Bloomz was created to facilitate communication between schools and families in a safe and private environment. To provide this, Bloomz complies with regulations like FERPA and COPPA and all applicable privacy laws, and is a signatory of the Student Privacy Pledge.
Bloomz accounts for privacy and security at both the front end, where teachers, students and parents interact with our service, and the backend, where all information is stored and organized. This page provides an overview of the policies and practices that comprise our security approach.
Bloomz continually acts upon industry-leading security guidelines and regulation. Our policies are intended to safeguard sensitive information. We are developing privacy and security training that all employees take at hire and annually thereafter. All employees and contractors sign agreements requiring them to protect the confidentiality of sensitive information, and our information security controls are in constant evolution to remain current and compliant.
Sensitive information is protected at rest and in transit across untrusted networks using encryption. Clear-text passwords are never stored; salted, one-way-encrypted passwords are recorded, and passwords must be at least 8 characters with one letter and one number. Passwords are only sent via HTTPS, the old password is required to set a new one, and authentication tokens are valid for one week. All cookies are HTTPS and domain-associated so other services cannot read them.
Logging into sensitive systems is controlled by strong password requirements, with access assigned by role on a need-to-know basis. All devices used by Bloomz personnel require antivirus software and strong authentication. Bloomz is hosted in AWS and Microsoft Azure data centers with rigorous physical controls including security staff, layered electronic access controls, intrusion detection and surveillance monitoring.
Bloomz uses Amazon Web Services (AWS) and Microsoft Azure to host and operate the service. Their environmental protections reduce risks from fire, power loss, flood, humidity and temperature changes, with fault tolerance and redundancy. The AWS infrastructure is managed in compliance with standards including HIPAA, SOC 1/2/3, PCI DSS Level 1, ISO 27001, FedRAMP, FISMA, ITAR and FIPS 140-2. All APIs run on HTTPS; only ports 443 (HTTPS) and 22 (SSH) are open on API servers, and SSH access requires a provided certificate.
Databases run on Linux Ubuntu 64-bit servers using MongoDB, accepting connections only from specific API servers through a restricted virtual network. Hard backups are stored on MongoDB's MMS service. Bloomz runs a bug bounty program with security researchers, prioritizes and remediates discovered vulnerabilities, and follows an industry-standard secure development process designed to avoid common security exposures.
Bloomz uses groups, classes and communities with controlled access levels. Classroom membership is by invitation only, classrooms are visible only to members of a school community, and no child information is pushed to analytics services. Processing of personal information is limited to the purposes identified in our terms and never repurposed. Bloomz will never sell, trade or barter consumers' personally identifiable information. In the event of a data breach, Bloomz will promptly notify impacted parties and authorities.
Bloomz works with legal counsel to ensure our products and practices remain compliant with relevant mandates. Bloomz meets COPPA legislative requirements and helps schools comply with federal FERPA regulations.
Bloomz, PO Box 6, Redmond, WA 98074