Storage
Azure Blob with user-delegation SAS, Google Cloud Storage V4, and S3-compatible SigV4, including optional custom endpoints.
Architecture
Control plane on Trustholm. Data plane in your tenancy. Signed upload and download URLs are minted. File bytes stay in your cloud.
Staff and guests use a branded portal. Trustholm stores workflow metadata and audit. Your object storage holds the files. Your IdP holds workforce identity. Optional scanners and SIEM stay in tools you already run.
BYOS mint-only · Blob, GCS, and S3 · White-label portal · SIEM audit
Your files stay in your cloud. Your identity stays in your IdP. We orchestrate.
That is the golden path for Trustholm Bridge. Every feature has to pass two tests. First, does this put customer file bytes, or full-content extracts, onto Trustholm infrastructure? If yes, it is redesigned. Second, does adding a new customer cloud require rewriting routes and onboarding? If yes, the cloud leaked out of the adapter.
The result is a white-label secure file exchange: share, file-request, and workspaces. Closest peer is Kiteworks. Files at rest stay in storage you already operate.

The control plane is a Cloudflare Worker with metadata in Neon. It holds workflow config, policy, audit metadata, UI, billing, and envelope-encrypted connector secrets for storage and IdP. That is credential custody, not file-byte custody.
The data plane is yours: Azure Blob with user-delegation SAS, Google Cloud Storage with V4 signed URLs, or S3-compatible storage with SigV4 (including optional custom endpoints such as MinIO). Browsers upload and download directly to that storage after the Worker mints a short-lived URL.
0. Guests prefer Microsoft or Google work login, then a one-time email code to the invited mailbox.
Passkey and TOTP cover guest MFA and staff step-up.
What may persist in the control plane: filename, size, content-type, object key, optional content hash, timestamps, actor, auth method, IP, user-agent, ACL, expiry, max downloads, classification label, scan verdict plus engine name, and hashed invite tokens. File bytes at rest stay in your object storage.
A staff user authenticates to the branded portal, creates a share, a file-request, or a workspace, sets expiry, max downloads, watermark or view-only where needed, and invites guests. Guests prove identity with work login when they have it, a one-time email code to the invited mailbox, or passkey / TOTP when you require MFA.
The Worker authorises the action, writes audit, and mints storage access. Every invite is a deliberate grant.
A workspace is a governed deal room. Internals and externals browse and contribute. Each replace is a new revision and a re-scan.
File-request accepts folder upload as well as files.
When a share, file-request, or workspace expires, the link stops working. Bridge then deletes the objects from your bucket after the delay you set. Legal hold on the tenant or the share skips that erase.
You can require information markings (AU PSPF, HIPAA PHI, or US CUI). Banners show on the app, claim page, viewer, and email. Markings are labels. They are not a certification.
Malware scanning can quarantine before promote. The default engine is platform MetaDefender. You can bring a customer webhook engine or Defender Event Grid ingest so scan verdicts stay on a path you already operate. Local DLP covers extension, MIME, and regex gates.
View-only uses a short-lived inline SAS after a one-shot view token. Watermark is a deterrent and an attribution aid.
Access, ACL changes, auth events, and admin actions are retained in a hash-chained audit log. You can export CSV and stream to Microsoft Sentinel, Splunk HEC, a signed webhook, or GCP Pub/Sub. SIEM replay is part of the product.
Metadata residency: the login hub is bridge.trustholm.com. Product cells run at us, au, and eu.bridge.trustholm.com. That is a control-plane residency choice you can name in an architecture pack.
This is the diligence conversation: who opened what, when, under whose authority. Retention and legal hold apply to shares. A hold skips erase after expiry.
Bridge is branded share, file-request, and workspaces with files in your cloud. Staff and guests use a portal that presents as your organisation. Browsers upload and download on short-lived signed URLs. You keep object storage, identity, and SIEM.
Read the overview for the conversion story, then pick a client path or a compare page if you are leaving a named tool.
Cloud-specific code belongs in adapters. Routes and onboarding speak capabilities: mint an upload URL, start IdP login, deliver an audit event, scan a quarantine object.
Azure Blob with user-delegation SAS, Google Cloud Storage V4, and S3-compatible SigV4, including optional custom endpoints.
Entra, Google Workspace, and SAML 2.0 for workforce. Guests use work login, a one-time email code, or passkey / TOTP when you require MFA.
Sentinel, Splunk HEC, webhook, and GCP Pub/Sub, including replay.
MetaDefender Cloud default, customer webhook, or Defender Event Grid ingest. Local DLP gates on extension, MIME, and regex.
Request Bridge access. We scope Blob, GCS, or S3, Entra or Google or SAML, brand, cell residency, and what good audit means before the first production guest.
In your Azure Blob, GCS, or S3-compatible bucket. Browsers talk to that storage with minted URLs. Trustholm keeps workflow metadata and audit.
Azure Blob, Google Cloud Storage, and S3-compatible object storage for files. Entra, Google Workspace, and SAML for identity.
Workforce identity stays in your IdP. Guests use Microsoft or Google work login, a one-time email code to the invited mailbox, or passkey / TOTP when you require MFA. Storage access is a short-lived signed URL. Call it mint-only BYOS with audit.
Yes. Bring a customer webhook engine or Defender Event Grid ingest off the MetaDefender default. Confirm during onboarding.
Yes. Customer hostnames CNAME to the Bridge customer apex. Staff and guests stay on that hostname. Theme and email identity are part of the white-label offer.
Yes, after the delay you set. The link stops first. Bridge then deletes the objects from your Blob, GCS, or S3. Default is the next daily job. Legal hold on the tenant or the share skips that erase.
Files stay in storage you already operate. AU, US, and EU cells name control-plane residency. Information markings (AU PSPF, HIPAA PHI, US CUI) are labels with banners. They are not a certification. We supply architecture and shared-responsibility material for your assessor. Classification stays with you.