Security
Security is the product — not a feature
As the system of record for who your people are and what they can do, IdentiQ is built to be the hardest target in your estate. Engineered, hosted and operated entirely from the United Kingdom.
Defence in depth
Six layers between attackers and your identities
Every layer independently verified, continuously tested, fully documented.
Encryption Everywhere
AES-256 at rest, TLS 1.3 in transit, EdDSA-signed tokens. Customer keys held in UK-based HSMs with BYOK support.
UK Data Residency
All identity data stored and processed in United Kingdom data centres. No offshore support access, ever.
Certified & Assured
ISO/IEC 27001 certified, Cyber Essentials Plus, SOC 2 Type II and aligned to NCSC Cloud Security Principles.
Continuous Red Team
An internal red team attacks the platform weekly. External penetration tests twice yearly by CREST-accredited firms.
Immutable Audit Trail
Every authentication, authorization and administrative event is cryptographically chained — tamper-evident by design.
Threat-Aware Routing
Live threat intelligence from UK and EU feeds feeds adaptive risk scoring on every identity decision.
Compliance & assurance
Audited to the standards your regulators expect
Evidence packs are generated from live platform telemetry — not assembled manually weeks before an audit.
ISO/IEC 27001
Information security management — certified
SOC 2 Type II
Security, availability & confidentiality — attested
Cyber Essentials Plus
UK government scheme — certified
NCSC CSP 1–13
Cloud Security Principles — aligned
UK GDPR / DPA 2018
Data protection by design — compliant
PSN-ready architecture
Public Services Network patterns — supported
Incident response
When seconds matter, the clock is public
Our incident response commitments, published to every tenant in real time.
0 min
Detection
Automated anomaly detection or customer report opens the incident.
15 min
Triage
On-call security engineer acknowledges and classifies severity.
1 h
Containment
Affected tenants isolated; compromised credentials revoked platform-wide.
24 h
Notification
Affected customers briefed with timeline, impact and remediation steps.
72 h
Resolution
Root-cause analysis published internally; controls updated permanently.
Security researchers: report vulnerabilities through our coordinated disclosure programme.
security@identiq-systems.co.ukReady to secure every identity in your organisation?
Join the enterprises that trust IdentiQ to move identity securely between people, applications and organisations.