Trust Centre

Trust, treated as a first-class commitment

Enterprise buyers should never have to guess. This Trust Centre distinguishes implemented controls from roadmap commitments, and it never implies certification or approval before evidence exists.

Security by design

Security

Security by design

AlphaBridge applies security by design, least privilege, tenant isolation, governed production access, audit logging, change control, backup and recovery discipline.

Production claims are held to implemented controls and available evidence. We publish what we can support — and clearly mark what is still on the roadmap.

Privacy across the whole lifecycle

Privacy

Privacy across the whole lifecycle

Privacy is designed across collection, use, support, migration and retention.

We publish controller and processor roles, lawful processing information, retention principles, data-subject rights, our international-transfer approach and subprocessors as applicable.

Governed, human-accountable AI

Responsible AI

Governed, human-accountable AI

Smart AI is governed as a decision-support capability. Material actions require human accountability.

AI outputs are traceable to authorised sources, display appropriate confidence and limitations, and are logged in accordance with retention and security policy.

Compliance & assurance

A living assurance register — no logos, no implied approvals

We track assurance across three honest states: Implemented, In Progress and Planned. We never use logos or wording that imply ISO certification, SOC 2 attestation, HMRC recognition or regulatory approval before formal evidence exists.

Assurance register
Assurance areaStatus
Security by design & least privilegeIn progress
Tenant isolation & governed production accessIn progress
Audit logging & change controlIn progress
Backup & recovery disciplineIn progress
Privacy notice & DPA request pathIn progress
Subprocessor registerPlanned
Responsible AI statementIn progress
Business continuity summaryPlanned
Vulnerability reporting routeIn progress
ISO / SOC / regulator certificationNot claimed

Statuses are maintained by management against evidence in data/trust.js. Where a status is “Planned” or “Not claimed”, no capability or approval is being asserted.

Enterprise procurement

Everything your procurement team asks for

We are building a documented set of assurance assets so security, legal and procurement reviews move quickly.

  • Security overview
  • Privacy notice & DPA request path
  • Subprocessor register
  • Responsible AI statement
  • Business continuity summary
  • Vulnerability reporting / contact route
  • Service status link (when operational)
  • Compliance / assurance roadmap