Skip to main content

Company

Security at BridgeCase

Organizations serving youth and families are trusted with information that must not leak, sprawl, or surprise anyone. Security is a design constraint on everything we build — including this website. Here is how we approach it.

How this website is built

The marketing site handles far less sensitive information than the product will, and we hold it to the same discipline anyway:

  • No participant data is collected here. Forms request professional contact details from prospective buyers — never information about young people or families. See the Privacy Policy for exactly what is collected and why.
  • Server-side validation — every form submission is validated on the server; nothing trusts the browser
  • Security headers — responses restrict where content can load from and whether the site can be framed
  • Minimal third parties — assets are served from our own infrastructure, and analytics runs only when explicitly enabled
  • Encryption in transit — the site is served over HTTPS

Product security

Principles the product is built on

BridgeCase is designed for organizations whose records include mentoring notes, referrals, and restricted case information. These principles shape the platform's architecture, not just its settings page.

Role-based access
Each role sees, edits, and exports only what it is explicitly granted. Access is configured per organization, not assumed.
Restricted records
Sensitive notes and flagged records are visible only to roles specifically authorized for them — invisible to everyone else, not merely read-only.
Audit history
Who viewed or changed a record, and when, is recorded — so oversight is a report, not an investigation.
Encryption in transit
Connections to the platform are encrypted. Data does not travel in the clear.
Data ownership and export
Customer organizations own their data, can export it in standard formats, and take it with them if they leave.
Least-privilege operations
Internal access to customer environments is granted narrowly, for specific purposes, and logged.
See how these appear in the product

Certifications and evidence

BridgeCase holds no third-party security certifications today. Evaluating organizations get the substance instead:

  • We share our security documentation with evaluating organizations and answer security questionnaires directly during the sales process
  • Formal attestations and audit results are published here as they are completed
  • We describe capabilities in plain terms on Security & Governance so your IT and compliance reviewers can evaluate substance rather than badges

Reporting a vulnerability

If you believe you have found a security issue in this website or any BridgeCase system, email security@solantis.health with the affected URL, steps to reproduce, and any relevant details. We will acknowledge your report, keep you informed as we investigate, and credit good-faith researchers who want it.

We ask that researchers act in good faith: do not access, modify, or retain data that is not yours, do not degrade service for others, and give us reasonable time to remediate before public disclosure.

Put your security questions to us directly.

Bring your evaluation checklist to a demo — we will walk through access controls, audit history, and data ownership in the product itself.

No youth or family data is required to request a demo.