Security and data
Where your data goes, and where it does not.
One gateway handles every model call. Brands and organizations are kept apart in code, not by a prompt. Runs land in a ledger with their exact cost. What we haven’t built yet is listed at the bottom.
One gatewayevery model call, no exceptions
Scope in codeorganization, brand, user
Five rolesfrom super admin to viewer
One ledgerwho, what, when, which model, cost
Checked against the codeAugust 23, 2026
One gateway. No exceptions.
A module that needs a model sends its call to one gateway, which forwards it to the provider your admin picked for that module.
The five providers a prompt can reach today are on the drawing. Check them against your approved-vendor list, and the changelog records when the list changes.
Click a module to send a call
Pick a provider on the right, then click a module.
No code path talks to a provider directly. One key, held on the server, never shipped to a browser.
Your choice
You decide which model each module uses.
The choice is made per module, per organization, by your admin. A model we stop supporting falls back to the default.
No training
Your prompts aren’t used to train anything.
Calls go to the providers on their API terms, which exclude training on API traffic. We keep the ledger line, not the transcript.
Walls enforced in code.
There’s no prompt asking the model to behave. A filter runs before any query does.
Your company is an organization holding brands. Pick a brand on the right and read what every query for it carries.
Brand A context and documentsbrand
Brand A drafts and findingsbrand
Brand B context and documentsbrand
Brand B drafts and findingsbrand
People, settings, ledger, walletorganization
Brand C context and documentsbrand
Brand C drafts and findingsbrand
People, settings, ledger, walletorganization
every query carries
No line between the two. Not a thin one.

What the wall stops
A brand can’t read another brand: the filter is applied before the model sees a result. An organization can’t see another organization either, and the database is reached only from our server, with a key that never leaves it. Pause an organization and every sign-in is refused. There’s no half-paused state.
Five roles. One gate.
Every user carries a role, a list of what they can do, not a pricing tier. A user on one brand’s Marketing sees nothing of another brand’s Sales. The detail is on the architecture and on Larger teams.
Under the roles sits a single gate that makes four checks on the server, in the order below. Fail one and the request is refused.
ViewerReads on their own credentials and their own budget. Can’t change anything. The role for a board member or a client.
EditorDrafts and runs the work inside the brands they’re granted. Can’t publish and can’t change settings.
Brand managerRuns one or several brands. Approves, publishes, and shapes the context of the brands they own.
AdminRuns the organization: people, brands, model choice, budgets, the wallet. Sees the ledger for the whole organization.
Super adminBearingBridge staff who operate the platform across organizations. Raw model cost and the interface dictionaries are visible at this level only.

A valid session, checked on the server before anything runssession
The organization has switched the module onmodule
The user has been granted it, and a viewer is refused anything that writesgrant
The brand on the request is one the user holdsbrand
If the database can’t be reached while a permission is being resolved, the answer is no. It never fails open.
If you’re skimming for the assistant, the next section is the one.
The assistant reads. It does not write.
Ask Intelligence answers from a fixed set of read-only tools, each one limited to the brand you asked about. Nothing gets written, and nothing comes in from outside.
The loop is bounded: a fixed number of steps, a fixed size for what each tool may hand back. When the base doesn’t contain an answer, the assistant says so rather than inventing one.
Steps, capped at six
What each tool may hand back

One box. The one you labelled.
Curated, not crawled
The base the assistant reads is the one you curate, and an admin approves what goes in. A guideline can shape the tone of an answer, not where it comes from.
Every run, on the record.
Every model call is written to the ledger before its cost is charged to your wallet: who asked, in which brand, which model answered, the tokens, the cost, the time. An admin sees the whole ledger; users see their own lines.
Three caps are checked before a call goes out: the prepaid balance, the user’s daily cap, and the organization’s monthly cap. The full picture is on Cost and control.
Prepaid balance$126.40 / $250.00
The wallet. Funded in dollars, never expires.
User daily cap$1.62 / $2.00
Set per person by the admin.
Organization monthly cap$318.90 / $600.00
Set once for the company.
| Who | Organization | Brand | Action | Model | Tokens in | Tokens out | Cost | When |
|---|---|---|---|---|---|---|---|---|
| L. Bernard | Your org | Brand A | Marketing · Draft | Anthropic | 1,204 | 412 | $0.0098 | 09:12:04 |
| S. Ito | Your org | Brand A | Sales · Brief | OpenAI | 2,310 | 655 | $0.0167 | 09:14:51 |
| R. Haddad | Your org | Brand B | Customer Service · Answer | Mistral | 640 | 188 | $0.0047 | 09:15:20 |
| M. Okafor | Your org | Brand B | Business Intelligence · Summary | DeepSeek | 3,980 | 902 | $0.0255 | 09:19:37 |
Click Run a call to add a line.

A ledger a controller would recognize.
Agents are on the record too
Every agent run is stored with its status, its result, and any error, and every finding is attributed to the agent that produced it.
Sign-in, money, files, and the public assistant.
Signing in
http-only cookie · one day · single-use reset
The sign-in cookie is HTTP-only, same-site, secure, and expires after a day. A password or email change asks for the current password first. The reset link is single-use, rate-limited, and the response never reveals whether an address exists.
Money
stripe · signed webhook · recorded once
Payments run on Stripe. Your balance only ever increases from a signed webhook we verify, and every event is recorded once, so a retry can’t add the money twice.
Files
type and size checked · signed links
Uploads are checked for type and size. Logos and avatars are public; everything else is private, served through short-lived signed links.
Public assistant
curated only · hashed visitor · daily cap
It answers only from what you curated and says so when it can’t. Visitors are identified by a salted hash, and a daily cost cap switches it off before the bill becomes a problem.
Sign-in and reset emails come from bearingbridge.com. We send nothing to your users that you didn’t trigger.
The built part ends here. What follows isn’t built.
What is not done yet.
An evaluator who finds one of these out on their own will trust nothing else on this page.
Here they are, in contract language. When one changes, this board changes the same day and the changelog records it. Send a security questionnaire through the contact page; a person answers it, line by line.
Last checked against the code August 23, 2026
No SOC 2 and no ISO 27001 today. The audit starts when customers need the report, and then this line changes.
Data lives in a single region, and a choice of region isn’t offered yet. Ask, and we’ll name the region in the contract.
Sign-in is email and password. A second factor is on the roadmap and isn’t for sale until it ships.
No SAML and no enterprise identity provider. If your policy requires it, say so before you buy, not after.
The ledger records what the models did. A record of who took what data out of the product isn’t built, and the catalog says the same.
Six things you can check.
Bring this page to the person who has to sign.
Start with one module on one brand. Or ask the question this page didn’t answer, and get it in writing.
No subscription. No seat fee. Money in a wallet, spent on tokens, storage and data, and your balance never expires.




