Security & Trust

Security is the infrastructure, not a feature

ID Network secures identity and access for schools, the public sector and enterprise. Encryption, EU data residency, strong authentication and full auditability are built in at every layer — and backed by one accountable team in Estonia since 1999.

Security posture

How we keep identity and access secure

The same foundations apply to every deployment, from a single school to a thousand sites.

Encryption everywhere

256-bit AES protects data in transit and at rest, end to end.

EU data residency

Data stays within the European Union — or fully on-premises where required.

Strong authentication

Identity activated through secure state eID — Smart-ID, Mobiil-ID and ID-card.

Access governance

Role-based, least-privilege access across every system.

Full auditability

Every access event logged and exportable as an audit trail.

Accountable partner

Built and operated in Estonia by one team, since 1999.

Data protection

How we protect your data

01

Data in transit and at rest

All traffic and stored data are protected with 256-bit AES encryption, so credentials and personal data are never exposed in the clear.

  • 256-bit AES end to end
  • Encrypted credentials
  • No plaintext personal data

02

Authentication you can trust

Identities are verified against official data and activated through secure state authentication, so access is tied to a real, verified person.

  • State eID: Smart-ID, Mobiil-ID, ID-card
  • Verified against official registries
  • Instant revoke on loss

03

Access governance and audit

Role-based access control enforces least privilege, while complete event logging turns every door and login into an exportable audit trail.

  • Role-based access control
  • Complete event logging
  • Exportable audit trails

04

Where your data lives

Deployments run on EU infrastructure with EU data residency, or fully on-premises for institutions that require it.

  • EU data residency
  • On-premises option
  • Data-processing agreement provided

Compliance

Compliance and data protection

ID Network is designed to meet the GDPR and EU data-protection requirements. Personal data stays within the EU, encryption is applied end to end, and a data-processing agreement (DPA) is available for every customer.

Security controls are aligned with recognised information-security practices and reviewed as part of our development process. We're glad to walk procurement and security teams through our architecture and data handling in detail.

ISO 27001 certification is currently in progress.

Responsible disclosure

Report a vulnerability

We welcome reports from security researchers. If you believe you've found a vulnerability, email security@idnetwork.eu. Our security contact is also published, following RFC 9116, at /.well-known/security.txt.

Please give us reasonable time to investigate and remediate before any public disclosure. We will acknowledge your report and keep you informed.

FAQ

Security questions

Is our data encrypted?

Yes. All data is protected with 256-bit AES encryption in transit and at rest.

Where is our data stored?

Within the EU, with EU data residency — or fully on-premises where required.

Are you GDPR-compliant?

The platform is designed to meet GDPR and EU data-protection requirements, and a data-processing agreement is provided.

Are you ISO 27001 certified?

ISO 27001 certification is currently in progress. Our security controls are already aligned with recognised information-security practices and reviewed as part of our development process.

How is access controlled and audited?

Role-based access control enforces least privilege, and every access event is logged and exportable as an audit trail.

How do we report a security issue?

Email security@idnetwork.eu. Our security contact is also published at /.well-known/security.txt, following RFC 9116.

Can it run fully on-premises?

Yes — for institutions that require data and systems to stay on their own infrastructure.

Security questions? Talk to our team.

We're happy to walk through our security architecture, data handling and compliance in detail.