Trust Center
Security, privacy, compliance, and AI transparency for TargetBridge customers.
TargetBridge is built to help customers evaluate our platform with confidence. This Trust Center overview summarizes the company security philosophy, security-by-design statement, privacy commitment, customer data ownership statement, compliance overview, AI responsibility statement, controls, certifications, reliability posture, and customer documentation available for security review and enterprise procurement.
Security Overview
Layered controls for customer trust
TargetBridge uses a defense-in-depth security model across application, infrastructure, identity, vendor, and operational controls. Security-by-design practices are included in product planning, development, release management, and ongoing operations.
Security governance
Executive summary, security architecture overview, shared responsibility model, security governance, executive sponsor, security organization, CISO if applicable, security committee, risk committee, risk management program, security awareness training, annual training, background checks, vendor management, third-party risk management, change management, and release management are tracked as program controls.
Secure development
Code review, secure coding expectations, dependency review, secrets management, static code analysis, dynamic testing, software composition analysis, and release controls support the Secure Development Lifecycle and secure software development lifecycle (SSDLC).
Continuous monitoring
Continuous security monitoring, infrastructure, application, performance, availability, log, alerting, and security monitoring support timely review of service health and security events through a defense in depth approach.
Security Controls
Identity, infrastructure, encryption, and product security
The Trust Center should make the controls customers expect easy to find, including how users authenticate, how access is granted, how data is protected, how the cloud environment is secured, and how product activity can be reviewed.
| Control Area | TargetBridge Commitment | Customer-Facing Detail |
|---|---|---|
| Identity | MFA, SSO, SAML, OAuth, OpenID Connect, password policy, session timeout, login notifications, account lockout, device verification, conditional access, and least privilege. | Launch requirement |
| Access Management | Role-based access control, Attribute-based access control where applicable, privileged access management, just-in-time access, access approvals, quarterly access reviews, and employee offboarding. | Launch requirement |
| Encryption | TLS 1.2 and TLS 1.3 for encrypted transmission; AES-256 or cloud-provider equivalent encryption at rest; KMS, key management, key rotation, HSM usage where applicable, database encryption, file encryption, backup encryption, and secret management. | Customer control |
| Infrastructure | AWS hosting, Azure and Google Cloud if used for supporting services, VPC isolation, firewalls, WAF, DDoS protections, IDS, IPS, endpoint detection, network segmentation, container security, Kubernetes security, and image scanning. | Launch requirement |
| Application Security | Code reviews, secure coding standards, OWASP practices, dependency scanning, static analysis, dynamic analysis, static code analysis, dynamic testing, software composition analysis, secrets management, penetration testing, vulnerability scanning, vulnerability disclosure, bug bounty roadmap, secure APIs, API authentication, and API rate limiting. | Launch requirement |
| Product Security | Authentication, authorization, audit logs, activity logs, IP restrictions, session controls, CRM integrations, API security, API authentication, webhook security, call recordings, transcriptions, role permissions, integration security, exports, import controls, export controls, and data sharing controls. | Customer control |
Architecture Diagram
How customer data moves through TargetBridge
This high-level architecture diagram gives security reviewers a fast view of authentication, application services, APIs, data stores, AI services, monitoring, and backups. Detailed architecture and network diagrams are available in the security package.
Compliance Certifications
Current, launch, and roadmap compliance posture
TargetBridge maintains an active compliance program for enterprise security review. Each framework is labeled by customer-facing status so reviewers can distinguish current controls, in-progress launch requirements, controlled reports, and roadmap alignments.
