Trust center

Security you can inspect and prove.

Identity is the front door to everything. Here's exactly how HelixIAM is built to protect it — the controls, the standards, and the sovereignty guarantees.

Cryptography you control

  • Per-realm signing keys (KMS / HSM / PKCS#11)
  • Zero-downtime key rotation
  • Argon2id password hashing
  • Keys generated and held where you run

Token security

  • FAPI client policies
  • DPoP sender-constrained tokens (RFC 9449)
  • mTLS certificate-bound tokens
  • PKCE + short-lived, audience-bound tokens

Data & sovereignty

  • Self-hostable — your cloud, on-prem, air-gapped
  • EU data residency
  • No third-party control plane
  • GDPR rights tooling built in

Auditability

  • Persisted, searchable audit log
  • SIEM streaming (HTTP forwarder)
  • HMAC-signed outbound webhooks
  • Full admin-impersonation trail

Access governance

  • Fine-grained admin RBAC
  • Brute-force protection & lockout
  • Password policy + breached-password checks
  • Concurrent-session limits

Standards & interop

  • OAuth 2.1 / OIDC / SAML 2.0
  • WebAuthn / FIDO2 passkeys
  • RFC 8693, RFC 8707, RFC 8628
  • SCIM 2.0 provisioning
Certification roadmap

HelixIAM is built to satisfy FAPI-grade requirements and NL/EU eID assurance. Formal third-party attestations — OpenID Certified & FAPI conformance, SOC 2 / ISO 27001, independent penetration testing and signed releases — are on our roadmap. We'll publish them here as they land, and we're happy to share our current posture, SBOM, and security questionnaire under NDA.

Request our security pack

Put it under the microscope.

Bring your security questionnaire, your architecture, and your hardest questions. We'll walk through the controls on a live system.

No credit card. Self-hostable. Engineered in Europe.