Last updated: 2 September 2026
This page describes how the Leave & PTO Tracker app for monday.com is hosted, what it can and cannot reach, how it decides who may do what, and how to tell us about a vulnerability. It is written for the person in your organisation who has to sign off on installing it.
The app runs entirely on monday code, monday.com's own hosting for marketplace apps, in the European Union region. Its data is one JSON record per monday.com account, kept in the storage that platform gives the app.
We operate no infrastructure. There is no server of ours, no database of ours, no backup of ours and no administration console. There is nothing of ours for an attacker to break into, and no credential of ours that would unlock your data.
The app calls no external service: no analytics, no error reporting, no AI service, no third-party API. The only network it speaks to is monday.com's own. It sets no cookies, registers no service worker and stores nothing in the user's browser.
All traffic is HTTPS. Data at rest is encrypted by monday.com as part of the platform. The two secrets the app needs — the keys monday.com uses to sign what it sends — are held in the platform's own secrets store, mounted into the running app, and never written into the source code or into any log.
The app has no login of its own and no password to steal. Every call from the screen carries a token issued and signed by monday.com. The server verifies that signature before doing anything at all, and takes from that token only: who you are, which account you belong to, and whether you administer it. Nothing the browser asserts about identity is trusted.
Every authorisation check runs on the server, on every call — never by hiding a button:
DELETE must be typed, and the
server checks that word again.This was a deliberate rewrite, and it is worth stating. An earlier version of this app kept those rules in the browser. The calculations were right and the tests were green, and it was still wrong: anybody who opened the developer tools could have approved their own leave. The rules now live on the server, and the test suite exercises them through the real path — request in, storage, response out — rather than in isolation.
The leave type, the note written by the person requesting, and the reason given for turning a request down are removed from the response on the server for anybody who is neither the person concerned nor an approver. Colleagues see who is away and on which dates, and nothing else. Because the removal happens before the answer is sent, the sensitive part never reaches their machine — it is not merely hidden by the page.
This matters more than usual here: sick leave is one of the leave types, so it is health-related information about your staff. The Privacy Policy and the DPA set out the detail.
Each monday.com account's record is addressed by the account ID taken from the signed token, never from the body of a request. The automated test suite contains a case that erases one company and then proves its neighbour is untouched.
monday.com notifies the app when an account installs it, uninstalls it, or changes its subscription. That endpoint sits behind an address that ends in a secret held in the platform's secrets store and registered only in monday.com's developer console; no screen in the app ever calls it, so no user of the app ever sees it. An unknown key is answered as if the address did not exist.
The reason is specific rather than decorative. We measured what those notices actually carry, and they are signed with the same key as an ordinary user's token and contain the same fields — so there is no property of the message itself that distinguishes a genuine platform notice from one forged by any logged-in user. Since the notice is what triggers erasure, and the account it names comes from its own body, without that secret address anyone could have asked the app to erase a company. The signature is still checked, and the account named in the token must match the one in the body.
The app asks monday.com for the minimum it needs to work: enough to read the display name of the person using it, and its own storage. It does not ask for permission to read your boards — not items, not columns, not updates, not files — so it could not read them if a future version tried.
Email help@saoirsesoftware.com with the word SECURITY in the subject. Please include what you found, how to reproduce it and what you think the impact is.
If a security incident affects data processed by the app, we will contact affected customers without undue delay, and within 72 hours of becoming aware, describing what is known, the likely impact and what is being done. Section 9 of the DPA sets this out, including how to give us a specific mailbox for such notices.
Everything the app holds for your account is erased automatically when you uninstall, and can be erased at any time by an account administrator from the Setup tab. Both routes delete the record rather than marking it deleted, and we keep no copy to restore from. Export the year report first if you need to keep it.
Leave & PTO Tracker is supplied by Kauê Natan Gonçalves Bidim, trading as Saoirse Software, in Ireland. Security reports and questions go to help@saoirsesoftware.com.