Trust & Security

Be Blessed by Becoming a Blessing.

We know the information shared on a surrogacy journey is personal. This page explains, in plain language, the security practices that are currently in place at Surro Blessings. We only describe protections that are active today — we do not claim certifications or audits we have not completed.

Secure HTTPS connections

Every page and form on Surro Blessings is served over an encrypted HTTPS connection, so information you send to us travels privately between your device and our servers.

Authenticated account access

Accounts are managed by our authentication provider. Sign-in, password recovery, and session handling are performed by that service rather than by custom code, and passwords are never stored in plain text by our application.

Server-validated roles and permissions

What you can see and do depends on your role. Role checks are performed on the server for sensitive actions, so permissions cannot be changed by editing anything in your browser.

Row-level security and restricted data access

Our database enforces row-level security policies. Records are readable and writable only by the accounts our policies allow, which keeps one member's information from being visible to another.

Separation of demo and production information

Demonstration accounts and their sample records live in an isolated demo workspace, separate from real member information. Demo actions do not send real emails or text messages.

Restricted document visibility

Uploaded documents and sensitive files are limited to authorized users. Document areas require sign-in, and access is checked against your role and workspace.

Audit logging for sensitive administrative actions

Sensitive administrative actions, such as changes made from the owner administration area, are recorded in an audit log so they can be reviewed later.

Protection against unauthorized role changes

Role assignments are stored separately from profile information and are protected by server-side rules. Administrative accounts cannot escalate their own permissions or remove the highest-level administrator role.

Reporting a security or privacy concern

If you believe you have found a security issue, or you have a question about how your information is handled, please email support@surroblessings.com. Please include what you observed and how to reproduce it, and avoid sharing another person's private information in your report. We review reports and respond as quickly as we can. A dedicated security address is planned and will be published here once it is active.