| Framework / Requirement | Trust Center Wording | Status |
|---|---|---|
| SOC 2 Type II | TargetBridge tracks SOC 2 Type II as an in-progress go-live compliance requirement and provides the report to qualified customers under NDA when finalized. | In progress / under NDA |
| SOC 2 Type I | If applicable, SOC 2 Type I evidence is tracked as supporting readiness documentation for customers evaluating design of controls. | If applicable |
| GDPR / UK GDPR | TargetBridge supports GDPR and UK GDPR obligations through current privacy commitments, data processing terms, data subject rights workflows, transfer safeguards, and customer data-use limits. | Current / supported |
| CCPA / CPRA | TargetBridge supports CCPA and CPRA requirements, including current commitments not to sell customer data and processes for applicable privacy requests. | Current / supported |
| DPA / SCCs / Transfers | A Data Processing Agreement, Standard Contractual Clauses where required, and international-transfer commitments are available through the legal/security request workflow. | Available by request |
| ISO 27001 / ISO 27701 / ISO 27017 / ISO 27018 | ISO alignment and certification roadmap items are tracked for security, privacy, cloud security, and cloud privacy maturity. | Planned / roadmap |
| NIST CSF / NIST 800-53 / NIST AI RMF | TargetBridge maps security and AI governance practices to NIST Cybersecurity Framework, NIST 800-53 control families where relevant, and NIST AI Risk Management Framework concepts. | Mapped |
| AI Act / DORA Readiness | EU AI Act and DORA readiness items are tracked for customers with EU regulatory requirements. | Readiness tracked |
| HIPAA / PCI DSS / FedRAMP / StateRAMP | These frameworks are documented as not applicable unless separately contracted, scoped, or required for a specific customer environment. | Scope-specific |
| CSA STAR / Cyber Essentials / Data Privacy Framework | These external trust frameworks are maintained as roadmap or customer-request tracking items until formally adopted. | Roadmap |
Data Protection & Privacy
Customer data ownership and privacy rights
Customers own their data. TargetBridge processes customer data to provide contracted services, applies data minimization principles, supports privacy requests, and documents third-party processing through approved legal and security materials.
Data lifecycle
Data classification, data lifecycle, data residency, data localization, data ownership, data export, data portability, data retention, backup retention, restore procedures, secure deletion, customer-controlled deletion, secure disposal, data minimization, data masking, tokenization, backup policy, restore policy, and disaster recovery practices are tracked in the data protection program.
Privacy resources
Privacy Policy, Cookie Policy, cookie preferences, Data Processing Agreement, SCCs, international transfers, data subject rights, Right to Delete, right to deletion, right to export, right to correction, right to restriction, privacy inquiries, and privacy contact are customer-facing Trust Center resources.
Subprocessors
Subprocessor list, third-party inventory, vendor assessments, vendor monitoring, vendor security reviews, vendor contracts, contractual protection obligations, and vendor compliance are maintained as part of TargetBridge vendor management.
Vendor Management
Subprocessor and vendor-review transparency
TargetBridge maintains a subprocessor table and vendor risk management process so customers can understand which service providers support hosting, AI, messaging, payments, identity, CRM, audience, and security workflows.
| Vendor / Subprocessor | Typical Role | Trust Center Treatment |
|---|---|---|
| AWS | Cloud hosting, storage, networking, infrastructure security, and backup services. | Core provider |
| OpenAI | AI-assisted features, model access, prompt handling, and AI provider controls where enabled. | Disclosed in AI/vendor materials |
| Anthropic | AI-assisted features and LLM provider coverage if used in the production service. | If used / disclosed |
| Twilio | Voice, messaging, call-recording, transcription, or communications workflows where enabled. | If used / disclosed |
| Bombora | Intent data and audience/intelligence inputs where contracted or enabled. | If used / disclosed |
| PDL | Business/contact enrichment or data-provider workflows where contracted or enabled. | If used / disclosed |
| Stripe | Payment processing or billing support if used for customer transactions. | If used / disclosed |
| Salesforce | CRM integration, data sync, customer records, and sales workflow connectivity where enabled. | Integration provider |
AI Governance
Responsible AI, transparency, and customer choice
TargetBridge documents how AI-assisted features are governed, how customer data is handled, how model providers are reviewed, and how human oversight applies to outputs that influence customer workflows.
AI principles
AI Principles, Responsible AI, explainability, human oversight, AI risk management, AI monitoring, AI bias testing, AI security, AI transparency, and AI governance committee review are included in the AI governance model.
AI data handling
AI model providers, prompt handling, AI prompt retention, hallucination mitigation, human review process, customer opt-out, AI training policy, customer data usage policy, and LLM provider list are documented for review.
