Security & Compliance

Trust Center

At Blooio, we're committed to protecting your data and maintaining the highest standards of security. Explore our compliance journey and security practices.

5
Frameworks
12
Categories
89
Controls
34
In Progress

Compliance Frameworks

We are actively pursuing industry-standard certifications to demonstrate our commitment to security and data protection.

SOC 2 Type 1

Service Organization Control 2 Type 1 audit assesses the design of security controls at a specific point in time.

In Progress

We are preparing for SOC 2 Type 1 certification, which validates that our security controls are properly designed. This is the foundation for our Type 2 certification journey.

SOC 2 Type 2

Service Organization Control 2 Type 2 audit assesses the effectiveness of security controls over time (typically 6-12 months).

In Progress

Following Type 1 certification, we will pursue SOC 2 Type 2 to demonstrate our controls operate effectively over an extended period.

CSA STAR Level 1

Cloud Security Alliance Security Trust Assurance and Risk (STAR) program - self-assessment for cloud security.

In Progress

We are completing the CSA STAR Level 1 self-assessment using the Consensus Assessments Initiative Questionnaire (CAIQ) to document our cloud security posture.

GDPR

General Data Protection Regulation - EU regulation on data protection and privacy.

Passing

Blooio is committed to GDPR compliance for our EU customers. We have implemented data protection measures, privacy policies, and user rights mechanisms as required by the regulation.

CCPA/CPRA

California Consumer Privacy Act and California Privacy Rights Act - California state privacy laws.

Passing

Blooio complies with CCPA/CPRA requirements for California residents, including the right to know, delete, and opt-out of data sales.

Security Controls

Our comprehensive security controls cover all aspects of data protection, access management, and operational security.

|

Questions About Security?

Our team is here to help answer any questions about our security practices, compliance certifications, or data protection measures.