ISO 27001 Certified Security Management ISO 27001 Certified Security Management ISO 27001
SOC 2 Type 2 Attested SOC 2 Type 2 Attested SOC 2
OpenID Connect Certified Identity Provider OpenID Connect Certified Identity Provider OpenID
Part of the Avalon Engagement Fabric

Avalon Identity

Phishing-resistant, standards-grade identity for every application in the Avalon fabric. FIDO2 passkeys, modern multi-factor authentication, envelope-encrypted token signing and an end-to-end audit trail — OpenID Connect Certified by the OpenID Foundation, operated under ISO/IEC 27001:2022 certification and SOC 2 Type 2 attestation.

Why this matters

Identity is the most-attacked layer of the modern enterprise.

Stolen, phished or replayed credentials remain the dominant initial-access vector for confirmed breaches. Traditional password authentication — even with one-time-password multi-factor — is no longer sufficient on its own. Avalon Identity is engineered against the threats that actually matter today.

Credential stuffing

Attackers replay passwords leaked from unrelated breaches at scale. Any reused password becomes a foothold.

Adversary-in-the-middle phishing

Modern phishing kits proxy the login in real time, harvesting both the password and the one-time code. SMS or app-based one-time-passwords do not stop this.

Session and token theft

Browser-resident malware extracts session cookies and refresh tokens, bypassing authentication entirely.

Multi-factor fatigue and SIM-swap

Push-prompt fatigue and SIM-swap fraud erode the protections of legacy second-factor channels.

Operator compromise

The blast radius of a compromised identity provider is, by design, the entire customer base — making operator-account hardening and cryptographic-key isolation table stakes.

Forged or replayed tokens

Without rotating, envelope-encrypted signing keys, anyone who reads the keys can forge tokens for any user.

What’s inside

Built for the threat landscape that exists today.

Eight capabilities, one identity surface. Every capability is engineered against the relevant published standard — OpenID Connect, OAuth 2.0, FIDO2, NIST SP 800-63, OWASP ASVS — and every action is recorded under one of more than seventy structured audit event types.

FIDO2 Passkey sign-in

Phishing-resistant authentication bound to the user’s device. The credential never leaves the device and is rejected by the browser if the origin doesn’t match. Self-service registration and revocation across multiple devices.

Multi-channel multi-factor

Time-based one-time passwords, rate-limited SMS one-time passwords, and single-use backup codes. Consistent enrolment and challenge across every relying-party application.

Modern password lifecycle

Argon2id hashing — the Password Hashing Competition winner. Hardened self-service reset, username recovery, password-history enforcement, and silent legacy-hash auto-upgrade.

Standards-grade OpenID Connect

Authorisation code with PKCE, refresh-token rotation with reuse detection, private-key JWT client authentication, RP-initiated logout, back-channel logout to every connected application, public discovery and JWKS surface.

Envelope-encrypted signing keys

Token-signing private keys are encrypted with a unique data key, itself wrapped by a key held in Azure Key Vault. Automated 90-day rotation, configurable grace overlap, per-version pinning.

Hosted login surfaces

Sign-in, multi-factor challenge, password reset, account self-service — all delivered through a centralised, hardened identity surface with per-tenant branding.

Tamper-evident audit trail

Over seventy structured event types covering login, multi-factor, session, token, scope, consent, logout, password, passkey, signing-key and administrative actions — threaded by a stable correlation identifier.

Operator diagnostics

Role-gated diagnostics console with structured log search, audit-event browse, live signing-key state with full administrative-action history, and structured background-job operations.

External assurance

Mapped to every framework that matters to your auditors.

The platform is operated under three active third-party certifications — ISO/IEC 27001:2022, SOC 2 Type 2 and OpenID Connect. Other major frameworks — FAPI, CDR, CBUAE, NIST — are engineered to satisfy and ready for downstream certification.

ISO/IEC 27001:2022

Certified

Active information-security management system certification covering Annex A controls — cryptography, access control, evidence collection, secure deletion.

SOC 2 Type 2

Attested

Active attestation covering operating effectiveness across the Trust Services Criteria — logical access, system operations, change management, availability and confidentiality.

OpenID Connect

Certified

Independently certified by the OpenID Foundation across all four submitted conformance profiles — Basic OP, Configuration OP, RP-Initiated Logout, and Back-Channel Logout.

FAPI 1.0 / 2.0

Engineered for

Financial-grade API profile. ES256 supported and aligned with the base obligations; PS256 generation available on demand. Inherits the OpenID Connect baseline.

Australian CDR

Engineered for

Schedule 2 information-security controls for the Consumer Data Right. Encryption at rest and in transit, retention exceeding the six-year minimum, OAIC notifiable-breach scheme integrated.

CBUAE Open Finance

Engineered for

Article 6 cryptographic-key-management obligations under the Central Bank of the UAE’s Open Finance regulation. Two-person integrity for destructive cryptographic actions; 24-hour regulator notification.

NIST SP 800-57 / 800-63B

Aligned

Cryptoperiod, key-state taxonomy and key-wrapping algorithms per SP 800-57. Argon2id memorised-secret hashing and FIDO2 Authenticator Assurance Level 2 per SP 800-63B.

OWASP ASVS v4

Aligned

Application Security Verification Standard Level 2 controls covering authentication, session management, access control, cryptography, and error handling and logging.

Request the Avalon Identity Executive Brief.

A document covering the full enhancement programme, certification posture, audit-event taxonomy and compliance-evidence pack. Auditor-shareable under NDA.

Request the Brief