Security

Security begins with clear boundaries

SilverID uses standards-based flows, exact client configuration, isolated environments, secure session handling, and auditable identity activity.

Standards-based flows

Authorization Code, PKCE, OIDC metadata, asymmetric signing keys, and narrow supported grant types.

Controlled clients

Public and confidential client registration with exact redirect and logout URI validation.

Session and token handling

Session fixation protection, HTTP-only cookies, CSRF protection for browser actions, and short-lived access tokens.

Environment isolation

Sandbox and Production configuration, credentials, users, sessions, and activity remain separated.

Auditability

Relevant identity events and outcomes are recorded for review in the management console.

Deployment choice

Use the managed Cloud service or request a private self-hosted deployment when infrastructure control is required.

Accurate by design. SilverID does not claim certifications, guaranteed SLAs, passwordless authentication, SAML, SCIM, or completed MFA capabilities that are not present today.