polumana Tour Route Planner
Last updated by the developer on: November 20, 2023
General information
Information provided by blue-zone GmbH to Microsoft:
Information | Response |
---|---|
App name | polumana Tour Route Planner |
ID | WA200004331 |
Office 365 clients supported | Microsoft Teams |
Partner company name | blue-zone GmbH |
Company's website | https://blue-zone.de |
App's Terms of Use | https://azaap-disp-route-planning.azurewebsites.net/#/terms... |
Core functionality of the app | Polumana Tour & Route Planner for increased efficiency on your customer visits |
Company headquarter location | Germany |
App info page | |
What is the hosting environment or service model used to run your app? | Paas |
Which hosting cloud providers does the app use? | Azure |
Questions
Questions or updates to any of the information you see here? Contact us!
How the app handles data
This information has been provided by blue-zone GmbH about how this app collects and stores organizational data and the control that your organization will have over the data the app collects.
Information | Response |
---|---|
Does the app or underlying infrastructure process any data relating to a Microsoft customer or their device? | Yes |
What data is processed by your app? | Contacts, Email Address |
Does the app support TLS 1.1 or higher? | Yes |
Does the app or underlying infrastructure store any Microsoft customer data? | Yes |
What data is stored in your databases? | Email, Addresses of Contacts |
If underlying infastructure processes or stores Microsoft customer data, where is this data geographically stored? | Netherlands (the) |
Do you have an established data rentention and disposal process? | No |
How long is data retained after account termination? | More than 90days |
Do you have an established data access management process? | No |
Do you transfer customer data or customer content to third parties or sub-processors? | Yes |
Do you have data sharing agreements in place with any third party service you share Microsoft customer data with? | No |
Questions
Questions or updates to any of the information you see here? Contact us!
Information from the Microsoft Cloud App Security catalog appears below.
Information | Response |
---|---|
Do you perform annual penetration testing on the app? | No |
Does the app have a documented disaster recovery plan, including a backup and restore strategy? | No |
Does your environment use traditional anti-malware protection or application controls? | TraditionalAntiMalware |
Do you have an established process for indentifying and risk ranking security vulnerabilities? | No |
Do you have a policy that governs your service level agreement (SLA) for applying patches? | No |
Do you carry out patch management activities according to your patching policy SLAs? | No |
Does your enviroment have any unsupported operating systems or software? | No |
Do you conduct quarterly vulnerability scanning on your app and the infastructure that supports it? | No |
Do you have a firewall installed on your external network boundary? | Yes |
Do you have an established change management process used to review and approve change requests before they are deployed to production? | Yes |
Is an additional person reviewing and approving all code change requests submitted to production by the original developer? | Yes |
Do secure coding practices take into account common vulnerability classes such as OWASP Top 10? | No |
Multifactor Authentication (MFA) enabled for: | CodeRepositories, Credential |
Do you have an established process for provisioning, modification, and deletion of employee accounts? | Yes |
Do you have Intrusion Detection and Prevention (IDPS) software deployed at the perimeter of the network boundary supporting your app? | N/A |
Do you have event logging set up on all system components supporting your app? | Yes |
Are all logs reviewed on a regular cadence by human or automated tooling to detect potential security events? | No |
When a security event is detected are alerts automatically sent to an employee for triage? | No |
Do you have a formal information security risk management process established? | No |
Do you have a formal security incident response process documented and established? | No |
Questions
Questions or updates to any of the information you see here? Contact us!
Information | Response |
---|---|
Does the app comply with the Health Insurance Portability and Accounting Act (HIPAA)? | N/A |
Does the app comply with Health Information Trust Alliance, Common Security Framework (HITRUST CSF)? | N/A |
Does the app comply with Service Organization Controls (SOC 1)? | N/A |
Does the app comply with Service Organization Controls (SOC 2)? | No |
Does the app comply with Service Organization Controls (SOC 3)? | No |
Do you carry out annual PCI DSS assessments against the appand its supporting environment? | N/A |
Is the app International Organization for Standardization (ISO 27001) certified? | No |
Does the app comply with International Organization for Standardization (ISO 27018)? | No |
Does the app comply with International Organization for Standardization (ISO 27017)? | No |
Does the app comply with International Organization for Standardization (ISO 27002)? | No |
Is the app Federal Risk and Authorization Management Program (FedRAMP) compliant? | No |
Does the app comply with Family Educational Rights and Privacy Act (FERPA)? | N/A |
Does the app comply with Children's Online Privacy Protection Act (COPPA)? | N/A |
Does the app comply with Sarbanes-Oxley Act (SOX)? | N/A |
Does the app comply with NIST 800-171? | N/A |
Has the app been Cloud Security Alliance (CSA Star) certified? | No |
Questions
Questions or updates to any of the information you see here? Contact us!
Information | Response |
---|---|
Do you have GDPR or other privacy or data protection requirements or obligations (such as CCPA)? | No |
Questions
Questions or updates to any of the information you see here? Contact us!
Information | Response |
---|---|
Does your application integrate with Microsoft identity platform (Microsoft Entra ID) for single-sign on, API access, etc.? | Yes |
Have you reviewed and complied with all applicable best practices outlined in the Microsoft identity platform integration checklist? | No |
Does your app use the latest version of MSAL (Microsoft Authentication Library) or Microsoft Identity Web for authentication? | Yes |
Does your app support Conditional Access policies? | Yes |
List the types of policies supported | MFA |
Does your app support Continuous Access Evaluation (CAE) | No |
Does your app store any credentials in code? | Yes |
Apps and add-ins for Microsoft 365 might use additional Microsoft APIs outside of Microsoft Graph. Does your app or add-in use additional Microsoft APIs? | Yes |
Data access using Microsoft Graph
Graph Permission Permission Type Justification Microsoft Entra App ID Calendars.ReadWrite application After route optimization we need to create new appointments and delete existing ones d361752a-c257-474d-bb79-324fbe4898b5 Contacts.Read application We need to read the contacts in order to create the appointments d361752a-c257-474d-bb79-324fbe4898b5 User.Read application We need to get the Email of the user to persist settings d361752a-c257-474d-bb79-324fbe4898b5
This application does not have Additional APIs.
Questions
Questions or updates to any of the information you see here? Contact us!