ClientsAssessments

The reason for the client assessment

Our responsibility within the ecosystem involves conducting assessments on our clients, Issuers and Relying Parties, before onboarding them onto our platform. In these assessments, we validate the client's compliance commitment and assess their security and operational readiness. This process is crucial for maintaining the integrity and reliability of our platform, ensuring that the client’s customers can trust us to handle their sensitive information securely.

Establishing this trust is essential. Not only within the ecosystem itself, but also among the client's customers who use our services and encounter our trusted branding in a wide range of identity transactions. To support that trust, it is imperative to clarify the purposes for which sensitive attributes are shared, with whom, and why. This is not only a matter of compliance with regulations, but also of transparency and user empowerment. Customers should always understand what data is being used and have the ability to opt out at any time if necessary.

The eIDAS 2.0 regulation outlines the contours of a Trust Registry, which comprises all the attributes that a client is permitted to access to ensure the provision of its services to its clients. To this end, we assess you as client before you can proceed by using our dashboard.

Client onboarding

Branding

Clients may upload branding logos to our platform that can be used in Authentication, Onboarding or issuance flows facing their customers. It is paramount that the branding and logos in the flows correspond to the correct client in order to instill trust and be compliant to GDPR regulations. In our dashboard, these branding and logos are self-serviced and managed.

We perform a review, automatically enforced, prior to a brand and/or logo can be applied in any flow. A client can have a 'default' logo and brand. As well as multiple brands or logos, for the larger type of organizations. The number of brands and logos are restricted based on the client tier.

Redirect URIs

Clients may set specific Redirect URIs in our platform that can be used in Authentication, Onboarding or issuance flows where their customers are redirected back to in case of success or failure.

OAuth2.1 requires the redirect URI to be specified in order to ensure the correct processing of a request. In our dashboard, the redirect URIs are self-serviced and managed. We perform a review, automatically enforced, prior to a redirect URI can be applied in any flow. A client can have multiple Redirect URIs, the number of URIs are restricted based on the client tier.

On this page