Skip to content

Security

Security that is verified, not promised

No generic claims: this page only lists measures we've verified in the code and configuration, with an explicit note whenever something isn't verifiable.

Verified measures

What we protect, specifically

Each card describes a real measure, verified in the code or confirmed by the site owner — not a generic principle.

App accounts

Passwords hashed with bcrypt

TooBloom app account passwords are hashed with the bcrypt algorithm (12 rounds) and are never stored or readable in clear text. The marketing site does not manage public user accounts; the only area with credentials is the internal showcase area, protected by a signed (HMAC), httpOnly session cookie not readable from JavaScript.

Sessions and tokens

Real duration, not a generic one

App authentication tokens are valid for 8 hours. Session cookies default to a 120-minute lifetime. The marketing site's showcase-area cookie lasts for a browsing session, or 7 days if "remember me" is selected.

Integrations

Google authorization kept separate

Authorization for Google services (GA4, Search Console) follows the provider's official OAuth flow and remains separate from the TooBloom application account. You can revoke it at any time from your Google account settings.

Transport and forms

HTTPS, CSRF and rate limiting

The marketing site enforces HTTPS with HSTS (one-year duration, including subdomains). POST requests to the contact and support forms are only accepted when they originate from the same origin (CSRF protection) and are limited to 5 submissions every 10 minutes per IP address, plus an anti-bot honeypot field. The API applies rate limiting (throttling) on most of its routes.

Secrets

No credentials in the code

Credentials (email access, database, third-party services) are managed as environment variables, never included in the code repository. The marketing site's email configuration is synced on every deploy via encrypted GitHub Actions Secrets.

Backup

Verified backup for the email mailbox

The mailbox used by the contact and support forms is hosted on Artera infrastructure, which runs rotating backups: 3 daily copies, 2 weekly, 4 monthly, for security and business continuity purposes. Backups of other components (e.g. application databases) are not verified by this page.

Transparency

What this page does not promise