Security

Last updated 5 September 2026

Security is foundational to Bloomsline. This page summarises the measures that protect the platform and the data it holds.

HDS-certified hosting

Personal and health data are hosted on HDS-certified (Hébergeur de Données de Santé) infrastructure in the European Union — the French certification required for hosting health data.

Encryption

Data is encrypted in transit (TLS) and at rest. Credentials and integration secrets — calendar access tokens, two-factor authentication secrets — carry a further layer of application-level encryption, each sealed with its own key so that no single compromised record exposes another.

Access control

Access is server-authoritative and ownership-scoped: every request is checked so a practitioner can only ever reach their own patients’ data. Two-factor authentication is available for accounts.

Auditability

Security-relevant actions are recorded in an audit log to support accountability and incident investigation.

Resilience

Data is backed up regularly, and backups are protected to the same standard as live data.

Responsible disclosure

If you believe you have found a security issue, please contact hi@bloomsline.com. We welcome responsible disclosure and will work with you to resolve valid reports.