redemption rules. The software for merchant reward programs enables merchants to list and sell vouchers from various categories directly on a digital rewards marketplace. Merchants gain access to a wide customer base and can promote their offerings through targeted campaigns. The solution also supports localized redemption, omnichannel voucher delivery, and real-time performance tracking, making it a scalable tool for merchant acquisition and engagement. The solution for merchant offer creation includes a robust inventory management module. Merchants can efficiently organize vouchers by categories (e.g., food, fashion), voucher types (e.g., digital, physical), and industries. This structured view enhances visibility and control, allowing merchants to optimize voucher availability and marketing efforts. Yes, the merchant payout automation software provides end-to-end order management capabilities. Merchants can track every stage of an order—whether it's pending, cancelled, or completed—through a centralized dashboard. This helps streamline operations, reduce manual overhead, and improve customer satisfaction through timely order handling. The software for merchant campaigns offers advanced analytics tools that let merchants monitor transaction orders in real time. They can access key metrics such as sales volume, redemption rates, and campaign performance. This enables data-driven decisions, proactive stock adjustments, and strategic optimization of voucher promotions. ## Customer Engagement & Loyalty The platform includes built-in customer engagement and loyalty tools to help merchants retain and grow their customer base. These include reward points, cashback campaigns, personalized offer targeting, referral programs, and automated notifications to keep customers engaged at every touchpoint. Merchants can also run segmented campaigns and track performance in real time to optimize retention strategies. ## Merchant Onboarding & Management Yes, internal teams can easily onboard merchants by granting them access through the admin console. The system supports role-based access control, allowing internal users to define merchant permissions, assign contract terms, and manage activation workflows seamlessly. Yes. The Xoxoday solution for merchant offer creation enables businesses to build and manage a vast merchant ecosystem across verticals such as: * Travel, retail, wellness, healthcare, dining, and lifestyle * Dynamic onboarding of merchants and partners * Configurable discount structures tailored to different segments * Customer access to exclusive benefits and reward privileges This multi-segment approach enhances customer engagement and drives brand affinity while ensuring compliance with data privacy and security protocols. ## Financial & Wallet Management Yes. The platform for merchant funded offers by Xoxoday supports both prefunded and postpaid charging models at the campaign or contract level. Users can define the applicable charging method, and the invoicing and settlement process will be configured accordingly. Yes. The platform offers automated invoice generation and settlement capabilities. Users can view campaign-level billing details, download invoices, and settle payments through integrated payment gateways or wallet balances. The Xoxoday wallet solution for merchant campaigns integrates with prefunding and invoicing systems to support multi-bank funding. Merchants can: * Nominate local, digital, or international banks to fund end-customer wallets. * Use third-party payment gateway integration to manage prefunding workflows. Yes. Through its third-party payment gateway integration, Xoxoday enables users to directly fund a customer wallet using their nominated bank account. This ensures seamless wallet top-ups while maintaining complete traceability and security across all funding actions. ## Reports and Analytics The Xoxoday solution provides advanced reporting and analytics tools that deliver deep insights into campaign performance and return on investment. Merchants can monitor key metrics such as clicks, views, redemptions, and customer interactions in real time. The platform highlights friction points across the customer journey, enabling data-driven optimizations for higher engagement and better conversion rates. Additionally, dynamic dashboards and exportable reports make it easy to evaluate offer success and fine-tune future campaigns. # For Admins Source: https://help-plum.xoxoday.com/faqs/offer-management/offer-management-for-admins-faqs Find answers to frequently asked questions about managing Plum's Offers Management portal as an account admin. *Get quick answers to questions on Loopr Admin platform* ## Overview The Xoxoday offer management solution is a comprehensive platform that helps businesses design, manage, and optimize their merchant-funded reward and offer programs. It supports a wide range of campaign types — from transactional incentives to behavioral rewards — ensuring flexibility and scalability. Key capabilities include: * **Flexible offer creation:** Design diverse reward programs aligned with your business objectives. * **Behavioral targeting:** Encourage specific customer actions through personalized, data-driven offers. * **Advanced analytics:** Gain full visibility into KPIs, ROI, and customer engagement metrics. * **Continuous optimization:** Identify performance trends and make real-time adjustments to enhance outcomes. * **Scalable infrastructure:** Manage multiple campaigns, merchants, and customer segments seamlessly across geographies. ## Campaign & Platform Management Yes, Xoxoday's merchant offer automation platform supports role-based access control, including a Maker role. Users with this role can: * Create and configure new campaigns * Define budgets and allocate funds * Generate and assign promo codes All Maker actions require approval from an assigned Approver role before execution. Yes, users can fully customize error messages specific to each campaign. This includes setting messaging for different failure scenarios such as invalid promo codes, expired offers, or redemption issues. Personalized error handling improves clarity and user experience across campaigns managed through Xoxoday merchant offer automation software. Yes. The platform provides a Super Admin role with full access and control over all modules, user roles, campaigns, and configurations within the account. Yes. User access can be restricted or customized based on company or group affiliation, ensuring proper governance and data visibility control. The platform stands out for its end-to-end campaign and offer management capabilities, real-time reporting, seamless merchant onboarding, multi-segment support, automated communication, and advanced rule configuration. It enables businesses to build, scale, and optimize their offer ecosystem efficiently while ensuring compliance and data security. Yes, Xoxoday's merchant campaign management software enables operations teams to: * View voucher and promo code status * Perform batch voucher recovery and extend expiry dates * Generate additional promo codes for ongoing campaigns * Create test codes for UAT or internal QA purposes ## Integration The Xoxoday merchant-funded offers platform enables smooth integration between brands, merchants, and partner ecosystems, making it simple to publish and manage offers across multiple touchpoints. Integration highlights: * **Unified merchant portal:** Merchants can easily connect with brands to share discounts, promotions, and exclusive deals. * **Automated publishing:** Offers appear instantly across connected digital storefronts or marketplaces, expanding merchant visibility. * **SME enablement:** Simplifies onboarding for small and medium businesses, helping them reach customers more efficiently. * **Seamless synchronization:** All offers remain up to date across channels, ensuring a consistent customer experience. * **Enhanced reach:** Strengthens partnerships and boosts engagement through collaborative reward ecosystems. ## Reports Xoxoday's platform for merchant funded offers provides users with the ability to view, generate, and export both transaction-level and summary reports through the Reports module. The system supports: * **Disbursement Reports:** Track the issuance of vouchers across customers. * **Usage Reports:** Monitor redemptions, claim trends, and offer performance in real time. * **Error Logs:** View logs such as failed shares, offer expiration, and redemption failures. * **Filtering & Drill-Down:** Apply filters like date range, campaign, or store-level views for granular insights. * **Export Options:** Reports can be downloaded in CSV or Excel formats for offline analysis or external integration. # For End Users Source: https://help-plum.xoxoday.com/faqs/offer-management/offer-management-for-customers-faqs Find answers to frequently asked questions about browsing and redeeming offers as a customer on the Plum platform. *Get quick answers for commonly asked questions on Loopr customer portal* Yes, the platform supports multi-voucher payments, enabling customers to combine multiple vouchers in a single transaction. They can also redeem the entire transaction amount using vouchers alone, providing a seamless and flexible payment experience powered by Xoxoday's merchant payout automation software. The platform for merchant funded offers provides users with an intuitive marketplace dashboard. Through this unified interface, users can browse all available vouchers, search specific vouchers by name or category, and access essential details like denominations, redemption instructions, and expiry dates. Users can also review their purchase history and monitor voucher delivery status, ensuring full transparency and control over their transactions. # Privacy and Security Source: https://help-plum.xoxoday.com/faqs/security-compliance/privacy-and-security Find answers to frequently asked questions about Plum's privacy and security practices for protecting user data. *Get quick answers to your questions relating to Privacy and Security on Xoxoday Plum.* ## Data The Xoxoday rewards, incentives, and payout platform ensures secure, compliant, and globally accessible data hosting infrastructure through Amazon Web Services (AWS). Key aspects of data storage include: * **Primary Data Centers in the United States:** All customer data is stored on AWS cloud infrastructure, with primary hosting facilities located within the United States. * **High Availability and Redundancy:** The platform leverages AWS's geographically distributed data centers to ensure business continuity, high availability, and disaster recovery. * **ISO 27001 and SOC 2 Compliance:** All hosting infrastructure complies with globally recognized data protection and security standards. * **Data Encryption:** Customer data is encrypted both in transit (via TLS 1.2) and at rest (via AES-256 encryption), ensuring maximum security. * **Optional Regional Hosting:** For enterprise clients, data can also be hosted in other jurisdictions such as Singapore or the European Union, based on compliance and data residency requirements. This architecture ensures that customer data is protected by rigorous physical, administrative, and technical safeguards as outlined by AWS. Learn more: [https://aws.amazon.com/trust-center/data-center/our-controls/](https://aws.amazon.com/trust-center/data-center/our-controls/) ## Data, Policy and Privacy Xoxoday follows a comprehensive, enterprise-grade information security framework to fully protect customer and end-user data. Core data security practices: * **Certifications:** ISO 27001, SOC 2 Type II, GDPR-compliant * **Encryption:** AES-256 for data at rest; TLS 1.2+ for data in transit * **Access Management:** Role-based access control (RBAC), Multi-factor authentication (MFA), Least privilege principle, Regular access reviews and logs * **Cloud Infrastructure:** Hosted on AWS with VPC isolation and auto-scaling; Monitored using real-time security event tracking and anomaly detection * **Data Retention & Deletion:** Aligned with client contracts, GDPR, and PIPL retention requirements * **Audits & Testing:** Periodic internal audits, Annual third-party vulnerability assessments, Penetration testing and risk remediation workflows * **Incident Management:** Structured incident response plan with SLA-bound notification and containment steps * Ensures high availability, confidentiality, and integrity of data across all geographies and client use cases All proprietary rights, including customizations built within the Xoxoday gift card marketplace or customer incentive software framework, remain with the platform provider. Clients may use these customizations as part of their subscription but do not acquire ownership of the platform's source code or IP. The Xoxoday customer rewards platform keeps comprehensive logs of all payments, user actions, and redemptions, ensuring audit readiness, transparency, and compliance. Authorized administrators can access these records anytime via the reporting dashboard. Xoxoday's privacy notice is publicly accessible via its official website and outlines its full commitment to data privacy and user rights. Privacy notice includes: * The types of personal data collected across services. * Purposes for data processing (e.g., reward fulfillment, communication, analytics). * Legal basis under GDPR, CCPA, and other applicable frameworks. * User rights and instructions for submitting access or deletion requests. * Contact details for privacy and data protection queries. The privacy policy can be accessed on [https://www.xoxoday.com/security](https://www.xoxoday.com/security) ## AI Data Security Yes, the Xoxoday rewards, incentives, and payout platform is designed with enterprise-grade data governance and compliance frameworks that support the removal or de-identification of sensitive data from AI models and systems, upon valid customer requests. Below is a breakdown by product. * **Xoxoday Rewards, Incentives, and Payout Platform:** Data deletion upon request: The platform supports data subject rights under regulations like GDPR and CCPA, including the right to erasure ("right to be forgotten"), which applies to both structured and unstructured data—including inputs processed by AI systems. Model behavior isolation: LLM-based AI features do not persist user-specific training data beyond a session scope. Multi-tenant architecture ensures each client's data is logically segregated with encryption keys per tenant. * **Employee Engagement Platform:** PII sanitization via content moderation: Em's AI scans and blocks the ingestion of personally identifiable information before it's processed by internal models. Consent-based AI processing allows user or admin-led revocation of processed data. Data control APIs allow admins to raise requests to remove engagement logs and user-generated content used in AI training. * **Sales Incentives Platform:** Custom dashboards and reports built through natural language queries do not permanently train AI models on client data. These are temporarily cached and can be purged or redacted based on user role or admin request. * **Loyalty Platform:** All customer data used in AI-driven segmentation or CLTV prediction models can be excluded or deleted upon request, thanks to configurable segmentation rules and data access policies. * **Merchant Offer Platform:** AI modules that use personalization logic operate within secure, tenant-specific boundaries. Sensitive user or partner data involved in offer targeting can be excluded or wiped via admin-level operations or customer success support. Xoxoday uses user input data to enhance feature performance and personalization, not to train generalized or foundational AI models. * **Purpose:** Data is leveraged for smart recommendations, sentiment analysis, predictive analytics, and engagement insights. * **Patterns used:** Recognition activity, reward redemptions, and survey feedback inform contextual outputs. * **Personalization focus:** Inputs are applied to improve user-specific experiences within the platform. * **Examples:** Skill mapping from recognition messages, reward suggestions based on behavior, and predictive trends for retention and engagement. Yes. The platform provides real-time analytics and reporting with detailed user activity logs. * AI Co-pilot tracks active users, pending nominations, award givers/receivers, budget utilization, and engagement reports * Logs are time-bound and actionable, helping admins monitor AI usage over time * Supports auditability and transparency, with timestamped logs available for compliance needs Yes. Xoxoday's AI solutions follow responsible AI practices aligned with the NIST AI Risk Management Framework. * Safety checks are built into AI features for content moderation, fraud detection, and decision transparency * Technical safeguards include anomaly detection, rule-based overrides, and configurable escalation protocols * Procedural controls allow workflows to be flagged, paused, or escalated for manual oversight * AI outputs are designed for explainability, ensuring interpretability and auditability Yes. The Xoxoday rewards, incentives, and payout platform is capable of processing Protected Health Information (PHI) in compliance with the Health Insurance Portability and Accountability Act (HIPAA) when required by the client's use case. The platform's design, infrastructure, and operational processes incorporate the necessary safeguards to protect sensitive healthcare data. This includes: * **HIPAA compliance framework** – implemented controls and processes aligned with HIPAA's Privacy, Security, and Breach Notification Rules. * **Data encryption** – PHI is encrypted both in transit (using TLS protocols) and at rest (using AES-256 encryption) to prevent unauthorized access. * **Access control measures** – role-based access controls (RBAC) and multi-factor authentication (MFA) restrict PHI access to authorized personnel only. * **Audit logging and monitoring** – comprehensive logging of system access, data interactions, and administrative actions for accountability and traceability. * **Secure hosting environment** – cloud infrastructure hosted on ISO 27001 and SOC 2 Type 2 certified data centers with strong physical and network security controls. * **Data segregation** – multi-tenant architecture with logical separation of client data, ensuring PHI is isolated and protected from other tenants. * **Incident response protocols** – documented procedures to identify, contain, and report any potential data breaches in compliance with HIPAA requirements. * **Business Associate Agreement (BAA)** – available for clients in the healthcare sector who require contractual assurance of HIPAA compliance. ## System Requirement The system is designed to comply with all regulatory recordkeeping and reporting standards applicable to vendors