Platform Security

Your data security is our highest priority

Sales Engineers put their customers' environments into Critical Bridge: asset inventories, network details, log volumes, compliance gaps and bid documents. That information is sensitive, and protecting it is the first requirement of the platform, not a feature added later.

Critical Bridge protects your data in layers: encrypted storage and transport, database-level isolation between organizations, server-side access control, records that cannot be rewritten, and continuous automated security testing.

Encryption and infrastructure

Your data is encrypted everywhere it lives and everywhere it moves.

  • ·At rest: databases, indexes, transaction logs, backups and uploaded files are encrypted with AES-256.
  • ·In transit: every connection to the platform uses TLS 1.2 or higher.
  • ·Infrastructure: Critical Bridge runs on Supabase, whose platform is SOC 2 Type 2 audited and ISO 27001 certified, hosted on AWS.

Your data stays yours

Every organization's data is walled off from every other organization's, enforced by the database itself.

  • ·Database-level isolation: row-level security policies scope every read and write to the organization that owns the record. A request for another organization's data returns nothing, regardless of how it is made.
  • ·Server-side, not screen-deep: isolation does not depend on what the app shows or hides. Hiding a button is never the control.
  • ·Organization from the record, not the request: the platform determines ownership from the data being accessed, so a user cannot claim to be in another organization.
  • ·Master Resellers see no customer data: reseller organizations handle commercial relationships only. The database denies them customer engagement data, and no sharing arrangement can grant it.
  • ·Deactivation is immediate: every access check requires an active organization and an active membership, so deactivating a person or account removes access at once.

Access control

Within your organization, people see and change only what their role allows.

  • ·Role-based access: each user has a role, and every permission check runs on the server.
  • ·Least privilege by default: features are available only to the roles and plans that need them.
  • ·Signed-in access only: platform data and functions require an authenticated session; public pages expose no customer data.
  • ·Single sign-on: partner organizations can sign in through SAML single sign-on with their own identity provider.

No standing access, not even for us

The Critical Bridge support team has no standing access to your engagement data.

  • ·Your approval opens the door: reaching your records requires a request tied to an open support ticket, a written purpose, a single scope and an expiry no more than 72 hours out. An administrator on your account approves it, and can end it at any time.
  • ·Read-only: support access can view, never change, approve or release anything.
  • ·Recorded: every support session records who, what, when and how, and the record cannot be edited.

Records that can't be rewritten

The records that matter most are locked at the database level once they are final, so history cannot be quietly changed.

  • ·Immutable records: issued quotes, compliance control results, evidence attestations, GRC document versions and bid review history cannot be edited or deleted after they are finalized, even by administrators using the app.
  • ·Audit trail: significant actions are written to an append-only, hash-chained audit log that records who did what, and when. Deleting entries is impossible, tampering is detectable, and a verification routine confirms the chain is intact.
  • ·Evidence you can stand behind: because finalized records cannot be altered, what you show an auditor or a customer is what was actually recorded at the time.

Safe handling of files and input

Everything that comes into the platform is checked, and everything that goes out is made safe to open.

  • ·Allowed file types only: uploads accept specific document and spreadsheet formats and refuse everything else with a clear message.
  • ·Spreadsheet safety: imports never bring in formula text, and downloadable audit exports are protected so planted text cannot run as a formula when a colleague opens the file.
  • ·Search and input as plain data: what users type is treated as data, never as instructions to the database or the platform's AI assistant.
  • ·Maintained dependencies: third-party libraries come from maintained, published releases and are scanned for known vulnerabilities.

Continuous security testing

Security is checked on every change, not once a year.

  • ·Automated scanning: code, database access rules and third-party dependencies are scanned for security issues as the platform changes.
  • ·Findings fixed, then verified: issues are fixed and re-scanned to confirm the fix, rather than marked closed on trust.
  • ·Security regression tests: automated tests cover permission logic and protected-record rules, and run as the platform changes.

Shared responsibility

Security is a partnership: we secure the platform, and you control who uses it.

Critical Bridge securesYou control
Encryption at rest and in transitWho is invited to your organization
Isolation between organizationsWhich role each user has
Server-side access controlRemoving users who leave your team
Immutable records and audit trailWhat data you enter and upload
Continuous security testingStrong, unique passwords for your users

Compliance posture

Critical Bridge helps you run compliance work, and we are precise about what that does and does not mean.

  • ·Frameworks supported: the platform includes assessment packs for CJIS, HIPAA, PCI DSS, NIST 800-53 Moderate and a general IT and security baseline, to help you assess and document your customers' environments.
  • ·Infrastructure certifications: our hosting provider, Supabase, is SOC 2 Type 2 audited and ISO 27001 certified.
  • ·Not a system of record for regulated data: do not store Criminal Justice Information (CJI), Protected Health Information (PHI) or payment card data in Critical Bridge. Record findings and evidence about those systems, not the regulated data itself.
  • ·Evidence stays where it lives: compliance registers record that a document exists, who owns it and where it is kept, not the document itself. Critical Bridge never becomes the custodian of your policies, audit reports or regulated data.

Questions about Critical Bridge security?