Send files to clients, suppliers, and the public.You own the storage and the identity.

Share a branded link that expires. Files stay in storage you own. Staff sign in with the identity you already run.

White-label secure file transfer with bring-your-own storage. Files stay in your Azure Blob, GCS, or S3. Identity stays in Entra, Google Workspace, or SAML. Audit streams to your SIEM.

Expiresset a time limit on every link
Your storagefiles stay in Blob, GCS, or S3
Your identityEntra, Google, or SAML

Links expire · Your storage · Your identity · White-label portal · SIEM audit

The problem

Sensitive files still leave as email and Dropbox links

You need to send a contract, an evidence pack, or a file a supplier asked for. Email hits a size limit. Someone pastes a personal Dropbox or OneDrive link. Then a client or an assessor asks who opened it, where it lived, and when it should have vanished.

Email is not a file send

Attachments vanish into inboxes. Forwards erase who saw the file. Size limits push people to the next risky link.

A consumer link is not yours

A generic Dropbox or personal OneDrive link is easy. You do not control the brand, the expiry, or the storage account.

A central file store is a target

If the transfer product also keeps everyone's bytes, a breach of that product is a breach of your files. Bridge leaves the files in your cloud.

White-label + BYOS

Your brand on the page. Files stay in your bucket.

Clients open a page that looks like your organisation. Uploads go to Azure Blob, Google Cloud Storage, or S3 you connect. Trustholm mints short-lived URLs and keeps the audit. File bytes stay in your bucket.

Enterprise agreement moment for invoice and PO based MSP contracts

Outcomes

What you can say in one sentence

You send files to people outside the organisation. The link expires. The files stay in your cloud. Staff use the logins you already run.

The same job as a file link

Share a file, request a file, or open a workspace. Clients, suppliers, and the public get a page that looks like you.

Links that go away

Set expiry, a download cap, or revoke access. The share ends when you say it should.

Storage and identity you already own

Files stay in Azure Blob, GCS, or S3. Staff sign in with Entra, Google Workspace, or SAML. Audit can land in your SIEM.

Client paths

Directed pages for how you actually buy

These paths match how you sell the handoff: MSP white-label, legal file-request, government partner exchange, and enterprise sharing.

MSPs

White-label file transfer as a service line. Your hostname, their (or your) storage, QBR-ready audit.

Open MSPs path

Government

Partner exchange with files in storage you already operate. Identity in your IdP. Audit in the SIEM you already staff.

Open Government path

Enterprises

Move branded share, file-request, and workspaces onto storage and identity you already operate.

Open Enterprises path

How it works

From IdP and storage to a governed handoff

Connect cloud and identity. Brand the portal. Prove audit. Then invite production guests.

01

Connect storage and identity

Azure Blob, GCS, or S3-compatible storage for files. Entra, Google Workspace, or SAML for staff. Confirm where CMEK and tenant policy already live.

02

Stand up the white-label portal

Hostname, theme, and email identity. Staff and guests get deliberate access with MFA.

03

Mint share, file-request, or a workspace

Expiry, max downloads, revoke, watermark. Workspaces add Explorer browse and revision history. Browsers upload to your bucket on short-lived signed URLs. We keep metadata.

04

Prove the audit path

Walk invite, transfer, access, quarantine, export. Stream to the SIEM your SOC already watches. Then expand the guest list.

Capabilities

Built for governed transfer

The everyday job is sending a file. The technical story is white-label plus bring-your-own storage plus audit. Partners land on your hostname. Files stay in your cloud.

Bring your own storage

User-delegation SAS on Azure Blob, V4 signed URLs on GCS, and SigV4 on S3-compatible buckets. File bytes at rest stay in your cloud.

Expiry and revoke

Set a time limit, a download cap, or revoke the share. Access goes away when the job is done. This is the control people miss on a personal Dropbox link.

White-label experience

Clients land on a portal that presents as your organisation. Useful when MSPs and enterprises white-label services for regulated customers.

Identity-aware access

Workforce federation plus guest passkey or TOTP, so invitations are deliberate. Step-up on mutating admin calls.

Workspaces (deal rooms)

Multi-party folder browse with revision history. Internals and externals contribute. Each replace is a new revision and a re-scan.

Audit and SIEM

Hash-chained trails, CSV, Sentinel, Splunk HEC, webhook, Pub/Sub, and replay. Designed for diligence, not anecdote.

Malware quarantine

MetaDefender default, optional customer webhook, or Defender Event Grid ingest so scan verdicts stay in your tenancy path.

Audit

Evidence for the conversation that matters

When cyber insurance, procurement, or a client security questionnaire asks how files move, you answer with a governed portal, customer-owned storage, and retained access history, not a forward chain from last Tuesday.

Compliance reviewer examining governance documents with laptop

Compare

Bridge vs a Dropbox link vs an MFT suite

Pick the tool for the job. Bridge is the branded file send: your storage, your identity, links that expire. Keep a classic MFT tool if you still need SFTP or AS2.

NeedConsumer syncFull MFT suiteBridge
Client sees your brand Generic product brand Often vendor-brandedFit White-label portal
File bytes at rest Vendor or mixed custody Usually central MFT storeFit Your Blob, GCS, or S3
Everyday team collaborationFit Designed for this Overkill for chatty syncFit Governed deal rooms
Audit for vendor review Limited / product-shapedFit Deep protocol + opsFit Transfer + SIEM trails
SFTP / AS2 / heavy protocols Usually noFit Core offering Keep on your MFT if you run it

Many programmes run Bridge for branded sharing and keep a classic MFT tool for protocols. Deep dives: GoAnywhere, MOVEit, and Kiteworks.

