Security and trust

Attendee data is limited to authorised access.

Attendee data is available only to authorised organisation members and authorised Bloomod personnel where operationally required. Data is protected in transit and at rest where supported by the deployed infrastructure.

Protected

Data protection depends on the controls supported by the deployed infrastructure.

Authorised

Organisation roles and operational need determine who can access attendee information.

Accountable

Important invite, consent and account activity can be recorded and reviewed.

Controls

What the security model requires.

Security controls and their scope
ControlCoversStatus
Transport protectionApplication and provider connectionsInfrastructure dependent
Data protection at restSensitive attendee and Event dataWhere supported
Organisation rolesAttendee and Event accessRequired control
Operational accessAuthorised Bloomod support and administrationNeed-to-know
Planned API credentialsFuture Business integration accessPlanned
Sender identity checksConnected providers and Business custom domainsContext-specific
Verification gateCalendar automation for each EventEvent-scoped
Activity recordsImportant Event and account actionsWhere implemented

This page describes the security model of the product as designed. It is not a certification claim. For current compliance documentation, write to hello@bloomod.com.

Sender identity

Identity checks match the sending model.

Free uses a connected Google or Microsoft identity where applicable, or Bloomod-managed transactional delivery when available. Business custom domains, custom reply-to addresses and own SMTP require ownership and configuration checks.

  • Free does not require a custom sender domain
  • Connected provider identity applies where used
  • Business custom domains require ownership verification
  • Higher-volume limits require a separate operational review
Planned API controls

Integration access remains subject to review.

The Event API is not yet in production. The proposed Business model keeps invitation writes in a review queue and does not treat API access as permission for unrestricted sending.

Your responsibilities

Shared model, stated plainly.

Platform security is ours. Consent and content are yours. Neither of us can cover the other's half.

Bloomod does

  • Apply access and infrastructure controls
  • Enforce organisation roles
  • Apply suppression and pacing
  • Record important activity where implemented

You do

  • Obtain and evidence consent
  • Keep your member list current
  • Protect account and integration credentials
  • Approve only what you intend to send

Questions about data handling?

Write to hello@bloomod.com for current product access or policy information.