Spotify: Cloud Confidence Index
Spotify: Cloud Confidence Index
Spotify: Cloud Confidence Index
43
Spotify
Consumer, Unsanctioned
Cloud Confidence
App Category: Streaming & Downloadable Audio
Location of Headquarters: Stockholm, Sweden
spotify.com
Business Risk
DUNS #
Activities
Summary
Spotify is a commercial music streaming service that provides restricted digital content from a range of record labels and artists. Users
can browse through the interface by artist, album, genre, playlist, record label, and direct searches. It also enables individuals to create,
share, and edit playlists with other users.
Pricing Plan
07/23/2021 Spotify
Cloud Confidence Index
Data Protection
Does the app allow data classification (e.g., public, confidential, proprietary)?
No published support
Yes, Under Research, Not Applicable
If yes, does the app allow admins to take action on classified data (e.g., encrypt, control access)?
No published support
Yes, Under Research, Not Applicable
Does the app increase the risk of data exposure by supporting weak cipher suites?
No
Does the app increase the risk of data exposure by supporting weak signature algorithm or key size ?
Does not support weak Algorithm
SHA1 with RSA/1024 Bits, SHA1 with RSA/2048 Bits, SHA1 with RSA/4096 Bits, Under Research
Does the app vendor use a Sender Policy Framework to protect customers from spam and phishing emails?
07/23/2021 Spotify
Cloud Confidence Index
Yes
The list of platforms through which the app traffic can be proxied:
Under Research
Access Control
SSO/AD hooks
OAuth, Facebook, Google Sign-in
SAML, OpenID, Twitter, AD/LDAP, Linkedin, No published support, Under Research
07/23/2021 Spotify
Cloud Confidence Index
Auditability
Does the app vendor provide notifications to customers about upgrades and changes (e.g., scheduled maintenance, new releases,
software/hardware changes)?
Yes
Does the app vendor back up customer data in a separate location from the main data center?
Yes
Does the application vendor utilize geographically dispersed data centers to serve customers?
Yes
Who owns the data/content uploaded to the application site? Does the customer own the data or does the application vendor own the data?
Customer owns the data
No published support, Under Research
07/23/2021 Spotify
Cloud Confidence Index
Does this app share users' personal information (e.g., name, email, address) with third parties?
Yes
Has this application been recently breached (in the past year)?
Yes
Spotify Hacked, 02/05/21, Source(s): Digital Music News
Credential stuffing attacks, 11/24/20, Source(s): welivesecurity
This value is a significant factor which adversely affects the overall score for this application
07/23/2021 Spotify
Powered by TCPDF (www.tcpdf.org)