in the rewards and incentive space. It incorporates robust mechanisms to ensure accurate documentation, timely reporting, and data traceability. Whether it's audit trails, transaction logs, or compliance records, the platform maintains structured data practices that fulfill regulatory obligations. If there are specific regulatory needs, the customer incentive software team is open to customizing workflows or discussing tailored solutions. The platform upholds high standards of data confidentiality and privacy for research participants. It utilizes end-to-end encryption, RBAC, anonymization techniques, and audit logs to ensure all sensitive data, including that of human subjects, is secured and de-identified where required. By applying secure design principles and adhering to data protection frameworks, the solution guarantees compliance with confidentiality requirements for human research data. The platform is not required to comply with PCI-DSS standards, as it does not collect, store, or process sensitive payment card data. Instead, all reward transactions are securely managed through the Xoxoday reward payout platform using industry-standard encryption and compliance protocols to ensure safety and integrity. Yes, Xoxoday is built for scalability and is capable of handling large user bases and high transaction volumes. The system currently supports over 10,000 transactions per minute and includes auto-scaling infrastructure to handle demand surges during promotions, campaigns, or seasonal reward cycles. Xoxoday's Platforms are engineered for horizontal scale and seasonal spikes in traffic. The core architecture uses containerized microservices, async messaging, and caching so components can scale independently and absorb spikes without blocking user flows. High-availability is built in with active-active deployment across availability zones, fronted by an AWS Application Load Balancer, plus managed Kafka, Redis, and Elasticsearch to decouple workloads and keep latency low during traffic surges. Datastores run with replication, snapshots, and DR, and the estate is continuously watched via APM/monitoring with PagerDuty alerts; target uptime is 99.99% with RTO/RPO of 120 minutes. How we handle Seasonal Spikes in Traffic: * Stateless services scale out behind the ALB; critical data is cached to avoid database hot spots. * Kafka-backed queues smooth "flash-sale" style traffic; consumers scale horizontally to drain backlogs. * Search & audit workloads are offloaded to managed Elasticsearch; analytics run on Redshift so reporting never competes with transactions. * WAF/Bot protection (Cloudflare) shields the perimeter, important during promos when bot traffic rises. **Kubernetes & modern scaling practices:** Our microservices are containerized and orchestrator-ready; for K8s-based deployments we apply industry patterns such as HPA/VPA for pod autoscaling, cluster autoscaler, Pod Disruption Budgets, readiness/liveness probes, and rolling/canary or blue-green rollouts. We also employ rate-limiting, back-pressure, circuit breakers, and exponential backoff to prevent thundering-herd effects. **Operational playbook for peak events:** Capacity planning & load tests ahead of campaigns; pre-scaling hot services and pre-warming caches. Messaging partitioning & consumer concurrency tuning to raise throughput without impacting latency. Read replicas/replication on primary databases; hourly snapshots and cross-AZ DR safeguard data while allowing scale. Real-time observability with APM + alerting to spot hotspots early and autoscale safely. ## Legal The Xoxoday gift card solution can support high-value physical Visa cards, but denomination limits vary by issuing partner and region. We recommend confirming availability and legal compliance during onboarding for denominations exceeding \$1,000. ## Security and Compliance Xoxoday recognizes the importance of compliance in operating across multiple states, countries, and regulatory jurisdictions. Our approach combines governance, continuous monitoring, and proactive adaptation to ensure our Platforms remain compliant for all customers and users, regardless of their location. * **Dedicated Compliance & Legal Teams:** We have specialized compliance, data privacy, and legal teams who continuously monitor state, federal, and international regulations affecting employment, data privacy, rewards, taxation, and payments. Regulations such as GDPR, CCPA/CPRA, HIPAA (where applicable), SOC 2, and ISO 27001 are embedded into our global frameworks. * **Regulatory Intelligence & Partnerships:** Xoxoday leverages partnerships with audit firms, legal advisors, and compliance consultants in different geographies to stay ahead of state-specific regulatory updates. We subscribe to regulatory intelligence feeds and compliance monitoring services that track multi-state taxation, digital rewards governance, data residency, and employment-related laws. * **Product Flexibility for Multi-State Needs:** Our Platforms allow localization of program rules, including tax handling, redemption catalogs, accrual structures, payout modes, and communication templates, ensuring adaptability to state or region-specific mandates. For payments and financial products, we integrate with licensed payment partners who are compliant with state money movement and tax reporting laws. * **Global Best Practices in Data Privacy and Security Compliance:** We adopt Privacy by Design and Security by Default principles across all products. Frequent third-party audits, penetration testing, and certification renewals validate compliance against changing standards. Our multi-region hosting options (e.g., USA, Singapore, EU) ensure adherence to data residency and sovereignty requirements. * **Customer Communication & Assurance:** Any regulatory changes impacting product usage are communicated through release notes, compliance updates, and customer success reviews. Clients benefit from configurable compliance controls such as audit trails, retention policies, and access management to meet their own internal governance needs. By combining dedicated compliance governance, expert partnerships, flexible platform configurations, and global data privacy and security best practices, Xoxoday ensures that multi-state and multi-location users are supported in a compliant, secure, and future-ready manner. ## Security Requirement Yes. The platform securely manages confidential and sensitive business data as part of its operations. Data types handled include: * Employee and customer PII (names, emails, contact details) * Transaction and redemption history * Financial identifiers for payouts and prepaid cards Security and compliance measures include: * Enterprise-grade encryption for data at rest and in transit * Role-based access control (RBAC) * Secure API integrations with audit logs * Compliance with GDPR and relevant local data privacy laws * Regular third-party audits to prevent unauthorized access and mitigate risks ## Technical Requirement No. All Xoxoday solutions are cloud-based and accessible via secure HTTPS connections, without requiring clients to host virtual appliances or modify firewall rules. * Global rewards marketplace & payout platform: Fully cloud-hosted, with optional on-premise deployment available for highly regulated environments. * Employee engagement & recognition platform: Delivered as SaaS, accessible via browsers and mobile apps with no additional network configuration. * Sales commission & incentive management system: Cloud-native, integrating securely with CRM and HRMS platforms via APIs. * Customer loyalty management solution: Entirely online, eliminating the need for local hosting or infrastructure. * Merchant-funded offers & promotion engine: Cloud-based with secure API access for seamless partner integrations. Yes, but only as required to deliver contracted services, with strict role-based access controls and full GDPR compliance. * Global rewards marketplace & payout platform: Uses recipient names, emails, and transaction data solely to process and deliver rewards. * Employee engagement & recognition platform: Stores and processes employee identifiers, email addresses, and engagement activity to support recognition and surveys. * Sales commission & incentive management system: Handles sales team identifiers, performance metrics, and payout details to calculate and distribute incentives. * Customer loyalty management solution: Manages loyalty member data including profiles, points balances, and redemption history. * Merchant-funded offers & promotion engine: Maintains merchant details, customer segment data, and redemption records for campaign management. Yes. All Xoxoday solutions operate under a corporate-level Business Continuity Plan owned by senior management and tested annually. * Global rewards marketplace and payout platform: Includes continuity procedures for reward delivery, catalog access, and payment processing. * Employee engagement and recognition platform: Ensures uninterrupted engagement, recognition, and survey operations during disruptions. * Sales commission and incentive management system: Maintains continuous access to commission tracking, incentive calculations, and reporting. * Customer loyalty management solution: Keeps loyalty enrolment, accrual, and redemption systems available in crisis scenarios. * Merchant-funded offers and promotion engine: Provides continuity for merchant offer creation, validation, and redemption tracking during outages. Yes. Xoxoday has a corporate Disaster Recovery Plan owned by the Information Security team and tested regularly to meet RTO/RPO objectives. * Global rewards marketplace and payout platform: Covers restoration of transaction processing, catalog services, and payment integrations. * Employee engagement and recognition platform: Ensures rapid recovery of recognition data, engagement analytics, and survey records. * Sales commission and incentive management system: Restores commission plans, sales performance data, and payout schedules promptly after incidents. * Customer loyalty management solution: Recovers loyalty member accounts, points balances, and redemption records with minimal downtime. * Merchant-funded offers and promotion engine: Brings back merchant campaign data, offer rules, and redemption history in line with recovery targets. ## Record Creation Yes. The Xoxoday gift card solution maintains detailed records of credit card issuance, including information on both issuers and recipients. These records are encrypted and accessible only by authorized personnel, ensuring complete confidentiality of participant data while supporting compliance and audit requirements. Yes, the Xoxoday customer rewards platform enables administrators to flag studies or projects as exempt from collecting personally identifiable information (PII), such as names or SSNs. These exemption flags are configurable based on user roles, allowing secure, role-specific access while ensuring compliance with research privacy protocols and institutional review board (IRB) requirements. The Xoxoday reward payout platform supports the secure upload and attachment of IRS Form W-9 during the input of subject information. This ensures streamlined compliance with U.S. tax documentation requirements, particularly for human subject payments that require IRS reporting, such as 1099 filings. Yes, the Xoxoday survey rewards platform includes geo-tagging capabilities that allow administrators to classify and flag studies based on their geographic scope. This supports accurate reporting, compliance, and operational tracking for global studies conducted outside the U.S. The platform is designed to support selective externalization of back-office functions via APIs. Transaction data necessary for reporting and reconciliation can be programmatically accessed using secure APIs provided by the Xoxoday reward payout platform. Yes. Xoxoday supports on-premise deployments and can host the reward portal within the client's internal network. This deployment option ensures full control over infrastructure, data governance, and security settings. Our implementation team will work closely with your IT and security stakeholders to align with existing policies and protocols, while ensuring seamless integration and compliance throughout the deployment process. Yes. Xoxoday plays a direct role in mission-critical engagement and incentive workflows for enterprises, SMBs, and global organizations: * Powers customer loyalty programs, employee recognition programs, sales and channel incentives, and instant payout delivery, all of which are essential for business continuity. * Delivers time-sensitive reward redemptions for events like sales milestones, festive gifting, employee anniversaries, and customer retention campaigns. * Supports multi-region and multi-currency operations, ensuring that global incentive programs remain uninterrupted. * Operates on high-availability infrastructure with redundancy, minimizing downtime risk. * Without Xoxoday, businesses would face disruptions in engagement programs, potentially leading to reduced retention, sales performance, and customer satisfaction. No. Xoxoday does not process, store, or transmit credit card information. It operates as a digital rewards and incentives engine and does not serve as a payment gateway or financial processing tool. ## Xoxolink Xoxoday adheres to all major global regulatory standards. It maintains comprehensive audit trails, logs, and exportable reports for every transaction. Custom reports can be scheduled or generated on-demand to support compliance with tax, financial, or internal audit policies. # Account Verification Source: https://help-plum.xoxoday.com/getting-started/for-admins/account-verification/account-verification-overview *In this article, you'll see the information you need to complete the KYB verification step to kick start rewarding journey with Xoxoday.* *Everything you need to complete the KYB verification step and kick start your rewarding journey with Xoxoday.* *Everything you need to complete the KYB verification step and kick start your rewarding journey with Xoxoday.* ## What is Account Verification? Xoxoday, as a Fintech company, verifies businesses and gift card usage to comply with regulations. Plum's account verification ensures we understand your business and intended use case to provide tailored assistance. *** ## Verification Process Provide the necessary business details via the Plum Admin Panel. Our compliance team reviews your submission within **2 working days** and may request additional information if needed. Once all details are gathered, the compliance team classifies your use case. Upon use case determination, the catalog team maps available products for immediate redemption. Expect an acknowledgement email within **2 hours** of submission. Any additional information needed will be requested via email. *** ## Use Case Classification Once verified, your account is classified into one of the following use cases, which determines the catalog products available to you: * **Regular Business** — Can procure vouchers from the catalog, excluding Amazon and Open Loop cards. Contact your Account Executive or [cs@xoxoday.com](mailto:cs@xoxoday.com) to request access to these cards. * **Resellers (B2B & B2C)** — Can purchase closed-loop cards, except for brands explicitly prohibiting resellers and Amazon/Open-Loop cards. * **Crypto** — Can only procure closed-loop cards and brands that permit crypto use cases. *** ## Escalation Matrix For anything related to account verification, reach out through the appropriate level: | Level | Designation | Email | | ------- | --------------------- | ------------------------------------------------- | | Level 1 | Customer Success Team | [cs@xoxoday.com](mailto:cs@xoxoday.com) | | Level 2 | Implementation Lead | [damodar@xoxoday.com](mailto:damodar@xoxoday.com) | | Level 3 | Customer Success Head | [kailash@xoxoday.com](mailto:kailash@xoxoday.com) | *** # Submitting Brand KYC Source: https://help-plum.xoxoday.com/getting-started/for-admins/account-verification/submitting-brand-kyc-amazon-india-and-mastercard Some brands and reward options require additional **KYC** or **KYB (Know Your Business)** verification before you can issue rewards through Plum. The verification required depends on the reward you want to issue: | Verification | Applicable rewards | | :------------------------------------------- | :------------------------------------------------------------------------------- | | **Amazon India Brand KYC** | Amazon India gift cards | | **Amazon Global Brand KYC** | Amazon gift cards in applicable international markets | | **Prepaid Instruments & Digital Wallet KYB** | Visa/Mastercard prepaid instruments, PayPal, Venmo, and other applicable rewards | ## Access the Verification Form 1. Sign in to your **Plum Admin Portal**. 2. Go to **Admins**. 3. Click the **Settings** icon. 4. Select **Verifications**. 5. Select the verification applicable to the reward you want to issue. Screenshot 2026 09 05 At 8 39 16 PM Before you begin, make sure you have the required company information and supporting documents ready. *** # Amazon India Brand KYC Amazon requires additional information about your organisation and reward programme for **security and compliance purposes** before you can issue Amazon India gift cards. ### Information required You will need to provide: * **Registered Email ID** – Email address registered with your Plum account. * **Company Legal Name** – Registered legal name of your organisation. * **Business Category** – Select the category that best describes your organisation. * **Reward Use Case** – Select how you plan to use the Amazon gift cards. * **Annual Reward Spend** – Estimated annual amount you plan to spend on rewards. * **Reward Programme Description and Goals** – Briefly explain what the programme is, who it is intended for, and its objective. ### Documents required | Requirement | Accepted document | | :---------------------------------- | :---------------------------------------------------------- | | **Business Establishment Document** | Company Incorporation/Registration Certificate | | **Company ID Document** | GST Registration Certificate or PAN Card | | **Business Address Proof** | Telephone Bill, Electricity Bill, or Water Bill | | **Company Declaration** | Declaration on company letterhead using the sample provided | ### Complete the verification Enter the required information, upload the supporting documents, and click **Submit**. Make sure that: * The company name matches your official registration documents. * All uploaded documents are valid and legible. * The information in the form is consistent with the supporting documents. * The declaration is prepared using the required format. Screenshot 2026 09 05 At 10 49 46 PM **Additional requirements for consumer and marketing use cases**

