Current safeguards
Bloom uses Django password hashing and password reset tokens, role checks, organisation-scoped business queries, CSRF protection, private media handling, request rate limits on key account routes and audit records for sensitive business actions. Production settings require HTTPS redirects, secure session and CSRF cookies and HTTP security headers. Database backup scripts are present; the deployment operator must run and test them. Security depends on correct deployment and staff access practices.
Report a vulnerability
Send a clear description and reproduction steps to security@plainspoken.co.za. Please avoid accessing other people's data, disrupting service, social engineering or publishing details before we have had a reasonable chance to investigate and fix the issue. We will acknowledge useful reports, investigate promptly and coordinate disclosure in good faith. No claim of certification or guaranteed security is made.
Incidents
We investigate and contain suspected incidents, preserve relevant logs, assess affected data and notify responsible customers, people and regulators where required by POPIA and other law.