Security
Last updated: 2026-09-18
Our security posture, stated so you can check it against reality.
Accounts and credentials
These are properties of the running system, not plans:
- Your password is stored as a scrypt hash; we cannot read it, and we never ask you to send it to us.
- Service credentials (WordPress admin, mailbox) are shown once, then destroyed server-side; the reveal is logged and never cached.
Servers and network
Each service runs behind its own boundary, and traffic is encrypted end to end:
- Every site runs on its own isolated server with its own firewall; a neighbor cannot reach your files.
- All traffic to the site and the client area is HTTPS.
- Every hosted site serves HTTPS with a certificate issued and renewed automatically. A dedicated or organization-validated certificate is arranged by conversation, with the price confirmed before you pay.
Payments
Card payments run through Stripe; card numbers never touch our systems.
How we handle reports
Tell us immediately on WhatsApp or at ahmed@bloomtechno.com. A report reaches the person who can act, without layers. Incidents that affect the service get an entry on the status page.