For government

Government secure file transferwith files in your tenancy

Give agencies and suppliers a branded portal for sensitive packs. Identity stays in your IdP. Files stay in storage you already assess. Audit streams to the SIEM you already operate.

Agencies and suppliers exchange sensitive packs on a branded portal. Object storage and identity stay in the tenancy you already assess. Trustholm mints access and keeps the audit trail your security team can export.

Files in your cloud · Identity in your IdP · Audit in your SIEM

A portal the architecture board can sign

Public sector programmes already know that email is not a transfer system. Suppliers, other agencies, and professional advisors still need a place to send and collect sensitive packs.

Bridge is that portal. Files stay in agency or designated object storage. Staff sign in with Entra or SAML. Guests prove identity before they upload or download. Every access can land in the SIEM your SOC already staffs.

The assessor question is where bytes live at rest, and who opened them. You answer with storage you already operate and an exportable audit trail.

Modern office workspace representing public sector IT programs

Controls you already own

You own the storage account and encryption keys. You own IdP policy, guest lifecycle, and SIEM monitoring. Trustholm owns the Worker control plane, minting, workflow UI, and hash-chained audit metadata.

Australian Government programmes can name the AU metadata cell (au.bridge.trustholm.com) in the pack. File bytes still follow BYOS into the subscription your architecture board accepts.

US and UK programmes use the same architecture with US or EU cells. Classification stays with the agency. Bridge supplies the custody diagram, identity story, and audit export your assessor can inspect.

You can keep malware scanning on a customer engine or Defender Event Grid ingest. Scan verdicts then stay on a path you already operate. Local DLP covers extension, MIME, and regex gates.

Identity for staff and suppliers

Staff use Entra or SAML, which is how most agencies already work. Guests (suppliers, counsel, other jurisdictions) use work login when they have it, otherwise a one-time email code to the invited mailbox, then passkey or TOTP when you require MFA. Step-up can be required on admin changes.

You decide who is invited and when shares expire. Suppliers do not need an agency account to return a pack.

What belongs in the architecture pack

Put the job in the pack: branded partner exchange with files in storage you already operate.

Name the controls you can demonstrate:

  • BYOS mint to Azure Blob, GCS, or S3
  • Entra or SAML for staff, plus guest work login, email one-time code, and optional passkey / TOTP
  • Expiry, revoke, watermark, then erase from your bucket unless legal hold is on
  • Information markings (AU PSPF, HIPAA PHI, US CUI labels; not a certification)
  • Workspaces with revision history
  • Malware quarantine, including a Defender Event Grid path
  • Hash-chained audit to Sentinel, Splunk, webhook, or Pub/Sub
  • White-label, SCIM, retention, and legal hold
  • US, AU, and EU metadata cells

Link assessors to how it works and the company trust hub for architecture and subprocessors.

Agency outcomes

A portal story that survives architecture review, not only the demo.

Bytes stay in storage you operate

Azure Blob, GCS, or S3 you already have a pattern for. Trustholm does not become a second records store.

Metadata cell you can name

AU cell for AU control-plane residency. US and EU cells for other programmes. File bytes still follow BYOS.

Audit in the SIEM you staff

Sentinel is the common agency path. Splunk, webhook, and Pub/Sub stream the same hash-chained events.

A portal suppliers will finish

Branded file-request and share, with expiry and revoke you control. Guests prove identity before they touch the pack.

What you take to architecture review

In the product

  • BYOS to Azure Blob, GCS, or S3 with minted SAS / V4 / SigV4 URLs
  • Entra or SAML staff identity; guest work login, email one-time code, then passkey / TOTP when you require MFA
  • Malware quarantine, Defender Event Grid ingest, and local DLP gates
  • Hash-chained audit plus SIEM replay
  • White-label, SCIM, retention, legal hold
  • Workspaces (deal rooms) with revision history
  • AU / US / EU metadata cells

In the assessor pack

  • Files at rest in the storage account your architecture board already accepts
  • Staff identity in Entra or SAML you already operate
  • Guest access with MFA you invite and revoke
  • Hash-chained audit in the SIEM your SOC already staffs
  • A named AU, US, or EU metadata cell for control-plane residency
  • Shared-responsibility table: you own storage, keys, IdP, and monitoring
  • Custody diagram your assessor can inspect without a vendor file warehouse

Ready to brief architecture and security together?

Request Bridge access for a named programme. We will walk storage, identity, scan path, and SIEM export with the people who sign the shared-responsibility table.

Frequently asked questions

How does Bridge fit an agency assessment?

Files stay in storage you already assess. The AU, US, or EU cell names control-plane residency. We supply architecture and shared-responsibility material for your assessor. Classification and authorisation stay with the agency.

Can files stay in a government subscription?

Yes. That is the point of BYOS. Connect Blob, GCS, or S3 in the subscription your architecture board already accepts.

Do you support SAML for agency IdPs beyond Entra?

SAML 2.0 is a shipped workforce adapter. Confirm attribute mapping and signing during onboarding.

How do classification decisions work?

You can require AU PSPF, HIPAA PHI, or US CUI markings on shares, file-requests, and workspaces. Banners show on the app, claim page, viewer, and email. Markings are labels. Classification and authorisation stay with the agency. This is not a HIPAA, IRAP, or CUI certification.

Can suppliers use the portal without agency accounts?

Guest access is designed for that. They use work login, a one-time email code, or passkey / TOTP when you require MFA. You still decide who is invited and when shares expire.

How do we start a pilot?

Request Bridge access, name the agency programme, and bring storage, IdP, SIEM, and branding contacts.