Security
Last updated: June 6, 2026
Our Security-First Approach
Security is not an afterthought at Bridgeside — it is foundational to our architecture. From isolated sandbox environments to encrypted data transmission, every layer of our platform is designed with security in mind.
Isolation by Design
Every workflow runs in an isolated E2B sandbox with no shared kernel space. Sandboxes are ephemeral — created on demand and destroyed immediately after task completion. Your codebase never coexists with another tenant's data.
Zero Code Exfiltration
Our self-hosted runner architecture ensures that raw source code, diff patches, and repository contents never leave your network perimeter. Only aggregated metadata and log frames are transmitted to the control plane.
Data Protection
- Encryption at Rest: All persistent data is encrypted using AES-256.
- Encryption in Transit: All communications use TLS 1.2 or higher.
- Secrets Management: Workspace secrets are encrypted with AES-256-GCM and decrypted only at runtime within the sandbox.
- Key Rotation: Encryption keys are rotated on a regular schedule and after any security event.
Infrastructure Security
- Cloud Infrastructure: Built on AWS with SOC 2 Type II certified data centers.
- Network Segmentation: Strict VPC isolation between tenant environments.
- DDoS Protection: AWS Shield Standard protection against network-layer attacks.
- Intrusion Detection: Continuous monitoring and automated threat response.
- Backup and Recovery: Encrypted backups with tested recovery procedures.
Access Control
- Authentication: Auth0-managed authentication with support for SSO/SAML.
- Authorization: Role-based access control (RBAC) at organization and project levels.
- Audit Logging: Comprehensive audit trails for all administrative actions.
- Multi-Factor Authentication: Enforced for all administrative accounts.
Compliance
- SOC 2 Type II (in progress)
- GDPR compliant data processing
- Regular third-party penetration testing
- Vulnerability disclosure program
Vulnerability Disclosure
We welcome security researchers to report vulnerabilities. If you discover a security issue, please contact us at security@bridgeside.dev. We commit to:
- Acknowledging receipt within 48 hours
- Providing regular updates on remediation progress
- Not pursuing legal action against researchers acting in good faith
- Publicly crediting researchers who responsibly disclose issues (with their permission)
Security Certifications and Reports
Upon request, enterprise customers may receive our latest security questionnaire, penetration test summary, or SOC 2 report (where available). Contact your account representative or security@bridgeside.dev.
Contact
For security-related inquiries, contact security@bridgeside.dev. For general data protection questions, contact dpo@bridgeside.dev.