Security - most frequently asked questions
Below, you'll find the answers to the most frequently asked security-related questions:
ApprovalMax supports 2FA via TOTP standard
ApprovalMax is compliant with Xero and Intuit security standards
ApprovalMax goes through a 3rd party penetration test once a year. We do perform regular internal self-assessment in addition to external penetration testing. Details can be shared once an NDA has been signed.
ApprovalMax has a Data Security Policy. Details can be shared once an NDA has been signed.
ApprovalMax has a 98/100 score on the automated security scanning system. Details can be shared once an NDA has been signed.
ApprovalMax does not have SOC Type2, ISO27001 and alike certifications at this point.
ApprovalMax has a standard incident response plan, it is covered in “ApprovalMax Data Security Management Policy”. Details can be shared once an NDA has been signed.
Here is ApprovalMax password policy. We do perform strong checks and automated check agains the list of compromised passwords. In case of multiple (6) failed login attempts, users are locked out for 30 minutes.
Budget Checking feature v1 discontinuation support – frequently asked questions
Question: What will happen with my data if I don’t upgrade? Answer: On the date of discontinuation, Budget Checking v1 will be deactivated and hidden from the menu. All Budget Checking information will be removed from requests. Question: How can I ...
What happens to the emails sent to firstname.lastname@example.org?
Such emails go to a dead-end mailbox, which gets cleaned up. We are not monitoring such emails. The security rules applicable to the customer data itself are also applied here.
Does ApprovalMax support SAML?
Currently, ApprovalMax does not support SAML. However, we'll consider this for future enhancements. In the meantime, you're welcome to contact our Customer Success team with any questions you might have.
Does ApprovalMax have security and privacy accreditation? (SOC Type2, ISO27001, etc.)
We do not have any such certifications (SOC Type2, ISO27001 and the likes) at the moment. However, we do go through a 3rd party penetration testing every year.
Does ApprovalMax perform regular self-assessments based on international security practices?
We do go through 3rd party penetration testing every year, and perform regular internal self-assessment in addition to the external penetration testing.