Our approach
Cuebloom combines multiple models, providers, files, people, and publishing paths in one production service. Security therefore starts with clear workspace boundaries, least-necessary data movement, and evidence-based claims.
We do not present certifications, penetration-test results, single-tenant deployment, or formal service levels as standard features unless they are documented in a customer agreement.
Implemented controls
- Identity and access: authenticated sessions, workspace-scoped records, membership roles, and authorization checks on protected routes and actions.
- Credential protection: scoped and revocable integration credentials, expiration, refresh rotation, replay protections, and protected server-side secrets.
- Upload controls: file-count and size limits, extension and MIME allowlists, file-signature checks, and controlled provider input materialization.
- Generation governance: spend checks, rights attestations where required, provider-independent policy enforcement, job reconciliation, and webhook validation.
- Activity records: workspace and generation events with restricted metadata fields; sensitive prompt or media content is not included in routine lifecycle analytics.
- Operational safeguards: rate limits, idempotency boundaries, signed cursors and artifacts, and authenticated internal job processing.
Creative data and AI providers
Cuebloom does not use private customer content to train generalized AI models. A generation request may be sent to the selected model provider or infrastructure partner so the requested feature can run. We aim to send only the prompt, reference, configuration, or source media needed for that job.
Review the Privacy Policy and Subprocessor List for the public data-flow summary. Customers with additional retention, residency, DPA, or provider requirements should define those controls in a signed enterprise agreement before sending regulated or highly sensitive data.
Customer responsibilities
Security is shared. Workspace owners and members should:
- use a unique password and protect the email account used for sign-in;
- invite only intended members and review roles and connected services;
- keep API, MCP, and integration credentials private and revoke them when no longer needed;
- avoid uploading passwords, secret keys, payment-card data, health records, or other regulated data unless a signed agreement expressly covers that use;
- review share links, published pages, and exported assets before distribution;
- report suspicious activity promptly.
Responsible disclosure
If you believe you found a vulnerability, email rakeen@cuebloom.ai with a clear description, affected route or feature, and safe reproduction steps. Do not access other users’ data, degrade the Service, use social engineering, or publicly disclose an unresolved issue.
We will acknowledge a good-faith report, investigate it, and coordinate remediation and disclosure based on severity. This page is not a bug-bounty promise and does not authorize destructive testing.
Enterprise review
Security questionnaires, DPA terms, subprocessor review, retention requirements, SSO, data residency, dedicated deployment, audit evidence, incident terms, and service levels are scoped during enterprise review. They become commitments only when written into the applicable agreement.
Visit Cuebloom for Enterprise or contact us to start a technical and contractual review.
Questions or requests
We would rather answer a direct question than hide an important detail in fine print. Email rakeen@cuebloom.ai with the name and email associated with your workspace.