Compliance status

Where our certifications actually stand.

We do not hold the certifications a large identity vendor holds. We have started the work to get them, and this page is the running record. It is updated when something moves, not once a year when a buyer asks.

Last updated26 August 2026

Evaluating us and want to be told when an item moves? Ask to be on the update list.

The whole list, including the ones we do not have.

Every row your procurement team is likely to ask about. Where the answer is no, the row says no.

Certification frameworks, their current status, and target dates
FrameworkStatusWhere it actually isTarget
FIDO Functional CertificationServer, not authenticatorIn progressFunctional Certification is the FIDO program that applies to a server. Authenticator Certification levels apply only to authenticator hardware, so no vendor of a login service can hold one. Conformance self-validation is under way.
GovRAMPOur primary SLED targetIn progressCore Verification is the rung that puts a vendor on the Authorized Product List, which your procurement team can look up directly. We are a member today. A Single Security Snapshot is the next step, and we are not on the Authorized Product List.
SOC 2 Type IISecurity and availabilityNot startedNot on our roadmap this year. It is buyable if a specific contract or insurer makes it a condition of award, and we would rather say that than imply a schedule we have not funded.If a contract requires it
CJIS Security PolicyCriminal justice workloadsAsk usRequirements vary by state CSA. If your workload touches CJI, raise it on the first call and we will tell you plainly whether we can serve it today.
Accessibility / VPATSection 508, WCAGNot startedLogin screens are the surface that matters here, and every employee has to use them. No VPAT yet, and the built site has not been independently tested, so we claim no conformance level anywhere.
FedRAMPFederal civilianNot in scopeWe are not selling to federal civilian agencies and will not imply otherwise. If that changes, this row changes first.
CMMCDefense industrial baseNot in scopeOutside the market we serve today.
In place today

What you can verify right now, without waiting for a certificate.

A certification is a third party telling you they checked. Until we have one, we would rather give your team the means to check directly, which is a stronger position anyway and one most vendors cannot offer.

Built on FIDO2 / WebAuthn

The open standard behind passkeys and hardware security keys, not a proprietary scheme you would have to take on trust.

Source is public

Your security team, or an assessor you hire, can read the entire authentication path before you buy anything. No NDA.

A dedicated instance per agency

Nothing your agency depends on is reachable from another customer's environment, because there is not one in it.

Published 800‑63B mapping

Which authenticator types we support at each assurance level, written down so your assessor can check our work.

If you are evaluating us anyway

Three questions worth putting to us, and to everyone else on your list.

We would rather compete on these than on who has the longer badge row.

01

"Can our assessor read your authentication code before we buy?"

Ours is public, so the answer is yes with nothing to arrange. Ask the same of the vendors who do hold certifications and see what comes back.

02

"Who else is in the database our accounts live in?"

Ours: nobody. Most answers to this question are some version of "other customers, separated logically," which is a different risk than it sounds.

03

"What happens to our identity data if we leave you?"

Ours is your database, running open-source software, with a documented export. Exit terms are easiest to negotiate before you sign, and hardest after.

If a missing certification rules us out, that is a fair call.

Some agencies cannot buy from a vendor without a GovRAMP listing, and we would rather you know that on day one than in month four. Tell us your requirement and we will tell you straight whether we can meet it, or when we expect to.