An accurate posture, not a checkbox page.
Bridgewerks is mid-migration from a single-tenant deployment model to one shared, organization-scoped service. We'd rather tell you exactly where that stands than round it up.
SOC 2 is a hard gate before general sale: we will not claim SOC 2 completion, and we have not started a Type I or Type II audit. A gap-analysis document tracks the control work against SOC 2's expectations and is available under NDA once a pilot conversation is underway.
Every session-bearing route gates through a shared auth check. Sign-in supports Microsoft Entra ID, Google, and email/password, with domain or email allowlisting for SSO.
Bcrypt password hashing; single-use, hashed, time-limited password reset tokens.
Durable, database-backed lockout after repeated failed logins — survives serverless restarts.
Postgres-backed sliding-window limits cover auth, borrower and broker portals, AI/Ask, generated exports, and selected high-cost uploads. User and organization budgets hold across server instances; auth and portals fail closed if the limiter store is unavailable.
Not enforced by Bridgewerks itself. Entra ID and Google sign-in may enforce MFA at your identity provider if you configure it there.
Database-backed admin flag is the source of truth for admin access, with an environment allowlist as an SSO fallback.
This is the section most worth reading closely if you're running a security review. Bridgewerks is moving from one deployment per customer to one shared multi-tenant service with row-level security as the enforced isolation boundary. That migration is underway in the same codebase you'd be evaluating — not finished, and not represented as finished.
Every lender is an organization; users get access through a verified membership record, not a client-supplied ID.
organization_id is being added across tenant-owned tables and enforced through row-level security, table family by table family — the migration is in progress, not finished across the whole schema.
RLS policies are shipping alongside a non-service-role database role so tenant queries are actually forced through them, replacing the prior service-role (RLS-bypassing) access pattern — in progress, being proven table family by table family, not yet the sole path everywhere.
Re-checking active membership on every request (so a suspended member's session can't outlive the suspension) is part of the same in-progress migration.
Automated tests that prove one organization cannot reach another's data are a required acceptance gate for the migration, not yet complete across every surface.
Integrations are configured deployment-wide today, not yet as per-organization encrypted rows — a named target of the same migration.
Every view, download, upload, and delete of a borrower document is recorded — actor, action, and linkage to the deal or loan.
Administrative actions are recorded to a durable audit-events table.
HSTS with preload, a restrictive Content-Security-Policy, X-Frame-Options, and X-Content-Type-Options are set on every response.
TLS everywhere; hosting and database providers encrypt data at rest by default.
No Sentry/Datadog-class monitoring or alerting on lockout spikes or anomalous admin activity exists yet.
Not yet adopted as formal, auditor-facing documents.
SOC 2 is a hard gate before Bridgewerks is sold at general list price. Today that means an internal gap-analysis document, not an audit: no compliance-automation platform is connected, no auditor is engaged, and no Type I or Type II report exists yet. A Type I report is a point-in-time design assessment; a Type II report requires an observation window of several months after that. Design-partner conversations can proceed on the strength of a completed Type I and a dated Type II commitment once that work starts — general sale waits for the completed Type II report.
Bridgewerks hosts on Vercel and Supabase, both of which publish their own SOC 2 reports as subservice organizations; encryption at rest and infrastructure redundancy below the application layer are their responsibility, tenant isolation above it is ours.
Ask us the hard question first.
Bring your security questionnaire. We'll answer what's shipped, what's in progress, and what isn't built yet — in that order.