Security

Last updated: 2026-09-18

Our security posture, stated so you can check it against reality.

Accounts and credentials

These are properties of the running system, not plans:

  • Your password is stored as a scrypt hash; we cannot read it, and we never ask you to send it to us.
  • Service credentials (WordPress admin, mailbox) are shown once, then destroyed server-side; the reveal is logged and never cached.

Servers and network

Each service runs behind its own boundary, and traffic is encrypted end to end:

  • Every site runs on its own isolated server with its own firewall; a neighbor cannot reach your files.
  • All traffic to the site and the client area is HTTPS.
  • Every hosted site serves HTTPS with a certificate issued and renewed automatically. A dedicated or organization-validated certificate is arranged by conversation, with the price confirmed before you pay.

Payments

Card payments run through Stripe; card numbers never touch our systems.

How we handle reports

Tell us immediately on WhatsApp or at ahmed@bloomtechno.com. A report reaches the person who can act, without layers. Incidents that affect the service get an entry on the status page.