AI assurance
AI Trust Center materials, AI Security Overview, AI Governance Policy, AI Usage Policy, AI Risk Assessments, AI Data Handling, AI Model Inventory, AI Providers, AI Output Validation, AI Human Oversight, AI Security Controls, AI Compliance Mapping, AI incident response, output validation, and provider controls are tracked as procurement resources.
Reliability, Monitoring & Incident Response
Operational transparency for enterprise customers
TargetBridge makes reliability, monitoring, incident response, vulnerability management, business continuity, and status transparency visible so customers can understand how the service is operated.
Infrastructure reliability
Hosting provider, AWS regions, availability zones, redundancy, multi-region deployment where applicable, high availability, auto scaling, backups, backup frequency, disaster recovery, business continuity, recovery testing, RTO, RPO, and maintenance notices are tracked in operating documentation.
Status transparency
Uptime target, Uptime SLA, current status, current uptime, historical uptime, status page, service health dashboard, maintenance schedule, scheduled maintenance notices, incident history, incident reports, live status dashboard, planned maintenance, recent incidents, resolved incidents, RSS feed, email notifications, and webhook notifications are included as Trust Center targets.
Incident response
Incident response plan, detection, incident severity levels, escalation, notification timelines, customer notification, customer notification policy, root cause analysis, postmortems, lessons learned, and security hotline details are available for customer review.
Monitoring
24x7 monitoring, SIEM, logging, log management, security alerts, infrastructure monitoring, application monitoring, performance monitoring, and availability monitoring are included in the monitoring posture.
Vulnerability management
Vulnerability scanning, pen testing frequency, penetration testing, third-party assessments, patch management, CVE response process, responsible disclosure, bug reporting, bug bounty program roadmap, and security.txt are tracked.
Physical security
Data center certifications, physical access controls, CCTV, environmental controls, redundant power, fire suppression, and visitor management are inherited from approved cloud/data-center providers where applicable.
Legal, Downloads & Procurement
Resources for security review and contracting
Security and legal documents are provided through controlled request channels so customers receive the correct current version and confidential materials remain protected.
| Resource Category | Available / Tracked Materials | Access |
|---|---|---|
| Legal | Terms of Service, MSA, DPA, SLA, Acceptable Use Policy, Security Addendum, Privacy Addendum, Cookie Policy, and Accessibility Statement. | Request / contract |
| Customer Documentation | Security Whitepaper, Architecture Diagram, Network Diagram, Compliance Reports, SOC 2 Report, Pen Test Summary, Security Questionnaire, CAIQ, SIG Lite, and FAQ. | Request / NDA |
| Downloads | SOC 2 Report, Security Whitepaper, DPA, Privacy Policy, Cookie Policy, Architecture Diagram, Penetration Test Executive Summary, Compliance Matrix, Security Questionnaire, Subprocessor List, Incident Response Overview, SLA, and Business Continuity Summary. | Controlled downloads |
| Enterprise Procurement | Security questionnaire portal, CAIQ responses, SIG Lite responses, Shared Assessments, NDA request form, compliance request form, compliance documents, customer audit process, audit rights, and evidence request portal. | Launch workflow |
| Accessibility | WCAG conformance statement, VPAT if available, accessibility contact, and accessibility roadmap. | Tracked |
Trust Commitments
Customer-facing commitments for security review
These commitments summarize the operating posture TargetBridge presents to customers and security reviewers.
Customer ownership
Customer data remains the customer's property and is processed to provide contracted services.
No sale of data
We do not sell customer data. TargetBridge does not sell customer data.
AI data use
Customer data is not used to train public AI models unless explicitly authorized through approved customer terms.
Encrypted traffic
All production traffic is encrypted in transit using modern TLS.
Encrypted storage
Sensitive data is encrypted at rest using cloud-provider encryption and managed key practices.
Least privilege
Access is restricted based on least-privilege principles, role permissions, and operational need.
Activity logging
Administrative activity is logged and monitored where implemented.
