Q: Does the company restrict to only authorized, supported, and properly licensed software being installed on its owned and/or managed systems, with only its IT administrators installing such software?
Yes. Xoxoday enforces a strict software governance policy under which only authorized, licensed, and security-vetted software can be installed on company-owned or managed systems. Installation is restricted to IT administrators or personnel explicitly approved by the Information Security team. This prevents the introduction of malicious or unsupported applications and ensures compliance with licensing agreements.
Q: Describe data center compliance with those standards, including independent audit results or certifications?
We use Amazon Web Services (AWS), Azure & Oracle as our Cloud Service Providers (CSP). They are compliant with various standards and frameworks, including PCI-DSS, HIPAA/HITECH, FedRAMP, GDPR, FIPS 140-2, and NIST 800-171. Our organization is ISO 27001, ISO 14001, CCPA & CPRA, HIPAA, and SOC 2 Type 1 & Type 2 certified. We also comply with GDPR. We conduct regular internal audits and independent third-party external audits to assess compliance and the effectiveness of our controls.
