Compliance & Trust

IdentityBridge is designed to help organizations operate identity migrations within controlled security and governance processes. Compliance obligations vary by organization, jurisdiction, workload and deployment configuration.

Compliance & Trust

Security & Governance Capabilities

  • Authenticated access with role-aware workflows
  • Approval gates and state transitions for migration activities
  • Audit evidence and actor attribution where implemented
  • Tenant isolation to the degree actually implemented
  • Credential protection using implemented encrypted storage
  • Controlled execution of supported migration jobs

Customer Responsibilities

Customers remain responsible for determining whether their IdentityBridge configuration and use satisfy their legal, regulatory, contractual and organizational requirements.

Compliance Roadmap

FrameworkIdentityBridge position
GDPR / privacy legislationPrivacy-supporting architecture; applicability depends on processing and customer context
SOC 2Do not claim certification unless completed
ISO/IEC 27001Do not claim certification unless completed
HIPAANot represented as HIPAA compliant unless formally supported
FedRAMPNot FedRAMP authorized unless formally achieved
PCI DSSIdentityBridge must not store raw payment-card PAN/CVV; payment processing should use approved providers

Privacy/Data Protection

IdentityBridge is designed with a privacy-supporting architecture. Data processing depends on the deployment, customer context and applicable law. See the Privacy Notice for details.

Audit/Evidence

Security, commercial and migration events are recorded with actor attribution where implemented, supporting operational review and evidence retention.