Where we stand today. BridgeCorp is early in its journey. We operate the controls described on this page from day one, and we are candid about what we have not yet certified. We would rather you audit us than take our word for it — see Due diligence.
On this page
1. Our approach
We are a remote-first company. That is a deliberate operating model, not a cost shortcut, and it changes what good security looks like: there is no office perimeter to defend, so the controls sit on the person, the device and the access path instead.
Three principles run through everything below.
- Your data stays in your systems. Wherever the engagement allows, our agents work inside your platforms rather than copying data into ours.
- Least privilege by default. People get access to what their role requires, for as long as they need it, and no longer.
- Dedicated, never shared. An agent assigned to your account works only on your account. No pooling across clients means no cross-contamination of data or context.
2. People
Most security failures in this industry are human, not technical. We treat hiring as a control.
- Background verification on every agent before they are assigned to a client account — identity, address, employment history and [criminal record check where lawful]
- Enforceable confidentiality agreements signed by every employee and contractor before touching a client system, with obligations that survive the end of employment
- Role-specific onboarding covering data handling, your escalation paths and your industry's obligations before an agent takes their first live interaction
- Ongoing training at [quarterly] intervals, including phishing awareness and social engineering
- Structured offboarding — access revoked on the same day a person leaves a role or account, with a documented checklist
3. Devices and workspaces
Every agent works from a home setup that we verify before they go live, and re-verify [annually].
- Full-disk encryption required on every machine used for client work
- Managed endpoint protection with automatic updates and centralised patch status
- Screen privacy and workspace checks — a private working area, no shared or family devices, no unattended unlocked screens
- Removable media, printing and local file storage disabled on accounts handling sensitive workloads
- Clean audio environment for voice and interpreting work, so conversations are not overheard
For engagements with stricter requirements — healthcare, legal, financial — we can supply company-owned, locked-down devices instead of a bring-your-own arrangement. Discuss this during scoping; it affects lead time and cost.
4. Access and networks
- Multi-factor authentication on every system that supports it, with no shared logins between agents
- Named accounts only, so every action in your systems traces to one identifiable person
- Encrypted connections for all client system access, via [VPN / your preferred remote access method]
- Quarterly access reviews, with revocation of anything no longer required
- Segregated credentials per client — no password reuse across accounts, managed in [password manager]
5. How we handle your data
In most engagements we are a data processor: you decide what is collected and why, and we act on your documented instructions under a signed Data Processing Agreement. We do not use your data for our own purposes, and we never use it to train models or build our own datasets.
- Work in place — agents operate inside your CRM, helpdesk or scheduling platform wherever possible, so data is not duplicated
- No local retention — where data must be handled outside your systems, it is not stored on agent devices
- Encryption in transit on all channels we control
- Sub-processors disclosed in advance, with your right to object before we engage one
- Return or deletion on exit, certified in writing at the end of an engagement
6. Business continuity
Remote delivery removes some risks and introduces others. A single office fire cannot take us offline; a single agent's broadband can. We plan for the second.
- Trained backup agents shadowing each account, so coverage holds when someone is unavailable
- Redundant connectivity — every agent maintains a secondary internet connection, typically mobile
- Power backup appropriate to the region they work in
- Documented failover and escalation plans agreed with you during onboarding rather than improvised during an outage
- Coverage across time zones, so an incident in one region does not stop work in another
7. Incident response
We maintain a documented incident response procedure. In summary:
- Contain and assess immediately on detection
- Notify your named contact without undue delay, and in any event within [24] hours of becoming aware of a personal data breach, so you can meet your own regulatory deadlines
- Investigate and remediate, with a written root cause analysis
- Support your notifications to regulators and affected individuals — as processor, that reporting duty is yours, and we give you what you need to discharge it
8. Regulatory alignment
We choose our words carefully here, because this is where providers tend to overclaim.
| Framework | Our position |
|---|---|
| UK GDPR / EU GDPR | We contract as a processor under Article 28 terms, support data subject requests, and transfer data under the UK IDTA or Standard Contractual Clauses. See our Privacy Policy. |
| HIPAA | We are HIPAA-aware: our agents are trained on PHI handling and minimum necessary access. We can enter into a Business Associate Agreement where the engagement requires one. We are not independently HIPAA-audited. |
| India DPDP Act 2023 | As an Indian entity we operate under the Digital Personal Data Protection Act and its obligations on data fiduciaries and processors. |
| NHS suppliers | We can complete the NHS Data Security and Protection Toolkit as part of your supply chain assurance, and support your own submission with evidence of our controls. |
9. Certifications and due diligence
Being straight with you is worth more than a logo wall.
ISO/IEC 27001 — not yet certifiedSOC 2 — not yet auditedPCI DSS — not in scopeHITRUST — not held
Controls above operating todayDPA and BAA availableClient audit welcomed
We are working toward [ISO/IEC 27001] certification, targeted for [timeframe]. Until an independent auditor has signed something, we will not imply that they have.
What you can ask us for
- Our security policy set and incident response procedure
- Sample Data Processing Agreement and Business Associate Agreement
- A completed vendor security questionnaire in your own format
- Evidence of background verification and confidentiality agreements
- A remote audit or interview with the team who would run your account
Email security@bridgecorpcommunication.com and we will respond within [2] business days. If you have found a vulnerability in this website or our systems, please report it to the same address; we will acknowledge it and will not pursue researchers who act in good faith.