Appriana Platform · Enterprise Security
Enterprise security as a
foundational element.
Building secure systems and protecting customer data is a specific priority for our team. Appriana and Bloom are direct realizations of that investment, and of our intent to set a higher standard for how everyone's data is protected. The controls are documented in full and available for review under NDA.
Runs on Appriana
One platform.
First-class constituents.
Bloom runs on Appriana, a multi-tenant SaaS platform built and maintained by our team, with full access to operate, extend, and improve it. Fortress is the identity and access layer woven through all of them.
Outpost
Collects customer signal
Orbit
Schedules background work
AIHub
Runs the intelligence pipeline
Bostanci
Watches the platform
Fortress
Identity & access
01 · Data protection
Encrypted in motion.
Encrypted at rest.
In transit
Traffic to and from Bloom is encrypted with TLS 1.3, and database traffic, between nodes and from clients, is encrypted with TLS as well.
At rest
Data is encrypted at rest across both the compute layer and the database that holds it.
Key management
Secrets and the third-party credentials Bloom uses to reach your sources are protected with AWS KMS.
Passwords
Passwords are hashed with Argon2id, a memory-hard algorithm built to resist offline cracking.
Backups
Backups are managed across regions, through AWS for compute images and CockroachDB for data.
Deletion
Customer data can be deleted on request. Access-control records are retained for audit integrity.
02 · Access & identity
Identity and access,
handled by Fortress.
Identity, isolation, and permissions are handled by Fortress, the access layer deeply integrated through the whole platform. It governs how your team reaches Bloom, and on the rare occasions Bloom staff need access to a tenant, that runs the same way, under the same isolation.
Tenant isolation
Enforced at query time. One tenant's data and another's are never in reach of the same query.
SSO and MFA
SAML or OIDC, with MFA set at the population level so it covers everyone in it.
Sessions
Every active session is visible and revocable, one at a time or all at once, by your own admins.
03 · Where Bloom runs
Runs where you need it.
Your cloud, your boundary.
Bloom's constituent components are built and maintained by our own team, which keeps the stack portable. For teams with strict requirements, that portability is the control.
Your cloud, or on-prem
Because our team has full rights to, builds, and maintains the components, Bloom can run in your preferred cloud, in dedicated VPCs, or on-premises, arranged with you as the deployment requires.
Network-level isolation
Traffic to Bloom can be locked down at the network level through dedicated DNS, so access is confined to the paths you define.
Where your data sits
Multi-region by default, and where geography matters for your data, residency is part of the deployment discussion rather than a fixed constraint.
04 · Application hardening
Hardened where it matters.
Credentials are masked from logging
Sensitive fields are redacted automatically before any log line is written, including values nested deep inside a payload.
Credentials are never sent via URL parameters
This keeps credentials out of the caches, browser history, and referrer headers that URLs leak into. Magic links are the one necessary exception.
Payloads are sieved for exploits
Inbound request payloads are sanitized, so malformed or hostile input is caught before it reaches anything that matters.
Access pages minimize supply-chain surface
The pages where you sign in or create magic links are served as minimal static HTML rather than a heavy single-page app, trimming the third-party code that becomes a prized target for supply-chain attacks.
05 · Monitoring & people
Monitored as it runs.
Operated under least privilege.
Attributed logging
Requests are logged with the acting principal and organization attached and a trace identifier, so an action can be followed through the work it set off.
Least-privilege staff access
Bloom staff reach customer tenants only through Fortress, in a separate Realm, under the same isolation that governs everyone else.
Background checks
Staff with access to production and customer data are background-checked, and that can be documented for your review.
Reviewed changes to production
Changes reach production through pull requests with code review and a tracked ticket, so every production change has an author, a reviewer, and a record.
Monitored platform
Bostanci watches the platform's own health, with alerting wired to the team so issues surface quickly.
On the roadmap
Committed and in progress.
These are in active development. We list them so a security review has the current picture rather than only the finished parts.
Customer-facing audit log
Access events surfaced to you directly, so your team can review who reached what, in progress.
Metrics & retained logs
High-resolution platform metrics and longer log retention, in active development toward launch.
Formal incident response
A written incident-response process with clear notification commitments, being formalized.
Third-party penetration test
An independent penetration test, planned with an external firm.
Formalized vendor management
A written process around subprocessor review and approval, being documented.
06 · Privacy & compliance
In line with what
the regulations require.
Appriana, the platform Bloom runs entirely on, is built around the ideas that data-protection regulations like GDPR and CCPA exist to enforce: collect what is needed, delete on request, be clear about who else touches the data, and put the terms in writing. These principles shape how the product works today.
For the paperwork a procurement process runs on, a Data Processing Addendum is available, and our subprocessors are listed publicly and kept current.
For your security review
Documented in full, available under NDA.
The controls on this page are documented in more depth than a public page should carry. Security and vendor-risk teams can review that documentation under NDA, and we will walk through it with you directly.
Putting Bloom through security review?
Let's do it together.
A briefing with your IT, security, or compliance leads covers isolation, access, data handling, and our control documentation, with the people who build and run the platform in the room.