Security
Last updated: 5 August 2026
Plain answers about where your data lives, who can touch it, and what we do and do not claim.
01 Where your data lives
Your data sits on dedicated servers in the EU (Germany), not shared hosting. Messages, contacts, campaigns, appointments, files, media and backups all remain in the EU.
02 Access control
A small operations team has access. Servers use SSH keys only with password login disabled, the database is unreachable from the public internet, 2FA is available, and API keys are stored hashed and never retrievable.
03 In transit and at the edge
TLS 1.2+ is enforced everywhere, Cloudflare provides DDoS protection, repeated failed logins are blocked automatically, and admin interfaces are not publicly exposed.
04 Backups and recovery
Daily backups are kept with seven retained copies inside the EU, transaction logging enables point-in-time restore, and recovery is rehearsed on isolated hardware.
05 Sub-processors
The full list is at /subprocessors/. Some AI providers operate outside the EU under Standard Contractual Clauses. We give 14 days' notice before adding any new processor.
06 Data protection
A GDPR Article 28 DPA applies automatically to every customer, with a countersigned copy at /dpa/. Export or deletion is available at any time. We comply with the Philippine Data Privacy Act of 2012 (RA 10173) and maintain National Privacy Commission registration.
07 AI transparency
From 2 August 2026, AI interaction is disclosed as required by EU AI Act Article 50, and disclosure is enabled by default on new campaigns.
08 What we do not claim
BloomCONNECT is not SOC 2 or ISO 27001 certified. We would rather say so plainly and answer specific questions than imply a certification we do not hold.
09 Reporting a vulnerability
Email security@bybloomlabs.com. We respond within two business days, welcome good-faith research, and will not pursue researchers acting in good faith.
