SSOE A.I CyberSecurity Scoring
12/03/2026
Access Monitoring Plan
Access Monitoring Plan
No incidents recorded for Shared Services & Outsourcing Exchange in 2026.
No incidents recorded for Shared Services & Outsourcing Exchange in 2026.
No incidents recorded for Shared Services & Outsourcing Exchange in 2026.
Sempre inovador, o Grupo Souza Lima desenvolve soluções completas e híbridas, que realmente funcionam, em serviços de Segurança, Limpeza e Facilities. Essas soluções já são realidade para clientes Souza Lima e integram colaboradores treinados com tecnologia avançada para otimizar recursos e melhorar a performance nos segmentos de indústrias, shoppings, condomínios, instituições de ensino e de saúde, entre diversas outras empresas. Com mais de 30 anos de mercado e atuação nacional, conta com mais de 30.000 colaboradores, 2000 clientes e 22 filiais em 14 estados.
We established our back office here in Pakistan back in 2016 after which we have been providing complete support to our registered office in Florida. Our main aim has been to function as an effective thirdparty service provider in order to maintain beneficial relationships with multiple US based clients.Our sole focus has always been to deliver our best in an efficient and timely manner. We make sure that we develop a relationship of trust with our clients so that they can highly improve their business performance and shareholder value, at the same time reducing their costs to a greater extent. We function to cater businesses unique needs for multiple industries such as accounting, e‐commerce, pharmaceuticals, telecommunications and more. A highly committed, multi‐talented and energetic team is the sole reason we have been able to offer solutions to complex problems within a specified timeframe so that our clients’ needs and requirements are completely fulfilled with complete satisfaction.
As the global leader in trusted technology services, empowering secure mobility for governments and citizens, VFS Global embraces technological innovation including Generative AI to support governments and diplomatic missions worldwide. VFS Global continuously transforms its business model with secure and efficient processes, market offerings and advanced technologies including AI/Analytics. With a responsible approach to technology development, adoption and integration, the company prioritizes ethical practices and sustainability while serving as a trusted partner to 69 client governments. VFS Global enhances cross border mobility for global citizens through highly secure, reliable, efficient, and innovative technology solutions. With an extensive global network and reach of over 3,900 Application Centres in 165 countries, VFS Global has efficiently processed more than 514 million transactions since 2001. We are an employee-centric organisation, creating meaningful work opportunities and fostering successful careers. Headquartered in Zurich and Dubai and majority owned through investment funds managed by Blackstone Inc, along with minority stakeholders including Swiss-based Kuoni and Hugentobler Foundation, we have been recognised for our commitment to nurturing a diverse and inclusive workplace, empowering women in our workforce and promoting gender equality at all levels of the organisation. We’re proud to be Great Place to Work-certified in Nigeria, China, India, and UAE, and hold multiple international certifications in data privacy, anti-bribery systems, and customer satisfaction. *Comprised of 325.54 million transactions by VFS Global and 189.12 million transactions by CiX Citizen Experience
A global customer experience (CX) management solutions provider, Startek® delivers best-in-class omnichannel CX, digital transformation and enterprise tech services for leading brands, from Fortune 500s to fast-growing startups. Our innovation and expertise ensure CX excellence across traditional and non-traditional channels. Working both in-center and via work at home, our 40,000 CX experts are present in 13 countries ensuring global reach and local connection no matter where your customers are based. The award-winning Startek Cloud, a hybrid-cloud platform integrated with AI capabilities, empowers remote and home-based team members, to deliver business agility and continuity. At Startek we believe that every organization can deliver meaningful customer experience (CX) at every touchpoint by harnessing the power of empathy. Empathy is looking through your customer’s eyes to understand the world as they see it and leveraging that understanding to build human-centric experiences that create an effortless 1-2-1 connection. Applying empathy across data, technology and people, we enable our clients to build long-term, profitable customer relationships by closing the CX gap. To find out more visit www.startek.com.
We are TP Group. You’ve been calling us Teleperformance for almost 47 years. But in the AI era, the world has changed, and we had to change too to keep leading the digital business services market. We’re sharper, more modern, and even more empathetic. We are TP. Simple as that. Intelligent as always, and future-proof for the journey ahead.
ResultsCX is a leading provider of transformational Customer Experience Management (CXM) solutions to 75+ global brands, including Fortune 100 and 500 companies. For 30+ years, we have been driving superior customer and business outcomes for brands across Healthcare, Media, Telecom, Fast Growth technology, Retail, Banking and Financial Services, and other industries. Our award-winning approach helps brands prioritize investments and build digitally influenced customer journeys, creating high-value impact across three areas: Revenue Acceleration, Cost Optimization, and Enhanced Experience. Supported by 23,000+ colleagues and 25+ engagement hubs worldwide, our innovative solutions and services solve persistent customer experience challenges, making life easier for millions of consumers.
We’re TTEC (pronounced t.tec). For over 40 years we have been obsessed with one thing: Helping the world’s best brands deliver exceptional customer experiences (CX). We're not just another BPO company. We're CX innovators, with deep understanding of what makes customers happy. We seamlessly blend human expertise with the power of AI to deliver optimized solutions across every touchpoint – from customer care and tech support to sales, collections, and trust & safety.
Offering flexible solutions for all of the UAE’s staffing needs since 2001, Transguard Group is the region’s most trusted expert in security, facilities management, cash services and white-collar staffing, and more. With an annual turnover of AED 3.2 billion in FY24/25, Transguard’s expertise is in supplying the right people for its clients, precisely when and where they’re needed. To learn more, visit www.transguardgroup.com.
