Security

Security is the product — not a feature

As the system of record for who your people are and what they can do, IdentiQ is built to be the hardest target in your estate. Engineered, hosted and operated entirely from the United Kingdom.

Layered translucent geometric shields protecting a glowing core

Defence in depth

Six layers between attackers and your identities

Every layer independently verified, continuously tested, fully documented.

Encryption Everywhere

AES-256 at rest, TLS 1.3 in transit, EdDSA-signed tokens. Customer keys held in UK-based HSMs with BYOK support.

UK Data Residency

All identity data stored and processed in United Kingdom data centres. No offshore support access, ever.

Certified & Assured

ISO/IEC 27001 certified, Cyber Essentials Plus, SOC 2 Type II and aligned to NCSC Cloud Security Principles.

Continuous Red Team

An internal red team attacks the platform weekly. External penetration tests twice yearly by CREST-accredited firms.

Immutable Audit Trail

Every authentication, authorization and administrative event is cryptographically chained — tamper-evident by design.

Threat-Aware Routing

Live threat intelligence from UK and EU feeds feeds adaptive risk scoring on every identity decision.

Compliance & assurance

Audited to the standards your regulators expect

Evidence packs are generated from live platform telemetry — not assembled manually weeks before an audit.

ISO/IEC 27001

Information security management — certified

SOC 2 Type II

Security, availability & confidentiality — attested

Cyber Essentials Plus

UK government scheme — certified

NCSC CSP 1–13

Cloud Security Principles — aligned

UK GDPR / DPA 2018

Data protection by design — compliant

PSN-ready architecture

Public Services Network patterns — supported

Incident response

When seconds matter, the clock is public

Our incident response commitments, published to every tenant in real time.

0 min

Detection

Automated anomaly detection or customer report opens the incident.

15 min

Triage

On-call security engineer acknowledges and classifies severity.

1 h

Containment

Affected tenants isolated; compromised credentials revoked platform-wide.

24 h

Notification

Affected customers briefed with timeline, impact and remediation steps.

72 h

Resolution

Root-cause analysis published internally; controls updated permanently.

Security researchers: report vulnerabilities through our coordinated disclosure programme.

security@identiq-systems.co.uk

Ready to secure every identity in your organisation?

Join the enterprises that trust IdentiQ to move identity securely between people, applications and organisations.