Encryption everywhere
256-bit AES protects data in transit and at rest, end to end.
Security & Trust
ID Network secures identity and access for schools, the public sector and enterprise. Encryption, EU data residency, strong authentication and full auditability are built in at every layer — and backed by one accountable team in Estonia since 1999.
Security posture
The same foundations apply to every deployment, from a single school to a thousand sites.
256-bit AES protects data in transit and at rest, end to end.
Data stays within the European Union — or fully on-premises where required.
Identity activated through secure state eID — Smart-ID, Mobiil-ID and ID-card.
Role-based, least-privilege access across every system.
Every access event logged and exportable as an audit trail.
Built and operated in Estonia by one team, since 1999.
Data protection
01
All traffic and stored data are protected with 256-bit AES encryption, so credentials and personal data are never exposed in the clear.
02
Identities are verified against official data and activated through secure state authentication, so access is tied to a real, verified person.
03
Role-based access control enforces least privilege, while complete event logging turns every door and login into an exportable audit trail.
04
Deployments run on EU infrastructure with EU data residency, or fully on-premises for institutions that require it.
Compliance
ID Network is designed to meet the GDPR and EU data-protection requirements. Personal data stays within the EU, encryption is applied end to end, and a data-processing agreement (DPA) is available for every customer.
Security controls are aligned with recognised information-security practices and reviewed as part of our development process. We're glad to walk procurement and security teams through our architecture and data handling in detail.
ISO 27001 certification is currently in progress.
Responsible disclosure
We welcome reports from security researchers. If you believe you've found a vulnerability, email security@idnetwork.eu. Our security contact is also published, following RFC 9116, at /.well-known/security.txt.
Please give us reasonable time to investigate and remediate before any public disclosure. We will acknowledge your report and keep you informed.
FAQ
Yes. All data is protected with 256-bit AES encryption in transit and at rest.
Within the EU, with EU data residency — or fully on-premises where required.
The platform is designed to meet GDPR and EU data-protection requirements, and a data-processing agreement is provided.
ISO 27001 certification is currently in progress. Our security controls are already aligned with recognised information-security practices and reviewed as part of our development process.
Role-based access control enforces least privilege, and every access event is logged and exportable as an audit trail.
Email security@idnetwork.eu. Our security contact is also published at /.well-known/security.txt, following RFC 9116.
Yes — for institutions that require data and systems to stay on their own infrastructure.
We're happy to walk through our security architecture, data handling and compliance in detail.