If you plan to use Amazon gift cards for **consumer incentives or marketing campaigns**, you may also need to submit your marketing collateral. Make sure the collateral follows Amazon's applicable guidelines before submitting it for review. You will also need to prepare an **undertaking document on your company letterhead** using the sample undertaking provided as part of the verification process.
*** # Amazon Global Brand KYC Amazon Global KYC requires additional information about your organisation and reward program before you can issue Amazon gift cards in applicable international markets. ### Information required You will need to provide: * **Registered Email ID** * **Company Legal Name** * **Countries where you plan to distribute rewards** * **Business Category** * **Company Website** * **Annual Reward Spend** in USD * **Applicable Business Activities** * **Reward Programme Description and Goals** * **Programme Start Date** * **Reward Use Case** You may also be asked whether the Amazon gift cards will be distributed **exclusively within the US**. ### Complete the verification Enter the required information and review your responses before clicking **Submit**. Screenshot 2026 09 05 At 8 39 30 PM 1 Make sure the company and programme information provided in the form is accurate and consistent with your organisation's details. *** # Prepaid Instruments and Digital Wallet KYB KYB verification is required for certain **Visa/Mastercard prepaid instruments** and **digital wallet rewards such as PayPal and Venmo**. The information submitted through the form may be shared with the relevant card issuers and reward partners for review and approval. ### Information required You will need to provide details about both your organisation and the person submitting the form: * **Registered Email ID** * **Name** * **Designation/Title** * **Organisation Legal Name** * **Company Brand Name** * **Number of Employees** * **Type of Business** * **Tax ID** – TAX, VAT, EIN, GST, or other applicable tax identification number * **Official Website URL** * **Country of Business Formation** * **Date of Business Formation** * **Lawsuits or Regulatory Actions** – Indicate whether the company is currently or has previously been subject to any lawsuits or regulatory actions. ### Complete the verification 1. Enter the required user and business information. 2. Click **Next** to proceed through the form. 3. Complete all remaining sections. 4. Review the information you have provided. 5. Click **Apply for Verification**. Screenshot 2026 09 05 At 8 39 58 PM Ensure that all information submitted is complete and accurate. The information may be shared with the respective card issuers and partners as part of the approval process. *** # What happens after you submit the form? Once you submit the verification form, the relevant brand or issuing partner reviews the information and documents provided. The typical timelines are: * **Amazon India Brand KYC:** 3–4 business days * **Prepaid Instruments and Digital Wallet KYB:** 2–4 business days * **Amazon Global Brand KYC:** The timeline may vary depending on the market and programme details. The verification may take longer if additional information or documents are required. Once your verification is approved, the applicable reward options will become available for issuance through Plum. ## Need Help? If you need assistance with the verification process, contact [**cs@xoxoday.com**](mailto:cs@xoxoday.com) or reach out to your designated SPOC. # Submitting Verification Detail Source: https://help-plum.xoxoday.com/getting-started/for-admins/account-verification/submitting-verification-details *In this article, you'll see the information you need to complete the KYB verification step to kick start rewarding journey with Xoxoday!* ## Steps and some pre-requisites Start by logging in to the [Admin Dashboard](https://stores.xoxoday.com/marketplace/login) Here are some of the things you'll need to keep handy: Details of the company as follows: | Requirement | Details | | :---------------------- | :--------------------------------------------------------------------------------------------------------------------------- | | **Basic Admin Details** | Name, Email address, and a valid Phone number (you'll receive an OTP here). | | **Company Details** | Registered Business Name, Country of Registration, Registered Identification number (Example: GST, TAX ID, EIN, or DUNS etc) | | **Company Address** | Company's registered address. | KYB details must be completed before funds can be added or rewards can be sent. *** ## Step-by-step guide Alternatively, for select geographies, we can fetch company details based on the name input. This feature is currently supported only for customers in India. *** ## What to expect next Expect an acknowledgement email within 2 hours. Our compliance team will then verify your details for account approval. Any additional information needed will be requested via email. # Updating Billing Address Source: https://help-plum.xoxoday.com/getting-started/for-admins/changing-billing-address-during-wallet-recharge This article explains how administrators can **add or update the billing address while adding funds to a client's Plum wallet**. The billing address selected during the transaction is used on the **Proforma Invoice** and **Invoice PDF** generated for the wallet recharge. # Manage Billing Addresses The Account Page allows you to view, add, update, or remove billing addresses associated with your Plum account. To access the billing address settings, navigate to **Settings > Account & Billing Address** and click **Change**. ## Add a Billing Address To add a new billing address: 1. Navigate to **Settings > Account & Billing Address**. 2. Click **Change**. Image 3. Click **Add New**. 4. Enter the required billing address details: * **GST/Identification Number:** Mandatory for India and optional for other countries. * **Country, State, and City** * **Billing Address** 5. Click **Save**. The new billing address is added to your account. *** ## Edit a Billing Address To update an existing billing address: 1. Navigate to **Settings > Account >Billing Address**. 2. Click on Change 3. Select the billing address you want to update. 4. Click the **Edit** icon. Image 5. Update the required details: * **GST/Identification Number:** Mandatory for India and optional for other countries. * **Country, State, and City** * **Billing Address** Screenshot 2026 08 31 At 9 57 32 PM 6. Click **Update**. The updated billing address is saved to your account. *** ## Remove a Billing Address To remove an existing billing address: 1. Select the billing address you want to remove. 2. Click the **Remove/Delete** icon. Image 3. Confirm the deletion. The selected billing address is removed from your account. ## Update an Existing Billing Address You can update or add a billing address while adding funds to your Plum wallet. The selected billing address is used on the invoice generated for the transaction. To update the billing address while adding funds: 1. Navigate to **Payments > Wallet Balance** in the Plum Admin Dashboard. Screenshot 2026 08 31 At 8 27 05 PM 2. Click **View Funds**. 3. On the **Add Funds to Wallet** screen, locate the **Billing Details** section. 4. Click **Change**. Image 5. Update the required billing details: * **Billing Address** * **GST/Identification Number:** Mandatory for India and optional for other countries. * **Country, State, and City** * **Client POC, Email, and Phone:** These details are auto-filled based on the Admin's information. Image 6. Click **Update** and proceed. The selected billing address is included on the invoice generated for the transaction. ## Add a New Billing Address You can also add a new billing address while adding funds to the wallet. To add a new billing address: 1. On the **Add Funds to Wallet** screen, navigate to the **Billing Details** section. 2. Click **Add New**. 3. Enter the required billing details: * **GST/Identification Number:** Mandatory for India and optional for other countries. * **Country, State, and City** * **Billing Address** * **Client POC, Email, and Phone:** These details are auto-filled based on the Admin's information. 4. Click **Save**. The new billing address is saved and becomes available for selection when adding funds to the wallet. Feedback or Questions: Reach out to [**cs@xoxoday.com**](mailto:cs@xoxoday.com) # Signing Up Source: https://help-plum.xoxoday.com/getting-started/for-admins/signing-up *Follow the step-by-step instructions to create your Xoxoday business account.* We have enhanced the sign-up flow to improve usability and engagement, ensuring a seamless experience. This guide will walk you through the process. ## Prerequisites Before starting, ensure you have the following information ready: * **Full Name** * **Company Name** * **Business Email Address** * **Password** * Business Email Address * Password | Requirement | Details | | -------------------------- | -------------------------------------- | | **Full Name** | Your first and last name | | **Company Name** | Your organization's name | | **Business Email Address** | A valid company email (not personal) | | **Password** | Min. 8 characters including one number | *** ## Creating Your Account Open your browser and navigate to [https://stores.xoxoday.com/admin/signup](https://stores.xoxoday.com/admin/signup). Enter your **Full Name** and **Business Email Address**, then submit the information to proceed. Check your inbox for an OTP sent to your registered email. Enter the OTP on the sign-up page to validate your email address. Create a strong password (at least 8 characters, including one numeric digit) and confirm it to complete this step. Specify the number of employees in your organization. *** Need help? Contact our support team at [**cs@xoxoday.com**](mailto:cs@xoxoday.com) # Funding the Account Source: https://help-plum.xoxoday.com/getting-started/for-admins/wallet-management/funding-the-account To get started with Plum, you need to add funds to your **Company Wallet**. The available wallet balance is used to fund rewards sent through your Plum account. Screenshot 2026 08 31 At 8 27 28 PM Screenshot 2026 08 31 At 3 23 48 PM 1 Screenshot 2026 08 31 At 8 13 43 PM Screenshot 2026 08 31 At 8 17 52 PM Screenshot 2026 08 31 At 3 25 13 PM Screenshot 2026 09 05 At 8 18 28 PM Screenshot 2026 09 05 At 8 22 52 PM Once the payment is made, kindly **share the payment receipt** via email. After verification by our Finance team, the funds will be credited to your Xoxoday wallet within **2–3 business days**. You can view the status in the reports section. It might take a couple of minutes to show up on the dashboard. Feedback or Questions: Reach out to [**cs@xoxoday.com**](mailto:cs@xoxoday.com) # Payment Methods Source: https://help-plum.xoxoday.com/getting-started/for-admins/wallet-management/payment-methods *Learn about different ways to fund your Plum account.* Plum supports multiple ways for you to fund your account. Below is a list of a few, please select as applicable: *** ## 1. Online Payment Methods Online Payment Methods using Credit Card & Debit Card. ### Fund addition for INR Accounts Online options available - UPI, Credit/Debit Card, Net banking, e-Wallets and more. *** ## 2. Pay Offline ### Create an Invoice An invoice (or pre-payment invoice) is a great way if you want to get your finance team involved in making the payment. Here's how to do this: Input the desired amount in your base currency click "Create Invoice" to proceed. Enter the Purchase Order Number (Optional) and Purchase Order Date using the calendar icon. The selected date is stored in the system and displayed clearly on the invoice template, giving finance and procurement teams the visibility they need for smooth tracking and reporting. That's it! The invoice will be sent to your email address. After the payment is made, share the details with [ar@xoxoday.com](mailto:ar@xoxoday.com). The finance team will verify the details, and after the verification, the funds will be credited to your account. **Pro tip** * You can optionally enter a PO number at the time of generating the invoice. * You can view the status in the reports section. It might take a couple of minutes to show up on the dashboard. *** Feedback or Questions: Reach out to [cs@xoxoday.com](mailto:cs@xoxoday.com) # Wallet Management Source: https://help-plum.xoxoday.com/getting-started/for-admins/wallet-management/wallet-management-overview Super Admins can manage the organization's pre-funded Plum wallet. You can add funds to the wallet and use the available balance to send rewards. ## Base Currency The **Base Currency** is the currency in which your organisation's wallet, funds, and transactions are maintained. The Base Currency is selected by the **Super Admin** when the account is created and is used as the default currency for activities such as adding funds and redeeming rewards. To view your account's Base Currency: 1. Navigate to **Settings**. 2. Select **Account**. 3. View the configured **Base Currency**. Screenshot 2026 08 31 At 12 17 30 AM Plum supports major currencies, allowing Super Admins to select the appropriate currency for their organization when creating a business account. ## Pre-funded Wallet Plum uses a **pre-funded wallet** to process rewards. You must add funds to the wallet before you can send rewards. Super Admins can add other Admins to help manage the Plum account and send rewards. ## Add Funds to the Wallet To add funds to your Plum wallet: 1. Sign in to your **Plum Admin Dashboard**. 2. Navigate to **Payments** from the left navigation menu 3. Click **Add Funds to Wallet**. 4. Enter the amount you want to add in your **Base Currency**. 5. Complete the payment using the designed payment method. Once the payment is successfully completed, the funds are added to the company wallet. Screenshot 2026 08 31 At 8 38 34 PM ## Payment Methods Plum supports multiple payment methods for adding funds to your wallet. Check out this article to learn all payment methods [Payment Methods.](/getting-started/for-admins/wallet-management/payment-methods) # Redeem Reward Link Source: https://help-plum.xoxoday.com/getting-started/for-end-users/how-to-redeem/redeem-reward-link Learn how to redeem a reward link you've received as an end user on Plum, from opening the link to claiming your reward. Learn how to redeem a Reward Link as an end user. Click "**Redeem Now**" when you get the email about the reward. You'll be taken to a page where all of your vouchers are listed. Image On click of '**Redeem Now**', you will see a landing page. Here, you can view your reward value and the link validity. Image Pick the brand you like the most. Click on **Send OTP.** Image Enter your information, either your email address or phone number, if asked to get vouchers. You'll be asked to enter the OTP for verification purposes. Image You can also choose other gift cards by clicking on the cross. This will take you back to the previous page so you can use another gift card. Once you have the code, you can copy it or click the "**Send me a copy**" button to send it to your email or phone number. *** ## HRMS such as Darwinbox, Here is how you can redeem **Here are the steps to redeem:** Under "**My Access**", click the "**Recognition**" tile. Within the "**Recognition Overview**", you check your accumulated reward points balance. Click **"Redeem".** You will now be redirected to the Plum Storefront via single sign-on. You can check your points balance in the top right corner of the page. Choose any experience, gift vouchers, etc, from categories based on location.Click on "**Add to cart**" on the selected option. Please read the item's Terms and Conditions, Validity, and Description before proceeding. After adding all the items to the cart, click on the cart icon to proceed with the purchase. Verify your items and click on "**Proceed to Checkout**". *** ## If you are using SAP® SuccessFactors or a custom platform, here is how you can redeem Under the **"Home"** tab, click the **"Compensation"** module. You can check your accumulated reward points under "**My Team**". Now, click **"Redeem"**; with a single sign-on, you will be redirected to the Plum Storefront. Choose any experience, gift vouchers, etc, from 30+ categories based on location. Click on **"Add to cart"** on the selected option. Please read the item's Terms and Conditions, Validity, and Description before proceeding. After adding all the items to the cart, click on the cart icon to proceed with the purchase. Verify your items and click on **"Proceed to Checkout".** *** ## How to redeem Mastercard/Virtual Visa Card using Reward Code/Reward Points **To redeem your Mastercard/Virtual Visa Card, follow these steps below:** * Visit [**https://stores.xoxoday.com/**](https://stores.xoxoday.com/). Select the Product of your choice and choose the "**Guest Checkout**" option on the landing page. Enter a valid email ID to proceed as a guest user. You can successfully place an order by choosing the Guest Checkout option. Mention your name, email, dialling code, and phone number. Before continuing with the purchase, an OTP will be sent to the mobile number provided. Select the option to use available reward points for the purchase. If you have a gift card, add the gift card code and click on **"Apply"**. You can also pay the excess amount by selecting the option to pay via "Credit Card" and choosing the card of your choice. Click "**Pay Now**" to continue with the selected payment mode. # Redeem Reward Points Source: https://help-plum.xoxoday.com/getting-started/for-end-users/how-to-redeem/redeem-reward-points Learn how to redeem the reward points you've received as an end user on Plum, from browsing options to confirming your choice. *Learn how to redeem Reward Points as an end user.* Upon registration, you will receive mail from Xoxoday to set up your account as shown below. *** Your reward points balance is shown at the top right corner of the page. Choose any gift vouchers, etc, from the different categories shown. Click on "**Add to cart**" on the selected brand. Once you add the product to your card, "Add to cart" button will show the "**Go to Cart**" option making the journey simple. You can click on the "**Go to Cart**" button. You can also "**Go to cart**" by clicking on the cart icon in the top right corner beside the profile. Please read the Terms and Conditions, Validity, and Description of the item before proceeding. Click on "**Checkout Now**" to move to the check-out page. Enter your name, email, dialing code, and phone number. An OTP will also be sent to the mobile number provided before continuing with the purchase. The user will be able to see the reward point balance and ask if he wants to use the points for the order payment. # Redeem Reward Code Source: https://help-plum.xoxoday.com/getting-started/for-end-users/how-to-redeem/reward-code Learn how to redeem a reward code you've received as an end user on Plum, step by step from entry to confirmation. *Learn how to redeem your reward code on the Plum Marketplace.* The user has to visit [stores.xoxoday.com](https://stores.xoxoday.com/) to redeem the code. Users can redeem reward codes through Guest Checkout. You don't have to log in or sign up. **Things to Remember:** * Reward code can be used within the validity period only. * Partial redemptions for Reward codes are allowed and can be used until the code balance is exhausted. * You can choose multiple codes (**Up to 10 reward codes in a single transaction**) to order as long as the amount does not exceed your code Balance. *** ## Redeeming Reward Codes On receiving the reward email, click on "**Redeem Now**" as shown below. You will be redirected to our marketplace to consume the code. Image Choose any gift vouchers or search your favorite brand from 30+ categories and 21,000+ branded options and click "**Add to Cart**". Visit the cart or click on "**Go to Cart**" and click on "**Checkout Now**". Under the Payment Details Card, select '**Click here**' and paste your Reward Code. You can paste code in the input text field. You can apply up to 10 valid codes against a single order. Once done, click '**Proceed**' to move ahead. Enter your **name, email, dialling code, and phone number.** An OTP will also be sent to the mobile number provided before continuing with the purchase. Enter your contact details and click 'Proceed' to check out. You will get an OTP for confirmation in the email. * You can also pay the excess amount with credit/debit cards or net banking. * You'll receive an order delivery email with the necessary details. *** We regret that the reward code cannot be exchanged for cash. If you face a code error, kindly share a screenshot of the code and the error with us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Sign Up Source: https://help-plum.xoxoday.com/getting-started/for-end-users/signing-up-logging-in Learn how to sign up and log in as an end user on Plum so you can view and redeem the rewards you've received. *How to Login/Signup to the Storefront?* *** ## Sign up to Plum Storefront Go to [https://stores.xoxoday.com/](https://stores.xoxoday.com/)companyname. Login using your registered email address and password. You have successfully signed up for Xoxoday Plum. **Note:** Users with a valid Reward Code do not need login credentials. During checkout, they can continue as a guest and redeem the code directly. * For Signing up, select the signup option from the accounts dropdown. Provide necessary information such as name, email address, country etc to proceed with the signup process. Congratulations! You have successfully signed up for Xoxoday Plum. **Note:** Users with a valid Reward Code need not have login credentials. During checkout, they can continue as guest users and redeem the Reward Code. *** ## Forgot your password? Visit [https://stores.xoxoday.com/vouchers](https://stores.xoxoday.com/nreachtech/vouchers/) Enter your registered email ID and click "**Forgot password**". A reset password link is sent to the email ID provided. Click on the link and set a password. You will now be able to log into the portal with a new password. **Note:** Any users with a valid Reward Code need not have login credentials. During the checkout, continue as a guest user and redeem the Reward Code. *** ## Logging in for the first time First-time users, please follow the steps below: Go to [stores.xoxoday.com](https://stores.xoxoday.com/)/companyname, click on the login page and select sign up and this opens the Sign-up form as below. Enter the required information, such as your "Name", "Email ID", "Country Code for Phone Number", and "Password". You will receive an OTP to verify and you will be successfully signed up. *** Feedback or Questions: Reach out to [cs@xoxoday.com](mailto:cs@xoxoday.com) # Overview Source: https://help-plum.xoxoday.com/getting-started/overview Get an overview of Plum, Xoxoday's rewards platform, and learn how admins send gift cards, reward links, codes, and points. Welcome to Xoxoday Plum's Help Center — here you'll find comprehensive guides and documentation to help you get started with Plum as quickly as possible. You can also find self-help guides, tips, and tricks. Let's jump right in. # Account Set up First things first — below is a collection of articles that will help you get up and running in no time and get you acquainted with Xoxoday Plum's features in an instant! Here is a collection of articles that will get you started with your Xoxoday plum account: # Account Verification As part of regulatory requirements, customers need to complete a quick verification step as part of the KYB requirements for bands. ## KYB Verification Head over to this article [Submitting Verification Details](/getting-started/for-admins/account-verification/submitting-verification-details) to know everything about the KYB verification steps. # Add Funds Xoxoday Plum works on a pre-funded wallet that gives you total control over your spending and budget for all your rewards. ## Wallet Management Xoxoday operates on a pre-funded wallet. Head over to [Recharge & Wallet Management](/getting-started/for-admins/wallet-management/wallet-management-overview) to know everything about managing your Xoxoday wallet. # Rewards Distribute rewards and incentives the way you want seamlessly and quickly. First things first, let's start with different modes of reward in Xoxoday Plum. ## Modes of Reward Plum lets you reward anyone, anywhere, in your own special way as a Code, a Link or as a Point. [Click here](/send-rewards/reward-modes/reward-modes-types-overview) to learn all about it. ## Reward Code Reward Code provides a fast and secure method to send unique reward codes to participants. Learn more here [Reward Code](/send-rewards/reward-code/reward-code-overview) ## Reward Link A unique reward link that can be sent to each recipient and provide a one-click redemption experience. [Reward Link](/send-rewards/reward-links/reward-link-overview) ## Reward Point Reward points can be accumulated, and used for redemption from our extensive rewards catalog. Learn more here: [Reward Points](/send-rewards/reward-points/reward-points-overview) ## Brand Vouchers Instantly send brand gift cards directly to recipients' inboxes. There are over 8,000 top global brands from Amazon to Walmart and everything in between! Learn more here [Brand Vouchers](/getting-started/for-end-users/gift-vouchers-faqs) If you want to learn more about which mode fits best for you, [check out this article](/send-rewards/reward-modes/comparison-of-when-to-use-what). # Send Reward ## Send Reward Links * [Send Reward Links: to a Few](/send-rewards/reward-links/send-reward-links-send-individually) * [Send Reward Links: to Many](/send-rewards/reward-links/send-reward-links-bulk-upload) * [Send Reward Links: to Self](/send-rewards/reward-links/send-reward-links-to-self) ## Send Reward Code * [Send Reward Code: to Many](/send-rewards/reward-code/send-reward-code-bulk-upload) * [Send Reward Code: to a Few](/send-rewards/reward-code/send-reward-code-individually) ## Reward Points * [Reward Points](/send-rewards/reward-points/reward-points-overview) # Campaigns Xoxoday Plum enables super admins and admins to create and manage bespoke campaigns, enriching the rewarding experience for end-users by offering customizable storefronts and personalized rewards, thereby boosting engagement and driving outcomes. Click here: [Overview: Campaigns](/campaigns/campaigns-overview) # Plug-n-Play Native Integration Plum Apps enables seamless integration with leading SaaS platforms in marketing automation, CRMs, customer engagement tools, HR software, collaboration platforms, and more. This integration streamlines workflows and enriches Plum with contextual information, providing a comprehensive perspective on your mutual growth. ## List of Most Popular Integration * [HubSpot](/integrations/hubspot/hubspot-overview) * [Salesforce](/integrations/salesforce/salesforce-overview) * [Zoho CRM](/integrations/zoho-crm/zoho-crm-overview) * [ActiveCampaign](/integrations/activecampaign/activecampaign-overview) * [SAP SuccessFactors](/integrations/sap-successfactors/sap-successfactor-overview) * [Darwinbox](/integrations/darwinbox/darwinbox-overview) * [Zoho People](/integrations/zoho-people) * [Qualtrics](/integrations/qualtrics/using-qualtrics-workflow-extension-to-send-rewards) * [SurveyMonkey](/integrations/surveymonkey/public-survey-automation) * [Typeform](/integrations/typeform/typeform) # ‍ For Developers Xoxoday’s developer platform is a core part of our mission to empower organizations to bake in rich rewarding experiences inside their application(s) and blitzkrieg growth and revenue. Unlock seamless rewards distribution and redemption within your application using our extensive library of API integrations. Developer Documentation is here: [Overview](https://developers.xoxoday.com/reference/api-reference-documentation) ## Rewards API Add rewards to your application with seamless integration to our rewards catalog, featuring over 8,000 gift cards from top brands. Check out the documentation. [About Rewards API](https://developers.xoxoday.com/reference/about-rewards-api) ## Integrate Marketplace Transform your reward points redemption process instantly with our plug-and-play global rewards catalog integration, delivering an exhilarating experience to your users within minutes. Check out the documentation [About Marketplace Integration](https://developers.xoxoday.com/reference/about-marketplace-integration) ## Reward Link API Programmatically send unique reward links to recipients from within your application, redeemable against a curated catalog. Check out the documentation [About Reward Link APIs](https://developers.xoxoday.com/reference/about-xoxolink-apis) ​ ​ # Plum Help Center Source: https://help-plum.xoxoday.com/home Guides and walkthroughs for Plum — sending rewards, campaigns, the reward marketplace, wallets and payments, reports, offers management, and integrations.

