Security

Last updated 11 July 2026

Draft — pending legal and DPO review. This wording is not final and should not be relied upon until reviewed.

Security is foundational to Bloomsline. This page summarises the measures that protect the platform and the data it holds.

HDS-certified hosting

Personal and health data are hosted on HDS-certified (Hébergeur de Données de Santé) infrastructure in the European Union — the French certification required for hosting health data.

Encryption

Data is encrypted in transit (TLS) and at rest. High-sensitivity clinical fields receive additional application-level encryption.

Access control

Access is server-authoritative and ownership-scoped: every request is checked so a practitioner can only ever reach their own patients’ data. Two-factor authentication is available for accounts.

Auditability

Security-relevant actions are recorded in an audit log to support accountability and incident investigation.

Resilience

Data is backed up regularly, and backups are protected to the same standard as live data.

Responsible disclosure

If you believe you have found a security issue, please contact privacy@bloomsline.care. We welcome responsible disclosure and will work with you to resolve valid reports.