
Workforce data is among the most sensitive data a company holds — salaries, identities, attendance, performance. We treat it accordingly. Security is not a feature we added on top of Bulma; it shapes how the product is built, hosted, and operated.
All data transmitted between your browser or mobile app and our servers is encrypted using TLS 1.2 or higher. Data at rest is encrypted with AES-256. Sensitive fields such as salaries and tax identifiers are masked by default and only revealed to people with explicit permission.
Bulma runs on enterprise-grade cloud infrastructure across multiple availability zones, with automatic failover and a 99.9% uptime target. We deploy immutable infrastructure-as-code, keep databases on private networks with no public endpoints, run continuous vulnerability and dependency scanning, and take automated daily backups with point-in-time recovery.
Bulma enforces role-based access control at every level, so an HR manager can run payroll without seeing engineering salaries and a team lead sees only their own reports. Single sign-on is supported via SAML 2.0 and OIDC, multi-factor authentication is enforced for admin accounts, sessions expire automatically, and every permission change and data access event is written to an immutable audit log.
Our own team follows the same standards we build into the product. Employees complete background checks and security training on hire, production access is limited to a small on-call group on a least-privilege basis, and any internal access to customer data requires justification and is logged. We run annual penetration tests with a specialist third-party firm alongside a continuous bug bounty programme.
Bulma is designed to help your organisation stay compliant with relevant labour, data, and privacy regulations, including GDPR, UAE PDPL, and Saudi PDPA data subject rights. Data residency options and data processing agreements are available for enterprise plans, retention schedules are configurable per data category, and export and deletion tools cover data subject access requests.
In the event of a confirmed security incident, we notify affected customers within 72 hours of discovery, in line with GDPR Article 33. Notifications describe what happened, what data was involved, and what we are doing about it. Our documented incident response plan is tested through tabletop exercises twice a year.
If you believe you have found a security vulnerability in Bulma, please disclose it responsibly by reporting your findings to support@bulma.ai with enough detail to reproduce the issue. We acknowledge reports within two business days.
For security questions, audit report requests, or data processing enquiries, email support@bulma.ai or call us on +971 58 577 3705.