Secure by Design Pledge
OfficeSpace Software, a cloud-native SaaS workplace management platform, aligns with the CISA Secure by Design Pledge by embedding security into its processes and architecture through mandatory multi-factor authentication, elimination of default passwords, integration of secure development lifecycle practices to reduce vulnerabilities, managed risk-based patching without customer involvement, a vulnerability disclosure policy with plans for public publication, and internal tracking of vulnerabilities despite not distributing software or issuing CVEs.
Overview
OfficeSpace Software is a cloud-native Software as a Service (SaaS) platform focused on workplace management. As a steward of customer workplace operational data, security is embedded into processes, architecture, and engineering practices.
In alignment with the Cybersecurity and Infrastructure Security Agency (CISA) Secure by Design Pledge, OfficeSpace has assessed its existing controls and is working to demonstrate measurable progress against each of the seven pledge goals over time.
Secure by Design Practices
Multi-Factor Authentication (MFA)
What we do today:
- MFA is mandatory for all internal OfficeSpace employees and administrators.
- Customers may enforce MFA via SSO integrations (SAML, Google Workspace).
- Administrative roles require phishing-resistant MFA.
No Default Passwords — Ever
What we do today:
- OfficeSpace does not use default, shared, or manufacturer passwords.
- Strong password policies and unique credentials are enforced.
Reducing Entire Classes of Vulnerabilities
What we do today:
- SDLC integrates SAST, DAST, threat modeling, peer review, and OWASP-aligned frameworks.
- These practices reduce entire categories of vulnerabilities such as SQLi and XSS, and more.
Security Patching and Updates
What we do today:
- OfficeSpace manages all platform patches and updates.
- Risk-based patch timelines are enforced (Critical: 0–15 days, High: 0–30 days, etc.).
- Customers do not need to deploy or maintain patches.
Vulnerability Disclosure Policy (VDP)
What we do today:
- Our VDP includes safe harbor, scope boundaries, and a reporting channel.
- Unauthorized scanning of production systems is prohibited.
Where we are improving:
- Publishing the VDP publicly.
CVE Transparency
What we do today:
- As a SaaS provider, OfficeSpace does not distribute software, and CVEs reporting generally not applicable.
- Vulnerabilities are tracked and validated through internal SAST, DAST, WAS, tests, as well as external penetration testing.
Evidence of Intrusions and Logging
What we do today:
- Centralized logging and monitoring are in place.
- SIEM tools aggregate logs across infrastructure, app layers, and authentication.
- Incident response procedures govern investigation and customer notification.
Shared Responsibility Model
OfficeSpace is responsible for platform security including patching, monitoring, authentication controls, and infrastructure security.
Customers are responsible for configuring their own identity provider settings, MFA policies, access controls within their organization, and internal data governance.
Related Documentation
The following documentation is available to authorized customers and prospects in our Trust Center:
- SOC 2 Type II
- CSA STAR level 1
- Information Security Policies
- SDLC documentation
- Access Control, Patch Management, Logging, and Incident Response Standards
- Prefilled Vendor Security Assessment (VSA) questionnaire
Access: https://trust.officespacesoftware.com
Contact
For questions or to report a potential security concern:
Related
Client Privacy Policy
The Client Privacy Policy of OfficeSpace Software Inc. details how it collects, uses, and protects personal data from clients who use its Subscription Services, specifying that OfficeSpace collects necessary contact information and client-uploaded data to provide services per client instructions, processes additional data from client communications for service support and administration, gathers technical data from devices for optimization, and commits to processing client data solely to fulfill contracted services under strict data protection obligations.
Plans | OfficeSpace
OfficeSpace offers two AI-powered plans—Essentials Plus, which automates space planning and workplace experience to streamline office operations and employee desk booking, and Pro Plus, which adds advanced AI-driven analytics and real-time utilization tracking to help leaders forecast space needs and manage portfolios with executive-ready insights and enhanced integrations.
Desk Booking Software for Hybrid Teams
The AI-powered Desk Booking Software for Hybrid Teams enables seamless desk reservations with features like real-time occupancy tracking, interactive floor plans, hot desking, hoteling, reverse hoteling, automatic check-ins, and integration with sensors to eliminate ghost bookings, all designed to optimize workspace utilization, improve attendance, and enhance employee experience in flexible office environments.
Desk Booking Software for Hybrid Teams
The Desk Booking Software for Hybrid Teams offers AI-powered, flexible desk reservation and management features—including real-time occupancy tracking, interactive floor plans, hot desking, hoteling, reverse hoteling, and automated desk release via sensor integration—to optimize workspace utilization, improve employee experience, and maximize office ROI.
Office Neighborhoods and Flexible Workspace Management
OfficeSpace’s AI-powered platform enables flexible, activity-based office neighborhoods with intuitive tools for creating and managing seating assignments, optimizing hybrid work layouts, increasing desk sharing ratios, automating role-based booking rules, tracking occupancy and capacity, assigning neighborhood captains, and integrating seamlessly with major collaboration tools to enhance workplace experience and real estate efficiency.
Finance | OfficeSpace
OfficeSpace offers a secure, easy-to-use workplace management software tailored for the finance industry that enhances hybrid work strategies, optimizes real estate use with real-time data, ensures enterprise-grade security with features like access controls and single sign-on, and integrates seamlessly with existing tools to improve employee and client experiences while reducing costs.