Skip to content
You’re offline. You can look around, but changes won’t be saved until you reconnect.
Bloom/Legal
Plainspoken · Bloom

Security and Responsible Disclosure

Version 1.0 · Effective 30 September 2026 · Last updated 30 September 2026

On this pageCurrent safeguardsReport a vulnerabilityIncidents

Current safeguards

Bloom uses Django password hashing and password reset tokens, role checks, organisation-scoped business queries, CSRF protection, private media handling, request rate limits on key account routes and audit records for sensitive business actions. Production settings require HTTPS redirects, secure session and CSRF cookies and HTTP security headers. Database backup scripts are present; the deployment operator must run and test them. Security depends on correct deployment and staff access practices.

Report a vulnerability

Send a clear description and reproduction steps to security@plainspoken.co.za. Please avoid accessing other people's data, disrupting service, social engineering or publishing details before we have had a reasonable chance to investigate and fix the issue. We will acknowledge useful reports, investigate promptly and coordinate disclosure in good faith. No claim of certification or guaranteed security is made.

Incidents

We investigate and contain suspected incidents, preserve relevant logs, assess affected data and notify responsible customers, people and regulators where required by POPIA and other law.

Bloom

Your salon, in one place.

Bloom is a product of Plainspoken.
ProductFeaturesPricingSign in
CompanyPlainspokenContact
LegalTermsPrivacyData Processing AddendumCookiesAcceptable UseBilling & RefundsData RetentionSubprocessorsPAIAPAIA ManualSecurity
© 2026 Plainspoken. All rights reserved.Plainspoken is a trading brand operated by [LEGAL_ENTITY_NAME], registration number [COMPANY_REGISTRATION_NUMBER].