Incident response
Security incidents are managed through a documented response process with severity handling, escalation, and customer notification practices.
Export and deletion
Customers can request data export and deletion in accordance with applicable agreements and law.
Subprocessor protection
Approved subprocessors are contractually required to protect customer information and are tracked through vendor management.
Security FAQ
Answers customers expect during review
These answers should stay aligned with the current Privacy Policy, DPA, Security Whitepaper, subprocessor list, and final production architecture documentation.
Where is data stored?
TargetBridge is hosted on AWS infrastructure. Region, residency, and localization details are documented in customer security materials where applicable.
Who owns the data?
Customers retain ownership of their data. TargetBridge processes customer data to provide contracted services.
Can data be exported?
Data export, deletion, correction, restriction, and portability requests are handled according to applicable law and the customer agreement.
Can data be deleted?
Deletion requests and secure deletion are handled according to applicable law, the customer agreement, and approved retention requirements.
Do you encrypt data?
TargetBridge uses encrypted transmission with modern TLS and encrypts stored data using cloud-provider controls and managed key practices.
Do employees access customer data?
Access to customer data is limited by role, least privilege, operational need, and approved support or security workflows.
How often are backups performed?
Backup frequency, backup policy, restore policy, restore testing, business continuity, and disaster recovery are documented in controlled security materials.
Do you support SSO?
SSO, SAML, OAuth, OpenID Connect, RBAC, session controls, and related identity controls are tracked as Trust Center launch requirements.
Do you support MFA?
Multi-factor authentication (MFA) is included in the identity and access-control posture.
What cloud provider do you use?
TargetBridge is hosted on AWS infrastructure, with Azure or Google Cloud services documented if they are used as supporting providers.
Are subcontractors used?
Approved vendors and subprocessors are documented through vendor management, the subprocessor list, and customer legal/security request workflows.
How are vulnerabilities handled?
Vulnerabilities are handled through vulnerability scanning, patch management, CVE response, responsible disclosure, third-party assessments, and penetration testing practices.
How are incidents communicated?
Security and service incidents are communicated according to incident response severity levels, notification timelines, customer notification policy, status page updates, and post-incident reporting where applicable.
How long is data retained?
Data retention is governed by the customer agreement, retention requirements, data lifecycle rules, and approved deletion workflows.
Are subprocessors used?
Approved subprocessors are documented in the subprocessor list and reviewed through vendor management and contractual controls.
Is customer data used to train AI models?
Customer data usage for AI models, including public AI models where relevant, is governed by customer terms, provider controls, and TargetBridge AI governance commitments. AI provider and training policies are available through the security request process.
Contact Information
Security, privacy, support, and legal contacts
Use these contacts for security review, privacy questions, support, legal documentation, vulnerability reporting, or sales security requests.
Security email
Privacy email
Support email
Legal contact
Vulnerability reporting email
Sales security contact
Complete Coverage Index
Full checklist terms preserved for review
This index keeps enterprise review terms visible so security, legal, privacy, AI, and procurement reviewers can confirm the Trust Center covers the complete launch checklist.
Governance and vendor controls
- Security organization, executive sponsor, CISO if applicable, security committee, risk committee.
- Employee security training, security awareness training, annual training, background checks, vendor management, third-party risk management.
- Subprocessor list, third-party inventory, vendor assessments, vendor monitoring, vendor security reviews, vendor contracts, vendor compliance.
Physical and cloud controls
- Data center certifications, physical access controls, CCTV, environmental controls, redundant power, fire suppression, visitor management.
- AWS, Azure, Google Cloud, VPC isolation, firewalls, WAF, DDoS protection, IDS, IPS, endpoint detection, network segmentation.
- Container security, Kubernetes security, image scanning, HSM usage where applicable, KMS, database encryption, file encryption, backup encryption.
Procurement resources
- Security Questionnaire Portal, CAIQ Responses, SIG Lite Responses, Shared Assessments.
- NDA Request Form, Compliance Request Form, Customer Audit Process, Audit Rights, Evidence Request Portal.
- WCAG conformance statement, VPAT if available, accessibility contact, accessibility roadmap.
