✦ Data Security

Your employees trusted you with their honest answers. We take that seriously.

Bloomder runs on managed cloud infrastructure with encryption at rest and in transit, least‑privilege access controls, documented incident response, and a security posture we're happy to show you — including which parts of it are live today and which arrive with 1.0.

k = 5
Anonymity floor, enforced
AES‑256
At‑rest encryption
TLS 1.2+
In‑transit encryption
≤72h
Breach notification
The three pillars

Infrastructure. Access. Accountability.

Every security decision at Bloomder falls into one of three buckets. Here's the short version, in plain language.

Infrastructure

Cloud built on proven foundations, not rolled from scratch.

  • Managed cloud hosting and managed PostgreSQL, both in United States regions
  • Automated backups with point‑in‑time restore
  • Tenant data isolation at the database layer, enforced by every query
  • DDoS protection and TLS termination at the edge
  • AWS multi‑availability‑zone deployment with private VPCs: the target for 1.0 — see what runs today, and what 1.0 changes

Access

Least privilege by default. Nothing more.

  • Password hashing with bcrypt
  • SSO via Google and Microsoft (OIDC)
  • Role‑based access controls (RBAC): Owner/Admin/Manager/Member permissions enforced on every API endpoint
  • Session-based authentication with expiry, revoked server-side on password change or removal from an organization
  • Enforced SSO (Enterprise): prohibit password sign-in org-wide and restrict allowed email domains, with a single-use break-glass recovery code
  • Brute-force lockout: 5 failed sign-ins locks the address for 15 minutes
  • MFA (authenticator app) and SAML SSO: on the roadmap, not yet available

Accountability

If something goes wrong, we know. And so do you.

  • Documented incident response with ≤72h notification
  • Responsible disclosure program for researchers
  • Annual internal access reviews, recorded in the audit trail
  • Admin-level audit logging: append-only record of every administrative action — actor, target, IP and user agent — retained 400 days and exportable to CSV from Settings, on every plan
Infrastructure

What runs today, and what 1.0 changes

Bloomder is pre‑1.0 and the production stack is moving. Rather than describe the destination in the present tense, here is both — line by line, so a security reviewer can tell which sentence is a control and which is a plan.

Hosting

TodayAmazon Web Services, a single EC2 instance in a United States region, behind Cloudflare for TLS termination and DDoS protection at the edge.

At 1.0Multi‑availability‑zone deployment inside private VPCs with network segmentation.

Database

TodaySelf‑hosted PostgreSQL on that same EC2 instance, United States region. Tenant isolation is enforced at the data layer: every query is scoped to one organization.

At 1.0Amazon RDS for PostgreSQL, multi‑AZ, with the same tenant isolation.

Backups

TodayAutomated nightly backups, retained 35 days, stored on the same instance as the database.

At 1.0Automated RDS backups, capped at 35 days, geographically redundant and independent of the database instance. Our deletion promise is written against 35 days either way, so it holds before and after the migration.

Keys & secrets

TodayHeld in the server's environment configuration, scoped per environment. No production secret is ever committed to source control.

At 1.0AWS KMS with scoped IAM roles and rotation on a documented schedule.

Why say this

Because the alternative is a security page that reads well and is wrong. If a control matters to your review and it sits in the second row here, ask us for the migration date before you sign — [email protected].

Anonymity

How anonymity actually works

"Confidential" and "anonymous" aren't the same thing. Here's the specific, verifiable mechanism Bloomder uses — not a marketing promise.

What's the actual anonymity threshold?

Bloomder enforces a minimum of 5 distinct respondents (what's known as k‑anonymity, k = 5) before showing any result. A department, a matrix cell, or an entire survey run that has fewer than 5 responses shows Insufficient data to protect anonymity instead of a score — no matter how the data would otherwise look.

Where is the threshold applied?

Everywhere results can be broken down: the results dashboard, the department × dimension health matrix, and CSV exports. It's enforced once, at the data layer, so there's no view or export path that bypasses it.

Can an admin lower the threshold to see individual answers?

No. It's a platform‑wide floor, not a per‑survey or per‑admin setting — the same way a locked door doesn't have a setting for "sometimes unlocked." Zero responses is treated as "no data yet," which is different from "suppressed for anonymity."

Why does this matter more than "we promise not to look"?

Most engagement tools call themselves anonymous but will still show you a department's results if only one person answered — which means that one person's honest answer is the department's result. A verifiable minimum is what makes "anonymous" mean something instead of just a word on a landing page.

Encryption

Every byte, in transit and at rest

Strong, widely‑reviewed cryptography — not custom. We use the same standards banks and major cloud providers use.

Data at rest
AES‑256 at the storage layer for production databases and their backups, applied by the managed database provider. Object storage is encrypted with provider‑managed keys.
Data in transit
TLS 1.2+ required for all HTTPS endpoints. HSTS enabled. Deprecated ciphers disabled.
Credentials
Passwords stored hashed with bcrypt (or Argon2id where available). Raw passwords never logged.
Keys & secrets
Held today in the server's environment configuration, scoped per environment; AWS KMS with scoped IAM access at 1.0. No production secrets in source control, and rotation on a documented schedule either way.
Backups
Nightly, with periodic restore testing. Retention windows and the 1.0 change are in Infrastructure above.
Sub‑processors

The short list of vendors
who touch your data

We keep it small on purpose. Every additional vendor is an additional surface area. Each one below has a Data Processing Agreement in place, and each is named — a list of categories tells a security reviewer nothing.

