Security

What personal information do we collect from the people that visit our blog, website or app?

Xoxoday products are used across companies employees, channel partners, sales and consumers. With critical information about your key stakeholders and business processes, the security of the Xoxoday system needs to be of best standards.

The Xoxoday promise

Xoxoday takes data integrity and security very seriously. Over 2 million customers across the globe trust us with their data security. Due to the nature of the product and service we provide, it is important that we acknowledge that our responsibilities both as data controller as well as a data processor. Customer data security is an essential part of our product, processes, and team culture. Our facilities, processes and systems are reliable, robust and tested by reputed quality control and data security organizations. We continuously look for opportunities to make improvements in the dynamic technology landscape and give you a highly secure, scalable system to provide a great experience.

Xoxoday lets you deliver a secure subscription experience at different levels by,

Securing your data and personal information with compliance to GDPR.

Ensuring Internal Data security of your data that rests with Xoxoday with adherence to ISO standards.

Network Security within Xoxoday: Network, application and operational level security policies that we follow.

Governance, risk and compliance team ensuring best practices and standards across the employees and teams.

ISO 27001 certification

ISO 27001 (formally known as ISO/IEC 27001:2013) is a specification for an information security management system (ISMS). An ISMS is a framework of policies and procedures that includes all legal, physical and technical controls involved in an organisation’s information risk management processes with the aim of keeping information secure.

With ISO’s robust information security management system (ISMS) in place, you gain the additional reassurance that a full spectrum of security best practices are implemented across the organization.

Xoxoday is ISO 27001:2013 certified and we’re committed to identifying risks, assessing implications and putting in place systemised controls that inspire trust in everything that we do - right from our codebase to physical infrastructure to people practices.

EU-US privacy shield

Xoxoday complies with the EU-U.S. Privacy Shield by adhering to the principles and protecting the rights of anyone in the EU whose personal data is transferred to the United States as well as bringing legal clarity for businesses relying on transatlantic data transfers.

GDPR

At Xoxoday, we are committed to helping our users understand and, where applicable, comply with the General Data Protection Regulation (GDPR). The GDPR was introduced to bind each member state of the EU with a single, harmonious data protection law. It has been the most comprehensive European data privacy law in decades and came into force on May 25 2018.

Xoxoday's Commitment to GDPR

ISO 27001 (formally known as ISO/IEC 27001:2013) is a specification for an information security management system (ISMS). An ISMS is a framework of policies and procedures that includes all legal, physical and technical controls involved in an organisation’s information risk management processes with the aim of keeping information secure.

Physical and Network security

Xoxoday is hosted on Amazon's AWS platform and infrastructure. Xoxoday employees do not have any physical access to our production environment.
As an Amazon AWS customer, we are benefitted from a data center and network architecture built to meet the requirements of the most security-sensitive organisations.
AWS data centres are housed in nondescript facilities, with military-grade perimeter control berms with professional security staff utilising video surveillance, state of the art intrusion detection systems, and other electronic means. 
In addition to Apart from the physical security, AWS platform also provides significant protection against traditional network security issues including

Distributed Denial Of Service (DDoS)

AttacksMan In the Middle (MITM)

AttacksPort Scanning

Packet sniffing by other tenants

Administrative operations

Xoxoday uses two-factor authentication to grant access for our administrative operations - both infrastructure and services. We ensure that administrative privileges are granted to only a few employees. Additionally, role-based access is used to ensure specific users have only required operations that are allowed for specific users.
All administrative access is automatically logged and monitored by our internal security team. Detailed information on when/why the operations are carried out are documented and notified to the security team before performing any changes in the production environment.

Host security

SSH keys are required to gain console access to our servers and each login is identified by a user. All critical operations are logged to a central log server and our servers can be accessed only from restricted and secure IPs.
Hosts are segmented, and accesses are restricted based on functionality. That is, application requests are allowed only from AWS ELB and database servers can be accessed only from application servers.

Application security

ISO 27001 (formally known as ISO/IEC 27001:2013) is a specification for an information security management system (ISMS). An ISMS is a framework of policies and procedures that includes all legal, physical and technical controls involved in an organisation’s information risk management processes with the aim of keeping information secure.

Secure Access
Xoxoday's application servers are all secure HTTPS. We use industry-standard encryption for data traversing to and from the application servers.

XSS
All user inputs are well encoded when displayed to ensure XSS vulnerabilities are mitigated.

CSRF
All POST requests are checked for CSRF token before processing the request.

SQL Injection
We use prepared statements for database access to avoid SQL Injection attacks.

Encrypted Data Storage
Xoxoday does not store any sensitive user information. The keys for various third-party services (like payment gateway) - if stored, are all in the encrypted form in the database.

Vulnerability Scanning & Patching
We periodically check and apply patches for third-party software/services. As and when vulnerabilities are discovered we apply the fixes. We do periodic vulnerability scanning using the services of an authorised QSA.

Data storage & redundancy

We use Amazon's RDS for our database. The automated backup feature is configured for RDS. We backup data for upto 30 days. We have configured Amazon RDS in Multi-AZ which provides enhanced availability and durability. Each AZ runs on its own physically distinct, independent infrastructure, and is engineered to be highly reliable. Know more.

Monitoring

Xoxoday uses both internal and multiple external monitoring services to make sure the environment is secure. Our monitoring system will alert the concerned teams through emails and phone calls if there are any errors or abnormality in the request pattern.

Disclosure

At Xoxoday, we are continually working towards making our system secure. If you find any issues or have any queries regarding our security, please write to us at cs@xoxoday.com. We will make sure it gets addressed.