Security & trust

Your security is our security

You're trusting us with your users' data, and we treat that trust as core to the product, not an afterthought. We're ISO/IEC 27001:2013 certified, GDPR compliant, and our infrastructure goes through weekly third-party penetration tests.

Get started

Certified, compliant, continuously tested

  • ISO 27001 certified

    Certified against ISO/IEC 27001:2013, the international standard for information security management.

  • GDPR compliant

    Compliant by design: data processed in the EU, with a named Data Protection Officer.

  • Penetration tested weekly

    An independent third party tests our infrastructure for weaknesses every week.

Systemized information security

ISO 27001 certified

The Bridge is certified against ISO/IEC 27001:2013, the internationally recognized standard for information security management. Certification means an accredited auditor verified our information security management system, not just our marketing claims.

Getting certified meant formalizing how we manage security risk: asset inventory, access control, incident response, vendor review, and staff training all follow a documented management system, audited on a recurring cycle. That's the same system protecting the data flowing through login, billing, and feature flags today.

All datacenters we partner with carry ISO 27001 and SOC 2 certification too, so the bar doesn't drop the moment your data leaves our primary infrastructure.

ISO 27001 certification badge

Encryption at rest and in transit

Every piece of data The Bridge stores is encrypted, full stop. File stores, document stores, and databases are encrypted at rest, and everything in transit is protected with TLS 1.3, the same encryption layer behind the HTTPS in your browser bar.

We back up data on a regular schedule and test our restoration protocols, so a hardware failure or a bad deploy never turns into a data-loss incident. Recoverable is part of what "secure" means to us.

Infrastructure built on AWS

The Bridge runs inside a Virtual Private Cloud (VPC) on AWS, with our primary datacenter in AWS EU (Ireland) and other AWS regions available on request.

A VPC isolates our infrastructure at the network layer, so your data isn't sharing space with untrusted traffic. We picked AWS because their physical and digital security controls are independently audited at a scale we couldn't replicate ourselves, and we hold every partner datacenter to the same ISO 27001 and SOC 2 certification bar.

Security built into how we ship

Every code change goes through review, and only the CTO can approve a change for a production release. That approval gate exists because security review shouldn't be optional, and it shouldn't be left to the engineer who wrote the code.

Our test suite includes automated scenarios that try to penetrate the software the same way an attacker would: probing for access to resources that shouldn't be reachable. An independent third party runs additional penetration tests against our applications every week, and we run AWS Trusted Advisor continuously to keep infrastructure configuration current.

We review our frameworks and dependencies on a monthly security review cycle. Vital patches and security upgrades get prioritized in our two-week sprint schedule, and if a critical vulnerability drops in a framework we use, we escalate the update outside the normal schedule.

Independent penetration testing badge

Compliant by design

GDPR compliant

The Bridge is GDPR compliant by design, not by afterthought. Every AWS resource sits inside a VPC in an AWS EU datacenter in Ireland, and we have a named Data Protection Officer responsible for our data protection program.

Transparency, data minimization, explicit consent, and a documented breach response protocol are built into how we handle personal data. Under GDPR, you and your end users have the following rights:

  • Access the personal data we hold
  • Correct inaccurate or incomplete data
  • Delete personal data
  • Transfer data to another provider
  • Withdraw consent at any time

Read the full terms in our Privacy Policy and Data Processing Agreement, or contact our Data Protection Officer directly with any request.

GDPR compliance badge

Found a security issue?

If you find a vulnerability in The Bridge, tell us before you tell anyone else. We investigate every report and keep you updated as we work through it.

Email our Data Protection Officer at oscar(at)nebulr.group with what you found and how to reproduce it. We don't run a bug bounty program today, but we take every report seriously and respond directly.

Build SaaS how it should be built today

Skip the plumbing. Ship the product.

Get started