Skip to main content
Xoxoday Plum maintains defined and documented vulnerability management procedures encompassing scheduled vulnerability scanning, periodic penetration testing (VAPT), ISO 27001-certified ISMS governance, and independently verified controls through SOC 2 Type 1 and SOC 2 Type 2 audits.
Xoxoday Plum takes a structured, multi-layered approach to vulnerability management across its rewards, gifting, and incentives platform — covering the digital catalogue, redemption marketplace, supporting infrastructure, and associated operational processes. Vulnerability Scanning and Remediation Scheduled vulnerability assessments identify known weaknesses across application and infrastructure components. Each finding is risk-rated and tracked through a remediation workflow to closure. Where applicable, re-testing confirms that identified vulnerabilities have been fully addressed before the finding is marked resolved. Penetration Testing (VAPT) Xoxoday Plum conducts periodic penetration testing to validate real-world exploitability and uncover control gaps that automated scanning alone may not surface. Independent or third-party testers are engaged where appropriate, providing objective assurance that goes beyond internal review cycles. Security Certifications and Independent Audits Xoxoday Plum operates an ISO 27001-certified Information Security Management System (ISMS), subject to regular surveillance and recertification audits. Xoxoday Plum has also completed both SOC 2 Type 1 and SOC 2 Type 2 audits — giving enterprise buyers, including those managing procurement through platforms such as SAP SuccessFactors or Workday, independently verified assurance over the design and long-term operating effectiveness of key security controls. Security Configuration Reviews Security configuration reviews are performed as part of ongoing operational governance. These reviews cover perimeter controls, access controls, and secure configurations across hosted infrastructure and application security layers. All configuration changes are controlled, approved, and logged through documented procedures to prevent drift and maintain a full audit trail. Secure SDLC and Code-Level Security Xoxoday Plum applies secure engineering practices throughout the software development lifecycle. Code review and security testing activities are integrated at the development stage, enabling continuous identification and remediation of vulnerabilities introduced through code changes or third-party dependencies before they reach production. Patch and Change Management All patching and changes to production environments follow documented change control procedures that include approvals and pre-deployment testing. This process reduces the risk of introducing new vulnerabilities or configuration drift, and every change applied to production remains controlled and auditable. Together, these procedures give your organisation confidence that Xoxoday Plum maintains a proactive, documented, and independently verified security posture — backed by recognised international standards. Learn more: [Xoxoday Plum Help Centre — General](

Data Encryption and Security Controls

Learn how Xoxoday Plum protects data in transit and at rest using encryption and layered security controls.

Access Control and User Permissions

Understand how Xoxoday Plum manages role-based access, authentication, and user permission governance.