Phishing-resistant, standards-grade identity for every application in the Avalon fabric. FIDO2 passkeys, modern multi-factor authentication, envelope-encrypted token signing and an end-to-end audit trail — OpenID Connect Certified by the OpenID Foundation, operated under ISO/IEC 27001:2022 certification and SOC 2 Type 2 attestation.
Stolen, phished or replayed credentials remain the dominant initial-access vector for confirmed breaches. Traditional password authentication — even with one-time-password multi-factor — is no longer sufficient on its own. Avalon Identity is engineered against the threats that actually matter today.
Attackers replay passwords leaked from unrelated breaches at scale. Any reused password becomes a foothold.
Modern phishing kits proxy the login in real time, harvesting both the password and the one-time code. SMS or app-based one-time-passwords do not stop this.
Browser-resident malware extracts session cookies and refresh tokens, bypassing authentication entirely.
Push-prompt fatigue and SIM-swap fraud erode the protections of legacy second-factor channels.
The blast radius of a compromised identity provider is, by design, the entire customer base — making operator-account hardening and cryptographic-key isolation table stakes.
Without rotating, envelope-encrypted signing keys, anyone who reads the keys can forge tokens for any user.
Eight capabilities, one identity surface. Every capability is engineered against the relevant published standard — OpenID Connect, OAuth 2.0, FIDO2, NIST SP 800-63, OWASP ASVS — and every action is recorded under one of more than seventy structured audit event types.
Phishing-resistant authentication bound to the user’s device. The credential never leaves the device and is rejected by the browser if the origin doesn’t match. Self-service registration and revocation across multiple devices.
Time-based one-time passwords, rate-limited SMS one-time passwords, and single-use backup codes. Consistent enrolment and challenge across every relying-party application.
Argon2id hashing — the Password Hashing Competition winner. Hardened self-service reset, username recovery, password-history enforcement, and silent legacy-hash auto-upgrade.
Authorisation code with PKCE, refresh-token rotation with reuse detection, private-key JWT client authentication, RP-initiated logout, back-channel logout to every connected application, public discovery and JWKS surface.
Token-signing private keys are encrypted with a unique data key, itself wrapped by a key held in Azure Key Vault. Automated 90-day rotation, configurable grace overlap, per-version pinning.
Sign-in, multi-factor challenge, password reset, account self-service — all delivered through a centralised, hardened identity surface with per-tenant branding.
Over seventy structured event types covering login, multi-factor, session, token, scope, consent, logout, password, passkey, signing-key and administrative actions — threaded by a stable correlation identifier.
Role-gated diagnostics console with structured log search, audit-event browse, live signing-key state with full administrative-action history, and structured background-job operations.
The platform is operated under three active third-party certifications — ISO/IEC 27001:2022, SOC 2 Type 2 and OpenID Connect. Other major frameworks — FAPI, CDR, CBUAE, NIST — are engineered to satisfy and ready for downstream certification.
Active information-security management system certification covering Annex A controls — cryptography, access control, evidence collection, secure deletion.
Active attestation covering operating effectiveness across the Trust Services Criteria — logical access, system operations, change management, availability and confidentiality.
Independently certified by the OpenID Foundation across all four submitted conformance profiles — Basic OP, Configuration OP, RP-Initiated Logout, and Back-Channel Logout.
Financial-grade API profile. ES256 supported and aligned with the base obligations; PS256 generation available on demand. Inherits the OpenID Connect baseline.
Schedule 2 information-security controls for the Consumer Data Right. Encryption at rest and in transit, retention exceeding the six-year minimum, OAIC notifiable-breach scheme integrated.
Article 6 cryptographic-key-management obligations under the Central Bank of the UAE’s Open Finance regulation. Two-person integrity for destructive cryptographic actions; 24-hour regulator notification.
Cryptoperiod, key-state taxonomy and key-wrapping algorithms per SP 800-57. Argon2id memorised-secret hashing and FIDO2 Authenticator Assurance Level 2 per SP 800-63B.
Application Security Verification Standard Level 2 controls covering authentication, session management, access control, cryptography, and error handling and logging.
A document covering the full enhancement programme, certification posture, audit-event taxonomy and compliance-evidence pack. Auditor-shareable under NDA.
Request the Brief