Security
Last updated 5 September 2026
Security is foundational to Bloomsline. This page summarises the measures that protect the platform and the data it holds.
HDS-certified hosting
Personal and health data are hosted on HDS-certified (Hébergeur de Données de Santé) infrastructure in the European Union — the French certification required for hosting health data.
Encryption
Data is encrypted in transit (TLS) and at rest. Credentials and integration secrets — calendar access tokens, two-factor authentication secrets — carry a further layer of application-level encryption, each sealed with its own key so that no single compromised record exposes another.
Access control
Access is server-authoritative and ownership-scoped: every request is checked so a practitioner can only ever reach their own patients’ data. Two-factor authentication is available for accounts.
Auditability
Security-relevant actions are recorded in an audit log to support accountability and incident investigation.
Resilience
Data is backed up regularly, and backups are protected to the same standard as live data.
Responsible disclosure
If you believe you have found a security issue, please contact hi@bloomsline.com. We welcome responsible disclosure and will work with you to resolve valid reports.