Announcement

Collapse
No announcement yet.

4 big updates to enhance app security and compliance on monday code

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • 4 big updates to enhance app security and compliance on monday code

    1. monday code is now certified for SOC 2 and ISO 27001, and compliant with GDPR and HIPAA

    monday code, our secure app hosting solution, is now certified for SOC 2 and ISO 27001, providing you and your customers with greater confidence in the security and privacy of the apps hosted on our platform. Alongside these certifications, monday code also complies with GDPR and HIPAA, reflecting our dedication to maintaining data protection and privacy practices.

    This milestone demonstrates commitment to meet high security standards, availability and confidentiality standards in the industry, and creates new opportunities to serve enterprise customers whose security and privacy requirements are stricter.

    2. New CLI command to support your app’s privacy compliance

    The storage:remove-data CLI command simplifies the app’s data management by allowing you to remove customer account data from our storage service (for example, when an app is uninstalled), whether you are using it via monday code or not. This helps you comply with data retention requirements and ensures you can align with privacy best practices and regulations.

    oint_right: Learn more in our developer documentation

    3. Enhanced monday code security with WAF and DDOS protection

    The security of monday code was upgraded with enhanced Web Application Firewall (WAF) and Distributed Denial-of-Service (DDoS) protection. This upgrade fully aligns with monday.com’s WAF and DDoS protection standards, improving the resilience and trustworthiness of your monday code apps.

    4. Control monday code’s outgoing traffic - Join the beta

    We’re introducing new Advanced Networking capabilities in the developer center, including allowlist, which enables you to limit the outgoing traffic from your monday code apps to specific destinations (IP addresses or domains) or block outgoing traffic entirely, ensuring connections are made only to approved external services.

    Want to be among the first to use this powerful feature? Fill out this form to apply for participation in the beta program.​

  • #2
    Quick question, does it mean that every app passing the process review of Monday code is by default HIPa GDPR and ISO compliant?

    Comment


    • #3
      I tested the new settings and they work well with granular permissions, especially for apps handling sensitive user data. I’ve used similar setups before to prevent risks like misuse through tools such as an ip booter, and this gives me more peace of mind. The token expiration and audit logs are also super handy—makes it easier to track who changed what without guessing.

      Comment

      Working...
      X