Security assurance and account controls
Review available account protections, privileged access boundaries and procurement limitations.
Last updated 2026-08-28
What you'll achieve
- Evaluate available sign-in controls
- Understand secret-access boundaries
- Identify controls that require an enterprise agreement
Account and organization controls
BlinkHost supports its published account sign-in methods, session management, organization roles and project-scoped permissions. Workspace-wide SSO, SCIM provisioning, customer-enforced MFA and passkeys are not currently offered as generally available public controls. Do not represent them as available in a security review. Use individual accounts, remove access promptly and review active sessions and connected identities after a suspected compromise.
Secrets and privileged access
Application secret values are write-only in customer workflows and are separated from frontend source, Git exports and browser JavaScript. Runtime access is limited to an authorized module and environment binding. Authorized BlinkHost personnel may use restricted operational access only when needed to provide or secure the service, investigate an incident, follow a lawful instruction or support an authorized customer request. Such access is subject to role restrictions, confidentiality and audit controls.
Independent assurance
BlinkHost does not currently publish an ISO 27001 certificate, SOC 2 report or public penetration-test report. Public descriptions of technical controls are not independent certification. Organizations that require third-party assurance, a security questionnaire, data-location commitments, audit support or a defined breach-notification target should contact security@blinkhost.me and ensure the requirement is included in a signed agreement before adoption.
Report a suspected vulnerability or account compromise to security@blinkhost.me. Include the affected BlinkHost-owned asset, UTC time, reproducible non-destructive evidence and a safe contact method. Do not include unrelated personal data or credentials.
Sign-in and recovery available today
BlinkHost currently provides email-and-password sign-in plus Google, GitHub and Microsoft sign-in. Password recovery uses a verification code sent to the account email. Customers can review and end active sessions and manage connected sign-in identities. These controls do not amount to customer-enforced MFA, passkeys, workspace-wide SSO or SCIM; those controls remain unavailable unless a signed Enterprise agreement expressly provides them.
Secret values are not displayed back through normal customer workflows after storage. BlinkHost does not publish sensitive staff-access implementation details. The customer-facing assurance boundary is restricted operational need, role-limited access, confidentiality obligations and audit records; customers needing a specific approval or customer-managed access process must agree it in writing before placing that workload on the service.
Help improve this page
Sign in to send page-specific feedback. For account-specific help, email support@blinkhost.me.