Trust Centre

Where Bolrach runs, who else handles your data, how we recover from failure and how to tell us about a problem.

Service statusEvery public service is checked every five minutes. See what is up now and what happened recently.

Where your data lives

The platform and its databases run in one data centre in Toronto, Canada. Files you upload are kept in Cloudflare R2 and encrypted at rest. Everything between your browser and us is encrypted, with HSTS.

Backups you can recover from

The databases are backed up in full every night and streamed continuously, so they can be restored to a point in time. Restores are rehearsed on a schedule and checked table by table.

Secrets stay secret

Passwords never reach Bolrach products, API secrets are stored only as hashes and shown once, and payment credentials are encrypted field by field. Card numbers stay with the card processors.

A record of every change

Role changes, invitations, API keys, domains, webhooks, refunds and payouts are written to your organization’s audit log with who did it and from where, and money or access changes ask you to sign in again.

Subprocessors

The companies that handle some of your data so a feature can work. We add to this list before we start using someone new.

CompanyWhat they do for usWhere
Datacamp LimitedServer hosting for the platform and its databasesToronto, Canada
CloudflareDNS, content delivery, attack protection and file storage (R2)Global network
StripeCard payments in Bolrach PayUnited States and global
PayPalPayPal payments in Bolrach PayGlobal
voip.msPhone numbers and calls in Bolrach VoiceCanada
Google FirebaseDelivering push notifications to Android devicesGlobal
OpenAIAI features, only when you use oneUnited States

Certifications and registrations

Bolrach holds no security certification today, and we do not claim one. Our financial registrations and what screening already runs on every payment are set out on the compliance page.

Compliance

Legal documents

Report a security problem

Open a security report with enough detail to reproduce it. You only need an email address, and you get a case number to quote. We do not take legal action against anyone who reports in good faith and gives us time to fix it.

Report a vulnerability

If you are signed in

Your organization’s audit log, security settings and API keys are in the app.