Email is not a file send
Attachments vanish into inboxes. Forwards erase who saw the file. Size limits push people to the next risky link.
Share a branded link that expires. Files stay in storage you own. Staff sign in with the identity you already run.
White-label secure file transfer with bring-your-own storage. Files stay in your Azure Blob, GCS, or S3. Identity stays in Entra, Google Workspace, or SAML. Audit streams to your SIEM.
Links expire · Your storage · Your identity · White-label portal · SIEM audit
The problem
You need to send a contract, an evidence pack, or a file a supplier asked for. Email hits a size limit. Someone pastes a personal Dropbox or OneDrive link. Then a client or an assessor asks who opened it, where it lived, and when it should have vanished.
Attachments vanish into inboxes. Forwards erase who saw the file. Size limits push people to the next risky link.
A generic Dropbox or personal OneDrive link is easy. You do not control the brand, the expiry, or the storage account.
If the transfer product also keeps everyone's bytes, a breach of that product is a breach of your files. Bridge leaves the files in your cloud.
White-label + BYOS
Clients open a page that looks like your organisation. Uploads go to Azure Blob, Google Cloud Storage, or S3 you connect. Trustholm mints short-lived URLs and keeps the audit. File bytes stay in your bucket.

Outcomes
You send files to people outside the organisation. The link expires. The files stay in your cloud. Staff use the logins you already run.
Share a file, request a file, or open a workspace. Clients, suppliers, and the public get a page that looks like you.
Set expiry, a download cap, or revoke access. The share ends when you say it should.
Files stay in Azure Blob, GCS, or S3. Staff sign in with Entra, Google Workspace, or SAML. Audit can land in your SIEM.
Client paths
These paths match how you sell the handoff: MSP white-label, legal file-request, government partner exchange, and enterprise sharing.
White-label file transfer as a service line. Your hostname, their (or your) storage, QBR-ready audit.
Matter file-request, expiry with the close letter, watermarked view-only for drafts.
Partner exchange with files in storage you already operate. Identity in your IdP. Audit in the SIEM you already staff.
Move branded share, file-request, and workspaces onto storage and identity you already operate.
How it works
Connect cloud and identity. Brand the portal. Prove audit. Then invite production guests.
Azure Blob, GCS, or S3-compatible storage for files. Entra, Google Workspace, or SAML for staff. Confirm where CMEK and tenant policy already live.
Hostname, theme, and email identity. Staff and guests get deliberate access with MFA.
Expiry, max downloads, revoke, watermark. Workspaces add Explorer browse and revision history. Browsers upload to your bucket on short-lived signed URLs. We keep metadata.
Walk invite, transfer, access, quarantine, export. Stream to the SIEM your SOC already watches. Then expand the guest list.
Capabilities
The everyday job is sending a file. The technical story is white-label plus bring-your-own storage plus audit. Partners land on your hostname. Files stay in your cloud.
User-delegation SAS on Azure Blob, V4 signed URLs on GCS, and SigV4 on S3-compatible buckets. File bytes at rest stay in your cloud.
Set a time limit, a download cap, or revoke the share. Access goes away when the job is done. This is the control people miss on a personal Dropbox link.
Clients land on a portal that presents as your organisation. Useful when MSPs and enterprises white-label services for regulated customers.
Workforce federation plus guest passkey or TOTP, so invitations are deliberate. Step-up on mutating admin calls.
Multi-party folder browse with revision history. Internals and externals contribute. Each replace is a new revision and a re-scan.
Hash-chained trails, CSV, Sentinel, Splunk HEC, webhook, Pub/Sub, and replay. Designed for diligence, not anecdote.
MetaDefender default, optional customer webhook, or Defender Event Grid ingest so scan verdicts stay in your tenancy path.
Audit
When cyber insurance, procurement, or a client security questionnaire asks how files move, you answer with a governed portal, customer-owned storage, and retained access history, not a forward chain from last Tuesday.

Compare
Pick the tool for the job. Bridge is the branded file send: your storage, your identity, links that expire. Keep a classic MFT tool if you still need SFTP or AS2.
| Need | Consumer sync | Full MFT suite | Bridge |
|---|---|---|---|
| Client sees your brand | Generic product brand | Often vendor-branded | Fit White-label portal |
| File bytes at rest | Vendor or mixed custody | Usually central MFT store | Fit Your Blob, GCS, or S3 |
| Everyday team collaboration | Fit Designed for this | Overkill for chatty sync | Fit Governed deal rooms |
| Audit for vendor review | Limited / product-shaped | Fit Deep protocol + ops | Fit Transfer + SIEM trails |
| SFTP / AS2 / heavy protocols | Usually no | Fit Core offering | Keep on your MFT if you run it |
Many programmes run Bridge for branded sharing and keep a classic MFT tool for protocols. Deep dives: GoAnywhere, MOVEit, and Kiteworks.
Built for
One product story that each function can take into their own conversation. Use the client paths when the buying centre is a named industry motion.
Custody diagram plus SIEM export. Files in your cloud. Identity in your IdP. Audit your security team can take into a vendor review.
White-label handoffs for clients who expect your brand, without inventing a new consumer sync habit for every engagement.
If your team still sends Dropbox or OneDrive links to clients, this is the version you can defend. Security still gets BYOS and SIEM. The board gets a sentence they understand.
Trust
A branded portal, files in your cloud, identity in your IdP, and audit your security team can export. Company procurement materials live on the trust hub.
Engagements
Request access with Bridge selected. We route storage, identity, branding, and audit bar before you invite production guests.
Bridge handles governed file handoffs. Govern proves signed script evidence beside an RMM. ShareSight maps Microsoft 365 access. Migrate moves TRIM / Content Manager into SharePoint. Same trust surface on www. Each product app hosts its own sign-in.
Request Bridge access and we will scope storage, identity, branding, and audit. Or open the Bridge app when you already have credentials.
Send files to clients, suppliers, and the public from a branded page. Set the link to expire. You own the storage and the identity. For technical buyers this is white-label secure file transfer with share, file-request, and workspaces. Many programmes also keep a classic MFT tool for SFTP or AS2.
In your Azure Blob, Google Cloud Storage, or S3-compatible bucket. Trustholm mints short-lived access and stores workflow metadata plus audit.
You can expire the share, cap downloads, or revoke access. The link then stops working. File bytes stay in the Azure Blob, GCS, or S3 you connect until your own retention rules delete them.
People already know how to send a Dropbox or OneDrive link. Bridge is that same job: send a file out, with expiry, your brand, and storage plus identity you own. Those tools are built for everyday sync inside a team. Bridge is not a sync client or a mapped drive.
Branded HTTPS sharing, file-request, and workspaces with files in your cloud. Read the compare pages for the side-by-side.
Staff send and receive from the branded portal today. Outlook and Teams Send via Bridge is available as Preview for allowlisted tenants. File bytes still upload client-side to your storage. Ask on the access form.
Yes. White-label presentation, including hostname and theme, is part of the offer so partners and clients experience your organisation.
Yes. Hash-chained access and admin events support diligence workflows, with CSV and SIEM export. Details are confirmed during onboarding.
Yes. The login hub is bridge.trustholm.com. Product cells run at us, au, and eu.bridge.trustholm.com for metadata residency. File bytes still stay in the storage you connect.
Yes. We renamed to Bridge so the product is not confused with Microsoft Exchange. The offer is white-label secure file transfer with BYOS and audit.
On the Trustholm trust hub (www). Product apps host sign-in; procurement and security questionnaires start from published trust pages.
Request Bridge access from the access form with Bridge selected. We scope a pilot that matches your storage, identity, branding, and audit expectations.