Plum Help Center

Plum is Xoxoday's rewards, incentives and payouts infrastructure. Send gift cards, prepaid cards, experiences and cash-outs to employees, customers and channel partners across 100+ countries.

Search the Plum Help Center ⌘K
Popular: Sign up for Plum Send a reward link Fund your account Redeem reward points API docs

What you can do with Plum

The core of the platform, and the guides for each.

Get started

Sign up, verify your account, and take the first tour as an admin or as a recipient.

Send rewards

Reward links, reward codes and reward points — and how to choose between them.

Reward points

Issue points in bulk or one by one, and let recipients redeem them how they like.

Campaigns

Run recurring reward programmes without sending each reward by hand.

Reward marketplace

Gift cards, merchandise, experiences, flights, charity and cash-outs in one catalogue.

Wallet & payments

Fund the account, pick a payment method, and keep the balance topped up.

Reports

Track what was sent, what was claimed, and what it cost — with exports.

Prepaid cards

Virtual Visa and international PayPal payouts for recipients who want cash.

Integrations

Connect Plum to your CRM, survey tool or HRMS so rewards fire automatically.

Keep up with Plum

What shipped recently, how it works on screen, and where to get help.

Product updates

Release notes for every new feature and improvement.

See what's new →

Walkthrough videos

Short video tours of the dashboard, campaigns and offers management.

Watch the videos →

Talk to support

Stuck on something that is not covered here? Reach the customer success team.

Raise a ticket →

More from Xoxoday

The other two products, and the FAQs that cover all three.

Empuls Empuls

Employee engagement, recognition and rewards, surveys, and the social intranet.

Empuls Help Center →
Loyalife Loyalife

Build and run customer loyalty programmes — tiers, points, rules and member engagement.

Loyalife Help Center →
Xoxoday Xoxoday

Answers to the questions we are asked most often, across every Xoxoday product.

Product FAQs →
Privacy Policy Terms of Service Cookie Policy Talk to sales Partner Centre

© 2026 Xoxoday, Inc. · Make every day rewarding.

