Security & data

Your system stays under your control.

Every build has its own security and data requirements. We make the important decisions visible before production: where data lives, which providers touch it, who can access it, and how it can be recovered.

Where data lives

Data stays in the client-owned or client-approved systems agreed for the build. We document the hosting, storage, and data flows before production use.

AI model providers

Where a system uses generative AI, the approved provider is documented for that workflow. Bridge To AI currently supports OpenAI and Anthropic integrations, with project-specific controls around what is sent.

Access control

Access is designed around named users, appropriate roles, and the minimum permissions each integration needs. Administrative access and external connections are scoped to the project.

Backups and recovery

Backup, retention, and recovery requirements are agreed as part of the production scope and configured through the selected hosting and storage providers.

Code, data, and IP

The client owns the platform code and business data we create for them, subject to the signed project agreement. We build for handover, export, and continued operation without vendor lock-in.

The exact controls belong in the scope.

Security is not a generic badge. Data residency, retention, model use, access roles, backup frequency, and handover requirements are documented for the system being built and reflected in the commercial scope.

Book an audit