Trust Center

  • SOC 2 Type 2
  • GDPR
  • CCPA
  • CSA STAR

Explore our compliance journey and the security practices that protect your data.

5
Frameworks
12
Categories
89
Controls
55
Passing

Compliance Frameworks

Actively pursuing industry-standard certifications to demonstrate our commitment to security and data protection.

SOC 2 Type 1

Service Organization Control 2 Type 1 audit assesses the design of security controls at a specific point in time.

In Progress

We are preparing for SOC 2 Type 1 certification, which validates that our security controls are properly designed. This is the foundation for our Type 2 certification journey.

SOC 2 Type 2

Service Organization Control 2 Type 2 audit assesses the effectiveness of security controls over time (typically 6-12 months).

In Progress

Following Type 1 certification, we will pursue SOC 2 Type 2 to demonstrate our controls operate effectively over an extended period.

CSA STAR Level 1

Cloud Security Alliance Security Trust Assurance and Risk (STAR) program - self-assessment for cloud security.

In Progress

We are completing the CSA STAR Level 1 self-assessment using the Consensus Assessments Initiative Questionnaire (CAIQ) to document our cloud security posture.

GDPR

General Data Protection Regulation - EU regulation on data protection and privacy.

Passing

Blooio is committed to GDPR compliance for our EU customers. We have implemented data protection measures, privacy policies, and user rights mechanisms as required by the regulation.

CCPA/CPRA

California Consumer Privacy Act and California Privacy Rights Act - California state privacy laws.

Passing

Blooio complies with CCPA/CPRA requirements for California residents, including the right to know, delete, and opt-out of data sales.

Security Controls

Comprehensive security controls covering data protection, access management, and operational security.

Filter Controls
Framework
Status
|

Questions About Security?

Our team is here to help with questions about security practices, compliance, or data protection.