Introducing G2.ai, the future of software buying.Try now
Shane A.
SA
Professional Services Strategic Advisor | Board Advisor | Software and Services Executive

Security on Bubble

I recently went through a penetration test on my Bubble Applications. Interestingly the results were a concerning. We were unable to achieve GDPR or PCI compliance because of vulnerabilities in the core of Bubble's platform. After logging a ticket to understand if they were going to be resolved, I was told that all 16 of the vulnerabilities were known and most were with development as low priorities and I was not provided a fix for any of them. In response to my shock at this status, I was told that Bubble that "compliance" is a subjective thing for Bubble as it is up to us (Bubble's customer) to determine if we want to be compliant or not). I actually think that's a fair point of view, except that we want to be GDPR and PCI Compliant but we cannot as the vulnerabilities that are currently known and not fixed within the platform prevent that from happening. Has anyone else attempted to achieve such an outcome? If so, how have you dealt with it?
1 comment
Looks like you’re not logged in.
Users need to be logged in to answer questions
Log In
Philip M.
PM
0
Bubble has been aware that they do not currently allow any EU users to legally stored data for many many years now. Bubble will promise updates and features but they will often arrive 6 months later, half baked, full of bugs and only about 80% effective. Date Residency is seen as less important than, Opacity, Dynamic Goto Page (which is faulty) and many more pointless updates. I feel bad management is strangling this company. Flutterflow allows you to connect a Google Firebase account and you can host and store your data in the highest of standards from day 1.
Looks like you’re not logged in.
Users need to be logged in to write comments
Log In
Reply
Shane A.
SA
Shane A.
Professional Services Strategic Advisor | Board Advisor | Software and Services Executive
Expand/Collapse Options
Philip's not wrong. "Native Mobile" has now been in "Controlled Beta" for more than 6 months and the marketing hype has turned into crickets. Literally, the headline at their conference in October was "The Wait is Over!" Apparently, not.