Xoxoday Xoxoday
# ActiveCampaign: Overview Source: https://help-plum.xoxoday.com/integrations/activecampaign/activecampaign-overview Get an overview of the Plum-ActiveCampaign integration and how it automates rewards triggered by marketing automation events. *This article will guide you through integrating ActiveCampaign with Xoxoday Plum and setting up your first automation.* ## Here is how the Xoxoday ActiveCampaign Integration works? Follow the below steps to create ActiveCampaign Reward Automation in Plum. Creation of automation in ActiveCampaign to connect Xoxoday plum. ## Pre-requisite The App should be installed to be used as an action. ## Steps to Connect Rewards on ActiveCampaign with Plum Xoxoday Plum can simply be integrated into ActiveCampaign by following the steps below: You (the admin) can log in to ActiveCampaign and set up Xoxoday automation in either of the two ways. ## Method 1 * Sign in to **ActiveCampaign with** your credentials. * Under the **"Automations" tab, click on "Create an Automation**" * Choose "**Xoxoday Plum" from the "Actions**" tab to set up the workflow. * Click on the account to which you would like to set up the automation. ## Method 2: * Under the "**Automations**" tab * Click on "Create a new automation" and click on the\*\*"+"\*\* button to add your first action and choose Xoxoday Plum from the options below: ## Creation of Reward Automation on Plum * Next, sign in to Plum using [https://www.xoxoday.com/](https://www.xoxoday.com/) * Once signed up to Plum, add funds to your account. * Now go to Campaign on the sidebar, and click on Create New to create a reward campaign. * Define the Reward Amount, Select rewards from the catalog, customize your email and click on Proceed. * Now go to "Manage Integrations" and select ActiveCampaign Integration. * Click on "Create New Automation" give your reward automation a name and select the type of trigger manual or automated. * Finally, click on launch. * To view Reward automation statistics, open the reward automation from the dashboard. ## Disconnecting Xoxoday Plum from ActiveCampaign * Go to "Apps" on ActiveCampaign, Select Connected Apps 2\. Select "Xoxoday Plum" and Select the account you wish to disconnect 3. Click on "Disconnect": ​ ## Integrate Your ActiveCampaign with Plum and witness amazing results! Positively impact your audience’s journey and get that prospect which ultimately becomes a sale. Integrate your ActiveCampaign with Xoxoday Plum and see the difference with positive results. With dedicated account managers, full-time support to admins as well as end-users, and ISO, GDPR, and SOC compliance, Xoxoday Plum is as safe as it gets. ​ For any questions or feedback reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Creating Automation Source: https://help-plum.xoxoday.com/integrations/activecampaign/creating-automation Learn how to create a reward automation inside ActiveCampaign using Plum, so contacts are rewarded automatically at the right moment. *This page will help you in creating your first automation with Xoxoday's ActiveCampaign Integration* ## Steps to Connect & Automate Rewards on ActiveCampaign with Plum \*\*Step 1:\*\*Connect your Xoxoday & active campaign account.**Step 2:** Login/Signup to your Xoxoday account. ​ Step 3:\*\* Click on ActiveCampaign Integration under Manage Integration and select "Connect" to sync ActiveCampaign with Xoxoday. Login to your ActiveCampaign account and connect with Xoxoday Plum as shown in previous article. Create a Reward Campaign as shown in ::Xoxo-link:: ## Create Reward Automation Step 1: Click on '**Create New Automation**' in ActiveCampaign Dashboard.\*\*​ Step 2: Name your automation and click on 'Save and Proceed'.\*\* \*\*​ ## Set your Reward Here you can select the Campaign which holds the type of rewards and brands you want to use for this automation. You can set reward expiry and select the Approval type as manual or automatic. In Advanced Settings, you can set start and end date of automations and many more customisations.\*\*​ Now, click on "Save and Launch" \*\*to move to next step. Now, Click '**Yes, Launch'** button to launch automation. ### Automation created Successfully **Link to the Xoxoday Plum recipe:** Send Gift to New Client [https://www.activecampaign.com/marketplace/recipe/send-gift-card-to-new-client](https://www.activecampaign.com/marketplace/recipe/send-gift-card-to-new-client) ## Based on the triggers, rewards can be: * Sent automatically without restrictions, which will be automatically distributed based on a customized time range and the maximum count of rewards, or * Subjected to manual approval by admins. * Now that the reward triggers are set, head back to the ActiveCampaign dashboard and click on ‘Create an Automation’. The template can be created from scratch or a readymade template aka ‘Recipe\*\*’ can be put to use. * Next up, you ‘**Add a New Trigger**’ on the workflow builder, which is made easy with the recipe templates that come with their own sets of triggers. * Once this is done, you can **‘Add a New Action**’ by clicking on CX Apps and selecting Reward through Xoxoday Plum. In case the [Xoxoday Plum Rewards App](https://www.activecampaign.com/apps/xoxoday-plum-integration) hasn’t been installed, it can be done at this very step. * Remember the Automation we configured in Step 5? When the configured automation list appears, select your particular automation, and activate it with ‘Active’. Before activation, a quick review can be done with ‘View Contacts’. Refer to the above GIF for a better outlook. * Bravo! Your ActiveCampaign Reward Automation is all set to be launched. **Some points to note** * While setting up the reward automation, the denomination will be in the same currency as the one selected in your Billing Details. * You will have all access to the dashboard features of the Reward Automation and can deactivate the reward automation at any stage. * On the condition that someone on the recipients’ list matches the criteria on ActiveCampaign automation, he/she automatically receives the reward delivered to his inbox in the form of Reward Codes. As for your audience, check **how one can redeem the Xoxo Codes** on Marketplace. # Zapier Integration Source: https://help-plum.xoxoday.com/integrations/connect-plum-to-thousands-of-apps-using-zapier Learn how to connect Plum to thousands of apps using Zapier, letting you trigger reward sends from almost any tool you use. *Connect Xoxoday Plum to thousands of apps for various use-cases* Below are some of the many Apps and their Use-Cases with templatized triggers that can be connected to Xoxoday Plum to send rewards, via Zapier: ## HRMS Tools ## 1. BambooHR By connecting BambooHR with Xoxoday Plum, rewards can be sent to newly joined employees on successful onboarding completion. Step 1: Select BambooHR as the Trigger application, the Trigger, in this case, is\*\*“When a new employee is added to BambooHR”. First, log in to your BambooHR account and Test trigger to Find data.\*\* **Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to new employees on BambooHR. **Step 3:** After DIY set-up, log in as a registered user of Xoxoday Plum. Step 4: Click\*\*'Continue\*\*' and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the Recipient Email field is important if the gift card(s) need to be sent to the user via email. **Step 5: Test and Review or Continue.** **Congrats! Your Zap is ready.** As a result of this integration, when a new employee is added to BambooHR, he/she receives Xoxoday Plum’s customized Gift Card via email. **2. Namely** By connecting Namely with Xoxoday Plum, rewards can be sent to new employees on successful onboarding completion. Step 1: Select Namely as the Trigger application, the Trigger, in this case, is\*\*“When a new employee is added to Namely”\*\*. First, log into your Namely account and Test the trigger to Find data. **Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to new employees on Namely. **Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum. **Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use case of the Action you have set. Double-check everything. For example, the "Recipient Email" field is important if the gift card(s) need to be sent to the user via email. **Step 5:** Test and Review or Continue. As a result of this integration, when a new employee is added on Namely, he/she receives Xoxoday Plum’s customized Gift Card via email. **3. Beekeeper** By connecting Beekeeper with Xoxoday Plum, rewards can be sent for an employee’s personal milestones (birthdays, wedding anniversary celebration, etc.) as well as professional milestones (for work anniversaries, superior performance, employee referrals, achieving targets, participation in events conducted, etc.). **Step 1:** Select Beekeeper as the Trigger application, the Trigger, in this case, is \*“an employee celebrating an anniversary on a particular day”. First, log into your Beekeeper account and Test the trigger to Find data. **Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to new employees on Beekeeper. **Step 3:** After DIY set-up or login as a registered user of Xoxoday Plum. **Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use case of the Action you have set. Double-check everything. For example, the Recipient Email field is important if the gift card(s) need to be sent to the user via email. **Step 5:** Test and Review or Continue. **Congrats! Your Zap is ready.** As a result of this integration, the day on which an employee celebrates his/her anniversary on Beekeeper, he/she receives Xoxoday Plum’s customized Gift Card via email. ## Survey tools & Forms **1.Survey Monkey** **2. Survey Sparrow** By connecting SurveySparrow with Xoxoday Plum, rewards can be sent to a respondent on completion of any given survey. Step 1: Select SurveySparrow as the Trigger application, the Trigger, in this case, is\*\*“when a user completes a survey”\*\*. First, log into your SurveySparrow account and Test the trigger to Find data. **Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to new responses to a survey on SurveySparrow. **Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum. **Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the Recipient Email field is important if the gift card(s) need to be sent to the user via email. **Step 5:** Test and Review or Continue. **Congrats! Your Zap is ready.** As a result of this integration, whenever a new response is submitted by a user on SurveySparrow, the user receives Xoxoday Plum’s customized Gift Card via email. **3. SurveyGizmo** By connecting SurveyGizmo with Xoxoday Plum, rewards can be sent to a respondent on completion of any given survey. Step 1: Select SurveyGizmo as the Trigger application, the Trigger, in this case, is\*\*“when a user completes a survey”\*\*. First, log into your SurveyGizmo account and Test the trigger to Find data. **Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to new responses to a survey on SurveyGizmo. **Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum. **Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the Recipient Email field is important if the gift card(s) need to be sent to the user via email. **Step 5:** Test and Review or Continue. **Congrats! Your Zap is ready.** As a result of this integration, whenever a new response is submitted by a user on SurveyGizmo, the user receives Xoxoday Plum’s customized Gift Card via email. **4. TypeForm** By connecting TypeForm with Xoxoday Plum, rewards can be sent to new entries on TypeForm. Step 1: Select TypeForm as the Trigger application, the Trigger, in this case, is\*\*“when a new entry is made”\*\*. First, log into your TypeForm account and Test the trigger to Find data. **Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to new entries on TypeForm. **Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum. **Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the "Recipient Email" field is important if the gift card(s) need to be sent to the user via email. **Step 5:** Test and Review or Continue. **Congrats! Your Zap is ready.** As a result of this integration, whenever a new entry is made on TypeForm, the user receives Xoxoday Plum’s customized Gift Card via email. **5. Qualtrics** By connecting Qualtrics with Xoxoday Plum, rewards can be sent to new entries on Qualtrics. **Step 1:** Select Qualtrics as the Trigger application, the Trigger, in this case, is “when a new response is added to the survey”. First, log in to your Qualtrics account and Test the trigger to Find data. **Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to new responses to a survey on Qualtrics. **Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum. **Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the Recipient Email field is important if the gift card(s) need to be sent to the user via email. **Step 5:** Test and Review or Continue. **Congrats! Your Zap is ready.** As a result of this integration, whenever a new response is submitted by a user on a Qualtrics survey, the user receives Xoxoday Plum’s customized Gift Card via email. ## Sales and Marketing Enablement, CRM **1.** \*\*[Salesforce CRM](/integrations/connect-plum-to-thousands-of-apps-using-zapier)**​** **2. Zoho CRM** By connecting Zoho with Xoxoday Plum, rewards can be sent to new leads/prospects added on Zoho. Step 1: Select Zoho as the Trigger application, the Trigger, in this case, is\*\*“when a new lead(a record) is added”\*\*. First, log in to your Zoho account and Test the trigger to Find data. **Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to a new lead added on Zoho. **Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum. **Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the Recipient Email field is important if the gift card(s) need to be sent to the user via email. **Step 5:** Test and Review or Continue. **Congrats! Your Zap is ready.** As a result of this integration, whenever a new lead is added to Zoho, the user receives Xoxoday Plum’s customized Gift Card via email. **3. Freshsales CRM** By connecting Freshsales with Xoxoday Plum, rewards can be sent to new leads/prospects added on Freshsales. Step 1: Select Freshsales as the Trigger application, the Trigger, in this case, is\*\*“when a new lead(a record) is added”\*\*. First, log into your Freshsales account and Test the trigger to Find data. **Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to a new lead added on Freshsales. **Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum. **Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the Recipient Email field is important if the gift card(s) need to be sent to the user via email. **Step 5:** Test and Review or Continue. ​ **Congrats! Your Zap is ready.** As a result of this integration, whenever a new lead is added to Freshsales, the user receives Xoxoday Plum’s customized Gift Card via email. **4. Hubspot Marketing Automation**- By connecting HubSpot with Xoxoday Plum, rewards can be sent to **new form submissions** on HubSpot. ​ * By connecting HubSpot with Xoxoday Plum, rewards can be sent to \***new deals added** on HubSpot. Step 1: Select HubSpot as the Trigger application, the Trigger, in this case, is\*\*“when a new deal is added”\*\*. First, log into your HubSpot account and Test the trigger to Find data. **Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to a new deal added on HubSpot. **Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum. **Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Doublecheck everything. For example, the "Recipient Email" field is important if the gift card(s) need to be sent to the user via email. **Step 5:** Test and Review or Continue. **Congrats! Your Zap is ready.** As a result of this integration, whenever a new deal is added to HubSpot, the user receives Xoxoday Plum’s customized Gift Card via email. ### 5. Mailchimp Email Newsletter By connecting Mailchimp with **Xoxoday Plum**, rewards can be sent to every new subscriber of Mailchimp’s email newsletter. Step 1: Select Mailchimp as the Trigger application, the Trigger, in this case, is\*\*“new subscriber of the newsletter”\*\*. First, log in to your Mailchimp account and Test the trigger to Find data. **Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to a new subscriber on Mailchimp. **Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum. **Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the "Recipient Email" field is important if the gift card(s) need to be sent to the user via email. ​ **Step 5:** Test and Review or Continue. **Congrats! Your Zap is ready.** As a result of this integration, whenever a new subscriber is added to Mailchimp, the user receives Xoxoday Plum’s customized Gift Card via email. **6. Google Sheets** By connecting GoogleSheet with Xoxoday Plum, rewards can be sent to every new user row(prospect lead) added to the Google spreadsheet. Step 1: Select GoogleSheet as the Trigger application, the Trigger, in this case, is\*\*“new row added to spreadsheet”\*\*. First, log into your Google account and Test the trigger to Find data. **Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to a new row on Google Sheet. **Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum. **Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the Recipient Email field is important if the gift card(s) need to be sent to the user via email. **Step 5:** Test and Review or Continue. **Congrats! Your Zap is ready.** As a result of this integration, whenever a new spreadsheet row is added to GoogleSheet, the user receives Xoxoday Plum’s customized Gift Card via email. ## Webinar Tools **1. Go to Webinar** By connecting GoToWebinar with Xoxoday Plum, rewards can be sent to every new webinar attendee. Step 1: Select GoToWebinar as the Trigger application, the Trigger, in this case, is\*\*“new webinar attendee”. First, log in to your GoToWebinar account and Test the trigger to Find data. **Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to a new attendee of a webinar in GoToWebinar. **Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum. **Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the "Recipient Email" field is important if the gift card(s) need to be sent to the user via email. **Step 5:** Test and Review or Continue. **Congrats! Your Zap is ready.** As a result of this integration, every new webinar attendee in GoToWebinar receives Xoxoday Plum’s customized Gift Card via email. 2. Zoom \*\*By connecting Zoom with **Xoxoday Plum**, rewards can be sent to every new registrant. Step 1: Select Zoom as the Trigger application, the Trigger, in this case, is\*\*“new registrant in Zoom”. First, log in to your Zoom account and Test the trigger to Find data. **Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to new registrants in Zoom. **Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum. **Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the "Recipient Email" field is important if the gift card(s) need to be sent to the user via email. **Step 5:** Test and Review or Continue. **Congrats! Your Zap is ready.** As a result of this integration, every new registrant in Zoom receives Xoxoday Plum’s customized Gift Card via email. ## What Next? : Quick Zap Creation The use cases mentioned in the above section are a few of the many popular Zap templates that already exist to connect applications like **Salesforce, HubSpot, SurveyMonkey, GoToWebinar, Mailchimp, etc. to Xoxoday Plum**. Using these pre-created templates will help you automate the workflow and get it up and running in no time. For more information about building your first **Xoxoday → Zapier integration**, [Contact us](https://www.xoxoday.com/contact-us). # Darwinbox: Overview Source: https://help-plum.xoxoday.com/integrations/darwinbox/darwinbox-overview Learn how the Plum-Darwinbox integration works, connecting your HRMS to Plum so employee rewards can be triggered and disbursed automatically. *Learn all about integration of Darwinbox with Xoxoday Plum.* ## Overview Xoxoday integrates with DarwinBox, one of the leading HRMS automation platforms for modern businesses. This integration enables organizations using DarwinBox to not only streamline and automate HR workflows, but also seamlessly reward employees to keep them motivated, engaged, and appreciated. With Xoxoday Plum, companies can build a culture of recognition through a unified rewards platform offering a global catalog of products and experiences — helping teams feel valued and inspired to do their best work. ## Points Redemption procedure * Log in to your DarwinBox account. * \*\*Darwinbox + Xoxoday Integration \*\*Click on the **Recognition** tile. * Click **Redeem**, get redirected to [stores.xoxoday.com](https://docs.xoxoday.com/docs/stores.xoxoday.com), and get auto logged in via SSO. * Users will be automatically logged in to [Xoxoday plum stores](https://docs.xoxoday.com/docs/stores.xoxoday.com) (Catalog front). * Users can redeem their points in plum on a variety of experiences and vouchers. * Select your Country & Click on **Gift Vouchers, experiences**, or other classification of your choice. * Select the listed Brand Voucher or any other option. * Select the Denomination and Quantity and then Add to the Cart. * Under the payment option, click on Use available xxx points for this order and place the order. You may use a debit/credit card to augment points in case it is insufficient. * You can also view the integration video here: * You can view the interactive demo using this [***Link***](https://reward-path-showcase.lovable.app) # Guide to Configure End-points Source: https://help-plum.xoxoday.com/integrations/darwinbox/guide-to-configure-end-points Follow this step-by-step guide to configure the Darwinbox API endpoints needed to connect your HRMS with Plum for reward automation. *Learn about the configuration on Darwinbox.* Step 1: Initiate the process by logging in to the Xoxoday Admin dashboard using the provided link:\*\*stores.xoxoday.com.\*\*Step 2: Navigate to the "**Integrations" section and select "Darwinbox**". **Step 3:** Proceed to Configure the Darwinbox settings. Step 4: Fill in the necessary fields, namely **Username, Password, Datasetkey, and Redirect URL**. You should have received these specific details from the Darwinbox team. Step 5:\*\* Update the Endpoint URL and API Key for the following subsequent endpoints: * Fetch Point Balance API * Update Point Balance API Endpoint * Fetch Employee Master API Step 6: After completing the previous step, click "**Verify and Proceed"**. Afterwards, please notify to your implementation manager from Xoxoday, so that we can inform the Darwinbox team to activate the redemption button on your behalf. Step 7:\*\* Upon the successful completion of this configuration, feel free to arrange a call with us to facilitate an onboarding session. During this session, we will guide you through both the end user journey and the admin dashboard. ​ ​ # Forsta (Decipher) Integration Source: https://help-plum.xoxoday.com/integrations/forsta-decipher-integration Get an overview of the Plum integration with Forsta Decipher and how it automates reward distribution to survey respondents. *Learn more about Forsta and Xoxoday Plum Integration.