Company
Security at BridgeCase
Organizations serving youth and families are trusted with information that must not leak, sprawl, or surprise anyone. Security is a design constraint on everything we build — including this website. Here is how we approach it.
How this website is built
The marketing site handles far less sensitive information than the product will, and we hold it to the same discipline anyway:
- No participant data is collected here. Forms request professional contact details from prospective buyers — never information about young people or families. See the Privacy Policy for exactly what is collected and why.
- Server-side validation — every form submission is validated on the server; nothing trusts the browser
- Security headers — responses restrict where content can load from and whether the site can be framed
- Minimal third parties — assets are served from our own infrastructure, and analytics runs only when explicitly enabled
- Encryption in transit — the site is served over HTTPS
Product security
Principles the product is built on
BridgeCase is designed for organizations whose records include mentoring notes, referrals, and restricted case information. These principles shape the platform's architecture, not just its settings page.
- Role-based access
- Each role sees, edits, and exports only what it is explicitly granted. Access is configured per organization, not assumed.
- Restricted records
- Sensitive notes and flagged records are visible only to roles specifically authorized for them — invisible to everyone else, not merely read-only.
- Audit history
- Who viewed or changed a record, and when, is recorded — so oversight is a report, not an investigation.
- Encryption in transit
- Connections to the platform are encrypted. Data does not travel in the clear.
- Data ownership and export
- Customer organizations own their data, can export it in standard formats, and take it with them if they leave.
- Least-privilege operations
- Internal access to customer environments is granted narrowly, for specific purposes, and logged.
Certifications and evidence
BridgeCase holds no third-party security certifications today. Evaluating organizations get the substance instead:
- We share our security documentation with evaluating organizations and answer security questionnaires directly during the sales process
- Formal attestations and audit results are published here as they are completed
- We describe capabilities in plain terms on Security & Governance so your IT and compliance reviewers can evaluate substance rather than badges
Reporting a vulnerability
If you believe you have found a security issue in this website or any BridgeCase system, email security@solantis.health with the affected URL, steps to reproduce, and any relevant details. We will acknowledge your report, keep you informed as we investigate, and credit good-faith researchers who want it.
We ask that researchers act in good faith: do not access, modify, or retain data that is not yours, do not degrade service for others, and give us reasonable time to remediate before public disclosure.
Put your security questions to us directly.
Bring your evaluation checklist to a demo — we will walk through access controls, audit history, and data ownership in the product itself.
No youth or family data is required to request a demo.