We delete nothing we haven’t verified.
Every control on this page exists because an IT director asked us a hard question first.
The six controls your security team will ask about.
Two-stage, least-privilege consent
Access is application-only Graph—no delegated user sign-in and no stored user credentials—and it comes in two stages. The scan app is read-only: Sites.Read.All, Files.Read.All, User.Read.All, Group.Read.All, Reports.Read.All and Organization.Read.All. The separate protection app adds Sites.ReadWrite.All and Files.ReadWrite.All, plus read-only User.Read.All, Group.Read.All, Team.ReadBasic.All, Channel.ReadBasic.All, Reports.Read.All and Organization.Read.All. Both registrations are visible in your Entra admin center, and consent is yours to revoke at any time.
SHA-256 before delete
Every captured file is copied, then re-hashed in object storage and compared to the source. A mismatch is recorded and the source stays untouched. Only the SharePoint archive workflow removes an original and writes a stub, and only after an exact match.
Encrypted end to end
All traffic to Microsoft Graph and to object storage runs over TLS 1.2 or higher, and data lands encrypted at rest in object storage — either the dedicated bucket we provision in the region selected during onboarding, or your own S3-compatible bucket under keys you control. Secrets are never written in the clear.
Optional compliance retention
Paid accounts using ArchiveBridge-managed, Object-Lock-capable storage can enable S3 Object Lock in compliance mode. The retention window is 1–90 days; 90 days is the cap. Retention longer than 90 days is not supported. While enabled for an object, the storage layer—not an ArchiveBridge policy—enforces the lock until its retention date.
Regional processing you choose
Choose Australia (Sydney), the United States (Virginia) or Southeast Asia (Thailand) during onboarding. File content is processed by the selected regional worker, and managed storage defaults to the nearest Wasabi region — Sydney, Virginia, or Singapore for Thailand processing, because Wasabi operates no Thai region. Bring your own bucket and it lives wherever you put it. The control plane and service metadata remain in Australia. Further processing regions are being added.
RBAC + exportable audit
Role-based access and per-tenant isolation keep partners and clients separated. Every action—scan, copy, verify, delete, stub, skip—is written to an append-only log you can export in full.
What we will never touch.
Before a single file is considered for archiving, ArchiveBridge reads its compliance state from Microsoft Purview through the Graph API. Anything that carries an obligation to keep is removed from the candidate set and recorded—automatically, every run.
Retention labels
Files under a Purview retention label are detected and excluded. They stay exactly where they are.
Legal & eDiscovery holds
Items under a litigation, in-place, or eDiscovery hold are treated as off-limits. The hold is honoured at the source; we do not move data out from under it.
Quarantine, defined
“Quarantined” means the file stays in place, is flagged in the report, and is skipped with its reason logged. Nothing is hidden, moved, or altered—you can see precisely what was held back and why.
On the record
Every skip is written to the audit log with the file path and the reason (e.g. reason=legal-hold), so compliance and legal can check the exclusion list themselves.
Your escape hatch is built in.
Archived and backed-up files sit in standard S3 object format, in a dedicated Wasabi account created for you — with your bucket in it, not a shared pool or a proprietary vault. SharePoint archives can be restored in bulk, protected files can be recovered individually, and the objects remain readable with standard S3 tools. If you ever leave, that Wasabi account is handed over to you. It was never ours to keep.
Provider certifications are not ArchiveBridge certifications. Status labels: Available (in production or the named provider holds it today), In review (an ArchiveBridge attestation currently under auditor engagement), Roadmap (not started).
| Item | Whose | Status |
|---|---|---|
| RackCorp ISO 27001 (regional compute host; Australian sovereign cloud, operating since 2003) | Provider | Available |
| Wasabi ISO 27001 (object storage; A-LIGN, certificate current to June 2028) | Provider | Available |
| Wasabi data centres SOC 2 Type II and PCI-DSS | Provider | Available |
| Supabase ISO 27001 and SOC 2 Type 2 (service metadata database, assessed annually) | Provider | Available |
| ArchiveBridge SOC 2 | ArchiveBridge | Roadmap |
| ArchiveBridge ISO 27001 | ArchiveBridge | Roadmap |
Nothing is currently In review. The controls on this page — least-privilege consent, verify-before-delete, encrypted storage, exportable audit and the paid 90-day-capped compliance-retention option — are in the shipped product and available for your own review.
Send it to your security team.
This page is the whole security model — permissions, data flow, verification and where data is stored. Written to be forwarded to procurement as it stands.
Want the mechanism rather than the controls? How the verify-before-delete sequence works →
Deeper questions? Talk to an engineer. A human replies.