Security Policy
Last updated: August 6, 2026
This Security Policy describes BridgeFlow's security principles for its website, communications, and AI implementation projects. It is written around controls BridgeFlow can apply across different Client-owned and Third-Party Provider environments. It does not claim a certification, audit, or security architecture that has not been documented.
This policy supplements the Privacy Policy, Terms of Service, and AI Usage and Responsible AI Policy. Project-specific security requirements control where the applicable written project documentation contains more detail.
Terminology
- BridgeFlow means the business operating under the BridgeFlow name until the formal legal entity is identified.
- Client means a person or business that requests or receives BridgeFlow Services.
- Services means BridgeFlow's AI implementation, productized AI, custom development, workflow automation, and related implementation services.
- AI Services means Services that use AI models, AI agents, voice AI, or AI-assisted workflows.
- Deliverables means client-specific outputs expressly identified in applicable project documentation.
- Third-Party Providers means external providers used by BridgeFlow or a Client for hosting, booking, payment, automation, AI, CRM, communication, storage, or other project functions.
1. Security principles
BridgeFlow's security approach is based on:
- Protecting client data and credentials.
- Using access only for an identified business purpose.
- Applying least privilege where the relevant system supports it.
- Separating client accounts and data where practical.
- Minimizing unnecessary collection and retention.
- Testing workflows before launch.
- Escalating unexpected behavior or suspected incidents.
- Keeping client ownership and administrative control clear.
Security requirements that are specific to a project should be recorded in the applicable proposal, quote, MSA, SOW, service agreement, or implementation plan, if used for the engagement.
2. Access control
BridgeFlow limits access to project systems and information to people who need it for an approved task. Access should be:
- Granted for a defined purpose.
- Limited to the necessary systems and permissions.
- Removed or changed when the task or engagement no longer requires it.
- Reviewed when project responsibilities or personnel change.
Clients are responsible for controlling their own accounts after credentials or administrative ownership are transferred to them.
3. Credential handling
Clients should provide credentials through an agreed secure method rather than through public channels or general contact forms. BridgeFlow should avoid storing credentials longer than necessary and should not include secrets in source code, documentation intended for publication, screenshots, or ordinary chat messages.
Where practical, BridgeFlow may use Client-owned accounts, delegated access, scoped API keys, service accounts, or temporary credentials. Clients should rotate credentials when access is no longer required or when a security concern arises.
4. Client-owned infrastructure
BridgeFlow may temporarily provision Third-Party Provider accounts during implementation. Whenever practical, ownership and administrative control are transferred to the Client.
The Client owns its data, accounts, and Client-specific assets. The Client is responsible for maintaining account recovery methods, billing, provider settings, user permissions, and ongoing security after transfer unless managed support is expressly included in writing.
5. Encryption and secure transmission
BridgeFlow expects sensitive information to be transmitted through secure channels and will use encryption capabilities provided by the selected hosting, storage, communication, automation, CRM, and AI providers where available and appropriate for the project.
The exact encryption configuration depends on the selected infrastructure and project scope. BridgeFlow does not represent that every third-party service has identical encryption, retention, or access-control features.
6. Least privilege and data minimization
BridgeFlow aims to request and use only the data and permissions needed for an agreed workflow. Projects should avoid unnecessary access to unrelated client systems or records.
Where a third-party platform does not support the desired level of granularity, the limitation should be discussed during project planning and reflected in the implementation approach.
7. Third-party services
AI implementations may use Third-Party Providers such as n8n, Zapier, hosting providers, CRMs, calendars, messaging services, payment processors, storage systems, databases, and AI model providers.
Third-Party Provider security depends on each provider's architecture, terms, controls, availability, and configuration. BridgeFlow will consider provider fit during implementation, but cannot control a provider's internal systems or guarantee uninterrupted Third-Party Provider service.
Clients should review Third-Party Provider terms and security requirements relevant to their industry and data.
8. Incident response
If BridgeFlow becomes aware of a suspected security incident affecting a client project, it will assess the available information and take reasonable steps appropriate to the situation, which may include:
- Restricting or suspending affected access.
- Preserving relevant information for investigation.
- Rotating or revoking credentials where appropriate.
- Working with the client and relevant provider.
- Communicating material information where required by the project or applicable law.
- Documenting corrective actions and follow-up steps.
The response process and notification timing may depend on the affected system, available evidence, provider involvement, contractual requirements, and applicable law.
9. Responsible disclosure
If you believe you have found a security issue affecting BridgeFlow's website or systems, please report it responsibly to support@bridgeflow.agency. Include enough information for BridgeFlow to reproduce or assess the issue, but do not access, alter, download, or disclose data that does not belong to you.
10. Security limitations
No website, AI system, integration, or third-party service can be guaranteed completely secure. Security risk may arise from client configuration, credentials, user behavior, provider outages, software defects, changes to models or integrations, or events outside BridgeFlow's reasonable control.
Security controls, testing, managed support, monitoring, and incident-response obligations beyond this general policy must be agreed in writing for the relevant project.
11. Contact
- Security reports: support@bridgeflow.agency
- General: hello@bridgeflow.agency
- Sales: sales@bridgeflow.agency
- Website: https://bridgeflow.agency
- Legal entity: [Legal Entity Name]
- Registered address: [Registered Address]