Your employees trusted you with their honest answers. We take that seriously.
Bloomder runs on managed cloud infrastructure with encryption at rest and in transit, least‑privilege access controls, documented incident response, and a security posture we're happy to show you — including which parts of it are live today and which arrive with 1.0.
Infrastructure. Access. Accountability.
Every security decision at Bloomder falls into one of three buckets. Here's the short version, in plain language.
Infrastructure
Cloud built on proven foundations, not rolled from scratch.
- Managed cloud hosting and managed PostgreSQL, both in United States regions
- Automated backups with point‑in‑time restore
- Tenant data isolation at the database layer, enforced by every query
- DDoS protection and TLS termination at the edge
- AWS multi‑availability‑zone deployment with private VPCs: the target for 1.0 — see what runs today, and what 1.0 changes
Access
Least privilege by default. Nothing more.
- Password hashing with bcrypt
- SSO via Google and Microsoft (OIDC)
- Role‑based access controls (RBAC): Owner/Admin/Manager/Member permissions enforced on every API endpoint
- Session-based authentication with expiry, revoked server-side on password change or removal from an organization
- Enforced SSO (Enterprise): prohibit password sign-in org-wide and restrict allowed email domains, with a single-use break-glass recovery code
- Brute-force lockout: 5 failed sign-ins locks the address for 15 minutes
- MFA (authenticator app) and SAML SSO: on the roadmap, not yet available
Accountability
If something goes wrong, we know. And so do you.
- Documented incident response with ≤72h notification
- Responsible disclosure program for researchers
- Annual internal access reviews, recorded in the audit trail
- Admin-level audit logging: append-only record of every administrative action — actor, target, IP and user agent — retained 400 days and exportable to CSV from Settings, on every plan
What runs today, and what 1.0 changes
Bloomder is pre‑1.0 and the production stack is moving. Rather than describe the destination in the present tense, here is both — line by line, so a security reviewer can tell which sentence is a control and which is a plan.
TodayAmazon Web Services, a single EC2 instance in a United States region, behind Cloudflare for TLS termination and DDoS protection at the edge.
At 1.0Multi‑availability‑zone deployment inside private VPCs with network segmentation.
TodaySelf‑hosted PostgreSQL on that same EC2 instance, United States region. Tenant isolation is enforced at the data layer: every query is scoped to one organization.
At 1.0Amazon RDS for PostgreSQL, multi‑AZ, with the same tenant isolation.
TodayAutomated nightly backups, retained 35 days, stored on the same instance as the database.
At 1.0Automated RDS backups, capped at 35 days, geographically redundant and independent of the database instance. Our deletion promise is written against 35 days either way, so it holds before and after the migration.
TodayHeld in the server's environment configuration, scoped per environment. No production secret is ever committed to source control.
At 1.0AWS KMS with scoped IAM roles and rotation on a documented schedule.
Because the alternative is a security page that reads well and is wrong. If a control matters to your review and it sits in the second row here, ask us for the migration date before you sign — [email protected].
How anonymity actually works
"Confidential" and "anonymous" aren't the same thing. Here's the specific, verifiable mechanism Bloomder uses — not a marketing promise.
What's the actual anonymity threshold?
Bloomder enforces a minimum of 5 distinct respondents (what's known as k‑anonymity, k = 5) before showing any result. A department, a matrix cell, or an entire survey run that has fewer than 5 responses shows Insufficient data to protect anonymity instead of a score — no matter how the data would otherwise look.
Where is the threshold applied?
Everywhere results can be broken down: the results dashboard, the department × dimension health matrix, and CSV exports. It's enforced once, at the data layer, so there's no view or export path that bypasses it.
Can an admin lower the threshold to see individual answers?
No. It's a platform‑wide floor, not a per‑survey or per‑admin setting — the same way a locked door doesn't have a setting for "sometimes unlocked." Zero responses is treated as "no data yet," which is different from "suppressed for anonymity."
Why does this matter more than "we promise not to look"?
Most engagement tools call themselves anonymous but will still show you a department's results if only one person answered — which means that one person's honest answer is the department's result. A verifiable minimum is what makes "anonymous" mean something instead of just a word on a landing page.
Every byte, in transit and at rest
Strong, widely‑reviewed cryptography — not custom. We use the same standards banks and major cloud providers use.
The short list of vendors
who touch your data
We keep it small on purpose. Every additional vendor is an additional surface area. Each one below has a Data Processing Agreement in place, and each is named — a list of categories tells a security reviewer nothing.
| Sub‑processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, compute, storage, backups — today's deployment | United States |
| Anthropic PBC (Claude) | Generation of AI insights. It receives the question text, aggregate answer counts and the free‑text answers of a run with at least 5 respondents; never a name, an email address or anything tying an answer to a person. Inputs are not used to train models and are deleted within 30 days. | United States |
| Resend | Delivery of survey invitations, reminders, account notifications | United States |
| Stripe | Subscription billing (PCI‑DSS compliant; card details never reach our systems) | United States, global processing |
| Upstash | Rate limiting and sign‑in lockout counters (IP addresses and attempted email addresses, short‑lived; no survey content) | United States |
Every sub‑processor is under a Data Processing Agreement. Customers on enterprise DPAs receive 30 days' notice of material sub‑processor changes with the right to object — including the AWS migration above.
This table covers the product. The marketing website also uses a small set of web analytics providers, one of which records the session — see Privacy Policy → Sub‑processors — website analytics.
What's live, what's on the roadmap
We don't claim certifications we don't have. Here's the honest breakdown of where we are and where we're going.
When something goes wrong, you hear it first
We maintain a written incident response plan covering detection, triage, containment, eradication, recovery, and post‑incident review. It's rehearsed, not just filed.
Responsible disclosure
Found a vulnerability? Please report it to [email protected] with enough detail to reproduce.
We commit to:
- ✓ Acknowledge your report within 72 hours.
- ✓ Keep you updated on remediation progress.
- ✓ Not take legal action against good‑faith researchers.
- ✓ Publicly credit you after the fix ships, if you wish.
Please do not publicly disclose until we've had a reasonable opportunity to fix the issue.
The honest fine print
No system is 100% secure. These commitments describe the controls and processes we operate today; they are not a warranty or a guarantee. Your use of Bloomder implies acceptance of residual risk — which we work hard to minimize but cannot eliminate. For formal contractual security commitments, execute a DPA and order form with your account team.
Questions? Security questionnaire? DPA?
Our security team answers within 72 hours.
Contact [email protected] →