Compliance & Trust
IdentityBridge is designed to help organizations operate identity migrations within controlled security and governance processes. Compliance obligations vary by organization, jurisdiction, workload and deployment configuration.
Compliance & Trust
Security & Governance Capabilities
- Authenticated access with role-aware workflows
- Approval gates and state transitions for migration activities
- Audit evidence and actor attribution where implemented
- Tenant isolation to the degree actually implemented
- Credential protection using implemented encrypted storage
- Controlled execution of supported migration jobs
Customer Responsibilities
Customers remain responsible for determining whether their IdentityBridge configuration and use satisfy their legal, regulatory, contractual and organizational requirements.
Compliance Roadmap
| Framework | IdentityBridge position |
|---|---|
| GDPR / privacy legislation | Privacy-supporting architecture; applicability depends on processing and customer context |
| SOC 2 | Do not claim certification unless completed |
| ISO/IEC 27001 | Do not claim certification unless completed |
| HIPAA | Not represented as HIPAA compliant unless formally supported |
| FedRAMP | Not FedRAMP authorized unless formally achieved |
| PCI DSS | IdentityBridge must not store raw payment-card PAN/CVV; payment processing should use approved providers |
Privacy/Data Protection
IdentityBridge is designed with a privacy-supporting architecture. Data processing depends on the deployment, customer context and applicable law. See the Privacy Notice for details.
Audit/Evidence
Security, commercial and migration events are recorded with actor attribution where implemented, supporting operational review and evidence retention.