Trust

How this site and the client portal are run

  • Hosting: Vercel serves this site and the client portal; the application behind the portal runs on Render; client data is held in Supabase. Data region: not yet assessed.
  • Transport: every page is served over HTTPS, with Strict-Transport-Security set for two years across all subdomains.
  • Content-Security-Policy: in force on every response. Scripts load from this origin and named hosts only, and no other site may frame these pages.
  • Row-level security: enabled on every table in the database. The verification query of 19 September 2026 returned 0 tables without it.
  • Release gates: no change reaches this site until type checking, the test suite, the visual-standard lint, the production build and the rendering checks all pass.

Email authentication

The state of the records for bridghamcyber.com, read from live DNS when this page was built on 2026-10-09.

  • SPF: published, ending ~all.
  • DKIM: a key is published for selector google.
  • DMARC: published, policy p=reject.

Data handling

The client portal stores account details, engagement records and the documents delivered to each client. All of it is held in Supabase. Engagement records are kept for the engagement and five years after it ends; account details for three years after it ends. The full schedule is in the privacy policy.

Research use of a client's data and naming a client as a reference are two separate consents, each given in writing. No figure drawn from client data is published unless it rests on at least 20 firms in all, 10 within a segment, and 5 in every cell.

Sub-processors

Sub-processors and what each does
VendorPurpose
VercelHosting for this site and the client portal
RenderHosting for the application behind the portal
SupabaseDatabase, sign-in and file storage for client data
PostmarkTransactional email
Google WorkspaceBusiness mail and documents
MicrosoftDefender telemetry, read within each client's own tenant
StripePayment processing
PostHogSite analytics, EU-hosted, loaded only after consent

List not yet confirmed.

Vulnerability disclosure

Report a suspected vulnerability in this site, the client portal or the firm's own systems to support@bridghamcyber.com or by telephone on (984) 205-6193, with the address affected, the steps that reproduce it and the date it was found. Every report is acknowledged within 2 business days. The same contacts are published in security.txt.

The firm takes no legal action against research done in good faith within that scope: reported promptly, touching no more data than is needed to show the issue, and making no attempt to disrupt service. Client systems are out of scope; testing them requires that client's own written authorisation.

What this page does not claim

The firm holds no third-party attestation today: no SOC 2 report and no ISO 27001 certificate. Any attestation a sub-processor holds belongs to that vendor, not to the firm.

Facts as of 2026-10-09 · version 1.

Request an Introduction