Built for

Security, operations, and client-facing teams

One product story that each function can take into their own conversation. Use the client paths when the buying centre is a named industry motion.

Security and compliance

Custody diagram plus SIEM export. Files in your cloud. Identity in your IdP. Audit your security team can take into a vendor review.

Operations / MSP delivery

White-label handoffs for clients who expect your brand, without inventing a new consumer sync habit for every engagement.

Procurement and owners

If your team still sends Dropbox or OneDrive links to clients, this is the version you can defend. Security still gets BYOS and SIEM. The board gets a sentence they understand.

Trust

What you get with Bridge

A branded portal, files in your cloud, identity in your IdP, and audit your security team can export. Company procurement materials live on the trust hub.

In the product

  • White-label share, file-request, and workspaces
  • BYOS mint-only to customer Azure Blob, GCS, or S3-compatible storage
  • Entra, Google Workspace, and SAML workforce identity; guest passkey / TOTP
  • Expiry, max downloads, revoke, watermark / view-only
  • Malware quarantine: MetaDefender default, customer webhook, or Defender Event Grid ingest
  • Local DLP gates
  • Hash-chained audit, CSV, and SIEM (Sentinel, Splunk HEC, webhook, Pub/Sub) including replay
  • Multi-tenant, SCIM, retention, and legal hold
  • US / AU / EU metadata cells behind the bridge.trustholm.com login hub

What you can show

  • Files at rest in the storage account you already operate
  • Staff identity in the IdP you already enforce
  • Guest access with MFA you invite and revoke
  • Hash-chained audit in the SIEM your SOC already staffs
  • A named US, AU, or EU metadata cell for control-plane residency
  • White-label hostname and theme on the portal partners see
  • Shared-responsibility table for architecture review

Engagements

Start with a scoped Bridge pilot

Request access with Bridge selected. We route storage, identity, branding, and audit bar before you invite production guests.

Bridge evaluation

Conversation · custody + brand + audit

  • Capture white-label and domain expectations
  • Name Blob, GCS, or S3 and IdP tenants
  • Map security questionnaire themes and SIEM destination
  • Decide pilot versus broader rollout

White-label pilot

Fixed-scope pilot · one service motion

  • Stand up branded portal for a named use case
  • Staff federation and guest MFA pattern
  • Sample diligence walkthrough including quarantine
  • Go / no-go before wider invite lists

Rollout support

After pilot · ops and security ready

  • Expand to additional client motions
  • Harden retention, legal hold, and export paths
  • Align runbooks with your service desk
  • Expand runbooks with your service desk

Part of the Trustholm house

Bridge handles governed file handoffs. Govern proves signed script evidence beside an RMM. ShareSight maps Microsoft 365 access. Migrate moves TRIM / Content Manager into SharePoint. Same trust surface on www. Each product app hosts its own sign-in.

Ready to send the next file from storage you own?

Request Bridge access and we will scope storage, identity, branding, and audit. Or open the Bridge app when you already have credentials.

Frequently asked questions

What job does Bridge cover?

Send files to clients, suppliers, and the public from a branded page. Set the link to expire. You own the storage and the identity. For technical buyers this is white-label secure file transfer with share, file-request, and workspaces. Many programmes also keep a classic MFT tool for SFTP or AS2.

Where do the files actually live?

In your Azure Blob, Google Cloud Storage, or S3-compatible bucket. Trustholm mints short-lived access and stores workflow metadata plus audit.

Does the file auto-delete?

You can expire the share, cap downloads, or revoke access. The link then stops working. File bytes stay in the Azure Blob, GCS, or S3 you connect until your own retention rules delete them.

How is this different from Dropbox or OneDrive?

People already know how to send a Dropbox or OneDrive link. Bridge is that same job: send a file out, with expiry, your brand, and storage plus identity you own. Those tools are built for everyday sync inside a team. Bridge is not a sync client or a mapped drive.

What sharing motions does Bridge take from GoAnywhere or MOVEit?

Branded HTTPS sharing, file-request, and workspaces with files in your cloud. Read the compare pages for the side-by-side.

Do you have an Outlook or Teams add-in?

Staff send and receive from the branded portal today. Outlook and Teams Send via Bridge is available as Preview for allowlisted tenants. File bytes still upload client-side to your storage. Ask on the access form.

Can our customers use our brand?

Yes. White-label presentation, including hostname and theme, is part of the offer so partners and clients experience your organisation.

Will our security team get usable audit?

Yes. Hash-chained access and admin events support diligence workflows, with CSV and SIEM export. Details are confirmed during onboarding.

Can metadata stay in AU or EU?

Yes. The login hub is bridge.trustholm.com. Product cells run at us, au, and eu.bridge.trustholm.com for metadata residency. File bytes still stay in the storage you connect.

Was this formerly called Secure Exchange?

Yes. We renamed to Bridge so the product is not confused with Microsoft Exchange. The offer is white-label secure file transfer with BYOS and audit.

Where do company trust materials live?

On the Trustholm trust hub (www). Product apps host sign-in; procurement and security questionnaires start from published trust pages.

How do we evaluate?

Request Bridge access from the access form with Bridge selected. We scope a pilot that matches your storage, identity, branding, and audit expectations.