Bubble is the leader in NoCode. It is the best way to build webapps without code. Bubble is the most powerful no-code platform for creating digital products. Innovative companies like Zendesk, Lyft, Loreal use Bubble to create webapps.
Also, anyone accessing a Bubble account can view sensitive data in plain-text, introducing liability if that data is leaked or stolen.
Bubble logs sensitive data, including API Keys on servers. So, from a security and compliance perspective, that violates security best practice recommended by compliance and privacy laws.
How does Strac protect Bubble customers?
Strac launched a Bubble plugin and you can see the launch post on Bubble forum. Strac is HIPAA Compliant and will sign BAA agreement with customers who want to secure their sensitive PHI (Personal Health Identifiable) data.
Use Strac Bubble Plugin
Strac has built a Bubble Plugin that makes it easy for Bubble developers to collect and display sensitive data and send data to third-party partners if needed. Strac Bubble Plugin does the following:
To Collect Sensitive Data
Strac uses widgets (iFrames) on the front-end where Strac's widget will collect data. Due to iFrames, Strac can never access data residing on Customer's page, and vice-versa, the Customer can't access Strac's data residing in the iFrame. This security isolation ensures that Bubble never sees sensitive data during collection.
Strac will store sensitive data in its secure vault and generate tokens for the sensitive data.
The front-end JavaScript gets tokens and these tokens will be stored on the Bubble instance of the Customer
When the front-end wants to display sensitive data, front-end makes the call to Strac, Strac ensures the request is authenticated. If the request is authenticated, Strac will detokenize tokens and give back real values to Front End JavaScript.
In both cases, the Strac widgets are highly customizable.
Please book a demo if you'd like to get access to Strac's Bubble Plugin and API Keys to secure sensitive data on Bubble account. In less than 15 minutes, you will secure sensitive data on Bubble.
Discover & Protect Data on SaaS, Cloud, Generative AI
Strac provides end-to-end data loss prevention for all SaaS and Cloud apps. Integrate in under 10 minutes and experience the benefits of live DLP scanning, live redaction, and a fortified SaaS environment.
The Only Data Discovery (DSPM) and Data Loss Prevention (DLP) for SaaS, Cloud, Gen AI and Endpoints.