* # Overview Boost survey response rates and gather meaningful insights with instant rewards! Xoxoday Plum, integrated with Forsta, automates digital rewards, letting you engage respondents effortlessly. Create reward automation campaigns to send rewards instantly, eliminating manual gift-code management for a seamless experience. ## Highlights of the Integration Once the integration between the two platforms is enabled, you no longer have to juggle between spreadsheets to track or manage reward campaigns, or manually procure and distribute rewards. Xoxoday Plum not only simplifies the rewarding process but also brings a host of value additions to the integration. Here are some of the key highlights: * **Automated Rewards on Completion of Survey** The integration allows you to set up Reward automation Campaigns on Xoxoday Plum and send out rewards to respondents who complete the survey. Not just that, the survey respondents can choose gifts, perks, and experiences of their choice from Xoxoday’s extensive global catalog.You can also restrict the number of rewards sent out based on criteria like - campaign time range, Maximum Reward count, etc. * Built-in Approval Workflows Integration with Xoxoday allows you to have complete control over whom among your respondents to send the rewards to. The built-in approval system lets you review and approve respondents individually or in bulk. This ensures that there are no repeat claims that take place. * **Customised Communication Templates** Survey rewards can be sent to respondents through customized email templates that represent your organizational DNA - with your own logo, messaging, and images. This ensures they are instantly recognised and don't get lost in their inbox. * **Dedicated Redemption Support** Our API integrations ensure that the redemption process is seamless and non-intrusive for your users. Furthermore, we also offer global support for all your user queries during redemption. ## How does the Integration Work? Follow the step-by-step guide to set up the integration between Xoxoday Plum and Forsta, and create & run reward campaigns. ## STEP 1: Connect to Decipher Go to Integrations and Search for **Forsta (Decipher).** \*\*​ Click on ‘Connect\*\*’ ​ Enter the API Key provided by Forsta (Decipher) account to authenticate and connect your account. Once the Authentication is done, you are now successfully connected to Xoxoday. This authentication allows Xoxoday to fetch the Survey Projects on Frosta and set Reward Automation to send rewards. Setting up Reward Automation Reward Automation defines Reward Campaigns and provides additional settings to the reward processing. Click on ‘Create new Automation Here, Name the Automation and Select the Survey from the Frosta account for which you want to send rewards to respondents. ​ In the next steps, Select the Reward Campaign you already set up, which defines the reward denomination, catalog, and reward email. You can set: * Expiry of Automation: Define the end date of automation. * Approval type: Automatic: Automatically send rewards as soon as the survey is submitted by the respondent. * Manual: This will capture the respondents and you can choose whom they send reward by simply choosing to Approve or Reject button. Click on ‘Save and Launch’ to start reward Automation. ​ Once created, Copy the reward claim page link and paste it into Redirect URL of your Survey. ​ # Complete Wellness with Fitterfly Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/complete-wellness-with-fitterfly Learn how the Plum-Fitterfly integration gives employees access to Complete Wellness programs as part of your rewards and benefits catalogue. *Learn about integrating Wellness with Fitterfly* ## About Fitterfly Fitterfly is a health-tech startup specializing in digital therapeutics (DTx) for metabolic health. Fitterfly combines personalized coaching with advanced technology to help individuals manage and reverse chronic conditions. Fitterfly's programs are clinically validated and have shown significant improvements in health outcomes, including reductions in HbA1c levels, weight loss, and enhanced physical fitness. ## Key Benefits * **For HRs** Holistic Employee Wellness Empower your workforce with personalized digital health programs that address diabetes, weight, and lifestyle management — promoting overall well-being. * Improved Productivity & Engagement Healthier employees are more focused, energetic, and motivated, leading to better workplace performance. * Preventive Health Insights Gain access to anonymized wellness data and trends to identify potential health risks and plan proactive interventions. * Scalable, Digital Implementation Easily integrate Fitterfly’s digital platform across teams, ensuring smooth access without logistical challenges. * For Employees Personalized Health Coaching Get digital programs tailored to your unique needs — from managing diabetes to maintaining a healthy weight and lifestyle. * Continuous Progress Tracking Monitor your health metrics and track improvements with smart digital tools and real-time insights. * Expert Support at Your Fingertips Access guidance from certified coaches, nutritionists, and wellness professionals anytime, anywhere. * Sustainable Lifestyle Habits Adopt small, consistent changes that help build long-term health, energy, and confidence. ## Support For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Comprehensive Flexibility & Mobility Wellness with STRETCHIT Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/comprehensive-flexibility-mobility-wellness-with-stretchit See how the Plum-StretchIt integration lets you offer employees flexibility and mobility wellness programs through your rewards catalogue. *Learn all about integrating STRETCHIT* ## About STRETCHIT STRETCHIT is a digital flexibility and mobility training platform designed to improve movement, posture, and overall physical well-being. The platform provides structured stretching programs guided by expert coaches to help users reduce muscle stiffness, prevent injuries, and improve flexibility over time. Through the STRETCHIT mobile app, users gain access to personalized stretching routines, guided mobility sessions, and progressive training programs tailored to different fitness levels and health goals. The platform focuses on improving mobility, reducing musculoskeletal discomfort, and supporting healthier movement habits for people with sedentary or desk-based lifestyles. ## Why connect with STRETCHIT Integrating STRETCHIT enables organizations to support employee well-being by addressing mobility, posture, and physical strain caused by long working hours and sedentary routines. This integration helps companies introduce structured flexibility programs that encourage movement, reduce workplace discomfort, and improve overall employee wellness. ## Key Benefits **For Leaders and HR**- Improved workplace wellness Structured flexibility programs help address common workplace issues such as back pain, muscle stiffness, and poor posture. * Preventive health support Regular stretching routines can help reduce the risk of musculoskeletal issues and support long-term physical well-being. * Employee engagement Interactive wellness programs encourage employees to stay active and maintain healthier daily routines. * Seamless program access Employees can easily access flexibility training sessions through the platform. For Employees * Guided stretching programs Access professionally designed flexibility routines tailored to different skill levels. * Improved mobility and posture Programs designed to help relieve tension from long sitting hours and improve body alignment. * Convenient training sessions Short and effective sessions that can be performed anytime through the STRETCHIT mobile app. * Progressive flexibility training Structured programs that help employees gradually improve flexibility and range of motion. ## How Employees Can Use STRETCHIT * Guided Stretching Sessions Employees can follow structured stretching routines led by professional trainers that target flexibility, mobility, and posture improvement. * **Mobility Training Programs** Users can participate in progressive mobility programs designed to improve joint health and muscle flexibility. * **Workplace-Friendly Routines** Short routines designed specifically for people who spend long hours sitting or working at a desk. * **Progress Tracking** Employees can track their flexibility progress and stay consistent with guided sessions through the STRETCHIT mobile app. * **Corporate Wellness Programs** Organizations can introduce flexibility and mobility training programs to support employee health, reduce physical strain, and promote active lifestyles. For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Comprehensive Home Healthcare Made Easy with Portea Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/comprehensive-home-healthcare-made-easy-with-portea Learn how the Plum-Portea integration brings comprehensive home healthcare benefits to employees directly through your rewards program. *Learn more about integration with Portea* ## About Portea Portea is a trusted home healthcare company, delivering doctor consultations, physiotherapy, nursing, lab tests, and chronic care management right at patients’ doorsteps. Operating across 60+ cities with 4,000+ clinicians, Portea brings hospital-quality healthcare to homes—reducing hospital visits and ensuring continuous care with convenience for healthier, happier employees and families. ## Why Connect Portea with Xoxoday Plum Integrating Portea helps organizations provide employees and their families with easy access to home healthcare services. Employees can book medical visits, physiotherapy, or lab tests at home, while business leaders can promote preventive health, reduce absenteeism, and support employees’ holistic wellbeing—especially for aging family members or those recovering from illness. ## Key Benefits **For Employers**- \*\*End-to-end health support Offer home-based medical and nursing care as part of employee benefits. * Reduce absenteeism Enable faster recovery and continuity of work through at-home care. * Inclusive wellness Extend benefits to employees’ families and dependents. * Stronger wellbeing culture Promote preventive and post-hospitalization care programs. For Employees * **Convenient Home Healthcare** \*\* Access professional medical care, nursing, and wellness services from the comfort of home—saving time and ensuring continuous care. * Trusted Support for Family Health\*\* \*\* Receive reliable and compassionate healthcare solutions for yourself and your loved ones, including specialized elder care services. ## Support For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com) # Comprehensive Wellness with HealthiFy Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/comprehensive-wellness-with-healthify See how the Plum-Healthify integration lets you deliver comprehensive employee wellness programs as part of your rewards and benefits offering. *Learn how to integrate Xoxoday with HealthiFy* ## About HealthiFy HealthiFy is a global digital health and wellness platform offering AI-led nutrition, fitness, and wellness solutions. Combining advanced analytics with human expertise, it helps users build healthy habits through data-driven insights and coaching support. ## Why Integrate with HealthiFy The integration enables HR teams to deliver a unified, science-backed wellness experience for employees. Through this integration, employees can access wellness programs, monitor progress, and receive expert guidance—all within their corporate wellness ecosystem. ## Key Benefits * **For Employers/ HR Leaders** Comprehensive wellness ecosystem Offer employees AI-powered health tracking, expert coaching, and engagement tools in one platform. * Seamless integration Embed HealthiFy’s programs directly into the platform for unified wellness delivery. * Data insights & engagement Track participation, engagement, and overall wellness trends across teams. * Preventive health impact Encourage early health awareness and reduce long-term healthcare costs. * ## For Employees Personalised wellness journey Receive customized plans for diet, exercise, and mindfulness. * Continuous support Access guidance from professional health coaches and AI-driven insights. * Sustainable habit formation Build long-term healthy routines through consistent nudges and motivation. * Engaging digital experience Use the HealthiFy app to log meals, track progress, and celebrate milestones. ## How Employees Can Redeem Points Using HealthiFy * Enroll in the Program Employees can sign up through the Xoxoday platform and get a personalized wellness assessment. * Set Health Goals Define goals—such as fitness, nutrition, or mindfulness—and receive tailored plans. * Track Daily Progress Use the Healthify app to log meals, workouts, and hydration. * Get Expert Support Interact with nutritionists and fitness coaches for customized advice. * Stay Motivated Participate in wellness challenges, leaderboards, and team activities for engagement. ## Support For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Comprehensive Wellness with Humm Care Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/comprehensive-wellness-with-humm-care Learn how the Plum-Humm Care integration supports employee wellness with comprehensive care benefits available through your rewards catalogue. *Learn more about integration with Humm Care* ## About Humm Care Humm Care provides comprehensive, inclusive healthcare solutions focused on women’s health, family care, and eldercare. Through expert consultations and personalized programs, it supports employees across fertility, pregnancy, postpartum, and caregiving journeys. Why Connect with Humm Care Integrating Humm Care offers employees holistic wellness support across life stages while enabling HR teams to track engagement and well-being, fostering a healthier, more supported workforce. ## Key Benefits * For HRs Enhanced Employee Well-being Support employees through life’s most important phases with structured maternal and childcare programs that promote physical and emotional health. * Improved Retention & Loyalty Provide meaningful benefits that help new and expecting parents feel supported, reducing turnover and increasing long-term engagement. * Inclusive Wellness Offering Create a family-friendly workplace by extending wellness initiatives beyond traditional healthcare to include maternal and child development support. * Seamless Program Integration Easily enable Humm Care’s services through Xoxoday’s platform, ensuring convenient access for employees across locations. * For Employees \*\*Work-Life Balance Support Access flexible, family-centered care options that help balance personal wellness and professional responsibilities with ease. * Emotional and Mental Well-being Benefit from empathetic care programs and resources that promote mental resilience and reduce stress during major life transitions. * Reliable Expert Network Connect with trusted healthcare professionals, counselors, and specialists for guidance whenever needed. * Empowered Health Awareness Gain knowledge and confidence to make informed health and lifestyle choices for yourself and your family. ## How Employees Can Use Humm Care Humm Care provides comprehensive support programs for maternal health, prenatal care, and child development\*\*, helping parents and expecting parents navigate every stage with expert guidance and confidence. * Maternal Health Support Access tailored health programs that support physical and emotional well-being throughout pregnancy and postpartum recovery. * Prenatal Care Programs Receive personalised care plans, consultations, and resources to ensure a safe and well-supported prenatal experience. * Child Development Support Get expert advice and developmental guidance to monitor and enhance your child’s early milestones and well-being. * Easy Digital Access Connect with healthcare professionals, access educational content, and manage your journey conveniently through Humm Care’s digital platform. ## Support For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Comprehensive Wellness with Unlock.fit Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/comprehensive-wellness-with-unlockfit See how the Plum-UnlockFit integration enables comprehensive employee wellness benefits as part of your organization's rewards catalogue. *Learn how to integrate Unlock.Fit with Xoxoday* ## About Unlock.fit Unlock.fit is a cutting-edge wellness platform that leverages genetic insights to deliver personalized nutrition and fitness plans. By analyzing over 700,000 gene markers, Unlock.fit provides users with tailored recommendations that align with their unique genetic makeup. Their services include DNA testing, blood analysis, personalized diet plans, exercise routines, and expert consultations, all accessible through a user-friendly mobile app. ## Why this integration Integrating Unlock.fit enables HR teams to offer employees a holistic wellness program that combines genetic insights with personalized nutrition and fitness plans. This integration supports preventive healthcare, enhances employee engagement, and promotes a culture of health and well-being within the organization. ## Key Benefits * For Organization/ HR Leaders Comprehensive wellness supportDNA and blood-based analysis to tailor nutrition and fitness plans. * Data-driven insights Access to anonymized wellness reports to monitor employee health trends. * Employee engagement Personalized wellness programs that foster a healthier, more productive workforce. * Seamless integration Easy deployment and management through the platform. * For Employees Personalized wellness plans Tailored nutrition and fitness recommendations based on genetic and health data. * Expert guidance: Access to certified nutritionists and fitness coaches for ongoing support. * Convenient access Wellness programs available anytime, anywhere through the Unlock.fit app. * Holistic health approach Programs designed to address individual health goals and challenges. ## How Employees Can Use Unlock.fit * DNA & Blood Testing Employees can collect saliva and blood samples using provided kits, which are then analyzed to provide insights into their genetic and health profiles. * Personalized Wellness Plans Based on test results, employees receive customized diet and exercise plans designed to optimize their health and performance. * Expert Consultations Access to certified nutritionists and fitness coaches for personalized guidance and support. * Progress Tracking Monitor health metrics and track progress through the Unlock.fit mobile app, ensuring continuous improvement and engagement. * Corporate Wellness Programs Organizations can implement DNA-based wellness programs, like CorpGene, to enhance employee health and productivity on a larger scale. ## Co-Sponsor & Deliver Unlock.fit Benefits at Scale Employers can roll out Unlock.fit’s personalized wellness programs across their organization, ensuring every employee has access to tailored health solutions. By this integration, companies can streamline wellness initiatives, track engagement, and foster a culture of health and well-being. ## Support For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Dental Care with Clove Dental Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/dental-care-with-clove-dental Learn how the Plum-Clove Dental integration lets you offer employees dental care benefits directly through your rewards and benefits program. *Learn more about integration with Clove Dental with Xoxoday* ## About Clove Dental Clove Dental is India's largest dental chain with 600+ multi-specialty clinics, 1200+ expert dentists, and presence across 27 cities. Their Corporate Dental Health Programme addresses stress-related oral health issues through preventive education, assessments, and accessible healthcare delivery, helping organizations reduce dental-related absenteeism and healthcare costs. ## Why Connect Clove Dental Employees gain easy access to dental checkups, treatments, and emergency care at convenient locations, while HR can promote wellness, reduce absenteeism, and demonstrate care through accessible health benefits. ## Key Benefits * **For Organizations** All-in-one platform: rewards + comprehensive dental wellness * Nationwide coverage: 600+ clinics across 27 cities for easy employee access * Reduced absenteeism: Preventive care addresses dental issues before they escalate * Simplified administration: Centralized booking and benefit delivery at scale * **For Employees** Convenient access: Walk-in appointments at 600+ clinics near home or office * Weekend availability: All clinics open on Saturdays and Sundays * Comprehensive care: From routine checkups to complex procedures * Expert treatment: 1200+ qualified dentists including specialists * Flexible payments: Cash, card, and digital payment options ## How Employees Can Use Clove Dental * **Preventive Care** Routine dental checkups, cleanings, and oral health assessments to catch issues early and maintain healthy gums and teeth. * **Restorative Treatments** Comprehensive solutions like root canal therapy, crowns, dentures, and dental implants to restore function and comfort. * **Orthodontics & Alignment** Consultations and treatments for braces, clear aligners, and bite correction to achieve proper teeth alignment. * **Cosmetic Dentistry** Teeth whitening, veneers, and smile enhancement procedures to boost confidence and appearance. * **Surgical & Emergency Care** Safe wisdom tooth extractions, emergency dental treatments for pain or injury, and immediate care for infections or trauma. * **Corporate Dental Wellness** On-site dental camps, awareness sessions, and educational programs to promote preventive oral health at the workplace. ## Co-Sponsor Health Benefits with Ease Xoxoday allows organizations to co-sponsor wellness benefits like Clove Dental at reduced costs, making it simple to invest in employee well-being without exceeding budget constraints. ## Support For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Digital Healthcare for Employees with Practo Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/digital-healthcare-for-employees-with-practo See how the Plum-Practo integration gives employees access to digital healthcare consultations as part of your organization's benefits catalogue. *Learn more about integration with Practo* ## About Practo Practo is a digital healthcare platform that connects employees with doctors across 25+ specialties for both online and in-person consultations. It