What controls are used to mitigate DDoS (distributed denial–of-service) attacks?
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently.
Are you capable of supporting litigation holds (freeze of data from a specific
point in time) for a specific tenant without freezing other tenant data?
Yes, we can freeze data from a specific time without freezing other data if need be.
Do you support movement of applications and data from one cloud service
provider to another cloud service provider or back to in-house data center whenever required?
Yes, Xoxoday Plum comes with a full set of integration with various platforms for enriched utility and maximum output from the platform.No, we keep it with one data center for maximum safety, privacy, and security of database of our tenants.
What are the available management reporting capabilities?
Reports and analysis can be extracted from the platform. These reports give detailed insights with respect to what’s being the reward and recognition input and output throughout the concerned period.
What procedures are in place to manage and recover from the compromise of keys?
We use the Key Management Service by AWS to manage all the keys. In the event that keys get compromised, they can be recovered through the Key Management Service.
What is the SLA (Time) for different levels of support different incidents and change requests?
Standard example: Critical - 2 hrs. or less, Moderate - 4 hrs. or less, Minimum - 8 hrs. or less
The time of support ranges between six to forty-eight hours. This depends on the level of service and the gravity of incidents.
What are the inbuilt APIs for third-party tools available?
Can you integrate with SailPoint, ForgeRock, Splunk, OneCert, EDM?
We are a SAAS company hence we do not have in built APIs, we maintain quarterly/yearly audit logs. No we do not integrate with the above third party tools
How is the overall Application logging operation managed? - Does the solution
support monitoring for security events and can event notifications/incident response be integrated with bank system?
We maintain the logging of applications and alerts by ourselves. We cannot be integrated with the bank system, According to our company policy we do not share the logs with any third party.
Does the application have robust authentication methods (e.g.
SSO, multi-factor authentication, One-time password, secure token, etc.) for administrative access to this service?
Yes the application have robust authentication methods. We are integrated SAML 2.0 with SAP SuccessFactors, we also support OAuth 2.0 for seamless authentication.
How is the compatibility of the application with Desktop(Mac/OS); Tablet;
Mobile (Android/iPhone)?’- Any additional components required to download in user’s computer in order to access the application?
Our applications are compatible with desktops, tablets and Mobiles, No additional components are required.
Does the application have a robust Backup and Restore procedures?
Is the duration configurable? Can you share your DR strategy and tests results? Is it Active-active?
Since we are SAAS product, we maintain backup and restore all the customer data by ourselves. We use AES 256 encryption for data at rest. We have a multi AZ deployment with periodic backup for our DR. DR is active-active.
Is the data in the non-prod instance refreshed with Prod data and masked? If data masking is performed, then how configurable are the masking scripts? What protection is used for Prod data at rest and at transit?
We use logical data isolation with the help of company-specific encryption keys. Data in non production environment is not updated with the production data. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256
How seamless is the Product upgrade release? What is the hosting model - public, private, hybrid, etc.
We are a SAAS solution, and hosting is handled by us. No instances needed from the client. We use Public cloud for hosting (AWS Singapore)
How mature is the technical capabilities of the product to be able to integrate
seamlessly and securely with the Bank’s tools and applications?
This solution doesn’t require any such API integration. The solution is seamlessly integrated with the SAP SuccessFactors solution already.
Does the Vendor and/or Business User have controls over elevated/privileged or operational access?
Does this mean SCB admin staff will have control and will be able to perform any administrative or operational activities? How are the roles ""Admin"" and ""Super Admin"" defined?”
We only have 2 roles. Super admin and user. Super admin have complete control of the platform and can configure everything. SCB Admin staff will become the super admins.
How is the overall Application logging operation managed? - Does the solution
support monitoring for security events and can event notifications/incident response be integrated with bank system?
Xoxoday will not be sharing logs with SCB as we have multi-tenant information in the logs. If there is a significant downtime or disruption of service, we will provide an alert notification to SCB
Web Content Accessibility Guidelines (WCAG) defines how to make Web content more accessible to people with disabilities. Accessibility involves a wide range of disabilities, including visual, auditory, physical, speech, cognitive, language, learning, and neurological disabilities.
Yes. We always give our best to make sure that our applications are developed as per WCAG guidelines and helping differently-abled people across the globe.
Can people with disabilities use your website and application without barriers?
Yes. We ensure that people with disabilities can use our websites and applications without any difficulties. Our website and products are having very simple options with very good visibility of the content.