Services About us How it works FAQ Careers Talk to us →
Trust

Security & Compliance.

How a remote-first team keeps client data safe, what we can evidence today, and what we are still working toward.

Last updated: 3 August 2026

Where we stand today. BridgeCorp is early in its journey. We operate the controls described on this page from day one, and we are candid about what we have not yet certified. We would rather you audit us than take our word for it — see Due diligence.

On this page

  1. Our approach
  2. People
  3. Devices and workspaces
  4. Access and networks
  5. How we handle your data
  6. Business continuity
  7. Incident response
  8. Regulatory alignment
  9. Certifications and due diligence

1. Our approach

We are a remote-first company. That is a deliberate operating model, not a cost shortcut, and it changes what good security looks like: there is no office perimeter to defend, so the controls sit on the person, the device and the access path instead.

Three principles run through everything below.

2. People

Most security failures in this industry are human, not technical. We treat hiring as a control.

3. Devices and workspaces

Every agent works from a home setup that we verify before they go live, and re-verify [annually].

For engagements with stricter requirements — healthcare, legal, financial — we can supply company-owned, locked-down devices instead of a bring-your-own arrangement. Discuss this during scoping; it affects lead time and cost.

4. Access and networks

5. How we handle your data

In most engagements we are a data processor: you decide what is collected and why, and we act on your documented instructions under a signed Data Processing Agreement. We do not use your data for our own purposes, and we never use it to train models or build our own datasets.

6. Business continuity

Remote delivery removes some risks and introduces others. A single office fire cannot take us offline; a single agent's broadband can. We plan for the second.

7. Incident response

We maintain a documented incident response procedure. In summary:

8. Regulatory alignment

We choose our words carefully here, because this is where providers tend to overclaim.

FrameworkOur position
UK GDPR / EU GDPRWe contract as a processor under Article 28 terms, support data subject requests, and transfer data under the UK IDTA or Standard Contractual Clauses. See our Privacy Policy.
HIPAAWe are HIPAA-aware: our agents are trained on PHI handling and minimum necessary access. We can enter into a Business Associate Agreement where the engagement requires one. We are not independently HIPAA-audited.
India DPDP Act 2023As an Indian entity we operate under the Digital Personal Data Protection Act and its obligations on data fiduciaries and processors.
NHS suppliersWe can complete the NHS Data Security and Protection Toolkit as part of your supply chain assurance, and support your own submission with evidence of our controls.

9. Certifications and due diligence

Being straight with you is worth more than a logo wall.

ISO/IEC 27001 — not yet certifiedSOC 2 — not yet auditedPCI DSS — not in scopeHITRUST — not held

Controls above operating todayDPA and BAA availableClient audit welcomed

We are working toward [ISO/IEC 27001] certification, targeted for [timeframe]. Until an independent auditor has signed something, we will not imply that they have.

What you can ask us for

Email security@bridgecorpcommunication.com and we will respond within [2] business days. If you have found a vulnerability in this website or our systems, please report it to the same address; we will acknowledge it and will not pursue researchers who act in good faith.