Trust and security

Security follows the work from the first idea.

Bridgly keeps identity, access, evidence and audit connected from idea to outcome. Each person sees the work allowed by their role. Leaders get approved summaries, not open access to every project.

Five professionals collaborate around a table inside a warm curved glass decision room.
Identity and access

Enterprise sign-in and access that fits the organisation.

Bridgly supports enterprise SSO, directory-backed roles and group mapping. Identity is established before the platform decides which project, evidence or summary a person can see.

Each person sees their permitted lane. Useful measures can move up the organisation without opening private detail from other teams or business units.
Verified identity

Know who is asking

Identity is established before Bridgly decides which work, evidence or summary a person can see.

Granular access

Keep people in their lane

Tenant, role, team, business-unit and project scope shape every authorised view.

Row-level controls

Protect the data before retrieval

Access rules are applied before context reaches an answer, agent or workflow.

Evidence and audit

Keep a clear record

Decisions, evidence, ownership, access checks and outcomes remain reviewable.

WorkOS is supported as an enterprise identity and SSO route.

Data, models and customer control

Use the model and data route that fits the organisation.

Customers can use their own provider agreements, gateways or local models. Bridgly keeps the same identity, access, policy and audit controls across those routes.

Customer-managed providers

Bring your existing model agreements

Use approved providers and customer-managed credentials where the deployment supports them.

Local models

Keep suitable workloads closer

Local and self-hosted models can sit behind the same Bridgly identity, scope, policy and audit contract.

Customer content

Keep control of organisational knowledge

Ideas, evidence and decision history remain customer content. Data and model routes can be configured around the customer's control needs.

Enterprise reference architecture

A controlled data and application foundation.

Bridgly connects enterprise identity, the application, approved work tools and a customer-scoped Databricks data plane. Identity, row-level access, evidence and audit controls apply across each route. Model, connector and deployment choices depend on the customer's agreed configuration.

Conceptual reference architectureA protected path from the team to the customer data plane
Customer security perimeter
01People and work surfaces
Enterprise identityWorkOS-supported SSO, groups and roles
Bridgly workspaceIdeas, decisions, goals and learning
IDEs and workbenchesVS Code, GitHub Copilot and specialist tools
Team and business toolsSlack, Teams, documents and project systems
02Bridgly application
Ideas and decision partnerAI assistance built into the flow
Ideas boardDecision rehearsalGoals and milestonesFluid analyticsGoverned skills
03Control and integration
Identity and scopeOrganisation, role, team and project boundaries
Evidence and lineageDecision history, receipts, audit and authorised evidence
Model and spend controlApproved routes, attribution, budgets and refusal before spend
Open connector routesCatalogue connectorsREST APIsSigned webhooksMCPOpenTelemetry
04Databricks data and AI foundation
FoundationUnity CatalogGovernance, classification, access, lineage and audit
FoundationCustomer data planeCustomer-scoped catalogues, evidence and governed telemetry
By profileUnity AI GatewayGoverned model and agent access, policy and usage controls
By profileOmnigentA common adapter for approved agent harnesses
05Customer separation
Customer environment ASeparate catalogue, policy and governed data plane
Customer environment BSeparate catalogue, policy and governed data plane
The exact deployment profile is agreed for each customer. A standard managed, dedicated managed or customer-owned workspace can use different components while keeping the same identity, scope, evidence, lineage and audit contract. Unity AI Gateway and Omnigent are included where the approved deployment profile supports them.
Private deployment

Designed for private cloud and VNet deployment.

Bridgly is designed to run within the customer security perimeter. Network topology, egress rules and production packaging are agreed for each enterprise rollout.

Network boundary

Private ingress and service routes

Use private endpoints and approved access paths that fit the customer cloud and network design.

Egress control

Only approved outbound destinations

Restrict model, connector and service traffic to the routes agreed for the deployment.

Customer authority

Identity, secrets and providers stay scoped

Customer identity, secret handling, provider routes and internal-system access remain deployment specific.

  1. Identity and scopeWho is asking and which lane applies
  2. Authorised evidenceOnly permitted context enters the route
  3. Decision recordRationale, owner and review stay connected
  4. Outcome and auditThe result remains traceable to its evidence
Governance is applied before context is returned and remains attached through the decision and outcome.
Governance and evidence

Apply controls before information is used.

Bridgly keeps source permissions, classification, ownership, evidence and decision history connected to the work. Access is checked before restricted context is returned to an answer, agent or workflow.

Access checked before context is returnedRestricted information is not treated as visible and hidden after generation.
Lineage from summary to evidenceAuthorised users can follow important claims back to the work that supports them.
One decision and audit recordRationale, owner, policy, review and outcome remain connected.
Accessible use

Designed to support WCAG 2.2 AA.

Bridgly is being built for keyboard use, visible focus, readable contrast, text resizing, reflow, clear labels, useful target sizes, screen-reader semantics and reduced motion.

InteractionKeyboard access, visible focus and clear control states
PresentationReadable contrast, text resizing, reflow and reduced motion
MediaUseful labels, alternative text, captions and transcripts where needed
EvidenceFormal WCAG 2.2 AA conformance will be confirmed through audit
Assurance

Clear evidence for security and procurement review.

Security and procurement teams can review the current controls, deployment assumptions, access model and evidence path. Formal certifications and customer-specific production proof are stated only when they exist.

Control position

What is supported now

Identity, scope, row-level controls, governed retrieval, evidence and audit.

Deployment evidence

What is confirmed for the customer

Network topology, provider routes, connector access, operating ownership and production controls.

Formal assurance

What needs independent proof

Certifications and formal accessibility conformance are published only when the evidence is complete.

Start with your real boundary

Show us how identity, data and networks work in your organisation.

We will explain how Bridgly fits the people, systems and controls involved.