Security

Security at Shoola Labs

Mortgage teams handle sensitive borrower information. Here is how Shoola Labs protects it in BloomOS — described plainly, without overstated claims.

Authenticated user accounts

Every user signs in with their own account. Access to the workspace requires authentication.

Organization-level access controls

Data belongs to an organization, and access is scoped to the organization a user belongs to.

Role and permission controls

Roles and permissions determine what each employee can see and do inside BloomOS.

Private connected email accounts

A connected mailbox belongs to the user who connected it and is not shared across the organization by default.

Server-side credential handling

Provider credentials and tokens are handled server-side and encrypted at rest rather than exposed in the browser.

Secure provider authorization

Email and other provider connections use the provider's standard authorization flow, and users can revoke access at any time.

Audit trails

Activity across records and communications is recorded so teams can review what happened and when.

Tenant separation

Each customer organization's data is separated from other organizations on the platform.

Transparency

What we do not claim

We publish only what is accurate today.

Shoola Labs does not currently claim SOC 2, HIPAA or ISO certification for BloomOS. If and when formal certifications or third-party audits are completed, they will be published on this page.

If your organization has a security review process or specific requirements, we're happy to walk through our practices directly. Contact us and we'll respond with detail.

For details on how information is collected and used, see our Privacy Policy.

Questions before you roll out BloomOS?

Our team can walk your organization through security, access controls and setup.

30 days free · $50 per user / month after