Bytes stay in storage you operate
Azure Blob, GCS, or S3 you already have a pattern for. Trustholm does not become a second records store.
For government
Give agencies and suppliers a branded portal for sensitive packs. Identity stays in your IdP. Files stay in storage you already assess. Audit streams to the SIEM you already operate.
Agencies and suppliers exchange sensitive packs on a branded portal. Object storage and identity stay in the tenancy you already assess. Trustholm mints access and keeps the audit trail your security team can export.
Files in your cloud · Identity in your IdP · Audit in your SIEM
Public sector programmes already know that email is not a transfer system. Suppliers, other agencies, and professional advisors still need a place to send and collect sensitive packs.
Bridge is that portal. Files stay in agency or designated object storage. Staff sign in with Entra or SAML. Guests prove identity before they upload or download. Every access can land in the SIEM your SOC already staffs.
The assessor question is where bytes live at rest, and who opened them. You answer with storage you already operate and an exportable audit trail.

You own the storage account and encryption keys. You own IdP policy, guest lifecycle, and SIEM monitoring. Trustholm owns the Worker control plane, minting, workflow UI, and hash-chained audit metadata.
Australian Government programmes can name the AU metadata cell (au.bridge.trustholm.com) in the pack. File bytes still follow BYOS into the subscription your architecture board accepts.
US and UK programmes use the same architecture with US or EU cells. Classification stays with the agency. Bridge supplies the custody diagram, identity story, and audit export your assessor can inspect.
You can keep malware scanning on a customer engine or Defender Event Grid ingest. Scan verdicts then stay on a path you already operate. Local DLP covers extension, MIME, and regex gates.
Staff use Entra or SAML, which is how most agencies already work. Guests (suppliers, counsel, other jurisdictions) use work login when they have it, otherwise a one-time email code to the invited mailbox, then passkey or TOTP when you require MFA. Step-up can be required on admin changes.
You decide who is invited and when shares expire. Suppliers do not need an agency account to return a pack.
Put the job in the pack: branded partner exchange with files in storage you already operate.
Name the controls you can demonstrate:
Link assessors to how it works and the company trust hub for architecture and subprocessors.
A portal story that survives architecture review, not only the demo.
Azure Blob, GCS, or S3 you already have a pattern for. Trustholm does not become a second records store.
AU cell for AU control-plane residency. US and EU cells for other programmes. File bytes still follow BYOS.
Sentinel is the common agency path. Splunk, webhook, and Pub/Sub stream the same hash-chained events.
Branded file-request and share, with expiry and revoke you control. Guests prove identity before they touch the pack.
Request Bridge access for a named programme. We will walk storage, identity, scan path, and SIEM export with the people who sign the shared-responsibility table.
Files stay in storage you already assess. The AU, US, or EU cell names control-plane residency. We supply architecture and shared-responsibility material for your assessor. Classification and authorisation stay with the agency.
Yes. That is the point of BYOS. Connect Blob, GCS, or S3 in the subscription your architecture board already accepts.
SAML 2.0 is a shipped workforce adapter. Confirm attribute mapping and signing during onboarding.
You can require AU PSPF, HIPAA PHI, or US CUI markings on shares, file-requests, and workspaces. Banners show on the app, claim page, viewer, and email. Markings are labels. Classification and authorisation stay with the agency. This is not a HIPAA, IRAP, or CUI certification.
Guest access is designed for that. They use work login, a one-time email code, or passkey / TOTP when you require MFA. You still decide who is invited and when shares expire.
Request Bridge access, name the agency programme, and bring storage, IdP, SIEM, and branding contacts.