Identity and tenancy
Independent Intelligence users, MFA, role checks, client context, query filters, host isolation, and audited administration.
AI migration platform security isolates client data, federates provider access, screens untrusted content, enforces approvals, and retains an auditable action record.
Certification statement. BridgeAD does not claim SOC 2 or ISO certification on this site. Control descriptions on this page describe implementation and operating expectations, not independent certification.
Controls cover the client account, migration project, model gateway, retrieved content, provider connection, execution stage, and retained evidence.
Independent Intelligence users, MFA, role checks, client context, query filters, host isolation, and audited administration.
AWS external-ID role assumption, Azure workload identity, separate read and execution roles, short lifetimes, and immediate revocation.
Central model resolution, region matching, request caps, token metering, content safety, prompt-template versions, and provider health checks.
Untrusted-input delimiting, injection screening, client-scoped search filters, source provenance, redaction, and citation retention.
Immutable manifests, artifact hashes, policy preconditions, approvals, JIT access, action allowlists, checkpoints, and kill switch.
Audit events, request correlation, retention policies, offboarding workflow, deletion evidence, monitoring, alerts, backup, and recovery.
| Responsibility | Representative authority | Control |
|---|---|---|
| Client administration | Users, retention and account policy | MFA, role checks and audit |
| Cloud connection | Federated source and target grants | External ID, audience and expiry |
| Architecture review | Target revisions and exceptions | Versioned decisions and impact diff |
| Plan approval | Manifest, budget, tests and recovery | Approval invalidated by material change |
| Apply and cutover | Exact approved stage and window | JIT access and named approvers |
Client residency determines eligible model deployments and processing regions. Requests do not silently cross an unsupported regional boundary.
Model and retrieval services are selected from deployments approved for the client’s pinned region.
Uploads, discovered metadata, retrieved context, and generated outputs pass capability-appropriate safety checks.
Conversation, imported snapshot, lead, account, search-index, and audit retention are governed separately.
Approved models are capability and region filtered; each usage record retains provider, model, tokens, cost, and feature.
Bring identity, residency, network, DPA, retention, logging, and separation-of-duty requirements.