Trust Center

SOC 2, CMMC, and the certification path.

Frameworks Bridger is actively pursuing or aligning with. We don't claim attestations we don't have; honest status indicators throughout.

Last updated 2026-05-09
§01 · SOC 2

Type II program in flight.

SOC 2 Type II — auditor selection underway.

In progress

Compliance readiness platform onboarded; auditor RFP out for response. Audit window opens once the platform has been instrumented for 90 consecutive days of clean evidence collection. Targeting Q3 2026 attestation.

Trust Services Criteria mapped.

Live

All five TSCs (Security, Availability, Processing Integrity, Confidentiality, Privacy) have control mappings drafted. Security + Confidentiality are the in-scope criteria for the initial Type II report.

§02 · CMMC

Alignment for contractor-side data.

CMMC 2.0 Level 2 alignment for FCI/CUI handling.

In progress

Bridger does not require contractors to upload FCI/CUI to operate, but alignment with CMMC 2.0 Level 2 controls is in progress for any contractor that opts to store CUI-adjacent capability statements. Self-assessment expected Q4 2026.

§03 · Other frameworks

Where we sit on adjacent standards.

GDPR + UK GDPR.

Live

Art. 17 (erasure) and Art. 20 (portability) self-serve from /settings. Data Processing Addendum incorporates EU Standard Contractual Clauses (Module Two, 2021/914). See /legal/dpa.

Data Processing Addendum

OFAC + BIS Entity List screening.

Live

Every new account is screened at signup against OFAC SDN and BIS Entity List. Sanctioned counterparties are flagged for human review before account activation.

ISO 27001 — under evaluation.

Planned

Considered for international customer demand. Not currently scoped; will be reassessed after SOC 2 Type II completes if EU/UK customer demand materialises.