Sub‑processor Purpose Location
Amazon Web Services (AWS) Cloud infrastructure, compute, storage, backups — today's deployment United States
Anthropic PBC (Claude) Generation of AI insights. It receives the question text, aggregate answer counts and the free‑text answers of a run with at least 5 respondents; never a name, an email address or anything tying an answer to a person. Inputs are not used to train models and are deleted within 30 days. United States
Resend Delivery of survey invitations, reminders, account notifications United States
Stripe Subscription billing (PCI‑DSS compliant; card details never reach our systems) United States, global processing
Upstash Rate limiting and sign‑in lockout counters (IP addresses and attempted email addresses, short‑lived; no survey content) United States

Every sub‑processor is under a Data Processing Agreement. Customers on enterprise DPAs receive 30 days' notice of material sub‑processor changes with the right to object — including the AWS migration above.

This table covers the product. The marketing website also uses a small set of web analytics providers, one of which records the session — see Privacy Policy → Sub‑processors — website analytics.

Compliance posture

What's live, what's on the roadmap

We don't claim certifications we don't have. Here's the honest breakdown of where we are and where we're going.

GDPR / UK GDPR
LiveWe support data subject rights via [email protected]. SCCs used where required. See our Privacy Policy.
CCPA / CPRA
LiveCalifornia residents can access, delete, correct, and limit use of their personal data. We do not sell or share personal data.
Mexican Federal Law (LFPDPPP)
LiveAs a Mexican company (Zafiro Technology, S.A. DE C.V.) we operate under the Federal Law on Protection of Personal Data Held by Private Parties.
DPA available
LiveData Processing Addendum available on request for B2B customers.
Deletion after cancellation
LiveAutomated, not a manual process. 30 days to export, production data deleted within 90 days of cancellation, and no copy survives past a further 35 days — the ceiling on an automated backup window that is 30 days with today’s database provider and 35 days on Amazon RDS at 1.0, so the promise holds on both sides of the migration. A deletion record with the dates and per-table row counts is kept as evidence; it holds no personal data. See section 9.1 of the Terms.
Audit trail
LiveEvery administrative action — role changes, member removals, employee imports, survey launches, API key creation, single sign-on policy changes — is recorded with the actor, the target, the IP address and the timestamp. Records cannot be edited or deleted by anyone, including us. Retained for 400 days and exportable to CSV by the account owner at any time.
Access reviews
LiveAccount owners can review who has access, with each person's role, join date, last sign-in and sign-in method, and record a signed-off snapshot of that roster in the audit trail.
Enforced single sign-on
LiveOn the Enterprise plan, an account owner can prohibit password sign-in across the whole organization and restrict which email domains may be invited. Includes a single-use recovery code so an outage at your identity provider never locks you out of your own account. Enterprise is a custom annual contract — talk to us.
SOC 2 Type II
RoadmapNot certified. The technical controls an audit depends on are in place today — the immutable audit trail, recorded access reviews and 400-day evidence retention described above — and the audit itself, which requires an external firm and an observation window, is planned for 2026. We can share a security questionnaire today and a gap assessment on request.
ISO 27001
EvaluatingUnder consideration for 2027 as enterprise demand justifies. Not certified today.
HIPAA
Not offeredBloomder is not HIPAA‑compliant and should not be used to collect protected health information. Contact us before using for healthcare workforce surveys.
Incident response

When something goes wrong, you hear it first

We maintain a written incident response plan covering detection, triage, containment, eradication, recovery, and post‑incident review. It's rehearsed, not just filed.

Detection
24/7 automated alerting on anomalous access, authentication failures, and infrastructure health.
Triage
On‑call rotation with documented severity levels and escalation paths.
Customer notification
For confirmed incidents affecting personal data, we commit to notify impacted customers within 72 hours of confirmation with: what happened, what data was involved, what we're doing, and what you should do.
Post‑mortem
Blameless post‑mortem published internally. Summary available to enterprise customers under NDA.

Responsible disclosure

Found a vulnerability? Please report it to [email protected] with enough detail to reproduce.

We commit to:

  • ✓ Acknowledge your report within 72 hours.
  • ✓ Keep you updated on remediation progress.
  • ✓ Not take legal action against good‑faith researchers.
  • ✓ Publicly credit you after the fix ships, if you wish.

Please do not publicly disclose until we've had a reasonable opportunity to fix the issue.

The honest fine print

No system is 100% secure. These commitments describe the controls and processes we operate today; they are not a warranty or a guarantee. Your use of Bloomder implies acceptance of residual risk — which we work hard to minimize but cannot eliminate. For formal contractual security commitments, execute a DPA and order form with your account team.

Questions? Security questionnaire? DPA?

Our security team answers within 72 hours.

Contact [email protected]

Or see all contact channels.