Security and governance

AI migration platform security for governed actions.

AI migration platform security isolates client data, federates provider access, screens untrusted content, enforces approvals, and retains an auditable action record.

Client-scoped isolationFederated cloud identitiesAudited model governance

Certification statement. BridgeAD does not claim SOC 2 or ISO certification on this site. Control descriptions on this page describe implementation and operating expectations, not independent certification.

BridgeAD IntelligenceSecurity & governance workspace
BridgeAD Intelligence workspace showing programme controls, governed decisions, risks, current activity, and traceable cost evidence
Controls visible at every boundaryClient isolation, federated access, model governance, approvals, and auditable actions remain attached to the migration programme.
Product view · synthetic demonstration data
Separate client scopeIdentity, SQL, search, storage and telemetry controls.
No stored cloud keysCustomer-owned federation and short-lived tokens.
Controlled model useRegion, safety, metering and audited administration.
Traceable actionsApprover, request ID, result and evidence.
Control domains

Apply security at the boundary where risk enters.

Controls cover the client account, migration project, model gateway, retrieved content, provider connection, execution stage, and retained evidence.

Identity and tenancy

Independent Intelligence users, MFA, role checks, client context, query filters, host isolation, and audited administration.

Cloud connections

AWS external-ID role assumption, Azure workload identity, separate read and execution roles, short lifetimes, and immediate revocation.

Model gateway

Central model resolution, region matching, request caps, token metering, content safety, prompt-template versions, and provider health checks.

Content and retrieval

Untrusted-input delimiting, injection screening, client-scoped search filters, source provenance, redaction, and citation retention.

Plan and execution

Immutable manifests, artifact hashes, policy preconditions, approvals, JIT access, action allowlists, checkpoints, and kill switch.

Evidence and lifecycle

Audit events, request correlation, retention policies, offboarding workflow, deletion evidence, monitoring, alerts, backup, and recovery.

Separation of duties

Separate who configures, connects, approves, and executes.

Separation of duties and representative authority
ResponsibilityRepresentative authorityControl
Client administrationUsers, retention and account policyMFA, role checks and audit
Cloud connectionFederated source and target grantsExternal ID, audience and expiry
Architecture reviewTarget revisions and exceptionsVersioned decisions and impact diff
Plan approvalManifest, budget, tests and recoveryApproval invalidated by material change
Apply and cutoverExact approved stage and windowJIT access and named approvers
Data and AI governance

Make processing location, purpose, and retention explicit.

Client residency determines eligible model deployments and processing regions. Requests do not silently cross an unsupported regional boundary.

Residency

Region-matched processing

Model and retrieval services are selected from deployments approved for the client’s pinned region.

Policy enforced
Safety

Input and output screening

Uploads, discovered metadata, retrieved context, and generated outputs pass capability-appropriate safety checks.

Fail closed
Retention

Defined lifecycle and deletion

Conversation, imported snapshot, lead, account, search-index, and audit retention are governed separately.

Auditable lifecycle
Models

Central configuration without client-side selection

Approved models are capability and region filtered; each usage record retains provider, model, tokens, cost, and feature.

Metered and audited

Review BridgeAD Intelligence against your security requirements.

Bring identity, residency, network, DPA, retention, logging, and separation-of-duty requirements.

Request a security review