Protected
Attendee names and email addresses are encrypted at rest and in transit.
You control the attendee records for your events. Names and email addresses are encrypted in transit and at rest; only the event owner can view them, and Bloomod cannot read them.
Attendee names and email addresses are encrypted at rest and in transit.
Event owners alone can view sensitive attendee information. Bloomod cannot view it.
Important invite, consent and account activity can be recorded and reviewed.
| Control | Covers | Status |
|---|---|---|
| Encryption in transit | All API and application traffic | In place |
| Encryption at rest | Attendee names, email addresses and invite content | In place |
| Owner-only access | Attendee names and email addresses | Enforced |
| Scoped API keys | Programmatic access, separate test and live | In place |
| Sender verification | Sending identity and domain | Required |
| Verification gate | Calendar automation for each event | Verified only |
| Event automation control | Each event’s calendar invitation workflow | Owner controlled |
| Activity recording | Event, verification and account events | In place |
This page describes the security model of the product as designed. It is not a certification claim. For current compliance documentation, write to hello@bloomod.com.
Verification proves the sending identity belongs to your business. It is what allows invites to carry your organiser name — and what stops anyone else from doing so.
A campaign created programmatically returns 202 Accepted and waits, exactly like one created in the interface. There is no flag that skips approval, because a flag that skips approval is the feature that causes incidents.
Approval required
AlwaysPlatform security is ours. Consent and content are yours. Neither of us can cover the other's half.
Bloomod does
You do
Write to hello@bloomod.com for current product access or policy information.