We do not hold the certifications a large identity vendor holds. We have started the work to get them, and this page is the running record. It is updated when something moves, not once a year when a buyer asks.
Every row your procurement team is likely to ask about. Where the answer is no, the row says no.
| Framework | Status | Where it actually is | Target |
|---|---|---|---|
| FIDO Functional CertificationServer, not authenticator | In progress | Functional Certification is the FIDO program that applies to a server. Authenticator Certification levels apply only to authenticator hardware, so no vendor of a login service can hold one. Conformance self-validation is under way. | — |
| GovRAMPOur primary SLED target | In progress | Core Verification is the rung that puts a vendor on the Authorized Product List, which your procurement team can look up directly. We are a member today. A Single Security Snapshot is the next step, and we are not on the Authorized Product List. | — |
| SOC 2 Type IISecurity and availability | Not started | Not on our roadmap this year. It is buyable if a specific contract or insurer makes it a condition of award, and we would rather say that than imply a schedule we have not funded. | If a contract requires it |
| CJIS Security PolicyCriminal justice workloads | Ask us | Requirements vary by state CSA. If your workload touches CJI, raise it on the first call and we will tell you plainly whether we can serve it today. | — |
| Accessibility / VPATSection 508, WCAG | Not started | Login screens are the surface that matters here, and every employee has to use them. No VPAT yet, and the built site has not been independently tested, so we claim no conformance level anywhere. | — |
| FedRAMPFederal civilian | Not in scope | We are not selling to federal civilian agencies and will not imply otherwise. If that changes, this row changes first. | — |
| CMMCDefense industrial base | Not in scope | Outside the market we serve today. | — |
A certification is a third party telling you they checked. Until we have one, we would rather give your team the means to check directly, which is a stronger position anyway and one most vendors cannot offer.
The open standard behind passkeys and hardware security keys, not a proprietary scheme you would have to take on trust.
Your security team, or an assessor you hire, can read the entire authentication path before you buy anything. No NDA.
Nothing your agency depends on is reachable from another customer's environment, because there is not one in it.
Which authenticator types we support at each assurance level, written down so your assessor can check our work.
We would rather compete on these than on who has the longer badge row.
Ours is public, so the answer is yes with nothing to arrange. Ask the same of the vendors who do hold certifications and see what comes back.
Ours: nobody. Most answers to this question are some version of "other customers, separated logically," which is a different risk than it sounds.
Ours is your database, running open-source software, with a documented export. Exit terms are easiest to negotiate before you sign, and hardest after.
Some agencies cannot buy from a vendor without a GovRAMP listing, and we would rather you know that on day one than in month four. Tell us your requirement and we will tell you straight whether we can meet it, or when we expect to.