offers a complete healthcare ecosystem including medicine delivery, diagnostic tests, dental care, and preventive health checkups. Through one easy-to-use app, Practo ensures employees can access trusted medical care anytime, anywhere. ## Why Connect with Practo? Integrating with Practo enables organizations to extend reliable, round-the-clock healthcare support to their workforce. Employees can easily access medical consultations, book diagnostic tests, or schedule health checkups from their devices. For HR, it simplifies benefit distribution, strengthens employee wellbeing, and reduces absenteeism through preventive care. ## Key Benefits ## For Business Leaders/HR * Seamless healthcare integration Offer employees convenient access to medical services directly through Xoxoday platform. * Preventive wellness programs Encourage regular checkups and early diagnosis to maintain workforce health. * Improved productivity Reduce sick leaves and boost employee morale by providing easy access to care. ## For Employees * All-in-one medical access Connect with doctors, book tests, or get medicines—all through a single app. * Choice and convenience Select from 25+ specialties and access care online or at clinics near you. * Trusted quality care Consult certified doctors and specialists, ensuring reliable treatment and guidance. ## How Employees Can Use Practo * Health Checkup Book comprehensive preventive health packages and diagnostic tests online with quick scheduling and trusted results. * Teleconsultation Consult general physicians or specialists online for quick, reliable, and secure medical advice—without leaving home. * OPD Care Access affordable outpatient care packages for routine checkups and specialized medical consultations. ## Support For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Employee Wellness Sessions with 1to1 help Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/employee-wellness-sessions-with-1to1-help Learn how the Plum-1to1Help integration lets employees book wellness sessions through your rewards and benefits catalogue. *Learn all about integration with 1to1help* ## About 1to1help 1to1Help is a holistic employee well-being platform offering personalized counselling and expert-led support. It helps employees manage stress, mental health, and personal challenges, while enabling organizations to build a healthier, productive, and emotionally resilient workforce. ## Why Integrate with 1to1help? Integration with 1to1help brings well-being and recognition together on one platform. Employees get the mental health support they need, while HR teams can drive engagement and rewards alongside holistic wellness programs. ## Key Benefits For Organizations/Business Leaders/HR Leaders * Manage recognition and well-being from a centralized platform * Provide easy access to counselling services * Boost engagement with automated rewards and recognition For Employees * Confidential, one-on-one counselling sessions * Direct access to well-being resources within Empuls * Work in a supportive, mental health-friendly environment ## How Employees Can Use 1to1help 1to1Help gives employees a confidential and convenient way to address personal and professional challenges. * Manage Stress & Anxiety Get guidance on coping with work stress, deadlines, or anxiety * Learn practical techniques to reduce tension and stay focused * Maintain Work-Life Balance Receive support in balancing professional responsibilities with personal commitments. * Tips for managing time, prioritizing tasks, and avoiding burnout. * Career Guidance & Performance Coaching Improve productivity, focus, and overall performance. * Explore career decisions, goal-setting, and professional development opportunities. * Relationship & Family Support Guidance on managing interpersonal challenges, family stress, or parenting concerns. * Learn strategies to resolve conflicts and improve communication. * Emotional & Mental Health Support Discuss feelings of burnout, low motivation, or emotional distress in a safe space. * Receive practical advice from trained counsellors. ## Support For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Employee Wellness Support with Samvedna Care Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/employee-wellness-support-with-samvedna-care See how the Plum-Samvedna Care integration supports employee wellness by making counselling and care services available through your benefits catalogue. *Learn more about integrating Samvedna Care* ## About Samvedna Care Samvedna Care supports employee emotional wellbeing with counseling, individual and group therapy, and eldercare. Expert counsellors reduce stress, build resilience, and address work-life challenges, fostering a culture that prioritises mental health, awareness, and employee satisfaction. ​ ## Why Connect Samvedna Care Xoxoday Plum and Samvedna Care combine engagement and wellbeing—giving employees easy access to online counselling, psychiatrist consultations, eldercare and dementia support, while helping HR promote workplace mental health, drive participation, and improve overall well‑being and productivity. ## Benefits * **For Employers** One platform for counseling, therapy, and eldercare support. * Fosters a mental-health-first culture. * Boosts satisfaction with expert care. * Frees HR to focus on programs. * **For Employees** Easy access * Individual or group therapy options. * Eldercare guidance for better balance. * A workplace that prioritizes well-being. ## How Employees Can Use Samvedna Care * Access to Counseling Book one-on-one sessions easily with experienced counselors for stress management, emotional support, or personal issues. * Mental Health Assessments Take confidential self-assessments to evaluate their mental health and get personalized recommendations. * Elder Care Support Avail guidance and support for employees managing eldercare responsibilities, reducing stress and improving focus at work. * Workshops & Training Participate in mental wellness workshops and training sessions to build emotional resilience and improve overall well-being. * Confidentiality Completely confidential interactions allowing employees to feel safe and supported when seeking help. ## Support For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Empower Employee Mental Wellness with Your DOST Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/empower-employee-mental-wellness-with-your-dost Learn how the Plum-YourDOST integration empowers employee mental wellness by making counselling support available through your rewards catalogue. *Learn more about integrating Xoxoday with Your DOST.* ## About Your DOST Your DOST provides confidential mental health support through one-on-one counseling, self-help tools, and workshops. Its clinically validated approach builds emotional resilience and long-term wellbeing for employees. ## Why this integration This integration brings mental health and employee engagement together on one platform. Employees can access confidential counseling and self-care tools directly through Xoxoday, while HR teams can foster an open, stigma-free culture of emotional wellness — leading to improved morale, reduced burnout, and stronger team connections. ## Key benefits **For business leaders and HR**- **Enhance employee wellbeing** — Address emotional and mental health proactively. * **Boost productivity** — Support mental clarity, focus, and motivation at work. * **Reduce attrition** — Help employees manage burnout and stress effectively. * **Measure impact**— Access anonymized wellness insights to guide HR initiatives.**For employees**- **24/7 availability** — Access emotional support anytime, anywhere. * **Diverse expertise** — Reach professional counsellors specializing in stress, anxiety, relationships, career issues, and more. * **Personal growth** — Access life coaching for confidence, performance, and leadership skills. * **Completely private** — All sessions are 100% confidential and secure. ## How employees can use Your DOST * **Connect with a counselor** — Book one-on-one online sessions with licensed psychologists or life coaches. * **Instant chat support** — Get immediate help through real-time chat with emotional wellness experts. * **Video or audio therapy** — Choose flexible formats for therapy sessions based on comfort and need. * **Self-help tools** — Access personalized assessments, progress tracking, and self-guided exercises. * **Confidentiality and security** — All data and sessions are encrypted and anonymized to protect employee privacy. ## Deliver Your DOST benefits at scale Integrating Your DOST with Xoxoday unites mental health and engagement in one place — enabling easy access to mental health counselling while helping HR nurture a stigma-free culture of wellbeing. ## Support For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Empower Employee Wellbeing with TruWorth Wellness Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/empower-employee-wellbeing-with-truworth-wellness See how the Plum-Truworth Wellness integration empowers employee wellbeing with health programs available through your benefits catalogue. *Learn more about integrating TruWorth with Xoxoday* ## About TruWorth Wellness TruWorth Wellness is a leading digital corporate wellness platform helping organizations enhance employee health through analytics, preventive care, and expert coaching—creating happier, healthier, and more productive workplaces at scale. ## Why Connect with TruWorth Wellness Integrating TruWorth Wellness enables organizations to deliver data-driven wellness programs, monitor engagement, and give employees easy access to health assessments, fitness challenges, and expert consultations—all in one platform. ## Key Benefits * **For Business Leaders/HR** **Holistic Wellness Engagement:** Combine engagement activities with customized wellness journeys. * **Actionable Insights:** Use analytics and dashboards to measure program impact and participation. * **Enhanced Productivity:** Promote preventive health to reduce absenteeism and improve morale. ## Support For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Empower Women’s Wellness Journeys with Newmi Care Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/empower-womens-wellness-journeys-with-newmi-care Learn how the Plum-Newmi Care integration supports women's wellness journeys by making specialised care available through your rewards catalogue. *Learn more about Newmi Care integration* ## About Newmi Care Newmi Care is India’s first comprehensive women’s wellness ecosystem that supports women across every stage of life—menstruation, fertility, pregnancy, motherhood, and menopause. The platform brings together expert consultations, curated wellness programs, and a marketplace of trusted health and lifestyle products designed exclusively for women’s physical, mental, and emotional wellbeing. ## Key Benefits * **For Employers** **Inclusive wellness initiative:** Promote women’s health and wellbeing through tailored programs. * **Effortless rollout:** Deliver healthcare, counselling, and lifestyle benefits via Empuls. * **Engagement & retention:** Build a culture of care and inclusivity through holistic wellness support. * **For Employees** **End-to-end wellness support:** Access programs for fertility, pregnancy, parenting, and beyond. * **Expert consultations:** Book gynecologists, nutritionists, and therapists anytime. * Curated marketplace:Explore and shop trusted women’s health and wellness products.**How Employees Can Use Newmi** Care * Book Wellness Services Employees can use the Newmi Care platform to schedule consultations, join fitness or nutrition programs, and access specialized women’s health services—directly through Empuls. * Explore the Newmi Care Store Discover products across maternity, hygiene, and self-care categories tailored to women’s unique needs. ## Co-Sponsor & Deliver Newmi Care at Scale Integrate Newmi Care across your organization through Empuls to drive holistic women’s wellness initiatives. Celebrate inclusivity, support every stage of women’s health, and make wellbeing a core part of your workplace culture. ## Support For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Fast Diagnostic Testing with Orange Health Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/fast-diagnostic-testing-with-orange-health See how the Plum-Orange Health integration gives employees access to fast diagnostic testing as part of your organization's benefits catalogue. *Learn more about integrating Orange Health* ## About Orange Health Orange Health is a modern diagnostics platform that delivers lab tests at home in just 60 minutes, combining speed, accuracy, and convenience. With NABL-accredited labs and expert phlebotomists, Orange Health makes preventive and diagnostic testing simple, seamless, and trusted for individuals and families. ## Why Connect with Orange Health Adding Orange Health empowers employees to take charge of their health with quick, at-home diagnostics. It eliminates the need to visit labs or wait for appointments — ensuring health checks fit easily into employees’ schedules while maintaining the highest testing standards. ## Key Benefits **For HR/ Leaders**- **Wellbeing made easy:** Offer employees instant access to at-home lab testing. * **Low admin lift:** Partner-managed logistics, communication, and report delivery. * Reliable network:Backed by NABL-accredited labs for accurate, professional results.**For Employees**- **At-home testing:** Book tests online and get samples collected at home in 60 minutes. * **Quick results:** Receive verified reports digitally within 6–8 hours. * **Trusted care:** Enjoy hospital-grade accuracy, hygiene, and service quality. ## How Employees Can Use Orange Health Access Orange Health to book preventive or diagnostic lab tests. Choose your preferred time slot, have samples collected at home, and receive certified reports directly on your phone or email — all within hours . ## Co-Sponsor & Deliver Orange Health at Scale Employers can make Orange Health available across teams to promote preventive healthcare and early detection. It’s a powerful way to strengthen employee wellbeing through fast, reliable, and accessible diagnostics. ## Support For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Holistic Employee Wellness with YogiFi Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/holistic-employee-wellness-with-yogifi Learn how the Plum-YogiFi integration delivers holistic employee wellness benefits, including guided yoga and fitness, through your rewards catalogue. *Learn more about integrating with YogiFi* ## About YogiFi YogiFi is an innovative AI-powered yoga solution that integrates intelligent sensor technology to offer personalized, real-time posture feedback during yoga sessions. This intelligent yoga mat helps users enhance their practice by providing accurate corrections, ensuring a more effective and therapeutic yoga experience. ## Why Connect with YogiFi? Integrating YogiFi allows HR teams and business leaders to promote physical wellness through personalized yoga programs. Employees can access real-time posture feedback and therapeutic yoga sessions, fostering a healthier workforce. HR leaders can track engagement, encourage holistic wellness, and reduce stress-related absenteeism, all while promoting a culture of wellness within the organization. ## Key Benefits * For Business Leaders/ HR Leaders AI-driven wellness supportPersonalized yoga sessions that correct posture and enhance practice. * Data-driven insights Monitor engagement and track wellness metrics across your organization. * Employee retention boost Improve morale and productivity through tailored wellness initiatives. * Simplified program delivery Easily integrate YogiFi’s digital yoga programs across the workforce. * For Employees Real-time posture feedback Improve your yoga practice with AI-powered corrections. * Therapeutic yoga sessions Enjoy stress relief and mental clarity anytime, anywhere. * Accessible wellness Yoga sessions that fit into any schedule and require no prior experience. * Interactive learning Engage with personalized sessions that adapt to your skill level. ## How Employees Can Use YogiFi * Personalized Yoga Classes Employees can participate in yoga sessions tailored to their unique needs, with real-time feedback that helps improve posture and enhances the practice. * Therapeutic Sessions Enjoy instant stress relief and therapeutic benefits with sessions designed to promote mental clarity and physical wellness. * Anywhere, Anytime Access With YogiFi, employees can practice yoga from the comfort of their home, office, or while traveling, ensuring wellness is always within reach. * Posture Correction YogiFi’s AI-driven sensor technology provides accurate posture corrections during yoga sessions, helping employees maintain proper alignment and avoid strain. * Engagement & Tracking HR leaders can monitor employee engagement with the program, track wellness progress, and ensure that every employee has access to the resources they need for a healthier lifestyle. ## Support For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Holistic Fitness & Wellness with Cult.fit Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/holistic-fitness-wellness-with-cultfit See how the Plum-cult.fit integration offers employees holistic fitness and wellness benefits directly through your rewards and benefits catalogue. *Learn all about integrating Xoxoday with Cult.fit* ## About Cult.fit Cult.fit is India's largest integrated fitness and wellness platform with 200+ cult centers, 8,000+ partner gyms, and presence across 25+ cities. Their corporate wellness program combines fitness, nutrition, sports, and engagement activities to help organizations improve employee health, boost productivity, and create a culture of wellness through flexible access to workouts, expert guidance, and company-wide challenges. ## Why this integration This integration combines employee recognition with comprehensive fitness and wellness. Employees get flexible access to workouts, sports, nutrition, and wellness programs, while HR can drive engagement through wellness, track analytics, and demonstrate commitment to employee wellbeing. ## Key Benefits * **For HR** All-in-one platform Enhance the rewards and recognition ecosystem with easy access to fitness * Drive engagement Improve engagement with fitness challenges and transformation contests * Flexible offerings Avail the services at the center, at-home, and sports options for diverse workforce * For Employees Multiple workout options Easy access to 200+ cult centers + 8,000+ partner gyms nationwide * Flexible scheduling Avail the services from the center, at-home workouts * Expert guidance: Take guidance from the best of trainers, nutritionists, and wellness coaches * Convenience Book classes, track progress, and workout anytime through the cult app ## How Employees Can Use Cult.fit * Gym Access Across India Get a 12-month gym membership with options like Cult Elite, Fitternity OnePass (includes OnePass & Cult HOME), or Fitso/Cultpass PLAY — giving you flexibility to choose how and where you work out. * Train Your Way Enjoy access to top gyms, fitness studios, and Cult centers nationwide. Choose in-person workouts or home-based sessions through the Cult platform (as per your selected pass). * Dietician Consultations Opt for 3, 6, or 8 consultation sessions with certified dieticians to receive personalized nutrition guidance and maintain healthy habits. * All-in-One Fitness Solution Combine expert-led workouts and professional nutrition support to stay active, motivated, and balanced throughout the year. ## Support For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Integrated Health & Wellness Solutions with MediBuddy Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/integrated-health-wellness-solutions-with-medibuddy Learn how the Plum-MediBuddy integration provides employees with integrated health and wellness solutions through your rewards catalogue. *Learn all about integrating Xoxoday with MediBuddy* ## About MediBuddy MediBuddy is a leading digital healthcare platform offering comprehensive medical services, including online consultations, lab tests, medicine delivery, mental health support, and preventive care. With a trusted nationwide network, it makes quality healthcare accessible, affordable, and convenient for individuals and organizations alike. ## Why this integration Integrating MediBuddy with Xoxoday allows organizations to promote preventive care, reduce absenteeism, and improve employee wellness through on-demand digital healthcare. Employees gain instant access to qualified doctors and essential medical services, while HR leaders can track health engagement, drive wellness initiatives, and create a healthier, more productive workplace. ## Key Benefits * **For Employers/HR Leaders** Comprehensive wellness coverage Integrate physical and mental health services into employee benefits. * Reduce medical claims Encourage preventive care through early diagnosis and regular check-ups. * Boost productivity Support employees’ health to minimize downtime and stress-related issues. * Data insights Monitor utilization trends and wellness participation securely. * For Employees Convenient Access to Healthcare Employees can easily book health checkups, consultations, and diagnostic tests online, making healthcare accessible and hassle-free. * Affordable and Reliable Medical Support With cost-effective OPD and teleconsultation options, employees receive dependable medical care and advice without leaving home. ## How Employees Can Use MediBuddy * Book Health Checkups Schedule comprehensive preventive health checkups and diagnostic tests easily through MediBuddy for reliable results. * Access OPD Packages Choose affordable outpatient consultation packages for routine health checkups and specialized medical care. * Connect via Teleconsultation Consult with doctors online conveniently from home through MediBuddy’s teleconsultation feature. * Manage Healthcare Digitally Use the MediBuddy platform to book services, access reports, and track appointments in one place. ## Co-Sponsor & Deliver Medibuddy Benefits at Scale Employers can implement MediBuddy Corporate Health Programs to offer doctor access, preventive care, and comprehensive medical services to their teams. By digitizing healthcare delivery, organizations can ensure their employees stay healthy, engaged, and supported—both physically and mentally. ​ ## ​Support For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Master O Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/master-o See how the Plum-Master-O integration connects gamified learning and training outcomes to rewards, letting you incentivise employee skill-building. *Learn all about integration with Master O* ## About Master-O Master-O is a gamified microlearning platform delivering