Burnout-Zero
Last updated by the developer on: October 30, 2023
General information
Information provided by Burnout-Zero to Microsoft:
Information | Response |
---|---|
App name | Burnout-Zero |
ID | WA200006140 |
Office 365 clients supported | Microsoft Teams |
Partner company name | Burnout-Zero |
Company's website | https://www.burnout-zero.com/en/home |
App's Terms of Use | https://www.burnout-zero.com/en/terms-and-conditions |
Core functionality of the app | A fully automated All-in-One platform for Workplace Culture and Engagement for Microsoft Teams |
Company headquarter location | Chile |
App info page | |
What is the hosting environment or service model used to run your app? | Iaas |
Which hosting cloud providers does the app use? | Aws |
Customer support contact. | support@burnout-zero.com |
Questions
Questions or updates to any of the information you see here? Contact us!
How the app handles data
This information has been provided by Burnout-Zero about how this app collects and stores organizational data and the control that your organization will have over the data the app collects.
Information | Response |
---|---|
Does the app or underlying infrastructure process any data relating to a Microsoft customer or their device? | Yes |
What data is processed by your app? | User profile data |
Does the app support TLS 1.1 or higher? | Yes |
Does the app or underlying infrastructure store any Microsoft customer data? | Yes |
What data is stored in your databases? | Name, email, user id, chat_id |
If underlying infastructure processes or stores Microsoft customer data, where is this data geographically stored? | United States of America |
Do you have an established data rentention and disposal process? | No |
How long is data retained after account termination? | More than 90days |
Do you have an established data access management process? | Yes |
Do you transfer customer data or customer content to third parties or sub-processors? | No |
Questions
Questions or updates to any of the information you see here? Contact us!
Information from the Microsoft Cloud App Security catalog appears below.
Information | Response |
---|---|
Do you perform annual penetration testing on the app? | No |
Does the app have a documented disaster recovery plan, including a backup and restore strategy? | Yes |
Does your environment use traditional anti-malware protection or application controls? | ApplicationControls |
Do you have an established process for indentifying and risk ranking security vulnerabilities? | No |
Do you have a policy that governs your service level agreement (SLA) for applying patches? | No |
Do you carry out patch management activities according to your patching policy SLAs? | No |
Does your enviroment have any unsupported operating systems or software? | No |
Do you conduct quarterly vulnerability scanning on your app and the infastructure that supports it? | No |
Do you have a firewall installed on your external network boundary? | Yes |
Do you have an established change management process used to review and approve change requests before they are deployed to production? | Yes |
Is an additional person reviewing and approving all code change requests submitted to production by the original developer? | Yes |
Do secure coding practices take into account common vulnerability classes such as OWASP Top 10? | No |
Multifactor Authentication (MFA) enabled for: | CodeRepositories, DNSManagement, Credential |
Do you have an established process for provisioning, modification, and deletion of employee accounts? | No |
Do you have Intrusion Detection and Prevention (IDPS) software deployed at the perimeter of the network boundary supporting your app? | No |
Do you have event logging set up on all system components supporting your app? | Yes |
Are all logs reviewed on a regular cadence by human or automated tooling to detect potential security events? | Yes |
When a security event is detected are alerts automatically sent to an employee for triage? | Yes |
Do you have a formal information security risk management process established? | No |
Do you have a formal security incident response process documented and established? | No |
Questions
Questions or updates to any of the information you see here? Contact us!
Information | Response |
---|---|
Does the app comply with the Health Insurance Portability and Accounting Act (HIPAA)? | No |
Does the app comply with Health Information Trust Alliance, Common Security Framework (HITRUST CSF)? | No |
Does the app comply with Service Organization Controls (SOC 1)? | No |
Does the app comply with Service Organization Controls (SOC 2)? | No |
Does the app comply with Service Organization Controls (SOC 3)? | No |
Do you carry out annual PCI DSS assessments against the appand its supporting environment? | No |
Is the app International Organization for Standardization (ISO 27001) certified? | No |
Does the app comply with International Organization for Standardization (ISO 27018)? | No |
Does the app comply with International Organization for Standardization (ISO 27017)? | No |
Does the app comply with International Organization for Standardization (ISO 27002)? | No |
Is the app Federal Risk and Authorization Management Program (FedRAMP) compliant? | No |
Does the app comply with Family Educational Rights and Privacy Act (FERPA)? | No |
Does the app comply with Children's Online Privacy Protection Act (COPPA)? | No |
Does the app comply with Sarbanes-Oxley Act (SOX)? | No |
Does the app comply with NIST 800-171? | No |
Has the app been Cloud Security Alliance (CSA Star) certified? | No |
Questions
Questions or updates to any of the information you see here? Contact us!
Information | Response |
---|---|
Do you have GDPR or other privacy or data protection requirements or obligations (such as CCPA)? | No |
Questions
Questions or updates to any of the information you see here? Contact us!
Information | Response |
---|---|
Does your application integrate with Microsoft identity platform (Microsoft Entra ID) for single-sign on, API access, etc.? | No |
Does your app support Continuous Access Evaluation (CAE) | No |
Does your app store any credentials in code? | No |
Apps and add-ins for Microsoft 365 might use additional Microsoft APIs outside of Microsoft Graph. Does your app or add-in use additional Microsoft APIs? | No |
This application does not use Microsoft Graph.
This application does not have Additional APIs.
Questions
Questions or updates to any of the information you see here? Contact us!