NewBuild any Microsoft Entra ID attribute without code — conditions, text and date logic, no scripts. See how →
Pillar 01 · Isolated customer data

Your data is kept separate from every other customer’s.

Each organisation’s identity data is held in its own separate store, not mixed in with anyone else’s. Every request is checked against the organisation it belongs to before any data is returned.

  • A separate data store for each customer
  • Every request checked against your organisation
  • Your rules and settings apply to you alone
KEPT SEPARATE, CUSTOMER BY CUSTOMER
Your organisation Data Credentials Settings
Customer B Data Credentials Settings
Customer C Data Credentials Settings

Your data, credentials and settings are held apart from other customers'.

Pillar 02 · Protected credentials

The credentials we use on your behalf are locked away.

The credentials IDFusion uses to connect to your HR system and your Microsoft tenant are held in a dedicated, encrypted credential store for your organisation. They are retrieved only when a task needs them and are never stored in code or configuration files.

  • A dedicated, encrypted credential store for each customer
  • Retrieved only when a task needs them
  • Never stored in code or configuration files
YOUR CREDENTIALS, LOCKED AWAY
HR system credentials encrypted
Microsoft tenant credentials encrypted
Connection settings encrypted

Held in a dedicated store for your organisation and used only when a task needs them.

Pillar 03 · Microsoft-native sign-in

Your team signs in with your own Microsoft identity.

People sign in to IDFusion with their existing Entra ID accounts, so your multi-factor authentication and Conditional Access policies apply. There are no separate IDFusion passwords to issue or reset, and every request is authenticated and tied to your organisation.

  • Sign in with your organisation’s Entra ID
  • Your MFA and Conditional Access policies apply
  • No separate passwords to issue or reset
  • Portal access controlled by roles you assign
EVERY REQUEST, VERIFIED FIRST
RequestYour team, via Entra ID VerifiedYour MFA and policies Your dataYour organisation only

Requests are verified before they reach your data.

Pillar 04 · Complete audit evidence

Evidence for every access decision.

IDFusion records what changed, what caused it and what happened next — from the HR import through to the account and access in Entra ID. When auditors ask who got access and why, you can show them.

  • Change history for every identity
  • Provisioning log for every attempt, including failures
  • Import log for every HR connection
  • An auditor view for compliance reviewers
EXAMPLE AUDIT TRAIL
09:14 New Hire classified Sarah Chen
09:14 Business Role assigned: Senior Engineer Engineering rule
09:15 Account created in Entra ID Sarah Chen
09:15 Business Role synced to Entra ID Senior Engineer
09:55 Access granted by Entra ID Engineering tools package

What changed, what caused it and what happened next.

Pillar 05 · Encrypted and privately networked

Encrypted, privately networked and hosted in Australia.

Data is encrypted in transit and at rest. The data stores behind IDFusion are not reachable from the public internet, and the platform is hosted in Australia on Microsoft Azure.

  • Encrypted in transit and at rest
  • Data stores not reachable from the public internet
  • Hosted in Australia
HOW YOUR DATA IS PROTECTED
In transit Encrypted
At rest Encrypted
Network Not reachable from the public internet
Location Hosted in Australia
Pillar 06 · Disciplined operations

Discipline in how the platform is run.

Production access is restricted, time-bound and logged. The platform is independently penetration tested, with backups and disaster recovery in place. Availability and recovery commitments are set out in your agreement.

  • Production access is restricted, time-bound and logged
  • Independently penetration tested
  • Backups and disaster recovery in place
  • Availability and recovery commitments set out in your agreement
  • Security questionnaires completed on request
HOW THE PLATFORM IS RUN
Production access Restricted, time-bound and logged
Testing Independently penetration tested
Resilience Backups and disaster recovery
Commitments Set out in your agreement
Compliance

Built for the questions your auditors ask.

Our controls are designed to align with SOC 2 and ISO 27001, and we complete security questionnaires on request.

Our controls

Our controls are designed to align with SOC 2 and ISO 27001.

Our infrastructure

Hosted on Microsoft Azure, which holds certifications including ISO 27001, SOC 2 and IRAP.

Who builds it

Built by Increment, a Microsoft Solutions Partner holding designations across every Microsoft Cloud solution area.

Your privacy

Privacy by design — handled in line with the Australian Privacy Principles and, where it applies, the GDPR.

Read our privacy policy →
Next step

Put our security posture in front of your team.

Bring your security or compliance lead to the demo — we'll walk through our controls, the audit evidence and how your data is kept separate. Security questionnaires are completed on request.