bite-sized training to sales and support teams—boosting knowledge, engagement, and performance. ## Why Connect Master-O with Empuls Blend recognition with continuous, snackable learning—easy to launch, fun to complete, and proven to reinforce skills. ## Key Benefits ### For HR * High engagement: Game mechanics keep learners active. * Faster rollout: Micro modules fit busy schedules. * Skills tracking: Monitor progress and outcomes. ### For Employees * Short, impactful lessons: Learn in minutes, retain more. * Practice through play: Quizzes and challenges reinforce skills. * Sales & support focus: Directly tied to daily workflows. ## How Employees Can Use Master-O * Interactive Microlearning: Consume bite-sized lessons designed for quick retention. * Game-Based Assessments Reinforce learning with gamified quizzes and challenges. * Sales Enablement Use microlearning tools to strengthen sales techniques and customer engagement skills. * Spaced Learning Workflows Follow structured workflows that reinforce concepts over time. ## Support For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Personalized Nutrition and Weightloss with Fitelo Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/personalized-nutrition-and-weightloss-with-fitelo Learn how the Plum-Fitelo integration offers employees personalized nutrition and weight-loss coaching programs through your benefits catalogue. *Learn more about integrating Fitelo* ## About Fitelo Fitelo is India's personalized nutrition and wellness platform with 500+ doctors, nutritionists, and lifestyle experts, serving 25,000+ users across 55+ countries. Their evidence-based approach addresses weight management, disease management, and lifestyle transformation through customized diet plans based on individual body types, medical conditions, and preferences—helping organizations reduce lifestyle-related absenteeism and healthcare costs. ## Why Connect Fitelo with Xoxoday Plum Integrating Fitelo with Xoxoday Plum combines employee engagement with personalized nutrition and wellness. Employees gain access to expert-led diet plans, health coaching, and disease management support, while HR can promote preventive health, track wellness outcomes, and build a culture of sustainable wellbeing. ## Key Benefits ## For Employers * **All-in-one platform:** Execute employee engagement and personalized nutrition and wellness * **Reduce healthcare costs:** Address lifestyle diseases before they escalate * **Boost productivity:** Healthier employees with improved energy and focus * **Measurable outcomes:** Gain visibility into engagement levels, health scores, and program outcomes with real-time reports. ## For Employees * **Personalized plans:** Diet plans tailored to body type, lifestyle, and medical conditions * **Expert guidance:** 500+ nutritionists, doctors, and wellness coaches * **Holistic approach:** Nutrition, fitness, and habit coaching * **Long-term results:** Sustainable lifestyle changes, not quick fixes For set up or usage assistance, reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com) # Preventive Health Checkups with Healthians Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/preventive-health-checkups-with-healthians See how the Plum-Healthians integration gives employees access to preventive health checkups as part of your organization's rewards catalogue. *Learn all about integration with Healthians* ## About Healthians Healthians is India’s leading health test at-home service offering a wide range of diagnostic tests, full body check-ups, and preventive health packages. With certified labs, trained phlebotomists, and accurate reports delivered digitally, Healthians makes preventive healthcare simple, affordable, and accessible right at your doorstep. ## Why Connect with Healthians Integrating Healthians with Xoxoday brings preventive healthcare into your recognition and engagement ecosystem. Employees can book convenient at-home tests and receive digital reports, while HR can promote participation in checkups, support wellbeing initiatives, and signal a strong commitment to employee health. ## Key Benefits * **For Business Leaders/HR** Promote Employee Health and Productivity Encourage preventive checkups to reduce sick days and build a healthier, more productive workforce. * Boost Employee Satisfaction and Retention Improving employee satisfaction, loyalty, and retention with at-home health services. ## How Employees Can Use Healthians * Book At-Home Sample Collection Choose the required diagnostic test or check-up and schedule a doorstep visit at a convenient time. * Quality & Safety Benefit from certified labs and trained phlebotomists for a reliable testing experience. ## Support For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Preventive Health Checkups with Thyrocare Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/preventive-health-checkups-with-thyrocare Learn how the Plum-Thyrocare integration offers employees preventive health checkups directly through your organization's benefits catalogue. *Learn more about integration with Thyrocare* ## About Thyrocare Thyrocare is one of India’s leading diagnostic and preventive healthcare service providers, offering a wide range of pathology and wellness tests through a trusted, technology-driven network. With a focus on accuracy, affordability, and convenience, Thyrocare ensures early detection and proactive health management for employees and their families. ## Why Connect with Thyrocare Adding Thyrocare supports employee wellbeing by making preventive health checkups easy to access and affordable. With nationwide coverage, at-home sample collection, and digital reports, Thyrocare ensures a smooth and reliable health testing experience for every employee. ## Key Benefits **For HR**- **Employee wellbeing:** Promote preventive health with reliable and accessible diagnostics. * Nationwide reach:Enable employees to access health checkups anywhere in India.**For Employees**- **Convenient testing:** Get samples collected from home or office. * **Accurate results:** Benefit from advanced lab automation and quality processes. * **Comprehensive packages:** Choose from a wide range of health and wellness tests. ## How Employees Can Use Thyrocare Access Thyrocare to book preventive health checkups or specific diagnostic tests. Schedule at-home sample collection, receive updates digitally, and get reports directly through secure online access. ## Co-Sponsor & Deliver Thyrocare at Scale Employers can roll out Thyrocare health packages across teams to build a culture of wellbeing and preventive care. Enable hassle-free access to health services that keep employees proactive and productive. ## Support For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Seamless OPD Coverage for Employees with OPDSure Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/seamless-opd-coverage-for-employees-with-opdsure See how the Plum-OPDsure integration provides employees with seamless outpatient (OPD) coverage as part of your rewards and benefits program. *Learn more about integration with OPDSure* ## About OPDSure OPDSure is a healthcare platform that focuses on outpatient care, covering essential medical expenses such as doctor consultations, pharmacy costs, diagnostic tests, and preventive health checkups. It helps individuals and families manage the high proportion of healthcare spending that comes from routine outpatient needs, while promoting regular health monitoring and preventive care. ## Why Connect OPDSure Connecting OPDSure allows organizations to provide employees with structured support for everyday healthcare needs. Employees gain access to consultations, medicines, diagnostics, and checkups under a unified healthcare benefit, encouraging timely medical attention and contributing to overall well-being at work. ## Key Benefits for Employees * Offer Comprehensive and Manageable OPD Benefits Enable employees to access a wide range of outpatient services while managing everything effortlessly through seamless integration. * Gain Actionable, Data-Driven Insights Track utilization, engagement, and wellness trends to understand employee health behavior and enhance benefits strategies effectively. ## How Employees Can Use OPDSure * Access Routine Consultations Easily Employees can book convenient outpatient consultations for regular health checkups and everyday medical needs. * Get Specialized Care When Required Avail packages for specialized consultations, helping employees seek expert advice for specific health concerns. ## Support For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # Unlock Employee Wellness with Fitpass Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/unlock-employee-wellness-with-fitpass Learn how the Plum-Fitpass integration unlocks employee wellness benefits, including gym and fitness access, through your rewards catalogue. *Learn more about Fitpass integration* ## About Fitpass Fitpass is India’s largest fitness and wellness network offering flexible access to 7,500+ gyms, studios, and fitness centers across 40+ cities. It empowers users with an integrated fitness ecosystem that includes AI-powered fitness tracking, personalized nutrition guidance, and corporate wellness programs designed to enhance employee health, reduce sedentary habits, and improve workplace productivity. ## Why Connect Fitpass with Xoxoday Plum Integrating Fitpass helps organizations deliver holistic employee wellness experiences. Employees gain instant access to personalized fitness routines, gym memberships, and expert coaching, while organizations can promote healthy lifestyles, measure engagement, and enhance retention through data-driven wellness insights. ## Key Benefits * **For Employers** Unified wellness platform Combine engagement, rewards, and physical wellbeing. * Reduce absenteeism Encourage consistent fitness to improve employee health. * Data-backed insights Track participation and wellness outcomes. * Attract and retain talent Offer modern wellness benefits employees love. * For Employees Personalized Fitness Options Employees can select flexible subscription plans tailored to their lifestyle and fitness preferences. * Smart Wellness Integration Each plan enhances the fitness experience with connected tools to monitor progress and stay active. Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com) to get started with the integration. # Wellbeing Reimagined with Fitterfly Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/wellbeing-reimagined-with-fitterfly See how the Plum-Fitterfly integration reimagines employee wellbeing with structured wellness programs available through your rewards catalogue. *Learn more about integration with Fitterfly* ## About Fitterfly Fitterfly is a health-tech startup specializing in digital therapeutics (DTx) for metabolic health. Fitterfly combines personalized coaching with advanced technology to help individuals manage and reverse chronic conditions. The programs include: * Fitterfly Diabetes Prime A 6–12 month program designed to prevent, manage, or reverse type 2 diabetes and prediabetes. * Fitterfly Weight Loss A 3–6 month program focused on sustainable weight loss and maintenance. * Fitterfly FitHeart A program aimed at improving heart health through lifestyle modifications. Fitterfly's programs are clinically validated and have shown significant improvements in health outcomes, including reductions in HbA1c levels, weight loss, and enhanced physical fitness. ## Why Connect with Fitterfly This integration empowers HR leaders to offer employees data-driven, personalized care plans backed by science. With real-time progress tracking and expert support, it enhances engagement, well-being, and overall organizational productivity. ## Key Benefits * **For Employers/HR Leaders** AI-driven health solutions Provide employees with personalized metabolic health plans based on real-time data. * Seamless integration Easily incorporate Fitterfly's programs into existing wellness initiatives through the platform. * Data-driven insights Monitor employee health metrics and track program engagement to assess effectiveness. * Cost-effective Reduce healthcare expenses by addressing the root causes of chronic conditions and promoting preventive care. * For Employees Personalized care Receive tailored recommendations for nutrition, activity, sleep, and stress management. * Continuous support Access a dedicated care team of health coaches and medical professionals. * Sustainable health improvements Achieve long-term health goals, such as weight loss and medication reduction, through evidence-based interventions. * User-friendly technology Utilize the Fitterfly app to track progress and stay connected with your care team. ## How Employees Can Use Fitterfly * Enroll in the Program Employees can sign up for Fitterfly's program through the platform, providing basic health information to personalize their care plan. * Wearable Sensors Upon enrollment, employees receive wearable sensors that continuously monitor key health metrics, feeding data into their digital twin. * Personalized Recommendations The Fitterfly app provides daily guidance on nutrition, activity, sleep, and stress management based on the individual's unique metabolic profile. * Regular Check-ins Employees have access to regular consultations with health coaches and medical professionals to discuss progress and adjust their care plan as needed. * Track Progress Through the Fitterfly app, employees can monitor their health metrics, set goals, and celebrate milestones, fostering motivation and sustained engagement. ## Co-Sponsor & Deliver Fitterfly Benefits at Scale Enable employees to access Fitterfly’s personalized metabolic health programs organization-wide. Through this integration, employers can easily launch wellness initiatives, monitor participation, and foster a healthier workplace culture. ## Support For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com). # 1-Many Link for Xoxolink’s Reward Automation Source: https://help-plum.xoxoday.com/integrations/hubspot/1-many-link-for-xoxolinks-reward-automation Learn how to automate one-to-many reward distribution in HubSpot using Xoxoday reward links, so an entire segment can be rewarded in one action. *1 - many Xoxolink feature helps in enabling real-time rewarding and CTA hyperlinking for sending emails to the masses.* This feature is specially designed for sales and marketing teams using Xoxoday plum integrated with HubSpot. 1-many automation can be created from Xoxoday’s dashboard and the link generated can be copied and pasted to your marketing emails in HubSpot. Feature Specification: Only the ones who are part of the contact list in HubSpot will be eligible to redeem their rewards, anyone apart from that will not have access. ## Pre-requisites * As an admin, You should have already connected the Xoxoday with [HubSpot](/integrations/hubspot/hubspot-overview). ## Steps to create a 1-many campaign: **Step 1:** The admin creates the Xoxolink [campaign](/getting-started/overview). ​ Step 2: The admin creates Automation for HubSpot — and selects ‘1-many reward link’. Accepts the Information message and tick that you understood the guidelines. Click '**Continue'.** Step 3: Select 'Campaign' Upon selecting Campaign, set the Expiry date, select Approval type as Manual or Automatic as per your preferences. You can also add **Additional settings** on 1. Start and End Date of Automation 2. Maximum number of Rewards to sent - Upon reaching max limit, the Automation will be completed. \*Repeat Rewarding is disabled. **Step 4:** Upon creating a 1-many link for the automation — a link is generated to trigger rewards for that automation which users can ‘copy’ and use inside HubSpot emails. Pro Tip: Don't forget to copy the link( as shown in the above image), as you will have to hyperlink it to your email’s CTA on HubSpot. **Step 5:** Adding the link inside HubSpot for launching Emails: **Step 6:** Now you are good to go!! You can now send rewards to all of your contact lists in one go. ## Steps to Redeem a 1-Many campaign Below are the steps to redeem your rewards: **Step 1:** From your reward email Click the CTA to go about redeeming. **Step 2:** Below screen will open for you to redeem the reward: Step 3:Once Authenticated, you will receive a redemption email for selecting your desirable reward.**Step 4:** Select the Reward you wish to avail yourself: During the Redemption journey — * End user inputs email address say [xyz@gmail.com](mailto:xyz@gmail.com) * **If** the email address is present in the HubSpot contacts, we proceed to send the reward * **Else**, we show an error message saying ‘Unable to validate. Please contact the sender of the email for further assistance ‘ ​ # Email based Reward Automation Source: https://help-plum.xoxoday.com/integrations/hubspot/email-based-reward-automation See how to automate reward sends that are triggered by HubSpot email actions, using the Plum-HubSpot integration to reward engaged contacts. *Learn how to automate rewards for email recipients.* Now you can reward your prospects, contacts, and leads directly via email marketing campaigns (without any workflow-based triggers in HubSpot). Just select the contact 'List' from HubSpot. In a few simple clicks, you can set up a reward automation campaign in Plum and use the reward-enriched contacts to send emails with your own template from HubSpot. Not just that, the email recipient (contacts, prospects, or leads) can choose gift cards of their choice from Xoxoday’s extensive global catalog. You can also restrict the number of rewards sent out based on criteria like - campaign time range, Maximum Reward count as well as repeated rewards, etc. ## ​Follow the step to step guide to make your first rewarding automation for email recipients. Skip Section 1 if you have already integrated Xoxoday Plum with HubSpot # Section I: Sync up your HubSpot with Plum Step 1: \*\*Connect your Xoxoday plum to HubSpot.\*\*​ ## Step 2: Go to App Marketplace and search for Xoxoday plum. Now, click on the app marketplace by clicking on the shop icon on the right top corner of your dashboard. ## Step 3: Click on the Install app Search for Xoxoday Plum in the app marketplace, and click on the “Install” button. ## Step 4: Signup or Sign In on Plum If you are new to Xoxoday Plum, click on the “**Signup” button. You can learn how to set up a Plum account [here](https://xoxoday.gitbook.io/plum/for-admins-1/getting-started). It's recommended that you use the email registered with HubSpot to signup with Plum as well.If you are an existing user, use your Xoxoday credentials to log in to the admin dashboard.** **Congrats, you have successfully installed the application.** # Section II: Create Reward Automation in Plum ## Step 1: Setting up the Reward Automation. Once the Xoxoday Plum Rewards App is downloaded, follow the steps given below and hook Xoxoday Plum up to your Hubspot CRM. These are for the Admins operating the HubSpot CRM dashboard. Please ensure that you follow the steps on the dashboard to create the reward automation and recharge your account. ​ Step 2: Choose to Automate your first reward Once you choose ‘automate your first reward’ from the dashboard you will be shown a pop-up with the option to choose a type of reward automation. You need to choose “email-based reward automation” Existing Plum admins can go to their HubSpot integration and click on ‘create new automation’ and they will also be presented with the same automation selection pop-up. ## Step 3: Enter Reward Automation Name and Choose Contact list On the automation first step enter the reward automation name which you will be using during the email template creation to embed the reward link in HubSpot. Choose the contact list from HubSpot which will be fetched to enrich the contacts with reward links. Once selected, you can click on "Save & Proceed" to proceed to move to the next steps: ​ ## Step 4: Create or select the Xoxolink campaign As a first-time user, you have to create a Xoxolink campaign from where the rewards will actually flow. Perform the following actions to set up your Xoxolink campaign: Enter Campaign Name, Set Link expiry date, Select the country and denomination as per your choice. For existing users, you can select the existing Xoxolink campaign or choose to create a new one. ​ ## Step 5: Let the contact enrichment complete on plum. Once you launch the reward automation, then you will be redirected to the reward report page where you could see how the contact enrichment is progressing. (The time taken to complete the enrichment is relative to the number of contacts you have in the contact list). Once the enrichment is complete, follow the below-mentioned steps in HubSpot to generate and send emails with a reward link embedded into them. # HubSpot Integration Source: https://help-plum.xoxoday.com/integrations/hubspot/hubspot-overview Get an overview of the Plum-HubSpot integration, including how it connects your CRM workflows to automated reward disbursal for contacts. *Learn more about Xoxoday Plum and Hubspot integration* ## Overview The HubSpot ↔ Xoxoday Plum integration enables you to automate the way you send rewards, incentives, and branded gifts to your customers, prospects, and partners directly from HubSpot. Whether you want to reward a single contact when they convert, or send rewards at scale after an event, the integration makes the process seamless, branded, and trackable. **Typical use cases include:** * Sending welcome kits to new customers during onboarding. * Rewarding attendees of webinars and events. * Driving survey completions with incentives. * Encouraging referrals and advocacy programs. * Nudging trial users to upgrade to paid plans. * Re-engaging dormant leads or inactive users. * Recognizing partners, affiliates, and advocates. ## Key Features * **Seamless HubSpot integration**: Trigger rewards directly from workflows, contact lists, or emails. * **White-labeled experience**: Customize reward emails and landing pages with your branding. * **Flexible catalogues**: Choose from Xoxoday’s global catalogue or curate your own campaigns with selected items. * **Vast reward catalogue & automated fulfillment**: Choose from thousands of options including global gift cards and merchandise. Whether you curate branded swags or send digital gift cards, Plum handles delivery, redemption, and order tracking end-to-end. * **Multiple automation options**: Choose the flow that fits your use case — Workflow-based, Email-based, 1-Many Reward Links, or 1-1 Widget. * **Reporting & analytics**: Track rewards sent, claimed, and delivered directly within HubSpot and Plum. ## How to integrate HubSpot with Xoxoday? Discover how to integrate Xoxoday Plum with HubSpot to automate and personalize reward campaigns. This video walks you through connecting both platforms, mapping contact data, and triggering rewards directly from your HubSpot workflows.