About VXI Global Solutions VXI Global Solutions is a BPO leader in customer service, customer experience, and digital solutions. Founded in 1998, the company has 40,000+ employees in 43 locations in North America, Asia, Europe, and the Caribbean. VXI delivers omnichannel and multilingual support, revenue generation, software development, quality assurance, and CX advisory, automation, and process excellence to the world’s most respected brands. VXI is backed by private equity investor Bain Capital and is one of the fastest growing, privately held business services organizations in the United States and the Philippines. For more information, visit www.vxi.com. Contact Us: [email protected] Customer Experience Management | Omni Channel | Customer Journey Mapping | Digital Sales Channels | Application Development | Digital CX | Service Excellence | Contact Center | Call Center | Revenue Generation | Business Outcomes | CX Strategy | AI & automation | Business Analytics
Latest updates, reports, and threat intel affecting the global network.
LITTLE FALLS, NJ - The Township of Little Falls is applying for a grant along with other North Jersey municipalities to help fund a shared...
According to a recent LinkedIn post from AppZen, the company plans to participate in the Shared Services & Outsourcing Week Americas event...
A bipartisan, bicameral bill was introduced this week that would create a government-wide shared services lending platform known as...
The governor's state budget proposal for 2026-27 funds programs to reduce social media's impact on student health, and shared services by...
House and Senate lawmakers from both sides of the aisle have introduced new legislation that would create a “Lending.gov” shared services...
Opinion On the eve of its fifth birthday, the UK's Shared Services Strategy for Government got a couple of presents.
Eight years on from the launch of the government's shared services strategy, there is no clear ownership, funding remains uncertain and some...
Legislation introduced in both houses of Congress on Wednesday would require the government to create a new front door for loans at...
Alberta Premier Danielle Smith said the province will be looking to scale back administrative positions with the establishment of its new...
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc grpc (GRPC.Compressor.Gzip, GRPC.Message modules) allows a denial of service via a gzip decompression bomb. This vulnerability is associated with program files lib/grpc/compressor/gzip.ex, lib/grpc/message.ex and program routines 'Elixir.GRPC.Compressor.Gzip':decompress/1, 'Elixir.GRPC.Message':from_data/2. 'Elixir.GRPC.Compressor.Gzip':decompress/1 calls :zlib.gunzip/1 directly on attacker-controlled bytes with no decompressed-size limit, ratio check, or incremental decoding. Because this module is the registered gzip GRPC.Compressor implementation, it is invoked automatically whenever an incoming gRPC frame carries the grpc-encoding: gzip header. :zlib.gunzip/1 allocates the entire decompressed result as a single binary, so a small highly compressible payload (for example a few kilobytes of zeros, which gzip compresses at roughly 1000:1) expands to multiple gigabytes inside a single call. The max_receive_message_length limit is enforced only against the already-decompressed message, so it provides no protection. An unauthenticated remote peer can send a single crafted frame to exhaust the BEAM node's heap and trigger an out-of-memory kill. This issue affects grpc: from 0.4.0 before 1.0.0.
Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory and crash the server by streaming a large or slow-trickle unary request body. 'Elixir.GRPC.Server.Adapters.Cowboy.Handler':read_full_body/3 (lib/grpc/server/adapters/cowboy/handler.ex) accumulates every received chunk into a single growing binary with no size cap. Additionally, when the client omits the grpc-timeout header, the per-chunk read timeout resolves to :infinity, allowing a slow-trickle client to keep the connection alive indefinitely while memory grows. A single connection is sufficient to exhaust server memory and crash the node. This issue affects grpc from 0.3.1 before 1.0.0.
Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flows into a call site that invokes it, achieve remote code execution on the server. 'Elixir.GRPC.Codec.Erlpack':decode/2 (lib/grpc/codec/erlpack.ex) calls :erlang.binary_to_term/1 on the raw gRPC message body without the :safe option, no size bound, and no type guard. Any unauthenticated peer that sends a request with Content-Type: application/grpc+erlpack can send a crafted payload that mints arbitrary new atoms (which are never garbage-collected, exhausting the bounded atom table and crashing the VM) or that encodes a fun term which, if applied anywhere downstream, executes attacker-controlled code inside the server process. This issue affects grpc from 0.4.0 before 1.0.0.
The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions prior to 1.36.4 are vulnerable to OS command injection via the cypress_config_file configuration parameter. In readCypressConfigUtil.js, the loadJsFile() function constructs a shell command by interpolating the user-controlled cypress_config_filepath value into a template literal, then executes it via child_process.execSync(). Shell metacharacters in the config path (specifically " and ;) allow breaking out of the quoted argument and injecting arbitrary commands. This issue has been fixed in version 1.36.6.
Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting value for any path-bound field via the query string or request body. In 'Elixir.GRPC.Server.Transcode':map_request/5 (lib/grpc/server/transcode.ex), all three clauses use Map.merge/2 with path bindings as the first argument, giving them the lowest merge precedence. A request such as GET /users/me/profile?user_id=victim (or a POST with {"user_id": "victim"} when body: "*") yields a decoded protobuf struct where the path-bound field carries the attacker-supplied value rather than the router-extracted value. Any handler that uses the path-bound field for authorization, multi-tenancy scoping, or ownership checks is silently bypassed. This issue affects grpc from 0.8.0 before 1.0.0.
curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?
linkedin_id=axa' -H 'apikey: YOUR_API_KEY_HERE'
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.